Logdatei von AdwCleaner: Code:
# AdwCleaner v3.310 - Bericht erstellt am 13/09/2014 um 13:49:40
# Aktualisiert 12/09/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Kaan Baki - KAANBAKI-PC
# Gestartet von : C:\Users\Kaan Baki\Desktop\AdwCleaner_3.310.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\FilesFrog Update Checker
Ordner Gelöscht : C:\Users\Kaan Baki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker
Datei Gelöscht : C:\windows\System32\roboot64.exe
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\sweetimsetup_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\sweetimsetup_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_fl-studio_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_fl-studio_RASMANCS
Schlüssel Gelöscht : HKCU\Software\APN PIP
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\Somoto
Schlüssel Gelöscht : HKLM\SOFTWARE\PIP
Schlüssel Gelöscht : HKLM\SOFTWARE\Solvusoft
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FilesFrog Update Checker
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17041
-\\ Mozilla Firefox v28.0 (de)
[ Datei : C:\Users\Kaan Baki\AppData\Roaming\Mozilla\Firefox\Profiles\3hy8idis.default\prefs.js ]
-\\ Google Chrome v
[ Datei : C:\Users\Kaan Baki\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [2385 octets] - [13/09/2014 13:48:45]
AdwCleaner[S0].txt - [2110 octets] - [13/09/2014 13:49:40]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2170 octets] ##########
Logdatei von MBAM: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 13.09.2014
Suchlauf-Zeit: 13:56:23
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.09.13.01
Rootkit Datenbank: v2014.09.12.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Kaan Baki
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 343329
Verstrichene Zeit: 9 Min, 11 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 0
(No malicious items detected)
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 0
(No malicious items detected)
Dateien: 0
(No malicious items detected)
Physische Sektoren: 0
(No malicious items detected)
(end)
Logdatei von Zoek: Code:
Zoek.exe v5.0.0.0 Updated 10-September-2014
Tool run by Kaan Baki on 13.09.2014 at 14:25:42.44.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Kaan Baki\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
13.09.2014 14:29:16 Zoek.exe System Restore Point Created Succesfully.
==== FireFox Fix ======================
Deleted from C:\Users\KAANBA~1\AppData\Roaming\Mozilla\Firefox\Profiles\3hy8idis.default\prefs.js:
Added to C:\Users\KAANBA~1\AppData\Roaming\Mozilla\Firefox\Profiles\3hy8idis.default\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.com");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
==== Firefox Extensions ======================
ProfilePath: C:\Users\KAANBA~1\AppData\Roaming\Mozilla\Firefox\Profiles\3hy8idis.default
- Avira Browser Safety - %ProfilePath%\extensions\abs@avira.com
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://www.google.ch/"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
==== Reset Google Chrome ======================
C:\Users\Kaan Baki\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Kaan Baki\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== shortcuts on Users Desktops ======================
C:\Users\Kaan Baki\Desktop\Cheat Engine.lnk - C:\Program Files (x86)\Cheat Engine 6.4\Cheat Engine.exe
C:\Users\Kaan Baki\Desktop\Gw2 Combat mod.lnk - C:\Program Files (x86)\Guild Wars 2\ICM.exe
C:\Users\Kaan Baki\Desktop\Steam.lnk - C:\Program Files (x86)\Steam\Steam.exe
C:\Users\Kaan Baki\Desktop\TeamSpeak 3 Client.lnk - C:\Program Files (x86)\TeamSpeak 3 Client\ts3client_win32.exe
C:\Users\Kaan Baki\Desktop\Dokumente\ASIO4ALL v2 Instruction Manual.lnk - C:\Program Files (x86)\ASIO4ALL v2\ASIO4ALL v2 Instruction Manual.pdf
C:\Users\Kaan Baki\Desktop\Games\Amnesia.lnk - C:\Program Files (x86)\Amnesia - The Dark Descent\redist\Launcher.exe
C:\Users\Kaan Baki\Desktop\Games\Call of Duty(R) 4 - Modern Warfare(TM) - Einzelspieler.lnk - C:\Program Files (x86)\Activision\Call of Duty 4 - Modern Warfare\iw3sp.exe
C:\Users\Kaan Baki\Desktop\Games\Call of Duty(R) 4 - Modern Warfare(TM) - Mehrspieler.lnk - C:\Program Files (x86)\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe
C:\Users\Kaan Baki\Desktop\Games\Counter-Strike Source.lnk - C:\Program Files (x86)\VALVe\Counter-Strike Source\hl2.exe -game cstrike -nojoy
C:\Users\Kaan Baki\Desktop\Games\LogMeIn Hamachi.lnk - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Users\Kaan Baki\Desktop\Games\Play Outlast.lnk - C:\Games\Outlast\Launcher.exe
C:\Users\Kaan Baki\Desktop\Games\Steam.lnk - C:\Program Files (x86)\Steam\Steam.exe
C:\Users\Kaan Baki\Desktop\Games\TeamSpeak 3 Client.lnk - C:\Program Files (x86)\TeamSpeak 3 Client\ts3client_win32.exe
C:\Users\Kaan Baki\Desktop\Games\The Elder Scrolls Online Beta.lnk - C:\Program Files (x86)\Zenimax Online\Launcher\Bethesda.net_Launcher.exe /InstallOrRun "ESO_Beta"
C:\Users\Kaan Baki\Desktop\Games\World of Warcraft.lnk - C:\Program Files (x86)\World of Warcraft\World of Warcraft Launcher.exe
C:\Users\Kaan Baki\Desktop\Games\Arma\ARMA 2 Combined Operations.lnk - C:\Program Files (x86)\Bohemia Interactive\ArmA 2\arma2OA.exe
C:\Users\Kaan Baki\Desktop\Games\Arma\ArmA 2.lnk - C:\Program Files (x86)\Bohemia Interactive\ArmA 2\arma2.exe
C:\Users\Kaan Baki\Desktop\Games\Arma\DayZ Commander.lnk - C:\Program Files (x86)\Dotjosh Studios\DayZ Commander\Current\DayZCommander.exe
==== shortcuts on All Users Desktop ======================
C:\Users\Public\Desktop\Avira.lnk - C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe /showMiniGui
C:\Users\Public\Desktop\Battle.net.lnk - C:\Program Files (x86)\Battle.net\Battle.net Launcher.exe
C:\Users\Public\Desktop\DS3 Tool.lnk - C:\Program Files\MotioninJoy\ds3\DS3_Tool.exe
C:\Users\Public\Desktop\iTunes.lnk - C:\Program Files (x86)\iTunes\iTunes.exe
C:\Users\Public\Desktop\LogMeIn Hamachi.lnk - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
==== shortcuts in Users Start Menu ======================
C:\Users\Kaan Baki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP ENVY 110 series (Netzwerk).lnk -
C:\Users\Kaan Baki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\Benutzerhandbuch für die Konsolenversion von RAR.lnk -
C:\Users\Kaan Baki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\Hilfe zu WinRAR.lnk - C:\Program Files (x86)\WinRAR\WinRAR.chm
C:\Users\Kaan Baki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\Was ist neu in dieser Version.lnk - C:\Program Files (x86)\WinRAR\WhatsNew.txt
C:\Users\Kaan Baki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk - C:\Program Files (x86)\WinRAR\WinRAR.exe
==== shortcuts in All Users Start Menu ======================
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk - C:\Program Files\GIMP 2\bin\gimp-2.8.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\My Avira\Avira.lnk - C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe /showMiniGui
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.4\Cheat Engine 6.4 (32-bit).lnk - C:\Program Files (x86)\Cheat Engine 6.4\cheatengine-i386.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.4\Cheat Engine 6.4 (64-bit).lnk - C:\Program Files (x86)\Cheat Engine 6.4\cheatengine-x86_64.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.4\Cheat Engine 6.4.lnk - C:\Program Files (x86)\Cheat Engine 6.4\Cheat Engine.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.4\Cheat Engine help.lnk - C:\Program Files (x86)\Cheat Engine 6.4\CheatEngine.chm
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.4\Cheat Engine tutorial.lnk - C:\Program Files (x86)\Cheat Engine 6.4\Tutorial-i386.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.4\main.lua.lnk - C:\windows\system32\notepad.exe C:\Program Files (x86)\Cheat Engine 6.4\main.lua
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.4\Reset settings.lnk - C:\Program Files (x86)\Cheat Engine 6.4\ceregreset.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.4\Uninstall Cheat Engine.lnk - C:\Program Files (x86)\Cheat Engine 6.4\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.4\Kernel stuff\Unload kernel module.lnk - C:\Program Files (x86)\Cheat Engine 6.4\Kernelmoduleunloader.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\File Type Advisor\File Type Advisor.lnk - C:\Program Files (x86)\File Type Advisor\fileadvisor.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi\LogMeIn Hamachi.lnk - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi\Uninstall.lnk - C:\windows\SysWOW64\msiexec.exe /i {70B1DA58-A2B9-4EA0-B83D-F03CBEEAE22D} REMOVE=ALL
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Malwarebytes Anti-Malware entfernen.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Malwarebytes Anti-Malware.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Tools\Malwarebytes Anti-Malware Chameleon.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\chameleon.chm
==== shortcuts in Quick Launch ======================
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Kaan Baki\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\DS3 Tool.lnk - C:\Program Files\MotioninJoy\ds3\DS3_Tool.exe
C:\Users\Kaan Baki\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Free M4a to MP3 Converter.lnk - C:\Program Files (x86)\Free M4a to MP3 Converter\m4a_converter.exe
C:\Users\Kaan Baki\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Kaan Baki\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Nero StartSmart Essentials.lnk - C:\Program Files (x86)\Nero\Nero 9\Nero StartSmart\NeroStartSmart.exe
C:\Users\Kaan Baki\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Kaan Baki\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Kaan Baki\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\ArmA 2.lnk - C:\Program Files (x86)\Bohemia Interactive\ArmA 2\arma2.exe
C:\Users\Kaan Baki\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Skype.lnk - C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\Kaan Baki\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Users\Kaan Baki\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Kaan Baki\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Guild Wars 2.lnk - C:\Program Files (x86)\Guild Wars 2\Gw2.exe
C:\Users\Kaan Baki\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\iTunes.lnk - C:\Program Files (x86)\iTunes\iTunes.exe
C:\Users\Kaan Baki\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Skype.lnk - C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\Kaan Baki\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\WildStar.lnk - C:\Program Files (x86)\NCSOFT\WildStar\Wildstar.exe
C:\Users\Kaan Baki\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk - C:\windows\explorer.exe
==== Reset IE Proxy ======================
Value(s) before fix:
"ProxyOverride"="*.local"
"ProxyEnable"=dword:00000000
Value(s) after fix:
"ProxyEnable"=dword:00000000
==== C:\zoek_backup content ======================
C:\zoek_backup (files=0 folders=0 0 bytes)
==== EOF on 13.09.2014 at 14:29:41.29 ======================
Logdatei von FRST:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-09-2014
Ran by Kaan Baki (administrator) on KAANBAKI-PC on 13-09-2014 14:32:25
Running from C:\Users\Kaan Baki\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Ralink Technology, Corp.) C:\Windows\SysWOW64\MotWirelessSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP ENVY 110 series\Bin\ScanToPCActivationApp.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP ENVY 110 series\Bin\HPNetworkCommunicator.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Wireless Service) C:\Program Files (x86)\ANI\ANIWZCS2 Service\WZCSLDR2.exe
(D-Link) C:\Program Files (x86)\D-Link\D-Link Wireless G DWA-110\AirGCFG.exe
(Razer USA Ltd) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP ENVY 110 series\Bin\HPNetworkCommunicator.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Users\Kaan Baki\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Kaan Baki\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Kaan Baki\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Kaan Baki\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Farbar) C:\Users\Kaan Baki\Desktop\FRST64 (1).exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
HKLM\...\Run: [ShadowPlay] => C:\windows\system32\rundll32.exe C:\windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7541976 2014-02-21] (Realtek Semiconductor)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2199840 2014-04-30] (NVIDIA Corporation)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [10464536 2014-07-02] (Logitech Inc.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40312 2014-05-08] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-01-04] (Intel Corporation)
HKLM-x32\...\Run: [ANIWZCS2Service] => C:\Program Files (x86)\ANI\ANIWZCS2 Service\WZCSLDR2.exe [49152 2007-01-19] (Wireless Service)
HKLM-x32\...\Run: [D-Link D-Link Wireless G DWA-110] => C:\Program Files (x86)\D-Link\D-Link Wireless G DWA-110\AirGCFG.exe [1675264 2008-06-23] (D-Link)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [336304 2012-10-11] (Razer USA Ltd)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-03-24] (Hewlett-Packard)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [751184 2014-08-06] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3802448 2014-09-04] (LogMeIn Inc.)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [164656 2014-08-27] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-2731327778-6657166-479201913-1001\...\Run: [HP ENVY 110 series (NET)] => C:\Program Files\HP\HP ENVY 110 series\Bin\ScanToPCActivationApp.exe [2676584 2011-09-19] (Hewlett-Packard Co.)
Startup: C:\Users\Kaan Baki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP ENVY 110 series (Netzwerk).lnk
ShortcutTarget: Tintenwarnungen überwachen - HP ENVY 110 series (Netzwerk).lnk -> C:\Program Files\HP\HP ENVY 110 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.steg-electronics.ch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x0A34E646284DCD01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-CH
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: QUICKfind BHO Object -> {C08DF07A-3E49-4E25-9AB0-D3882835F153} -> C:\Program Files (x86)\IDM\QUICKfind\PlugIns\IEHelp.dll (IDM)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
FireFox:
========
FF ProfilePath: C:\Users\Kaan Baki\AppData\Roaming\Mozilla\Firefox\Profiles\3hy8idis.default
FF NewTab: hxxp://www.google.com/
FF DefaultSearchEngine: Google
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @java.com/DTPlugin,version=10.5.0 -> C:\windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.5.0 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 -> C:\Users\Kaan Baki\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 -> C:\Users\Kaan Baki\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Avira Browser Safety - C:\Users\Kaan Baki\AppData\Roaming\Mozilla\Firefox\Profiles\3hy8idis.default\Extensions\abs@avira.com [2014-08-06]
Chrome:
=======
CHR HomePage: Default -> 9BE51727BF305CC010FB05F4FF58C7BEFFD2462A719261279774927063B56245
CHR DefaultSearchKeyword: Default -> E6AF6D490CDDAEC6139F74AEF5DE087BEAFA4F800A61F3DF98871B6092CB04B7
CHR DefaultSearchProvider: Default -> 893C6AE54022E67CC333653B66952A6ADBB0535B373A083736E61DBF7034263A
CHR DefaultSearchURL: Default -> C3CBFF97FB066D7DD2F0EBE574D37227782591DEC21BFA329D0260BE07D4C183
CHR Profile: C:\Users\Kaan Baki\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Präsentationen) - C:\Users\Kaan Baki\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-13]
CHR Extension: (Google Docs) - C:\Users\Kaan Baki\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-02-23]
CHR Extension: (Google Drive) - C:\Users\Kaan Baki\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-02-23]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Kaan Baki\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-05]
CHR Extension: (YouTube) - C:\Users\Kaan Baki\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-06-08]
CHR Extension: (Google-Suche) - C:\Users\Kaan Baki\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-06-08]
CHR Extension: (Google Tabellen) - C:\Users\Kaan Baki\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-13]
CHR Extension: (Avira Browser Safety) - C:\Users\Kaan Baki\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-08-06]
CHR Extension: (AdBlock) - C:\Users\Kaan Baki\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-04-01]
CHR Extension: (Google Wallet) - C:\Users\Kaan Baki\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-24]
CHR Extension: (Google Mail) - C:\Users\Kaan Baki\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-06-08]
CHR StartMenuInternet: Google Chrome - C:\Users\Kaan Baki\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-08-06] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-08-06] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [160048 2014-08-27] (Avira Operations GmbH & Co. KG)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-07] (Intel Corporation)
R2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2010-08-16] (Hewlett-Packard Company) [File not signed]
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377616 2014-08-08] (LogMeIn, Inc.)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1618888 2014-04-30] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21009352 2014-04-30] (NVIDIA Corporation)
R2 PnkBstrA; C:\windows\SysWOW64\PnkBstrA.exe [66872 2013-10-17] ()
R2 RaAutoInstSrv_Motorola; C:\windows\SysWOW64\MotWirelessSvc.exe [20480 2008-09-11] (Ralink Technology, Corp.) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-07-19] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-06-03] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-19] (Avira Operations GmbH & Co. KG)
S3 LGPBTDD; C:\Windows\System32\Drivers\LGPBTDD.sys [30728 2009-07-01] (Logitech Inc.)
R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19744 2014-04-30] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
S3 USBTINSP; C:\Windows\System32\DRIVERS\tinspusb.sys [142848 2012-06-11] (Texas Instruments)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-13 14:31 - 2014-09-13 14:31 - 00012230 _____ () C:\Users\Kaan Baki\Desktop\zoek-results.txt
2014-09-13 14:28 - 2014-09-13 14:29 - 00012230 _____ () C:\zoek-results.log
2014-09-13 14:25 - 2014-09-13 14:25 - 00000000 ____D () C:\zoek_backup
2014-09-13 14:24 - 2014-09-13 14:24 - 01290240 _____ () C:\Users\Kaan Baki\Downloads\zoek.exe
2014-09-13 14:24 - 2014-09-13 14:24 - 01290240 _____ () C:\Users\Kaan Baki\Desktop\zoek.exe
2014-09-13 14:24 - 2014-09-13 14:24 - 00001162 _____ () C:\Users\Kaan Baki\Desktop\mbam.txt
2014-09-13 13:55 - 2014-09-13 14:22 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-13 13:55 - 2014-09-13 13:55 - 00001105 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-09-13 13:55 - 2014-09-13 13:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-09-13 13:55 - 2014-09-13 13:55 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-13 13:55 - 2014-09-13 13:55 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-09-13 13:55 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-09-13 13:55 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-09-13 13:55 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-09-13 13:52 - 2014-09-13 13:52 - 00002250 _____ () C:\Users\Kaan Baki\Desktop\AdwCleaner[S0].txt
2014-09-13 13:48 - 2014-09-13 13:49 - 00000000 ____D () C:\AdwCleaner
2014-09-13 13:47 - 2014-09-13 13:47 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Kaan Baki\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-13 13:47 - 2014-09-13 13:47 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Kaan Baki\Desktop\mbam-setup-2.0.2.1012.exe
2014-09-13 13:46 - 2014-09-13 13:46 - 01373475 _____ () C:\Users\Kaan Baki\Downloads\AdwCleaner_3.310.exe
2014-09-13 13:46 - 2014-09-13 13:46 - 01373475 _____ () C:\Users\Kaan Baki\Desktop\AdwCleaner_3.310.exe
2014-09-13 13:34 - 2014-09-13 13:34 - 00023138 _____ () C:\ComboFix.txt
2014-09-13 12:50 - 2014-09-13 12:50 - 05577449 ____R (Swearware) C:\Users\Kaan Baki\Desktop\ComboFix.exe
2014-09-13 12:50 - 2014-09-13 12:50 - 05577449 _____ (Swearware) C:\Users\Kaan Baki\Downloads\ComboFix (1).exe
2014-09-13 12:49 - 2014-09-13 13:34 - 00000000 ____D () C:\Qoobox
2014-09-13 12:49 - 2011-06-26 08:45 - 00256000 _____ () C:\windows\PEV.exe
2014-09-13 12:49 - 2010-11-07 19:20 - 00208896 _____ () C:\windows\MBR.exe
2014-09-13 12:49 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe
2014-09-13 12:49 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe
2014-09-13 12:49 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe
2014-09-13 12:49 - 2000-08-31 02:00 - 00098816 _____ () C:\windows\sed.exe
2014-09-13 12:49 - 2000-08-31 02:00 - 00080412 _____ () C:\windows\grep.exe
2014-09-13 12:49 - 2000-08-31 02:00 - 00068096 _____ () C:\windows\zip.exe
2014-09-13 12:48 - 2014-09-13 13:33 - 00000000 ____D () C:\windows\erdnt
2014-09-13 12:48 - 2014-09-13 12:48 - 05577449 ____R (Swearware) C:\Users\Kaan Baki\Downloads\ComboFix.exe
2014-09-13 12:39 - 2014-09-13 14:32 - 00020770 _____ () C:\Users\Kaan Baki\Desktop\FRST.txt
2014-09-13 12:39 - 2014-09-13 12:40 - 00041432 _____ () C:\Users\Kaan Baki\Desktop\Addition.txt
2014-09-13 12:39 - 2014-09-13 12:39 - 02105856 _____ (Farbar) C:\Users\Kaan Baki\Desktop\FRST64 (1).exe
2014-09-13 12:38 - 2014-09-13 12:39 - 02105856 _____ (Farbar) C:\Users\Kaan Baki\Downloads\FRST64 (1).exe
2014-09-13 12:30 - 2014-09-13 14:32 - 00000000 ____D () C:\FRST
2014-09-13 12:30 - 2014-09-13 12:31 - 00041433 _____ () C:\Users\Kaan Baki\Downloads\Addition.txt
2014-09-13 12:30 - 2014-09-13 12:31 - 00036827 _____ () C:\Users\Kaan Baki\Downloads\FRST.txt
2014-09-13 12:29 - 2014-09-13 12:30 - 02105856 _____ (Farbar) C:\Users\Kaan Baki\Downloads\FRST64.exe
2014-09-11 19:05 - 2014-09-11 19:06 - 00000000 ____D () C:\Users\Kaan Baki\Downloads\CS
2014-09-09 22:13 - 2014-09-09 22:13 - 17903792 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerInstaller.exe
2014-09-07 16:30 - 2014-09-07 16:30 - 00000422 _____ () C:\Users\Kaan Baki\Downloads\Nicht bestätigt 739871.crdownload
2014-09-07 16:30 - 2014-09-07 16:30 - 00000422 _____ () C:\Users\Kaan Baki\Downloads\Nicht bestätigt 329934.crdownload
2014-09-07 14:52 - 2014-09-07 14:52 - 00000146 _____ () C:\Users\Kaan Baki\Downloads\server.cfg
2014-09-07 14:50 - 2014-09-07 17:49 - 00000000 ____D () C:\Prophunt server
2014-09-07 14:50 - 2014-09-07 14:50 - 00774825 _____ () C:\Users\Kaan Baki\Downloads\steamcmd.zip
2014-09-05 21:29 - 2014-09-05 21:29 - 00000843 _____ () C:\Users\Kaan Baki\AppData\Local\recently-used.xbel
2014-09-05 21:29 - 2014-09-05 21:29 - 00000000 ____D () C:\Users\Kaan Baki\.thumbnails
2014-09-05 21:26 - 2014-09-05 21:34 - 00000000 ____D () C:\Users\Kaan Baki\.gimp-2.8
2014-09-05 21:26 - 2014-09-05 21:26 - 00000000 ____D () C:\Users\Kaan Baki\AppData\Local\gegl-0.2
2014-09-05 21:25 - 2014-09-05 21:25 - 00000901 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
2014-09-05 21:24 - 2014-09-05 21:25 - 00000000 ____D () C:\Program Files\GIMP 2
2014-09-05 21:22 - 2014-09-05 21:22 - 00961360 _____ (Chip Digital GmbH) C:\Users\Kaan Baki\Downloads\gimp.exe
2014-09-04 17:43 - 2014-09-04 17:43 - 00000933 _____ () C:\Users\Public\Desktop\LogMeIn Hamachi.lnk
2014-09-04 17:43 - 2014-09-04 17:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-09-04 17:43 - 2014-09-04 17:43 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2014-08-30 11:24 - 2014-08-30 11:24 - 00000000 ____D () C:\Users\Kaan Baki\AppData\Local\Adobe
2014-08-26 18:04 - 2014-08-26 18:05 - 00129024 _____ () C:\Users\Kaan Baki\Downloads\Organigramm-JO-Renngruppe 2014 15.xls
2014-08-24 17:48 - 2014-08-24 17:48 - 00000000 __SHD () C:\Users\Kaan Baki\AppData\Local\EmieUserList
2014-08-24 17:48 - 2014-08-24 17:48 - 00000000 __SHD () C:\Users\Kaan Baki\AppData\Local\EmieSiteList
2014-08-24 17:44 - 2014-08-24 17:44 - 00000000 __SHD () C:\ProgramData\SecuROM
2014-08-24 17:16 - 2014-08-24 17:16 - 00000222 _____ () C:\Users\Kaan Baki\Desktop\The Forest.url
2014-08-24 17:14 - 2014-08-24 17:14 - 00000219 _____ () C:\Users\Kaan Baki\Desktop\Counter-Strike Global Offensive.url
2014-08-23 18:15 - 2014-08-23 18:21 - 00000000 ____D () C:\Users\Kaan Baki\Desktop\Hardstyle Hardcore Speedcore
2014-08-23 17:08 - 2014-08-23 17:08 - 00001088 _____ () C:\Users\Kaan Baki\Desktop\Cheat Engine.lnk
2014-08-23 17:08 - 2014-08-23 17:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.4
2014-08-23 17:08 - 2014-08-23 17:08 - 00000000 ____D () C:\Program Files (x86)\Cheat Engine 6.4
2014-08-23 17:07 - 2014-08-23 17:08 - 09052192 _____ (Cheat Engine ) C:\Users\Kaan Baki\Downloads\CheatEngine64.exe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-13 14:32 - 2014-09-13 12:39 - 00020770 _____ () C:\Users\Kaan Baki\Desktop\FRST.txt
2014-09-13 14:32 - 2014-09-13 12:30 - 00000000 ____D () C:\FRST
2014-09-13 14:31 - 2014-09-13 14:31 - 00012230 _____ () C:\Users\Kaan Baki\Desktop\zoek-results.txt
2014-09-13 14:30 - 2009-07-14 06:45 - 00016976 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-13 14:30 - 2009-07-14 06:45 - 00016976 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-13 14:29 - 2014-09-13 14:28 - 00012230 _____ () C:\zoek-results.log
2014-09-13 14:26 - 2012-06-08 11:34 - 00001136 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2731327778-6657166-479201913-1001UA.job
2014-09-13 14:26 - 2012-06-08 11:14 - 02047995 _____ () C:\windows\WindowsUpdate.log
2014-09-13 14:25 - 2014-09-13 14:25 - 00000000 ____D () C:\zoek_backup
2014-09-13 14:24 - 2014-09-13 14:24 - 01290240 _____ () C:\Users\Kaan Baki\Downloads\zoek.exe
2014-09-13 14:24 - 2014-09-13 14:24 - 01290240 _____ () C:\Users\Kaan Baki\Desktop\zoek.exe
2014-09-13 14:24 - 2014-09-13 14:24 - 00001162 _____ () C:\Users\Kaan Baki\Desktop\mbam.txt
2014-09-13 14:22 - 2014-09-13 13:55 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-13 14:21 - 2012-08-13 20:45 - 00000000 ____D () C:\Users\Kaan Baki\AppData\Local\LogMeIn Hamachi
2014-09-13 14:20 - 2012-04-23 18:50 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-09-13 14:20 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-09-13 14:20 - 2009-07-14 06:51 - 00190740 _____ () C:\windows\setupact.log
2014-09-13 14:13 - 2012-04-23 18:48 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-09-13 14:01 - 2012-12-29 17:05 - 00000264 _____ () C:\windows\Tasks\HP Photo Creations Messager.job
2014-09-13 13:55 - 2014-09-13 13:55 - 00001105 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-09-13 13:55 - 2014-09-13 13:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-09-13 13:55 - 2014-09-13 13:55 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-13 13:55 - 2014-09-13 13:55 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-09-13 13:52 - 2014-09-13 13:52 - 00002250 _____ () C:\Users\Kaan Baki\Desktop\AdwCleaner[S0].txt
2014-09-13 13:50 - 2010-11-21 05:47 - 00303560 _____ () C:\windows\PFRO.log
2014-09-13 13:49 - 2014-09-13 13:48 - 00000000 ____D () C:\AdwCleaner
2014-09-13 13:47 - 2014-09-13 13:47 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Kaan Baki\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-13 13:47 - 2014-09-13 13:47 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Kaan Baki\Desktop\mbam-setup-2.0.2.1012.exe
2014-09-13 13:46 - 2014-09-13 13:46 - 01373475 _____ () C:\Users\Kaan Baki\Downloads\AdwCleaner_3.310.exe
2014-09-13 13:46 - 2014-09-13 13:46 - 01373475 _____ () C:\Users\Kaan Baki\Desktop\AdwCleaner_3.310.exe
2014-09-13 13:34 - 2014-09-13 13:34 - 00023138 _____ () C:\ComboFix.txt
2014-09-13 13:34 - 2014-09-13 12:49 - 00000000 ____D () C:\Qoobox
2014-09-13 13:34 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-09-13 13:33 - 2014-09-13 12:48 - 00000000 ____D () C:\windows\erdnt
2014-09-13 13:28 - 2009-07-14 04:34 - 00000215 _____ () C:\windows\system.ini
2014-09-13 13:26 - 2012-11-16 21:05 - 00000000 ____D () C:\Users\Kaan Baki\AppData\Roaming\SoftGrid Client
2014-09-13 13:18 - 2012-08-26 15:37 - 00000000 ____D () C:\Users\Kaan Baki\AppData\Roaming\Skype
2014-09-13 12:50 - 2014-09-13 12:50 - 05577449 ____R (Swearware) C:\Users\Kaan Baki\Desktop\ComboFix.exe
2014-09-13 12:50 - 2014-09-13 12:50 - 05577449 _____ (Swearware) C:\Users\Kaan Baki\Downloads\ComboFix (1).exe
2014-09-13 12:48 - 2014-09-13 12:48 - 05577449 ____R (Swearware) C:\Users\Kaan Baki\Downloads\ComboFix.exe
2014-09-13 12:40 - 2014-09-13 12:39 - 00041432 _____ () C:\Users\Kaan Baki\Desktop\Addition.txt
2014-09-13 12:39 - 2014-09-13 12:39 - 02105856 _____ (Farbar) C:\Users\Kaan Baki\Desktop\FRST64 (1).exe
2014-09-13 12:39 - 2014-09-13 12:38 - 02105856 _____ (Farbar) C:\Users\Kaan Baki\Downloads\FRST64 (1).exe
2014-09-13 12:31 - 2014-09-13 12:30 - 00041433 _____ () C:\Users\Kaan Baki\Downloads\Addition.txt
2014-09-13 12:31 - 2014-09-13 12:30 - 00036827 _____ () C:\Users\Kaan Baki\Downloads\FRST.txt
2014-09-13 12:30 - 2014-09-13 12:29 - 02105856 _____ (Farbar) C:\Users\Kaan Baki\Downloads\FRST64.exe
2014-09-13 02:57 - 2014-03-11 19:06 - 00003518 _____ () C:\windows\System32\Tasks\FileAdvisorCheck
2014-09-13 02:57 - 2014-03-11 19:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\File Type Advisor
2014-09-13 02:57 - 2014-03-11 19:06 - 00000000 ____D () C:\Program Files (x86)\File Type Advisor
2014-09-13 00:25 - 2012-06-08 11:34 - 00001084 _____ () C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2731327778-6657166-479201913-1001Core.job
2014-09-12 23:07 - 2012-07-06 10:16 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-09-12 19:06 - 2012-09-01 23:13 - 00000000 ____D () C:\Users\Kaan Baki\AppData\Roaming\TS3Client
2014-09-12 18:16 - 2012-09-01 23:12 - 00000000 ____D () C:\Program Files (x86)\TeamSpeak 3 Client
2014-09-12 18:15 - 2012-09-01 23:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2014-09-12 18:06 - 2014-03-15 19:06 - 00000000 ____D () C:\Users\Kaan Baki\AppData\Roaming\FileAdvisor
2014-09-11 19:06 - 2014-09-11 19:05 - 00000000 ____D () C:\Users\Kaan Baki\Downloads\CS
2014-09-10 20:40 - 2012-06-08 11:15 - 00062144 _____ () C:\Users\Kaan Baki\AppData\Local\GDIPFONTCACHEV1.DAT
2014-09-10 06:43 - 2014-04-09 22:06 - 00000000 ____D () C:\ProgramData\Package Cache
2014-09-10 06:42 - 2014-08-06 12:58 - 00001144 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-09-10 06:42 - 2013-03-08 14:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-09-10 06:42 - 2013-03-08 14:00 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-09-09 22:13 - 2014-09-09 22:13 - 17903792 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerInstaller.exe
2014-09-09 22:13 - 2012-04-23 18:48 - 00701104 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2014-09-09 22:13 - 2012-04-23 18:48 - 00071344 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-09-09 22:13 - 2012-04-23 18:48 - 00003822 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2014-09-07 17:49 - 2014-09-07 14:50 - 00000000 ____D () C:\Prophunt server
2014-09-07 16:30 - 2014-09-07 16:30 - 00000422 _____ () C:\Users\Kaan Baki\Downloads\Nicht bestätigt 739871.crdownload
2014-09-07 16:30 - 2014-09-07 16:30 - 00000422 _____ () C:\Users\Kaan Baki\Downloads\Nicht bestätigt 329934.crdownload
2014-09-07 14:52 - 2014-09-07 14:52 - 00000146 _____ () C:\Users\Kaan Baki\Downloads\server.cfg
2014-09-07 14:50 - 2014-09-07 14:50 - 00774825 _____ () C:\Users\Kaan Baki\Downloads\steamcmd.zip
2014-09-05 21:38 - 2013-10-14 12:23 - 00369664 ___SH () C:\Users\Kaan Baki\Desktop\Thumbs.db
2014-09-05 21:34 - 2014-09-05 21:26 - 00000000 ____D () C:\Users\Kaan Baki\.gimp-2.8
2014-09-05 21:29 - 2014-09-05 21:29 - 00000843 _____ () C:\Users\Kaan Baki\AppData\Local\recently-used.xbel
2014-09-05 21:29 - 2014-09-05 21:29 - 00000000 ____D () C:\Users\Kaan Baki\.thumbnails
2014-09-05 21:29 - 2012-06-08 11:14 - 00000000 ____D () C:\Users\Kaan Baki
2014-09-05 21:26 - 2014-09-05 21:26 - 00000000 ____D () C:\Users\Kaan Baki\AppData\Local\gegl-0.2
2014-09-05 21:25 - 2014-09-05 21:25 - 00000901 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
2014-09-05 21:25 - 2014-09-05 21:24 - 00000000 ____D () C:\Program Files\GIMP 2
2014-09-05 21:22 - 2014-09-05 21:22 - 00961360 _____ (Chip Digital GmbH) C:\Users\Kaan Baki\Downloads\gimp.exe
2014-09-04 19:53 - 2012-08-05 14:23 - 00000000 ____D () C:\Users\Kaan Baki\AppData\Roaming\.minecraft
2014-09-04 17:43 - 2014-09-04 17:43 - 00000933 _____ () C:\Users\Public\Desktop\LogMeIn Hamachi.lnk
2014-09-04 17:43 - 2014-09-04 17:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-09-04 17:43 - 2014-09-04 17:43 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2014-08-30 11:24 - 2014-08-30 11:24 - 00000000 ____D () C:\Users\Kaan Baki\AppData\Local\Adobe
2014-08-26 18:05 - 2014-08-26 18:04 - 00129024 _____ () C:\Users\Kaan Baki\Downloads\Organigramm-JO-Renngruppe 2014 15.xls
2014-08-24 18:21 - 2012-06-08 11:16 - 00446085 _____ () C:\windows\DirectX.log
2014-08-24 17:48 - 2014-08-24 17:48 - 00000000 __SHD () C:\Users\Kaan Baki\AppData\Local\EmieUserList
2014-08-24 17:48 - 2014-08-24 17:48 - 00000000 __SHD () C:\Users\Kaan Baki\AppData\Local\EmieSiteList
2014-08-24 17:44 - 2014-08-24 17:44 - 00000000 __SHD () C:\ProgramData\SecuROM
2014-08-24 17:16 - 2014-08-24 17:16 - 00000222 _____ () C:\Users\Kaan Baki\Desktop\The Forest.url
2014-08-24 17:16 - 2012-07-12 12:43 - 00000000 ____D () C:\Users\Kaan Baki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2014-08-24 17:14 - 2014-08-24 17:14 - 00000219 _____ () C:\Users\Kaan Baki\Desktop\Counter-Strike Global Offensive.url
2014-08-23 18:21 - 2014-08-23 18:15 - 00000000 ____D () C:\Users\Kaan Baki\Desktop\Hardstyle Hardcore Speedcore
2014-08-23 17:08 - 2014-08-23 17:08 - 00001088 _____ () C:\Users\Kaan Baki\Desktop\Cheat Engine.lnk
2014-08-23 17:08 - 2014-08-23 17:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.4
2014-08-23 17:08 - 2014-08-23 17:08 - 00000000 ____D () C:\Program Files (x86)\Cheat Engine 6.4
2014-08-23 17:08 - 2014-08-23 17:07 - 09052192 _____ (Cheat Engine ) C:\Users\Kaan Baki\Downloads\CheatEngine64.exe
2014-08-22 22:30 - 2012-08-26 15:37 - 00000000 ____D () C:\ProgramData\Skype
2014-08-22 21:51 - 2013-08-02 22:48 - 00000000 ___HD () C:\windows\msdownld.tmp
2014-08-14 13:08 - 2010-11-21 08:50 - 00710336 _____ () C:\windows\system32\perfh007.dat
2014-08-14 13:08 - 2010-11-21 08:50 - 00154514 _____ () C:\windows\system32\perfc007.dat
2014-08-14 13:08 - 2009-07-14 07:13 - 01650972 _____ () C:\windows\system32\PerfStringBackup.INI
Files to move or delete:
====================
C:\Users\Kaan Baki\jagex_cl_oldschool_LIVE.dat
C:\Users\Kaan Baki\jagex_cl_runescape_LIVE.dat
C:\Users\Kaan Baki\jagex_cl_runescape_LIVE_BETA.dat
C:\Users\Kaan Baki\random.dat
Some content of TEMP:
====================
C:\Users\Kaan Baki\AppData\Local\Temp\avgnt.exe
C:\Users\Kaan Baki\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-09-07 14:12
==================== End Of Log ============================ --- --- ---
Addition : Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-09-2014
Ran by Kaan Baki at 2014-09-13 14:33:11
Running from C:\Users\Kaan Baki\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Ableton Live 9 Suite (HKLM\...\{A7C273D4-3F82-4A08-94DC-7492FC151F15}) (Version: 9.0.0.0 - Ableton)
Ace of Spades (HKLM-x32\...\Steam App 224540) (Version: - Jagex Limited)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.9.0.1210 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 3.9.0.1210 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.152 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated)
Adobe Reader X (10.1.11) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.11 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.5.635 - Adobe Systems, Inc.)
Advertising Center (x32 Version: 0.0.0.2 - Nero AG) Hidden
Amnesia - The Dark Descent (HKLM-x32\...\{54B7A3C7-0940-4C16-A509-FC3C3758D22A}_is1) (Version: 1.0.0 - Frictional Games)
Amnesia: A Machine for Pigs (HKLM-x32\...\Amnesia: A Machine for Pigs_is1) (Version: - )
ANIWZCS2 Service (HKLM-x32\...\{4C590030-7469-453E-8589-D15DA9D03F52}) (Version: - )
Apple Application Support (HKLM-x32\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ARMA 2 Operation Arrowhead Uninstall (HKLM-x32\...\ARMA 2 Operation Arrowhead) (Version: - )
ArmA 2 Uninstall (HKLM-x32\...\ArmA 2) (Version: - )
ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.10 - Michael Tippach)
Audacity 2.0.3 (HKLM-x32\...\Audacity_is1) (Version: 2.0.3 - Audacity Team)
Aufstieg des Hexenkönigs™ (HKLM-x32\...\{B931FB80-537A-4600-00AD-AC5DEDB6C25B}) (Version: - )
Avira (HKLM-x32\...\{70e83cd8-4bd5-4039-ab5a-6b94a8abb641}) (Version: 1.1.21.25162 - Avira Operations GmbH & Co. KG)
Avira (x32 Version: 1.1.21.25162 - Avira Operations GmbH & Co. KG) Hidden
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.6.570 - Avira)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
BattlEye for OA Uninstall (HKLM-x32\...\BattlEye for OA) (Version: - )
BattlEye Uninstall (HKLM-x32\...\BattlEye for A2) (Version: - )
Beatport Downloader (HKLM-x32\...\com.beatport.BeatportDownloader) (Version: 1.4 - Beatport LLC)
Beatport Downloader (x32 Version: 1.4 - Beatport LLC) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Borderlands 2 (HKLM-x32\...\Steam App 49520) (Version: - Gearbox Software)
Burnout Paradise: The Ultimate Box (HKLM-x32\...\Steam App 24740) (Version: - Criterion Games)
Call of Duty(R) 4 - Modern Warfare(TM) (HKLM-x32\...\InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}) (Version: 1.00.0000 - Activision)
Call of Duty(R) 4 - Modern Warfare(TM) (x32 Version: 1.00.0000 - Activision) Hidden
Cheat Engine 6.4 (HKLM-x32\...\Cheat Engine 6.4_is1) (Version: - Cheat Engine)
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve)
CSS FULL DZ [Oct 15 2007] v18.1 (HKLM-x32\...\CSS FULL DZ [Oct 15 2007]) (Version: v18.1 - GrCs2Ek~)
Cube World v0.1.0 (FIXED)(5 July 2013) (HKLM-x32\...\Cube World v0.1.0 (FIXED)(5 July 2013)0.1.0) (Version: 0.1.0 - Friends in War)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DayZ (HKLM-x32\...\Steam App 221100) (Version: - Bohemia Interactive)
DayZ Commander (HKLM-x32\...\{D35C30C0-0A42-44C2-BBC9-23431832C89E}) (Version: 0.9.120 - Dotjosh Studios)
Deus Ex: Human Revolution (HKLM-x32\...\Steam App 28050) (Version: - Eidos Montreal)
Diablo III (HKLM-x32\...\Diablo III) (Version: - Blizzard Entertainment)
Die Schlacht um Mittelerde™ II (HKLM-x32\...\{2A9F95AB-65A3-432c-8631-B8BC5BF7477A}) (Version: - )
D-Link Wireless G DWA-110 (HKLM-x32\...\{5F753314-628E-4C13-B8AE-BFA7FD514CBE}) (Version: - D-Link)
DMG Extractor (HKCU\...\DMG Extractor) (Version: 1.1.7.0 - Reincubate Ltd)
Don't Starve (HKLM-x32\...\Steam App 219740) (Version: - )
Far Cry® 3 (HKLM-x32\...\Steam App 220240) (Version: - Ubisoft)
File Type Advisor 1.4 (HKLM-x32\...\File Type Advisor_is1) (Version: - filetypeadvisor.com)
FL Studio 10 (HKLM-x32\...\FL Studio 10) (Version: - Image-Line)
Free M4a to MP3 Converter 8.1 (HKLM-x32\...\Free M4a to MP3 Converter_is1) (Version: - ManiacTools.com)
Free Video to iPhone Converter version 5.0.27.725 (HKLM-x32\...\Free Video to iPhone Converter_is1) (Version: 5.0.27.725 - DVDVideoSoft Ltd.)
Free YouTube to MP3 Converter version 3.12.9.725 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.9.725 - DVDVideoSoft Ltd.)
Garry's Mod (HKLM-x32\...\Steam App 4000) (Version: - Facepunch Studios)
GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team)
Google Chrome (HKCU\...\Google Chrome) (Version: 37.0.2062.120 - Google Inc.)
Grand Theft Auto IV (HKLM-x32\...\Steam App 12210) (Version: - Rockstar North)
Grand Theft Auto: Episodes from Liberty City (HKLM-x32\...\Steam App 12220) (Version: - Rockstar North / Toronto)
GUILD WARS (HKLM-x32\...\Guild Wars) (Version: - )
Guild Wars 2 (HKLM-x32\...\Guild Wars 2) (Version: - )
Gumboy Tournament (HKLM-x32\...\Steam App 11230) (Version: - CINEMAX, s.r.o.)
Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment)
HP ENVY 110 series - Grundlegende Software für das Gerät (HKLM\...\{DC8A4058-3798-4B37-8D78-62624D2E1585}) (Version: 25.0.622.0 - Hewlett-Packard Co.)
HP ENVY 110 series Hilfe (HKLM-x32\...\{D4444B31-E9E9-4389-B35D-41B5BCA5E9FB}) (Version: 140.0.2.2 - Hewlett Packard)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.5192 - HP Photo Creations)
HP Update (HKLM-x32\...\{85DF2EED-08BC-46FB-90DA-28B0D0A8E8A8}) (Version: 5.003.000.004 - Hewlett-Packard)
IL Download Manager (HKLM-x32\...\IL Download Manager) (Version: - Image-Line)
ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden
Infestation: Survivor Stories (HKLM-x32\...\Steam App 226700) (Version: - Hammerpoint Interactive)
Insurgency (HKLM-x32\...\Steam App 222880) (Version: - New World Interactive)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.2.1410 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.0.0.1032 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.1.209 - Intel Corporation)
Intel® Trusted Connect Service Client (HKLM\...\{09536BA1-E498-4CC3-B834-D884A67D7E34}) (Version: 1.23.605.1 - Intel Corporation)
Intel® Watchdog Timer Driver (Intel® WDT) (HKLM-x32\...\{3FD0C489-0F02-481a-A3E1-9754CD396761}) (Version: - Intel Corporation)
Interstellar Marines (HKLM-x32\...\Steam App 236370) (Version: - Zero Point Software)
iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.)
Jade Empire (HKLM-x32\...\{DD401D5B-35E2-4EA4-8585-4A44CB2DCC78}) (Version: - BioWare Corp.)
Java 7 Update 67 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.670 - Oracle)
Java Auto Updater (x32 Version: 2.1.67.1 - Oracle, Inc.) Hidden
Java(TM) 7 Update 5 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417005FF}) (Version: 7.0.50 - Oracle)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Just Cause 2 (HKLM-x32\...\Steam App 8190) (Version: - Avalanche)
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version: - )
Left 4 Dead 2 (HKLM-x32\...\Steam App 550) (Version: - Valve)
LightScribe System Software (HKLM-x32\...\{705B639E-FAAF-40D7-AD58-C445321C7C3F}) (Version: 1.18.18.1 - LightScribe)
Loadout (HKLM-x32\...\Steam App 208090) (Version: - Edge of Reality)
Logitech Gaming Software (Version: 8.45.88 - Logitech Inc.) Hidden
Logitech Gaming Software 5.10 (HKLM\...\{1444D2EE-C7AD-44A8-844F-2634B49353D1}) (Version: 5.10.127 - Logitech)
Logitech Gaming Software 8.53 (HKLM\...\Logitech Gaming Software) (Version: 8.53.186 - Logitech Inc.)
LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.2.0.236 - LogMeIn, Inc.)
LogMeIn Hamachi (x32 Version: 2.2.0.236 - LogMeIn, Inc.) Hidden
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Menu Templates - Starter Kit (x32 Version: 9.6.0.0 - Nero AG) Hidden
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 1.1 (HKLM-x32\...\Microsoft .NET Framework 1.1 (1033)) (Version: - )
Microsoft .NET Framework 1.1 (x32 Version: 1.1.4322 - Microsoft) Hidden
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Games for Windows - LIVE (HKLM-x32\...\{2C9EE786-1DDB-4C98-8FA4-B1B9B5A66B77}) (Version: 3.1.186.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{00C5F4F4-62F9-40D7-8000-AD8A9CD0C669}) (Version: 3.1.99.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{42AA4CA8-DCD8-4308-BCAB-0B6D75856A9D}) (Version: 3.5.95.0 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{B3B750C0-8C22-439D-B7CE-67F3ED99CC2B}) (Version: 1.20.146.0 - Microsoft)
Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
Monaco (HKLM-x32\...\Steam App 113020) (Version: - Pocketwatch Games)
MotioninJoy Gamepad tool 0.7.1001 (HKLM\...\{330DAC67-5B62-452A-A0E4-6B4A5923940F}_is1) (Version: 0.7.1001 - www.motioninjoy.com)
Motorola Wireless USB Card (HKLM-x32\...\{1EEAEAD7-95F3-489C-AB71-D188D530AFFF}) (Version: 1.0.0.0 - Motorola)
Movie Templates - Starter Kit (x32 Version: 9.6.0.0 - Nero AG) Hidden
Mozilla Firefox 28.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Native Instruments Service Center (HKLM-x32\...\Native Instruments Service Center) (Version: - Native Instruments)
Native Instruments Service Center (Version: 2.2.6.676 - Native Instruments) Hidden
Nero 9 Essentials (HKLM-x32\...\{0105ab1a-39cb-456c-af4e-58bbbc9d7f05}) (Version: - Nero AG)
Nero BurnRights (x32 Version: 3.4.13.100 - Nero AG) Hidden
Nero BurnRights Help (x32 Version: 3.4.4.100 - Nero AG) Hidden
Nero ControlCenter (x32 Version: 9.0.0.1 - Nero AG) Hidden
Nero CoverDesigner (x32 Version: 4.4.23.100 - Nero AG) Hidden
Nero DiscSpeed (x32 Version: 5.4.13.100 - Nero AG) Hidden
Nero DriveSpeed (x32 Version: 4.4.12.100 - Nero AG) Hidden
Nero Express Help (x32 Version: 9.4.39.100 - Nero AG) Hidden
Nero InfoTool (x32 Version: 6.4.12.100 - Nero AG) Hidden
Nero Installer (x32 Version: 4.4.9.0 - Nero AG) Hidden
Nero Online Upgrade (x32 Version: 1.3.0.0 - Nero AG) Hidden
Nero ShowTime (x32 Version: 5.4.27.100 - Nero AG) Hidden
Nero StartSmart (x32 Version: 9.4.40.100 - Nero AG) Hidden
Nero StartSmart Help (x32 Version: 9.4.40.100 - Nero AG) Hidden
Nero Vision (x32 Version: 6.4.19.100 - Nero AG) Hidden
Nero Vision Help (x32 Version: 6.4.15.100 - Nero AG) Hidden
NeroExpress (x32 Version: 1.0.0.0 - Nero AG) Hidden
neroxml (x32 Version: 1.0.0 - Nero AG) Hidden
Neverwinter (HKLM-x32\...\Steam App 109600) (Version: - Cryptic Studios)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.1.5 - )
Nur Entfernen der CopyTrans Suite möglich (HKCU\...\CopyTrans Suite) (Version: 2.37 - WindSolutions)
NVIDIA 3D Vision Controller-Treiber 335.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 335.21 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 335.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 335.23 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.0.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.0.1 - NVIDIA Corporation)
NVIDIA Grafiktreiber 335.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 335.23 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.30.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.151.1095 - NVIDIA Corporation) Hidden
NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden
NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.13.1220 - NVIDIA Corporation) Hidden
NVIDIA PhysX-Systemsoftware 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)
NVIDIA ShadowPlay 12.4.67 (Version: 12.4.67 - NVIDIA Corporation) Hidden
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3523 - NVIDIA Corporation) Hidden
NVIDIA Systemsteuerung 335.23 (Version: 335.23 - NVIDIA Corporation) Hidden
NVIDIA Update 12.4.67 (Version: 12.4.67 - NVIDIA Corporation) Hidden
NVIDIA Update Core (Version: 12.4.67 - NVIDIA Corporation) Hidden
NVIDIA Virtual Audio 1.2.23 (Version: 1.2.23 - NVIDIA Corporation) Hidden
Orcs Must Die! (HKLM-x32\...\Steam App 102600) (Version: - )
Orcs Must Die! 2 (HKLM-x32\...\Steam App 201790) (Version: - )
Oxford Advanced Learner's Dictionary - 8th Edition (HKLM-x32\...\NSIS_oald8) (Version: - )
Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.6 - Pando Networks Inc.)
PAYDAY 2 (HKLM-x32\...\Steam App 218620) (Version: - OVERKILL - a Starbreeze Studio.)
PAYDAY: The Heist (HKLM-x32\...\Steam App 24240) (Version: - OVERKILL Software)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.)
QUICKfind server v1.1 (HKLM-x32\...\QUICKfind) (Version: - IDM)
Razer Synapse 2.0 (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.5.18 - Razer USA Ltd.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.49.927.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7183 - Realtek Semiconductor Corp.)
RIFT™ (HKLM-x32\...\Steam App 39120) (Version: - Trion Worlds)
Rise And Fall (remove only) (HKLM-x32\...\Rise And Fall) (Version: 1.7.0.11.2.4.3 - Midway Home Entertainment Inc.)
SHIELD Streaming (Version: 2.1.108 - NVIDIA Corporation) Hidden
Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version: - Firaxis Games)
Skype™ 6.18 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.18.106 - Skype Technologies S.A.)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
Studie zur Verbesserung von HP ENVY 110 series Produkten (HKLM\...\{FC87C2FD-540E-4AB5-807B-D4A172129C73}) (Version: 25.0.622.0 - Hewlett-Packard Co.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.24482 - TeamViewer)
TERA (HKLM-x32\...\{A2F166A0-F031-4E27-A057-C69733219434}_is1) (Version: 7 - Gameforge Productions GmbH)
Terraria (HKLM-x32\...\Steam App 105600) (Version: - Re-Logic)
Test Drive Unlimited 2 (HKLM-x32\...\Steam App 9930) (Version: - Eden Studios)
The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version: - Bethesda Game Studios)
The Forest (HKLM-x32\...\Steam App 242760) (Version: - Endnight Games Ltd)
The Game of Life (HKLM-x32\...\Steam App 224700) (Version: - Virtuos)
The Walking Dead (HKLM-x32\...\Steam App 207610) (Version: - )
Unturned (HKLM-x32\...\Steam App 304930) (Version: - Nelson Sexton)
Uplay (HKLM-x32\...\Uplay) (Version: 2.0 - Ubisoft)
WildStar (HKLM-x32\...\WildStar) (Version: - NCSOFT)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Language Selector (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Messenger Companion Core (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
WinRAR 5.10 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.10.0 - win.rar GmbH)
World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment)
Worms Clan Wars (HKLM-x32\...\Steam App 233840) (Version: - Team17 Digital Ltd)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-2731327778-6657166-479201913-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Kaan Baki\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2731327778-6657166-479201913-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Kaan Baki\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2731327778-6657166-479201913-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Kaan Baki\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2731327778-6657166-479201913-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Kaan Baki\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll No File
==================== Restore Points =========================
07-09-2014 17:00:04 Windows-Sicherung
13-09-2014 10:49:17 ComboFix created restore point
13-09-2014 12:28:58 zoek.exe restore point
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 04:34 - 2014-09-13 13:26 - 00000027 ____A C:\windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {1ACA1FBC-2F29-4C87-9882-59EB9450C92F} - System32\Tasks\FileAdvisorCheck => C:\Program Files (x86)\File Type Advisor\file-type-advisor.exe [2013-09-05] (filetypeadvisor.com )
Task: {20193486-874D-4BFE-98C3-A592A4E3D284} - System32\Tasks\HP Photo Creations Messager => C:\ProgramData\HP Photo Creations\MessageCheck.exe [2011-02-15] ()
Task: {2473AF72-7FD1-48FA-83E8-98C45D83B317} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2731327778-6657166-479201913-1001UA => C:\Users\Kaan Baki\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-08] (Google Inc.)
Task: {380A2651-892F-4DA3-8A79-4CE96FE5616C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {3E86CF97-7298-41EE-B915-ACCF1B569D23} - System32\Tasks\{DD918422-0A50-458B-B3AA-EFE159D317AF} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/abandoninstall?source=lightinstaller&page=tsPlugin
Task: {61F3D99A-0D22-4B41-9773-BCFA8C4FEEE7} - System32\Tasks\{4294F0B2-06E3-446B-B2D1-BF8DD0616C87} => C:\Users\Kaan Baki\Downloads\theme-hospital\Theme Hospital\HOSPITAL.EXE
Task: {73AC89D8-0B4F-4F0B-84C7-69567A0A3FC3} - System32\Tasks\HPCustParticipation HP ENVY 110 series => C:\Program Files\HP\HP ENVY 110 series\Bin\HPCustPartic.exe [2011-09-19] (Hewlett-Packard Co.)
Task: {874A4449-9E76-4F21-AC42-0D5D469A347D} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {8BC1B6B3-A0DF-409A-A9D1-E9D598397550} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-09] (Adobe Systems Incorporated)
Task: {949DAFA0-A30F-42F1-AB9A-462CE0AC3587} - System32\Tasks\{7824BF57-2F15-487A-A73B-6DA0B3038B0C} => C:\Users\Kaan Baki\Desktop\qc1110_x64.exe
Task: {A0E43537-800D-4901-B3F9-BF2D5C05674C} - System32\Tasks\{FB51CA3F-7A34-4600-96EE-A95B51741938} => C:\Users\Kaan Baki\Downloads\theme-hospital\Theme Hospital\HOSPITAL.EXE
Task: {CD0A2970-FA6A-4AC9-860C-54A7FAD724BE} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2731327778-6657166-479201913-1001Core => C:\Users\Kaan Baki\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-08] (Google Inc.)
Task: {D81FD74C-0A8F-4CBD-B56F-726591FC1A36} - System32\Tasks\FileAdvisorUpdate => C:\Program Files (x86)\File Type Advisor\fileadvisor.exe [2013-09-04] (File Type Advisor)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2731327778-6657166-479201913-1001Core.job => C:\Users\Kaan Baki\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2731327778-6657166-479201913-1001UA.job => C:\Users\Kaan Baki\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\HP Photo Creations Messager.job => C:\ProgramData\HP Photo Creations\MessageCheck.exe
==================== Loaded Modules (whitelisted) =============
2012-04-23 18:50 - 2014-03-04 15:05 - 00116056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2013-04-25 11:40 - 2013-10-17 00:33 - 00066872 _____ () C:\windows\SysWOW64\PnkBstrA.exe
2012-06-18 17:24 - 2012-06-18 17:24 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_05.dll
2014-07-02 23:54 - 2014-07-02 23:54 - 00866584 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll
2014-07-02 23:59 - 2014-07-02 23:59 - 01050904 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll
2014-07-02 23:54 - 2014-07-02 23:54 - 00059160 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll
2014-07-02 23:59 - 2014-07-02 23:59 - 00242456 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll
2014-02-12 20:58 - 2014-02-12 20:58 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-02-12 20:58 - 2014-02-12 20:58 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2014-08-27 15:00 - 2014-08-27 15:00 - 00139056 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.NativeCore.dll
2014-08-27 15:00 - 2014-08-27 15:00 - 00066864 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.AvConnectorNative.dll
2014-09-13 13:51 - 2014-08-27 15:00 - 00052472 _____ () C:\Users\Kaan Baki\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
2014-02-19 15:58 - 2014-02-19 15:58 - 00172032 _____ () C:\windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\b162055347700182d96325676dd591c4\IsdiInterop.ni.dll
2012-04-23 18:42 - 2011-11-29 20:00 - 00059392 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2012-04-23 18:41 - 2012-02-07 17:39 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2014-09-12 23:31 - 2014-09-04 05:01 - 01098056 _____ () C:\Users\Kaan Baki\AppData\Local\Google\Chrome\Application\37.0.2062.120\libglesv2.dll
2014-09-12 23:31 - 2014-09-04 05:01 - 00174408 _____ () C:\Users\Kaan Baki\AppData\Local\Google\Chrome\Application\37.0.2062.120\libegl.dll
2014-09-12 23:31 - 2014-09-04 05:01 - 08577864 _____ () C:\Users\Kaan Baki\AppData\Local\Google\Chrome\Application\37.0.2062.120\pdf.dll
2014-09-12 23:31 - 2014-09-04 05:01 - 00331592 _____ () C:\Users\Kaan Baki\AppData\Local\Google\Chrome\Application\37.0.2062.120\ppGoogleNaClPluginChrome.dll
2014-09-12 23:31 - 2014-09-04 05:01 - 01660232 _____ () C:\Users\Kaan Baki\AppData\Local\Google\Chrome\Application\37.0.2062.120\ffmpegsumo.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service"
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
MSCONFIG\Services: Steam Client Service => 3
MSCONFIG\startupreg: KiesTrayAgent => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
MSCONFIG\startupreg: LightScribe Control Panel => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
MSCONFIG\startupreg: LogMeIn Hamachi Ui => "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\Steam.exe" -silent
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (09/13/2014 02:21:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/13/2014 01:52:55 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/13/2014 01:51:31 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: svchost.exe_stisvc, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc3c1
Name des fehlerhaften Moduls: wiaservc.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7ca0f
Ausnahmecode: 0x40000015
Fehleroffset: 0x0000000000047a6b
ID des fehlerhaften Prozesses: 0xa60
Startzeit der fehlerhaften Anwendung: 0xsvchost.exe_stisvc0
Pfad der fehlerhaften Anwendung: svchost.exe_stisvc1
Pfad des fehlerhaften Moduls: svchost.exe_stisvc2
Berichtskennung: svchost.exe_stisvc3
Error: (09/13/2014 01:50:18 PM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) (EventID: 1) (User: )
Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008]
Error: (09/13/2014 01:29:09 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/12/2014 11:07:06 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm csgo.exe, Version 0.0.0.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 2744
Startzeit: 01cfcec7f32ad1ad
Endzeit: 175
Anwendungspfad: C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
Berichts-ID:
Error: (09/12/2014 10:19:31 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm csgo.exe, Version 0.0.0.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 634
Startzeit: 01cfcebc9f322683
Endzeit: 167
Anwendungspfad: C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
Berichts-ID:
Error: (09/12/2014 06:51:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 10016
Error: (09/12/2014 06:51:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 10016
Error: (09/12/2014 06:51:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
System errors:
=============
Error: (09/13/2014 02:19:10 PM) (Source: Service Control Manager) (EventID: 7016) (User: )
Description: Der Dienst "Motorola Wireless Service" hat einen ungültigen aktuellen Status gemeldet: 0
Error: (09/13/2014 01:56:44 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "Windows Update" wurde nicht richtig gestartet.
Error: (09/13/2014 01:51:44 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Windows-Bilderfassung (WIA)" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (09/13/2014 01:50:19 PM) (Source: Service Control Manager) (EventID: 7016) (User: )
Description: Der Dienst "Motorola Wireless Service" hat einen ungültigen aktuellen Status gemeldet: 0
Error: (09/13/2014 01:33:47 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "Windows Update" wurde nicht richtig gestartet.
Error: (09/13/2014 01:26:31 PM) (Source: Service Control Manager) (EventID: 7016) (User: )
Description: Der Dienst "Motorola Wireless Service" hat einen ungültigen aktuellen Status gemeldet: 0
Error: (09/13/2014 01:26:13 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (09/13/2014 01:25:49 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: Aufgrund der Inkompatibilität mit diesem System wurde \??\C:\ComboFix\catchme.sys nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten.
Error: (09/13/2014 01:19:31 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (09/13/2014 01:00:24 PM) (Source: Service Control Manager) (EventID: 7016) (User: )
Description: Der Dienst "Motorola Wireless Service" hat einen ungültigen aktuellen Status gemeldet: 0
Microsoft Office Sessions:
=========================
Error: (09/13/2014 02:21:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/13/2014 01:52:55 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/13/2014 01:51:31 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: svchost.exe_stisvc6.1.7600.163854a5bc3c1wiaservc.dll6.1.7601.175144ce7ca0f400000150000000000047a6ba6001cfcf4904968901C:\windows\system32\svchost.exec:\windows\system32\wiaservc.dll4d4912d3-3b3c-11e4-89d5-c86000c310fd
Error: (09/13/2014 01:50:18 PM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) (EventID: 1) (User: )
Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008]
Error: (09/13/2014 01:29:09 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/12/2014 11:07:06 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: csgo.exe0.0.0.0274401cfcec7f32ad1ad175C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
Error: (09/12/2014 10:19:31 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: csgo.exe0.0.0.063401cfcebc9f322683167C:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
Error: (09/12/2014 06:51:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 10016
Error: (09/12/2014 06:51:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 10016
Error: (09/12/2014 06:51:47 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
CodeIntegrity Errors:
===================================
Date: 2014-09-13 13:25:49.971
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-09-13 13:25:49.921
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i7-3770 CPU @ 3.40GHz
Percentage of memory in use: 32%
Total physical RAM: 8147.59 MB
Available physical RAM: 5516 MB
Total Pagefile: 16293.36 MB
Available Pagefile: 13459.07 MB
Total Virtual: 8192 MB
Available Virtual: 8191.85 MB
==================== Drives ================================
Drive c: (Windows) (Fixed) (Total:906.61 GB) (Free:365.45 GB) NTFS ==>[System with boot components (obtained from reading drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 76C436AD)
Partition 1: (Active) - (Size=500 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=24.4 GB) - (Type=27)
Partition 3: (Not Active) - (Size=906.6 GB) - (Type=07 NTFS)
==================== End Of Log ============================
Gruss Cemiboy |