xIanGaLaxY | 18.10.2014 18:49 | Nachdem Windows das Tool eingentlich blockieren wollte hat sich dann Spy Hunter gemeldet....das Tool würde eine Gefahr darstellen.
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-10-2014 01
Ran by Christian (administrator) on CHRISTIAN on 18-10-2014 17:45:02
Running from C:\Users\Christian\Desktop
Loaded Profile: Christian (Available profiles: Christian)
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Fuyu LIMITED) C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
() C:\Program Files (x86)\D-Link\DWA-131\WlanWpsSvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(TeamSpeak Systems GmbH) C:\Users\Christian\AppData\Local\TeamSpeak 3 Client\ts3client_win64.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee Security Scan\3.0.285\SSScheduler.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(D-Link Corp.) C:\Program Files (x86)\D-Link\DWA-131\wirelesscm.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Enigma Software Group USA, LLC.) C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe
(Enigma Software Group USA, LLC.) C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avscan.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-12-06] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [703736 2014-10-14] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-08-01] (Apple Inc.)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [165168 2014-09-23] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-2328503236-1580304465-2670958254-1001\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3600216 2014-09-27] (Electronic Arts)
HKU\S-1-5-21-2328503236-1580304465-2670958254-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-2328503236-1580304465-2670958254-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [22040168 2014-08-27] (Skype Technologies S.A.)
HKU\S-1-5-21-2328503236-1580304465-2670958254-1001\...\Run: [Optimizer Pro] => C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe
HKU\S-1-5-21-2328503236-1580304465-2670958254-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [6482200 2014-09-26] (Piriform Ltd)
HKU\S-1-5-21-2328503236-1580304465-2670958254-1001\...\MountPoints2: {1a2190b1-1513-11e4-826b-d0509914b003} - "F:\setup.exe"
HKU\S-1-5-21-2328503236-1580304465-2670958254-1001\...\MountPoints2: {e3b62d38-c491-11e3-824c-806e6f6e6963} - "D:\AUTORUN.EXE"
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.285\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Wireless Connection Manager.lnk
ShortcutTarget: Wireless Connection Manager.lnk -> C:\Program Files (x86)\D-Link\DWA-131\wirelesscm.exe (D-Link Corp.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://istart.webssearches.com/web/?type=ds&ts=1413578624&from=cvs&uid=WDCXWD10EFRX-68PJCN0_WD-WCC4J178455184551&q={searchTerms}
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x3947A325A158CF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/?type=hp&ts=1413578624&from=cvs&uid=WDCXWD10EFRX-68PJCN0_WD-WCC4J178455184551
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1413578624&from=cvs&uid=WDCXWD10EFRX-68PJCN0_WD-WCC4J178455184551&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1413578624&from=cvs&uid=WDCXWD10EFRX-68PJCN0_WD-WCC4J178455184551
SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1413578624&from=cvs&uid=WDCXWD10EFRX-68PJCN0_WD-WCC4J178455184551&q={searchTerms}
SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1413578624&from=cvs&uid=WDCXWD10EFRX-68PJCN0_WD-WCC4J178455184551&q={searchTerms}
BHO: Skype add-on for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll No File
BHO-x32: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll No File
BHO-x32: Free Download Manager -> {CC59E0F9-7E43-44FA-9FAA-8377850BF205} -> C:\Program Files (x86)\Free Download Manager\iefdm2.dll No File
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll No File
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\bxt9m00m.default
FF NewTab: hxxp://istart.webssearches.com/newtab/?type=nt&ts=1413578624&from=cvs&uid=WDCXWD10EFRX-68PJCN0_WD-WCC4J178455184551
FF DefaultSearchEngine: webssearches
FF SearchEngineOrder.2: google.de
FF SearchEngineOrder.3: Bing
FF SelectedSearchEngine: webssearches
FF Homepage: hxxp://istart.webssearches.com/?type=hp&ts=1413578624&from=cvs&uid=WDCXWD10EFRX-68PJCN0_WD-WCC4J178455184551
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_189.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @esn/npbattlelog,version=2.4.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\webssearches.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Avira Browser Safety - C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\bxt9m00m.default\Extensions\abs@avira.com [2014-08-06]
FF Extension: Fast Start - C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\bxt9m00m.default\Extensions\faststartff@gmail.com [2014-10-17]
FF Extension: Adblock Plus - C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\bxt9m00m.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-04-25]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-06-19]
FF HKLM-x32\...\Firefox\Extensions: [faststartff@gmail.com] - C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\bxt9m00m.default\extensions\faststartff@gmail.com
FF HKCU\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\bxt9m00m.default\extensions\cliqz@cliqz.com
FF StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://istart.webssearches.com/?type=sc&ts=1413578624&from=cvs&uid=WDCXWD10EFRX-68PJCN0_WD-WCC4J178455184551
Chrome:
=======
CHR HomePage: Default -> https://www.youtube.com/
CHR StartupUrls: Default -> "hxxp://youtube.com/", "hxxp://www.mmoga.de/", "hxxp://twitch.tv/", "hxxp://istart.webssearches.com/?type=hp&ts=1413578624&from=cvs&uid=WDCXWD10EFRX-68PJCN0_WD-WCC4J178455184551"
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Christian\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.5.671\_platform_specific\win_x86\widevinecdmadapter.dll No File
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\pdf.dll ()
CHR Plugin: (Battlelog Game Launcher) - C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll (EA Digital Illusions CE AB)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.670.1) - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U67) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll No File
CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll ()
CHR Profile: C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-07-27]
CHR Extension: (Flash Player\t) - C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aopeeahhaaggbnmdifpnjcpcpfndgkkp [2014-10-17]
CHR Extension: (Google Drive) - C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-07-27]
CHR Extension: (Lila Blüten(Non-Aero)) - C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\apifmdobolibbidmcdlofnnenabonodd [2014-10-17]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-05]
CHR Extension: (YouTube) - C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-07-27]
CHR Extension: (Google-Suche) - C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-07-27]
CHR Extension: (Avira Browser Safety) - C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-08-06]
CHR Extension: (Google Wallet) - C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-07-27]
CHR Extension: (Google Mail) - C:\Users\Christian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-07-27]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 70e6ca8c; c:\Program Files (x86)\Optimizer Pro\OptProCrash.dll [3113040 2014-10-17] ()
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-10-14] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-10-14] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [160560 2014-09-23] (Avira Operations GmbH & Co. KG)
S3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [44032 2013-08-22] (Microsoft Corporation)
S3 lfsvc; C:\Windows\SysWOW64\GeofenceMonitorService.dll [357376 2014-03-14] (Microsoft Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.285\McCHSvc.exe [234776 2012-09-05] (McAfee, Inc.)
S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [688640 2014-03-06] (Microsoft Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2014-07-07] ()
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.)
S3 smphost; C:\Windows\SysWOW64\smphost.dll [11776 2013-08-22] (Microsoft Corporation)
R2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [1025408 2014-01-09] (Enigma Software Group USA, LLC.)
S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18944 2013-08-22] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation)
R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [488960 2014-10-17] (Fuyu LIMITED) [File not signed]
R2 WlanWpsSvc; C:\Program Files (x86)\D-Link\DWA-131\WlanWpsSvc.exe [167936 2008-06-26] () [File not signed]
S2 c2cautoupdatesvc; "C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe" /service [X]
S2 c2cpnrsvc; "C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-14] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [131608 2014-10-14] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG)
U3 dtscsidrv; C:\Windows\System32\Drivers\dtscsidrv.sys [309248 2014-07-27] (Disc Soft Ltd)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-07-27] (Disc Soft Ltd)
R3 esgiguard; C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [14872 2014-01-07] ()
U2 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2012-06-22] ()
R3 ISCT; C:\Windows\System32\drivers\ISCTD64.sys [46568 2013-08-07] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-03] (Intel Corporation)
S3 MWAC; \??\C:\Windows\system32\drivers\ [0 ] () [File not signed]
S3 MWAC; \??\C:\Windows\SysWOW64\drivers\ [0 ] () [File not signed]
R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
R3 RtlWlanu; C:\Windows\system32\DRIVERS\rtwlanu.sys [1576080 2012-08-02] (Realtek Semiconductor Corporation )
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [386680 2014-07-27] (Duplex Secure Ltd.)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation)
R3 XSplit_Dummy; C:\Windows\system32\drivers\xspltspk.sys [26200 2014-07-02] (SplitmediaLabs Limited)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-10-18 17:45 - 2014-10-18 17:45 - 00020178 _____ () C:\Users\Christian\Desktop\FRST.txt
2014-10-18 17:44 - 2014-10-18 17:45 - 00000000 ____D () C:\FRST
2014-10-18 17:43 - 2014-10-18 17:43 - 02112000 _____ (Farbar) C:\Users\Christian\Downloads\FRST64.exe
2014-10-18 17:43 - 2014-10-18 17:43 - 02112000 _____ (Farbar) C:\Users\Christian\Desktop\FRST64.exe
2014-10-18 16:30 - 2014-10-18 16:30 - 00000000 _____ () C:\autoexec.bat
2014-10-18 16:29 - 2014-10-18 16:29 - 00003344 _____ () C:\Windows\System32\Tasks\SpyHunter4Startup
2014-10-18 16:29 - 2014-10-18 16:29 - 00000000 ____D () C:\Windows\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP
2014-10-18 16:29 - 2014-10-18 16:29 - 00000000 ____D () C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
2014-10-18 16:29 - 2014-10-18 16:29 - 00000000 ____D () C:\sh4ldr
2014-10-18 16:29 - 2014-10-18 16:29 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-10-18 16:29 - 2012-06-22 11:01 - 00022704 _____ () C:\Windows\system32\Drivers\EsgScanner.sys
2014-10-18 16:28 - 2014-10-18 16:28 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Christian\Downloads\SpyHunter-Installer.exe
2014-10-18 15:32 - 2014-10-18 15:56 - 00006246 _____ () C:\Windows\PFRO.log
2014-10-18 13:32 - 2014-10-18 13:32 - 04117346 _____ () C:\Users\Christian\Downloads\MotioninJoy_071001_signed.zip
2014-10-17 23:54 - 2014-10-17 23:54 - 01125200 _____ () C:\Users\Christian\Downloads\VSDC Free Video Editor - CHIP-Installer.exe
2014-10-17 23:27 - 2014-10-17 23:31 - 388133335 _____ () C:\Users\Christian\Downloads\Sony-Vegas-13-By-Dexter.rar
2014-10-17 23:26 - 2014-10-18 16:26 - 00003194 _____ () C:\Windows\System32\Tasks\SimpleFiles Installer Starter
2014-10-17 23:26 - 2014-10-17 23:26 - 03913960 _____ (New Monte Inc) C:\Users\Christian\Downloads\Sony-Vegas-13-By-Dexter.rar_downloader.exe
2014-10-17 23:18 - 2014-10-17 23:18 - 00000000 ____D () C:\Users\Christian\AppData\Local\StormFall
2014-10-17 23:15 - 2014-10-17 23:21 - 411058696 _____ (Sony Creative Software Inc.) C:\Users\Christian\Downloads\vegaspro13.0.373_64bit_CB-DL-Manager [1].exe
2014-10-17 23:13 - 2014-10-17 23:13 - 00000000 ____D () C:\Users\Christian\AppData\Roaming\Opera Software
2014-10-17 23:13 - 2014-10-17 23:13 - 00000000 ____D () C:\Users\Christian\AppData\Local\Opera Software
2014-10-17 23:12 - 2014-10-17 23:45 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-10-17 23:11 - 2014-10-17 23:11 - 00003456 _____ () C:\Windows\System32\Tasks\WOT WWED1
2014-10-17 23:11 - 2014-10-17 23:11 - 00003456 _____ () C:\Windows\System32\Tasks\WOT WW2
2014-10-17 23:11 - 2014-10-17 23:11 - 00003456 _____ () C:\Windows\System32\Tasks\WOT WW1
2014-10-17 23:11 - 2014-10-17 23:11 - 00003456 _____ () C:\Windows\System32\Tasks\WOT WTUE1
2014-10-17 23:11 - 2014-10-17 23:11 - 00003456 _____ () C:\Windows\System32\Tasks\WOT WTHUR1
2014-10-17 23:11 - 2014-10-17 23:11 - 00003456 _____ () C:\Windows\System32\Tasks\WOT WMON1
2014-10-17 23:11 - 2014-10-17 23:11 - 00003456 _____ () C:\Windows\System32\Tasks\WOT WFRI1
2014-10-17 23:11 - 2014-10-17 23:11 - 00003456 _____ () C:\Windows\System32\Tasks\WOT W2
2014-10-17 23:11 - 2014-10-17 23:11 - 00003456 _____ () C:\Windows\System32\Tasks\WOT W1
2014-10-17 23:11 - 2014-10-17 23:11 - 00003456 _____ () C:\Windows\System32\Tasks\WOT T
2014-10-17 23:11 - 2014-10-17 23:11 - 00000000 ____D () C:\Users\Christian\AppData\Roaming\WorldofTanks
2014-10-17 23:11 - 2014-10-17 23:11 - 00000000 ____D () C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WorldofTanks
2014-10-17 23:10 - 2014-10-17 23:10 - 00816064 _____ ( ) C:\Users\Christian\Downloads\vegaspro13.0.373_64bit_CB-DL-Manager.exe
2014-10-17 23:10 - 2014-10-17 23:10 - 00000000 ____D () C:\Users\Christian\AppData\Local\WorldofTanks
2014-10-17 23:09 - 2014-10-17 23:33 - 00000000 ____D () C:\Users\Christian\AppData\Roaming\Sony
2014-10-17 23:05 - 2014-10-17 23:08 - 335522780 _____ (Sony Creative Software Inc.) C:\Users\Christian\Downloads\vegaspro13.0.373_64bit.exe
2014-10-17 22:56 - 2014-10-17 22:56 - 00000834 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-10-17 22:56 - 2014-10-17 22:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-10-17 22:56 - 2014-10-17 22:56 - 00000000 ____D () C:\Program Files\CCleaner
2014-10-17 22:55 - 2014-10-17 22:55 - 03836936 _____ (Piriform Ltd) C:\Users\Christian\Downloads\ccsetup418_slim.exe
2014-10-17 22:44 - 2014-10-17 22:44 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
2014-10-17 22:42 - 2014-10-17 22:42 - 00616800 _____ () C:\Users\Christian\Downloads\vegaspro12.0.770.exe
2014-10-17 21:51 - 2014-10-17 21:55 - 00000000 ____D () C:\Program Files (x86)\Optimizer Pro
2014-10-17 21:50 - 2014-10-17 21:50 - 00001418 _____ () C:\Users\Public\Desktop\Free Video Editor.lnk
2014-10-17 21:50 - 2014-10-17 21:50 - 00001259 _____ () C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk
2014-10-17 21:50 - 2014-10-17 21:50 - 00000000 ____D () C:\Users\Christian\AppData\Roaming\RHEng
2014-10-17 21:50 - 2014-10-17 21:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2014-10-17 21:50 - 2014-10-17 21:50 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-10-17 21:49 - 2014-10-17 21:51 - 00000000 ____D () C:\Users\Christian\AppData\Roaming\DVDVideoSoft
2014-10-17 21:48 - 2014-10-17 21:48 - 30162808 _____ (DVDVideoSoft Ltd. ) C:\Users\Christian\Downloads\FreeVideo1010Editor (1).exe
2014-10-17 21:21 - 2008-02-11 00:52 - 08913920 _____ () C:\Windows\SysWOW64\mp22.dll
2014-10-17 21:21 - 2006-10-17 22:29 - 00487479 _____ (Appspeed Inc.) C:\Windows\SysWOW64\SkinMagic.dll
2014-10-17 21:19 - 2014-10-17 21:59 - 00000000 ____D () C:\Users\Christian\AppData\Roaming\vlc
2014-10-17 21:18 - 2014-10-17 21:18 - 00001086 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-10-17 21:18 - 2014-10-17 21:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-10-17 21:17 - 2014-10-17 21:17 - 24743106 _____ () C:\Users\Christian\Downloads\vlc-2.1.5-win32.exe
2014-10-17 21:17 - 2014-10-17 21:17 - 04394621 _____ (www.appfree.net ) C:\Users\Christian\Downloads\flv2all.exe
2014-10-17 21:17 - 2014-10-17 21:17 - 00000000 ____D () C:\Program Files (x86)\VideoLAN
2014-10-17 21:13 - 2014-10-17 22:27 - 00000000 ____D () C:\Users\Christian\AppData\Local\Adobe
2014-10-17 21:13 - 2014-10-17 21:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2014-10-17 21:13 - 2014-10-17 21:13 - 00000000 ____D () C:\ProgramData\McAfee Security Scan
2014-10-17 21:13 - 2014-10-17 21:13 - 00000000 ____D () C:\ProgramData\McAfee
2014-10-17 21:13 - 2014-10-17 21:13 - 00000000 ____D () C:\Program Files (x86)\McAfee Security Scan
2014-10-17 13:41 - 2014-03-23 03:11 - 01760768 _____ () C:\Users\Christian\Desktop\SMG.exe
2014-10-17 13:36 - 2014-10-17 13:37 - 15164860 _____ () C:\Users\Christian\Downloads\SMG 1.63 beta.zip
2014-10-17 12:58 - 2014-10-18 14:05 - 00000000 ____D () C:\Users\Christian\AppData\Roaming\OBS
2014-10-17 12:58 - 2014-10-17 12:58 - 07463237 _____ () C:\Users\Christian\Downloads\OBS_0_637b_Installer.exe
2014-10-17 12:58 - 2014-10-17 12:58 - 00000951 _____ () C:\Users\Christian\Desktop\Open Broadcaster Software.lnk
2014-10-17 12:58 - 2014-10-17 12:58 - 00000000 ____D () C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Open Broadcaster Software
2014-10-17 12:58 - 2014-10-17 12:58 - 00000000 ____D () C:\Program Files\OBS
2014-10-17 12:58 - 2014-10-17 12:58 - 00000000 ____D () C:\Program Files (x86)\OBS
2014-10-14 23:11 - 2014-10-14 23:11 - 00000000 ____D () C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dll Suite 2014
2014-10-14 23:11 - 2014-10-14 23:11 - 00000000 ____D () C:\Program Files (x86)\DLLSuite
2014-10-14 23:08 - 2014-10-14 23:11 - 16578402 _____ ( ) C:\Users\Christian\Downloads\DLLSuite_Setup_2013.exe
2014-10-14 23:08 - 2014-09-13 08:29 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-10-14 23:08 - 2014-09-13 07:49 - 00068608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-10-14 23:08 - 2014-09-04 02:12 - 00590336 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2014-10-14 23:08 - 2014-09-04 02:01 - 00514048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
2014-10-14 23:07 - 2014-10-14 23:07 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-10-14 23:07 - 2014-10-14 23:07 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies
2014-10-14 23:07 - 2014-10-10 00:16 - 00678400 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-10-14 23:07 - 2014-10-09 00:09 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-10-14 23:07 - 2014-09-19 03:24 - 00527360 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-10-14 22:39 - 2014-10-14 22:39 - 26728448 _____ () C:\Users\Christian\Downloads\PhysX-9.12.1031-SystemSoftware.msi
2014-10-14 21:48 - 2014-10-17 15:58 - 00000000 ____D () C:\Users\Christian\Documents\BioWare
2014-10-14 19:53 - 2014-10-14 19:57 - 00000000 ____D () C:\Users\Christian\Documents\NFSTR
2014-10-14 19:52 - 2014-10-14 19:52 - 00001354 _____ () C:\Users\Public\Desktop\Need for Speed(TM) The Run.lnk
2014-10-14 19:52 - 2014-10-14 19:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Need for Speed(TM) The Run
2014-10-11 19:23 - 2014-10-18 15:59 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-10-11 19:22 - 2014-10-11 19:22 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Christian\Downloads\mbam-setup-2.0.2.1012.exe
2014-10-11 19:22 - 2014-10-11 19:22 - 00001118 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-10-11 19:22 - 2014-10-11 19:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-10-11 19:22 - 2014-10-11 19:22 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-10-11 19:22 - 2014-10-11 19:22 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-10-11 19:22 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-10-11 19:22 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-10-11 19:22 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-10-11 11:27 - 2014-10-11 11:29 - 00000000 ____D () C:\AdwCleaner
2014-10-11 11:26 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-10-11 11:24 - 2014-10-11 11:25 - 01375089 _____ () C:\Users\Christian\Downloads\adwcleaner_3.311 (2).exe
2014-10-11 11:24 - 2014-10-11 11:24 - 01375089 _____ () C:\Users\Christian\Downloads\adwcleaner_3.311 (1).exe
2014-10-11 10:14 - 2014-10-11 10:14 - 00000000 ____D () C:\Windows\pss
2014-10-05 20:05 - 2014-10-05 20:05 - 06086425 _____ () C:\Users\Christian\Downloads\MW3sa_normal (4).zip
2014-10-05 20:05 - 2013-05-29 16:52 - 00881280 _____ () C:\Users\Christian\Desktop\MW3sa.exe
2014-10-03 13:59 - 2014-10-03 13:59 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-10-03 13:59 - 2014-10-03 13:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-10-01 20:26 - 2014-10-01 20:26 - 00000219 _____ () C:\Users\Christian\Desktop\Counter-Strike Global Offensive.url
2014-09-18 18:36 - 2014-09-30 00:45 - 00706016 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-18 18:36 - 2014-09-30 00:45 - 00105440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-10-18 17:32 - 2014-04-15 13:37 - 01968423 _____ () C:\Windows\WindowsUpdate.log
2014-10-18 17:31 - 2013-08-22 17:20 - 00000000 ____D () C:\Windows\CbsTemp
2014-10-18 17:29 - 2014-04-15 14:25 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-10-18 17:08 - 2014-07-27 18:58 - 00001138 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-10-18 17:07 - 2014-04-15 13:52 - 00003950 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{E46317B7-FE52-44EF-A94D-4892BA3F7843}
2014-10-18 17:00 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\sru
2014-10-18 16:55 - 2014-04-15 19:35 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-10-18 16:42 - 2014-04-15 15:42 - 00000000 ____D () C:\Users\Christian\AppData\Roaming\TS3Client
2014-10-18 16:31 - 2014-04-15 13:42 - 01776918 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-10-18 16:31 - 2013-08-23 01:24 - 00764340 _____ () C:\Windows\system32\perfh007.dat
2014-10-18 16:31 - 2013-08-23 01:24 - 00159160 _____ () C:\Windows\system32\perfc007.dat
2014-10-18 16:30 - 2014-04-15 13:46 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2328503236-1580304465-2670958254-1001
2014-10-18 16:26 - 2014-04-15 13:42 - 00000000 ___DO () C:\Users\Christian\SkyDrive
2014-10-18 16:25 - 2014-07-27 18:58 - 00001134 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-10-18 16:24 - 2013-08-22 16:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-18 15:46 - 2014-08-24 17:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Virtual Audio Cable
2014-10-18 15:37 - 2013-08-22 16:44 - 00363224 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-18 15:36 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-10-18 15:35 - 2013-08-22 17:36 - 00000000 ___RD () C:\Windows\ToastData
2014-10-18 15:35 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\WinStore
2014-10-18 15:35 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\MediaViewer
2014-10-18 15:35 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\FileManager
2014-10-18 15:35 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\Camera
2014-10-18 11:10 - 2014-07-27 18:59 - 00002413 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-10-18 10:56 - 2014-05-01 17:16 - 00033280 ___SH () C:\Users\Christian\Desktop\Thumbs.db
2014-10-18 00:14 - 2014-09-03 17:10 - 00000000 ____D () C:\ProgramData\Sun
2014-10-17 23:34 - 2014-04-15 13:40 - 00000000 ____D () C:\Users\Christian
2014-10-17 23:03 - 2014-07-27 18:58 - 00004110 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-10-17 23:03 - 2014-07-27 18:58 - 00003874 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-10-17 22:58 - 2014-07-27 00:16 - 00000000 ____D () C:\Users\Christian\AppData\Roaming\DAEMON Tools Lite
2014-10-17 22:58 - 2014-05-14 21:36 - 00000000 ____D () C:\Users\Christian\AppData\Roaming\Free Download Manager
2014-10-17 22:57 - 2014-04-15 14:34 - 00000000 ____D () C:\Windows\Panther
2014-10-17 22:43 - 2014-07-27 00:17 - 00001313 _____ () C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-10-17 22:43 - 2014-04-15 14:24 - 00001295 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-10-17 22:43 - 2014-04-15 14:24 - 00001283 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-10-17 22:43 - 2014-04-15 13:41 - 00001233 _____ () C:\Users\Christian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-10-17 22:27 - 2014-04-15 19:35 - 00003772 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-10-17 21:36 - 2014-04-15 13:41 - 00000000 ____D () C:\Users\Christian\AppData\Local\VirtualStore
2014-10-17 17:18 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\rescache
2014-10-17 15:58 - 2014-04-18 16:52 - 00000000 ____D () C:\Program Files (x86)\Origin Games
2014-10-17 14:48 - 2014-07-15 21:27 - 00012305 _____ () C:\Users\Christian\Desktop\Server.odt
2014-10-17 12:50 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\NDF
2014-10-16 17:31 - 2014-06-19 19:00 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-10-16 17:31 - 2014-04-18 16:36 - 00000000 ____D () C:\ProgramData\Origin
2014-10-16 14:18 - 2014-09-12 12:35 - 00001153 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-10-16 14:18 - 2014-04-18 16:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-10-16 14:18 - 2014-04-18 16:31 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-10-16 14:18 - 2014-04-15 13:50 - 00000000 ____D () C:\ProgramData\Package Cache
2014-10-15 16:23 - 2014-04-15 14:10 - 00000000 ____D () C:\Windows\system32\MRT
2014-10-15 16:20 - 2014-04-15 14:10 - 103265616 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-10-15 16:19 - 2014-07-12 23:26 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-10-14 17:16 - 2014-06-19 21:59 - 00000000 ____D () C:\Users\Christian\Documents\My Games
2014-10-14 16:00 - 2014-04-19 18:37 - 00043064 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-10-14 16:00 - 2014-04-18 16:31 - 00131608 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-10-14 16:00 - 2014-04-18 16:31 - 00119272 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-10-14 14:59 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\InputMethod
2014-10-12 19:15 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\AppReadiness
2014-10-11 11:29 - 2014-07-27 18:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-10-11 10:28 - 2014-07-27 00:16 - 00000000 ____D () C:\Program Files (x86)\DAEMON Tools Lite
2014-10-11 10:28 - 2014-07-14 15:07 - 00000000 ____D () C:\Program Files (x86)\WinPcap
2014-10-11 10:27 - 2014-08-24 17:45 - 00000000 ____D () C:\Program Files\Virtual Audio Cable
2014-10-10 22:26 - 2014-04-19 22:09 - 00000000 ____D () C:\Users\Christian\AppData\Roaming\Skype
2014-10-08 20:02 - 2014-05-02 23:19 - 00000000 ____D () C:\Users\Christian\Desktop\Schule
2014-10-03 13:59 - 2014-04-19 22:09 - 00000000 ____D () C:\ProgramData\Skype
Some content of TEMP:
====================
C:\Users\Christian\AppData\Local\Temp\avgnt.exe
C:\Users\Christian\AppData\Local\Temp\optprosetup.exe
C:\Users\Christian\AppData\Local\Temp\SHSetup.exe
C:\Users\Christian\AppData\Local\Temp\SimpleFiles2LBOUmAfaS.exe
C:\Users\Christian\AppData\Local\Temp\SimpleFilesu7yH716i9v.exe
C:\Users\Christian\AppData\Local\Temp\SimpleFilesWU6TtmtKER.exe
C:\Users\Christian\AppData\Local\Temp\SimpleFileswuKfYBqNkg.exe
C:\Users\Christian\AppData\Local\Temp\SimpleFilesXgXl8Fyyuq.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-10-11 20:09
==================== End Of Log ============================ --- --- ---
--- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 18-10-2014 01
Ran by Christian at 2014-10-18 17:45:49
Running from C:\Users\Christian\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.189 - Adobe Systems Incorporated)
AMD Catalyst Control Center (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
Apple Application Support (HKLM-x32\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{6AF2AC2A-3532-43FD-9F4D-BDC9C0D724C7}) (Version: 7.1.2.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Avira (HKLM-x32\...\{9bd9b85e-7792-483b-a318-cc51ff0877ed}) (Version: 1.1.22.50000 - Avira Operations GmbH & Co. KG)
Avira (x32 Version: 1.1.22.50000 - Avira Operations GmbH & Co. KG) Hidden
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.7.306 - Avira)
Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.6.0.0 - Electronic Arts)
Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.4.0 - EA Digital Illusions CE AB)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Call of Duty: Black Ops II - Multiplayer (HKLM-x32\...\Steam App 202990) (Version: - Treyarch)
Call of Duty: Black Ops II - Zombies (HKLM-x32\...\Steam App 212910) (Version: - )
Call of Duty: Black Ops II (HKLM-x32\...\Steam App 202970) (Version: - Treyarch)
Call of Duty: Ghosts - Multiplayer (HKLM-x32\...\Steam App 209170) (Version: - Infinity Ward)
Call of Duty: Ghosts (HKLM-x32\...\Steam App 209160) (Version: - Infinity Ward)
Call of Duty: Modern Warfare 3 - Multiplayer (HKLM-x32\...\Steam App 42690) (Version: - Infinity Ward)
Call of Duty: Modern Warfare 3 (HKLM-x32\...\Steam App 42680) (Version: - Infinity Ward)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center (HKLM-x32\...\{8B1A559A-FB9D-42F5-A8A7-2F132CF28414}) (Version: 1.00.0000 - )
Catalyst Control Center InstallProxy (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (x32 Version: 2013.1206.1602.28764 - Advanced Micro Devices, Inc.) Hidden
ccc-utility64 (Version: 2013.1206.1603.28764 - Advanced Micro Devices, Inc.) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 4.18 - Piriform)
Cliqz (HKLM-x32\...\{5A0C0737-6AFE-4DC6-A8B4-6DFE509ACD75}_is1) (Version: 0.4.1.3 - Cliqz.com)
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve)
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
Dead Island: Epidemic (HKLM-x32\...\Steam App 222900) (Version: - Stunlock Studios)
D-Link DWA-131 Wireless N Nano USB Adapter (HKLM-x32\...\{98B82958-1DCA-4504-BE88-C91F1C7A7225}) (Version: 1 - D-Link)
DLL Suite 2013 (HKLM-x32\...\{885843E7-6CAC-4791-B7BF-1CD516017954}_is1) (Version: - )
Free Download Manager 3.9.4 (HKLM-x32\...\Free Download Manager_is1) (Version: - FreeDownloadManager.ORG)
Free FLV to AVI MP4 3GP WMV MP3 Converter v2.2 (HKLM-x32\...\Free FLV to AVI MP4 3GP WMV MP3 Converter_is1) (Version: 2.0 - www.appfree.net)
Free Video Editor version 1.4.5.1010 (HKLM-x32\...\Free Video Editor_is1) (Version: 1.4.5.1010 - DVDVideoSoft Ltd.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 38.0.2125.104 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.5 - Google Inc.) Hidden
iFunbox (v2.7.2386.747), iFunbox DevTeam (HKLM-x32\...\iFunbox_is1) (Version: v2.7.2386.747 - )
iTunes (HKLM\...\{77DE5105-D05E-448C-96CB-7FA381903753}) (Version: 11.3.1.2 - Apple Inc.)
Just Cause 2: Multiplayer - Dedicated Server (HKLM-x32\...\Steam App 261140) (Version: - )
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games )
League of Legends (x32 Version: 3.0.1 - Riot Games ) Hidden
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
McAfee Security Scan Plus (HKLM-x32\...\McAfee Security Scan) (Version: 3.0.285.6 - McAfee, Inc.)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden
Mozilla Firefox 31.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 31.0 (x86 de)) (Version: 31.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0 - Mozilla)
Need for Speed™ The Run (HKLM-x32\...\{0EDC9BA0-016E-406a-86DA-04FC1BE00C21}) (Version: 1.1.0.0 - Electronic Arts)
NVIDIA PhysX (HKLM-x32\...\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation)
Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version: - )
OpenOffice 4.1.0 (HKLM-x32\...\{E19483E2-6C18-494D-A307-D4498BCFD2C7}) (Version: 4.10.9764 - Apache Software Foundation)
Origin (HKLM-x32\...\Origin) (Version: 9.4.7.2799 - Electronic Arts, Inc.)
Outlast (HKLM-x32\...\Steam App 238320) (Version: - Red Barrels)
Pflanzen gegen Zombies™ (HKLM-x32\...\{5E6536C2-E79A-49CF-83EA-817AD81F9FC8}) (Version: 1.2.0.1093 - Electronic Arts, Inc.)
Skype Click to Call (HKLM-x32\...\{BB285C9F-C821-4770-8970-56C4AB52C87E}) (Version: 7.2.15747.10003 - Microsoft Corporation)
Skype™ 6.20 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.20.104 - Skype Technologies S.A.)
Spec Ops: The Line (HKLM-x32\...\Steam App 50300) (Version: - Yager)
SpyHunter (HKLM\...\{1F7E4FF9-D2E5-4258-9AE1-E16E6CB3252A}) (Version: 4.17.6.4336 - Enigma Software Group USA, LLC)
Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation)
Team Fortress 2 (HKLM-x32\...\Steam App 440) (Version: - Valve)
TeamSpeak 3 Client (HKCU\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH)
TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.27614 - TeamViewer)
Titanfall™ (HKLM-x32\...\{347EE0C3-0690-48F6-A231-53853C2A80D6}) (Version: 1.0.7.2 - Electronic Arts)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN)
WindowsMangerProtect20.0.0.1013 (HKLM-x32\...\WindowsMangerProtect) (Version: 20.0.0.1013 - WindowsProtect LIMITED) <==== ATTENTION
WinPcap 4.1.3 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.)
WinRAR 5.10 beta 2 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.10.2 - win.rar GmbH)
XSplit Gamecaster (HKLM-x32\...\{031899A3-1B82-49FE-A647-345A44515756}) (Version: 1.9.1408.1513 - SplitmediaLabs)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
==================== Restore Points =========================
01-10-2014 19:22:57 Geplanter Prüfpunkt
12-10-2014 17:14:47 DirectX wurde installiert
14-10-2014 15:14:28 DirectX wurde installiert
17-10-2014 20:53:20 TuneUp Utilities 2014 wird entfernt
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask
Task: {08AF38D2-8118-46C5-9D89-88FE88B63C5A} - System32\Tasks\WOT WWED1 => Iexplore.exe hxxp://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/
Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {25CB79C0-66D3-4395-A8A5-EAF073351068} - System32\Tasks\WOT WTHUR1 => Iexplore.exe hxxp://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/
Task: {2AEE0147-F1F5-4D95-A66A-8B93D137553E} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation)
Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation)
Task: {3B77A509-7208-4AE8-BF75-EF1281F1F497} - System32\Tasks\WOT WFRI1 => Iexplore.exe hxxp://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/
Task: {3BB09C4F-E0D2-40A3-B288-44214C6B43CE} - System32\Tasks\WOT WTUE1 => Iexplore.exe hxxp://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/
Task: {43D7E473-E7C7-4C08-BC92-C82A23864804} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network => Sc.exe start wuauserv
Task: {46EEB78B-CAB3-464B-B05A-22F8F597F6F5} - System32\Tasks\WOT WW2 => Iexplore.exe hxxp://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/
Task: {4741009F-FE5E-4511-8FFC-3A249E9A5E3C} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics
Task: {47E783B8-8619-446D-B010-7F3E078F0209} - System32\Tasks\WOT WMON1 => Iexplore.exe hxxp://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/
Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance
Task: {4AF342A5-87FA-4556-AD05-AA766A7AC6F8} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Management
Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup
Task: {6B9F217D-5618-44A7-BA3D-8CAF80F5850E} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe [2014-01-09] (Enigma Software Group USA, LLC.)
Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task
Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {818B4F1F-8365-402F-9248-E0369AD4AFE5} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload
Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task
Task: {8C219260-9F17-4F6D-B32D-0323B155E1CE} - System32\Tasks\WOT WW1 => Iexplore.exe hxxp://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/
Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
Task: {9AE607F6-FC64-4881-8368-3E6296FB899D} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2014-10-15] (Microsoft Corporation)
Task: {9FE6FC03-A523-4B69-9548-3C141011ACC2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-10-17] (Adobe Systems Incorporated)
Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work
Task: {A12B4EAF-AE9D-4878-A311-F3E4138B9069} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-27] (Google Inc.)
Task: {AC81D5E2-BAA2-4F93-A1C4-63A752A72219} - System32\Tasks\WOT W2 => Iexplore.exe hxxp://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/
Task: {B0EA7B21-2379-4DC1-8E1E-A3582C259999} - System32\Tasks\SimpleFiles Installer Starter => C:\Users\Christian\AppData\Local\Temp\SimpleFiles2LBOUmAfaS.exe [2014-10-17] (New Monte Inc) <==== ATTENTION
Task: {B1EB12D0-28B4-4AFA-9A01-5B5B6360DAB3} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Validation
Task: {C89C7B72-18A0-4C80-B16C-B768F38CC7DC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-27] (Google Inc.)
Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask
Task: {D27B9BED-2AF5-480A-8FE8-6A24D65B7B0A} - System32\Tasks\WOT W1 => Iexplore.exe hxxp://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/
Task: {D555FC9D-7710-48E6-A13F-0EB2180015EA} - System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup => C:\Windows\system32\cleanmgr.exe [2014-02-22] (Microsoft Corporation)
Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization
Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE
Task: {FC61C091-5F4D-4545-9253-CF734C4BA166} - System32\Tasks\WOT T => Iexplore.exe hxxp://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Uninstaller_SkipUac_Administrator.job => C:\Users\Christian\Desktop\IObitUninstallerPortable\App\uninstaller\IObitUninstaler.exe
==================== Loaded Modules (whitelisted) =============
2014-05-29 19:27 - 2014-07-07 20:53 - 00076152 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-04-19 12:18 - 2008-06-26 19:09 - 00167936 _____ () C:\Program Files (x86)\D-Link\DWA-131\WlanWpsSvc.exe
2014-02-28 11:14 - 2014-02-28 11:14 - 00173568 _____ () C:\Users\Christian\AppData\Local\TeamSpeak 3 Client\quazip.dll
2014-02-27 16:51 - 2014-02-27 16:51 - 01080832 _____ () C:\Users\Christian\AppData\Local\TeamSpeak 3 Client\platforms\qwindows.dll
2014-02-27 16:51 - 2014-02-27 16:51 - 00833024 _____ () C:\Users\Christian\AppData\Local\TeamSpeak 3 Client\sqldrivers\qsqlite.dll
2014-02-28 15:07 - 2014-02-28 15:07 - 00102344 _____ () C:\Users\Christian\AppData\Local\TeamSpeak 3 Client\soundbackends\directsound_win64.dll
2014-02-28 15:07 - 2014-02-28 15:07 - 00108488 _____ () C:\Users\Christian\AppData\Local\TeamSpeak 3 Client\soundbackends\windowsaudiosession_win64.dll
2014-02-27 16:51 - 2014-02-27 16:51 - 00030208 _____ () C:\Users\Christian\AppData\Local\TeamSpeak 3 Client\imageformats\qgif.dll
2014-02-27 16:51 - 2014-02-27 16:51 - 00233984 _____ () C:\Users\Christian\AppData\Local\TeamSpeak 3 Client\imageformats\qjpeg.dll
2014-02-28 15:10 - 2014-02-28 15:10 - 00563656 _____ () C:\Users\Christian\AppData\Local\TeamSpeak 3 Client\plugins\clientquery_plugin.dll
2014-02-27 16:51 - 2014-02-27 16:51 - 00159232 _____ () C:\Users\Christian\AppData\Local\TeamSpeak 3 Client\accessible\qtaccessiblewidgets.dll
2014-09-25 20:44 - 2014-09-25 20:44 - 00053248 _____ () C:\Program Files\CCleaner\lang\lang-1031.dll
2014-09-12 12:43 - 2014-09-12 12:44 - 00183296 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20605_x64__8wekyb3d8bbwe\ErrorReporting.dll
2014-10-17 21:51 - 2014-10-17 21:51 - 03113040 _____ () c:\Program Files (x86)\Optimizer Pro\OptProCrash.dll
2014-02-12 20:58 - 2014-02-12 20:58 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-02-12 20:58 - 2014-02-12 20:58 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2014-04-19 12:18 - 2011-01-07 14:29 - 00413696 _____ () C:\Program Files (x86)\D-Link\DWA-131\WlanDll.dll
2014-10-18 11:09 - 2014-10-10 04:03 - 01042760 _____ () C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\libglesv2.dll
2014-10-18 11:09 - 2014-10-10 04:03 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\libegl.dll
2014-10-18 11:09 - 2014-10-10 04:04 - 08910664 _____ () C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\pdf.dll
2014-10-18 11:09 - 2014-10-10 04:03 - 01681224 _____ () C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\ffmpegsumo.dll
2014-10-18 11:09 - 2014-10-10 04:04 - 14902600 _____ () C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\PepperFlash\pepflashplayer.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\Users\Christian\SkyDrive:ms-properties
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
HKLM\...\StartupApproved\Run32: => "iTunesHelper"
HKCU\...\StartupApproved\Run: => "EADM"
HKCU\...\StartupApproved\Run: => "Skype"
HKCU\...\StartupApproved\Run: => "Browser Infrastructure Helper"
HKCU\...\StartupApproved\Run: => "Optimizer Pro"
========================= Accounts: ==========================
Administrator (S-1-5-21-2328503236-1580304465-2670958254-500 - Administrator - Disabled)
Christian (S-1-5-21-2328503236-1580304465-2670958254 - Administrator - Enabled)
Gast (S-1-5-21-2328503236-1580304465-2670958254-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2328503236-1580304465-2670958254-1003 - Limited - Enabled)
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (10/18/2014 04:25:21 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: mbamservice.exe, Version: 3.0.2.0, Zeitstempel: 0x5318d363
Name des fehlerhaften Moduls: mbamservice.exe, Version: 3.0.2.0, Zeitstempel: 0x5318d363
Ausnahmecode: 0x40000015
Fehleroffset: 0x0007da8a
ID des fehlerhaften Prozesses: 0x744
Startzeit der fehlerhaften Anwendung: 0xmbamservice.exe0
Pfad der fehlerhaften Anwendung: mbamservice.exe1
Pfad des fehlerhaften Moduls: mbamservice.exe2
Berichtskennung: mbamservice.exe3
Vollständiger Name des fehlerhaften Pakets: mbamservice.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: mbamservice.exe5
Error: (10/18/2014 03:57:34 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: mbamservice.exe, Version: 3.0.2.0, Zeitstempel: 0x5318d363
Name des fehlerhaften Moduls: mbamservice.exe, Version: 3.0.2.0, Zeitstempel: 0x5318d363
Ausnahmecode: 0x40000015
Fehleroffset: 0x0007da8a
ID des fehlerhaften Prozesses: 0x738
Startzeit der fehlerhaften Anwendung: 0xmbamservice.exe0
Pfad der fehlerhaften Anwendung: mbamservice.exe1
Pfad des fehlerhaften Moduls: mbamservice.exe2
Berichtskennung: mbamservice.exe3
Vollständiger Name des fehlerhaften Pakets: mbamservice.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: mbamservice.exe5
Error: (10/18/2014 03:51:11 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: mbamservice.exe, Version: 3.0.2.0, Zeitstempel: 0x5318d363
Name des fehlerhaften Moduls: mbamservice.exe, Version: 3.0.2.0, Zeitstempel: 0x5318d363
Ausnahmecode: 0x40000015
Fehleroffset: 0x0007da8a
ID des fehlerhaften Prozesses: 0xcf4
Startzeit der fehlerhaften Anwendung: 0xmbamservice.exe0
Pfad der fehlerhaften Anwendung: mbamservice.exe1
Pfad des fehlerhaften Moduls: mbamservice.exe2
Berichtskennung: mbamservice.exe3
Vollständiger Name des fehlerhaften Pakets: mbamservice.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: mbamservice.exe5
Error: (10/18/2014 03:49:18 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm backgroundTaskHost.exe, Version 6.3.9600.16384 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 5bc
Startzeit: 01cfead999596dc6
Endzeit: 4294967295
Anwendungspfad: C:\Windows\system32\backgroundTaskHost.exe
Berichts-ID: 8cd69989-56cd-11e4-8288-d0509914b003
Vollständiger Name des fehlerhaften Pakets: Facebook.Facebook_1.4.0.9_x64__8xx8rvfyw5nnt
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: App
Error: (10/18/2014 03:37:40 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: mbamservice.exe, Version: 3.0.2.0, Zeitstempel: 0x5318d363
Name des fehlerhaften Moduls: mbamservice.exe, Version: 3.0.2.0, Zeitstempel: 0x5318d363
Ausnahmecode: 0x40000015
Fehleroffset: 0x0007da8a
ID des fehlerhaften Prozesses: 0x734
Startzeit der fehlerhaften Anwendung: 0xmbamservice.exe0
Pfad der fehlerhaften Anwendung: mbamservice.exe1
Pfad des fehlerhaften Moduls: mbamservice.exe2
Berichtskennung: mbamservice.exe3
Vollständiger Name des fehlerhaften Pakets: mbamservice.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: mbamservice.exe5
Error: (10/18/2014 03:33:40 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: mbamservice.exe, Version: 3.0.2.0, Zeitstempel: 0x5318d363
Name des fehlerhaften Moduls: mbamservice.exe, Version: 3.0.2.0, Zeitstempel: 0x5318d363
Ausnahmecode: 0x40000015
Fehleroffset: 0x0007da8a
ID des fehlerhaften Prozesses: 0x710
Startzeit der fehlerhaften Anwendung: 0xmbamservice.exe0
Pfad der fehlerhaften Anwendung: mbamservice.exe1
Pfad des fehlerhaften Moduls: mbamservice.exe2
Berichtskennung: mbamservice.exe3
Vollständiger Name des fehlerhaften Pakets: mbamservice.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: mbamservice.exe5
Error: (10/18/2014 00:39:10 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 6343
Error: (10/18/2014 00:39:10 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 6343
Error: (10/18/2014 00:39:10 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (10/18/2014 00:39:08 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 5187
System errors:
=============
Error: (10/18/2014 05:21:18 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x800f0922 fehlgeschlagen: Update für Windows 8.1 für x64-Systeme (KB3000988)
Error: (10/18/2014 05:21:18 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x800f0922 fehlgeschlagen: Update für Windows 8.1 für x64-Systeme (KB2984006)
Error: (10/18/2014 05:21:15 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x800f0922 fehlgeschlagen: Kumulatives Sicherheitsupdate für Internet Explorer 11 für Windows 8.1 für x64-Systeme (KB2987107)
Error: (10/18/2014 05:21:15 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x800f0922 fehlgeschlagen: Sicherheitsupdate für Microsoft .NET Framework 4.5.1 und 4.5.2 unter Windows 8.1 und Windows Server 2012 R2 für x64-basierte Systeme (KB2978041)
Error: (10/18/2014 05:21:15 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x800f0922 fehlgeschlagen: Update für Windows 8.1 für x64-Systeme (KB2989542)
Error: (10/18/2014 05:21:15 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x800f0922 fehlgeschlagen: Update für Windows 8.1 für x64-Systeme (KB2998174)
Error: (10/18/2014 05:21:15 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x800f0922 fehlgeschlagen: Sicherheitsupdate für Windows 8.1 für x64-basierte Systeme (KB3000061)
Error: (10/18/2014 04:25:35 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "MBAMService" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (10/18/2014 04:25:03 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Skype Click to Call PNR Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (10/18/2014 04:25:03 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Skype Click to Call Updater" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Microsoft Office Sessions:
=========================
Error: (10/18/2014 04:25:21 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: mbamservice.exe3.0.2.05318d363mbamservice.exe3.0.2.05318d363400000150007da8a74401cfeadf4f5ff91bC:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exeC:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe97355d18-56d2-11e4-828c-d0509914b003
Error: (10/18/2014 03:57:34 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: mbamservice.exe3.0.2.05318d363mbamservice.exe3.0.2.05318d363400000150007da8a73801cfeadb6dec1b4dC:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exeC:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exeb58115bf-56ce-11e4-828a-d0509914b003
Error: (10/18/2014 03:51:11 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: mbamservice.exe3.0.2.05318d363mbamservice.exe3.0.2.05318d363400000150007da8acf401cfeada9379ac98C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exeC:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exed1413362-56cd-11e4-8288-d0509914b003
Error: (10/18/2014 03:49:18 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: backgroundTaskHost.exe6.3.9600.163845bc01cfead999596dc64294967295C:\Windows\system32\backgroundTaskHost.exe8cd69989-56cd-11e4-8288-d0509914b003Facebook.Facebook_1.4.0.9_x64__8xx8rvfyw5nntApp
Error: (10/18/2014 03:37:40 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: mbamservice.exe3.0.2.05318d363mbamservice.exe3.0.2.05318d363400000150007da8a73401cfead8a72460beC:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exeC:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exeeda68ff1-56cb-11e4-8288-d0509914b003
Error: (10/18/2014 03:33:40 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: mbamservice.exe3.0.2.05318d363mbamservice.exe3.0.2.05318d363400000150007da8a71001cfead818990996C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exeC:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe5ec53128-56cb-11e4-8287-d0509914b003
Error: (10/18/2014 00:39:10 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 6343
Error: (10/18/2014 00:39:10 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 6343
Error: (10/18/2014 00:39:10 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (10/18/2014 00:39:08 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 5187
CodeIntegrity Errors:
===================================
Date: 2014-10-18 17:30:35.968
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\Avira\AntiVir Desktop\avscan.exe) attempted to load \Device\HarddiskVolume2\Program Files (x86)\Avira\AntiVir Desktop\avnotify.exe that did not meet the Store signing level requirements.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i5-4570 CPU @ 3.20GHz
Percentage of memory in use: 30%
Total physical RAM: 8111.09 MB
Available physical RAM: 5647.96 MB
Total Pagefile: 9391.09 MB
Available Pagefile: 6412.02 MB
Total Virtual: 131072 MB
Available Virtual: 131071.79 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:931.17 GB) (Free:697.31 GB) NTFS
Drive d: (DWA-131) (CDROM) (Total:0.1 GB) (Free:0 GB) UDF
==================== MBR & Partition Table ==================
==================== End Of Log ============================ Jetzt kommt es so wie es kommen musste...ein Windows Update wird nicht komplett vollzogen und es tritt immer ein Fehler auf, Grund dafür wird wohl ein Virus sein :(( |