hallo schrauber hier die logs, und vielen dank für deinen einsatz während der feiertage, finde ich richtig nett hoffentlich hattest du schon deinen :kaffee: :)
malewarebyte Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 26.12.2014
Suchlauf-Zeit: 10:34:16
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2014.12.26.06
Rootkit Datenbank: v2014.12.23.02
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: ***
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 356098
Verstrichene Zeit: 3 Min, 56 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente erkannt)
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 1
PUP.Optional.Softonic.A, HKU\S-1-5-21-1421196489-2289078169-999504329-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Softonic, In Quarantäne, [cba377f0aad29f97dfe73f1e5ea5aa56],
Registrierungswerte: 0
(Keine schädliche Elemente erkannt)
Registrierungsdaten: 0
(Keine schädliche Elemente erkannt)
Ordner: 1
PUP.Optional.BuyNSave.A, C:\Program Files (x86)\BuYNsaVe, In Quarantäne, [9cd2a8bfb3c9cc6a341e87ce867d7b85],
Dateien: 2
PUP.Optional.Bunndle, C:\Program Files\CamStudio 2.7\BunndleOfferManager.exe, In Quarantäne, [323cf176413ba88e66fad8859f610000],
PUP.Optional.BuyNSave.A, C:\Program Files (x86)\BuYNsaVe\BuYNsaVe.dat, In Quarantäne, [9cd2a8bfb3c9cc6a341e87ce867d7b85],
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end) adw (s) Code:
# AdwCleaner v4.106 - Bericht erstellt am 26/12/2014 um 10:44:05
# Aktualisiert 21/12/2014 von Xplode
# Database : 2014-12-21.4 [Live]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : *** - DESKTOP
# Gestartet von : E:\Users\***\Downloads\AdwCleaner_4.106.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\baidu
Ordner Gelöscht : C:\Program Files (x86)\Common Files\Tobit
Ordner Gelöscht : C:\Users\***\AppData\Roaming\Tobit
Ordner Gelöscht : C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Datei Gelöscht : C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\wiwlwb2k.default\foxydeal.sqlite
Datei Gelöscht : C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.best-deals-products.com_0.localstorage-journal
Datei Gelöscht : C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.best-deals-products.com_0.localstorage-journal
Datei Gelöscht : C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.best-deals-products.com_0.localstorage
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{842C4394-47F7-60DE-480B-C09116B63559}
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17496
-\\ Mozilla Firefox v34.0.5 (x86 de)
[wiwlwb2k.default\prefs.js] - Zeile gelöscht : user_pref("extensions.fvd_single.surfcanyon.ramp.start_time", "1396631258406");
-\\ Google Chrome v39.0.2171.95
[C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\preferences] - Gelöscht [Extension] : eofcbnmajmjmplflapaojjnihcjkigck
-\\ Opera v0.0.0.0
*************************
AdwCleaner[R0].txt - [2642 octets] - [26/12/2014 10:42:10]
AdwCleaner[S0].txt - [2399 octets] - [26/12/2014 10:44:05]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2459 octets] ########## jkw Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.0 (11.29.2014:1)
OS: Windows 7 Home Premium x64
Ran by *** on 26.12.2014 at 10:47:06,19
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"
~~~ FireFox
Emptied folder: C:\Users\***\AppData\Roaming\mozilla\firefox\profiles\wiwlwb2k.default\minidumps [37 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 26.12.2014 at 10:49:29,63
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-12-2014
Ran by *** (administrator) on DESKTOP on 26-12-2014 10:51:27
Running from E:\Users\***\Downloads
Loaded Profile: *** (Available profiles: ***)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
() C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Foxit Corporation) C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe
() C:\ProgramData\DatacardService\HWDeviceService64.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Updater\Updater.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Dropbox, Inc.) C:\Users\***\AppData\Roaming\Dropbox\bin\Dropbox.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(ROCCAT GmbH) C:\Program Files (x86)\ROCCAT\Kone Pure Mouse\KonePureMonitor.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7202520 2013-08-19] (Realtek Semiconductor)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2014-12-14] (AVAST Software)
HKLM-x32\...\Run: [RoccatKonePure] => C:\Program Files (x86)\ROCCAT\Kone Pure Mouse\KonePureMonitor.EXE [561152 2013-10-22] (ROCCAT GmbH)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2014-11-20] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [DivXMediaServer] => E:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [448856 2014-11-17] (DivX, LLC)
HKU\S-1-5-21-1421196489-2289078169-999504329-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [30524520 2014-11-27] (Skype Technologies S.A.)
Startup: C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\***\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-1421196489-2289078169-999504329-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1421196489-2289078169-999504329-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: BBuyNssavE -> {0ffbbd18-89da-48f8-8a4a-c4b825b6559b} -> C:\Program Files (x86)\BBuyNssavE\oUs9wUfzmUwtqP.x64.dll No File
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/130321/CTPID.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\wiwlwb2k.default
FF DefaultSearchEngine: Google (avast)
FF DefaultSearchUrl: https://www.google.com/search/?trackid=sp-006
FF SearchEngineOrder.1: Google (avast)
FF SelectedSearchEngine: Google (avast)
FF Homepage: https://www.google.com/?trackid=sp-006
FF Keyword.URL: https://www.google.com/search/?trackid=sp-006
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_235.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_235.dll ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> E:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> E:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll (Foxit Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF SearchPlugin: C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\wiwlwb2k.default\searchplugins\google-avast.xml
FF Extension: DownloadHelper - C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\wiwlwb2k.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-09-06]
FF Extension: Classic Theme Restorer - C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\wiwlwb2k.default\Extensions\ClassicThemeRestorer@ArisT2Noia4dev.xpi [2014-04-30]
FF Extension: MEGA - C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\wiwlwb2k.default\Extensions\firefox@mega.co.nz.xpi [2014-08-09]
FF Extension: Deutsch (DE) Language Pack - C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\wiwlwb2k.default\Extensions\langpack-de@firefox.mozilla.org.xpi [2014-08-18]
FF Extension: FlashGot - C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\wiwlwb2k.default\Extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi [2014-07-16]
FF Extension: Adblock Plus - C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\wiwlwb2k.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-02-14]
FF Extension: User Agent Switcher - C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\wiwlwb2k.default\Extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi [2014-09-13]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-02-14]
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\***\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (ProxFlow) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek [2014-05-16]
CHR Extension: (Google Docs) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-02-14]
CHR Extension: (Google Drive) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-02-14]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-02]
CHR Extension: (YouTube) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-02-14]
CHR Extension: (Google-Suche) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-02-14]
CHR Extension: (AdBlock) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-05-16]
CHR Extension: (Avast Online Security) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-02-14]
CHR Extension: (TweetDeck by Twitter) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbdpomandigafcibbmofojjchbcdagbl [2014-02-14]
CHR Extension: (FVD Downloader) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfmhcpmkbdkbgbmkjoiopeeegenkdikp [2014-10-18]
CHR Extension: (Google Wallet) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-14]
CHR Extension: (Google Mail) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-02-14]
CHR Extension: (BuYNsaVe) - C:\ProgramData\plmjfdnplhahmfkgdmmclnfjmlgekgpg\ [2014-02-14]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-12-14]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe [936728 2013-05-07] ()
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-12-14] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4012248 2014-12-14] (Avast Software)
S2 CLKMSVC10_38F51D56; C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [243464 2013-09-02] (CyberLink)
S3 Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [79360 2014-03-08] (Creative Labs) [File not signed]
S3 Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2014-03-08] (Creative Labs) [File not signed]
R2 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [286720 2010-02-12] (Creative Technology Ltd) [File not signed]
S2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1840128 2011-05-24] (MAGIX AG) [File not signed]
S4 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed]
R2 FoxitCloudUpdateService; C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe [242216 2014-06-17] (Foxit Corporation)
S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [614624 2014-09-02] (Futuremark)
R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [351824 2013-04-10] ()
S2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-03] (Intel Corporation)
S4 lxdx_device; C:\Windows\system32\lxdxcoms.exe [1039872 2009-10-16] ( ) [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
S4 Mobile Broadband HL Service; C:\ProgramData\MobileBrServ\mbbservice.exe [239696 2013-07-23] ()
S4 Radio.fx; E:\Tobit Radio.fx\Server\rfx-server.exe [3999512 2013-06-03] ()
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5419792 2014-11-28] (TeamViewer GmbH)
R2 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1042808 2013-06-19] (Western Digital Technologies, Inc.)
R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [296312 2014-05-23] (Western Digital Technologies, Inc.)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [47512 2013-01-10] (Asmedia Technology)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2012-08-22] ()
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-12-14] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2014-12-14] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-12-14] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-12-14] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2014-12-14] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2014-12-14] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2014-12-14] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2014-12-14] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-03-14] (Disc Soft Ltd)
R3 e1dexpress; C:\Windows\System32\DRIVERS\e1d62x64.sys [495376 2013-05-30] (Intel Corporation)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-08-07] (Intel Corporation)
R3 ksaud; C:\Windows\System32\drivers\ksaud.sys [1558528 2013-03-26] (Creative Technology Ltd.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2014-12-26] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-09-03] (Intel Corporation)
S3 MotioninJoyXFilter; C:\Windows\System32\DRIVERS\MijXfilt.sys [121416 2012-05-12] (MotioninJoy) [File not signed]
S3 SMIGrabber3C; C:\Windows\System32\Drivers\SmiUsbGrabber3C.sys [827040 2013-09-14] (Windows (R) Win 7 DDK provider)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [271752 2014-12-14] (Avast Software)
S3 VBoxUSB; C:\Windows\System32\Drivers\VBoxUSB.sys [115488 2014-05-16] (Oracle Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 GPUZ; \??\C:\Windows\TEMP\GPUZ.sys [X]
S3 MSICDSetup; \??\G:\CDriver64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-26 10:49 - 2014-12-26 10:49 - 00000829 _____ () C:\Users\***\Desktop\JRT.txt
2014-12-26 10:47 - 2014-12-26 10:47 - 00000197 _____ () C:\Windows\system32\2014-12-26-09-47-18.005-AvastVBoxSVC.exe-3744.log
2014-12-26 10:47 - 2014-12-26 10:47 - 00000000 ____D () C:\Windows\ERUNT
2014-12-26 10:42 - 2014-12-26 10:44 - 00000000 ____D () C:\AdwCleaner
2014-12-26 10:41 - 2014-12-26 10:41 - 00000197 _____ () C:\Windows\system32\2014-12-26-09-41-21.024-AvastVBoxSVC.exe-3552.log
2014-12-26 10:40 - 2014-12-26 10:40 - 00001644 _____ () C:\mbam.txt
2014-12-26 10:33 - 2014-12-26 10:50 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-12-26 10:32 - 2014-12-26 10:32 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-12-26 10:32 - 2014-12-26 10:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-12-26 10:32 - 2014-12-26 10:32 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-12-26 10:32 - 2014-12-26 10:32 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-12-26 10:32 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-12-26 10:32 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-12-26 10:32 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-12-26 10:31 - 2014-12-26 10:32 - 00000197 _____ () C:\Windows\system32\2014-12-26-09-31-29.076-AvastVBoxSVC.exe-3456.log
2014-12-25 16:44 - 2014-12-25 16:44 - 00000197 _____ () C:\Windows\system32\2014-12-25-15-44-50.068-AvastVBoxSVC.exe-3304.log
2014-12-25 16:35 - 2014-12-25 16:35 - 00033700 _____ () C:\ComboFix.txt
2014-12-25 16:30 - 2014-12-25 16:35 - 00000000 ____D () C:\Windows\erdnt
2014-12-25 16:30 - 2014-12-25 16:35 - 00000000 ____D () C:\Qoobox
2014-12-25 16:30 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-12-25 16:30 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-12-25 16:30 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-12-25 16:30 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-12-25 16:30 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-12-25 16:30 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2014-12-25 16:30 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2014-12-25 16:30 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2014-12-25 16:29 - 2014-12-25 16:29 - 05603624 ____R (Swearware) C:\Users\***\Desktop\ComboFix.exe
2014-12-25 15:50 - 2014-12-26 10:51 - 00000000 ____D () C:\FRST
2014-12-25 15:40 - 2014-12-25 15:40 - 00000197 _____ () C:\Windows\system32\2014-12-25-14-40-54.093-AvastVBoxSVC.exe-3268.log
2014-12-25 12:48 - 2014-12-25 12:48 - 00000197 _____ () C:\Windows\system32\2014-12-25-11-48-47.062-AvastVBoxSVC.exe-3204.log
2014-12-25 09:30 - 2014-12-25 09:31 - 00000197 _____ () C:\Windows\system32\2014-12-25-08-30-42.084-AvastVBoxSVC.exe-3272.log
2014-12-25 01:46 - 2014-12-25 01:47 - 00003258 _____ () C:\Windows\System32\Tasks\avastBCLRestartS-1-5-21-1421196489-2289078169-999504329-1000
2014-12-25 01:43 - 2014-12-25 01:43 - 00000000 ____D () C:\Users\***\AppData\Roaming\24467
2014-12-25 01:41 - 2014-12-25 01:41 - 00000000 ____D () C:\ProgramData\plmjfdnplhahmfkgdmmclnfjmlgekgpg
2014-12-25 01:40 - 2014-12-25 01:40 - 00000280 _____ () C:\Windows\system32\2014-12-25-00-40-35.033-aswFe.exe-7532.log
2014-12-25 01:39 - 2014-12-25 01:39 - 00001203 _____ () C:\Users\***\Desktop\DVDFab 9 Crack plus keygen Full Version Download.lnk
2014-12-25 01:39 - 2014-12-25 01:39 - 00000280 _____ () C:\Windows\system32\2014-12-25-00-39-16.008-aswFe.exe-5128.log
2014-12-25 01:06 - 2014-12-25 01:09 - 00001258 _____ () C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MediaInfo.lnk
2014-12-25 01:06 - 2014-12-25 01:06 - 00000000 ____D () C:\Program Files\MediaInfo
2014-12-25 01:03 - 2014-12-25 01:03 - 00000000 ____D () C:\Users\***\AppData\Local\Blu-ray Master
2014-12-25 01:02 - 2014-12-25 01:03 - 00000000 ___HD () C:\ProgramData\tks
2014-12-25 01:02 - 2014-12-25 01:03 - 00000000 ____D () C:\Users\***\AppData\Roaming\log
2014-12-25 01:02 - 2014-12-25 01:02 - 00000000 ___HD () C:\ProgramData\vid
2014-12-24 23:59 - 2014-12-25 00:00 - 00000197 _____ () C:\Windows\system32\2014-12-24-22-59-51.038-AvastVBoxSVC.exe-2336.log
2014-12-24 13:50 - 2014-12-24 13:50 - 00000247 _____ () C:\Windows\system32\2014-12-24-12-50-10.005-aswFe.exe-7136.log
2014-12-24 13:48 - 2014-12-24 13:50 - 00000247 _____ () C:\Windows\system32\2014-12-24-12-48-15.087-aswFe.exe-1436.log
2014-12-24 13:48 - 2014-12-24 13:48 - 00000197 _____ () C:\Windows\system32\2014-12-24-12-48-10.083-AvastVBoxSVC.exe-1064.log
2014-12-24 08:13 - 2014-12-24 08:13 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2014-12-24 08:12 - 2014-12-24 08:13 - 00000197 _____ () C:\Windows\system32\2014-12-24-07-12-53.097-AvastVBoxSVC.exe-3412.log
2014-12-23 09:54 - 2014-12-23 09:54 - 00000197 _____ () C:\Windows\system32\2014-12-23-08-54-41.025-AvastVBoxSVC.exe-3380.log
2014-12-22 11:05 - 2014-12-22 11:05 - 00000197 _____ () C:\Windows\system32\2014-12-22-10-05-14.019-AvastVBoxSVC.exe-3456.log
2014-12-22 09:46 - 2014-12-22 09:47 - 00000197 _____ () C:\Windows\system32\2014-12-22-08-46-37.080-AvastVBoxSVC.exe-3204.log
2014-12-21 17:38 - 2014-12-21 17:39 - 00000197 _____ () C:\Windows\system32\2014-12-21-16-38-41.017-AvastVBoxSVC.exe-3212.log
2014-12-21 11:35 - 2014-12-21 11:39 - 00000000 ____D () C:\Users\***\Desktop\Neuer Ordner
2014-12-21 09:36 - 2014-12-21 09:36 - 00000197 _____ () C:\Windows\system32\2014-12-21-08-36-40.079-AvastVBoxSVC.exe-2160.log
2014-12-21 09:30 - 2014-12-21 09:30 - 00000197 _____ () C:\Windows\system32\2014-12-21-08-30-39.019-AvastVBoxSVC.exe-2208.log
2014-12-20 21:48 - 2014-12-20 21:48 - 00000197 _____ () C:\Windows\system32\2014-12-20-20-48-00.001-AvastVBoxSVC.exe-2128.log
2014-12-20 12:05 - 2014-12-20 12:06 - 00000197 _____ () C:\Windows\system32\2014-12-20-11-05-39.096-AvastVBoxSVC.exe-3076.log
2014-12-20 00:17 - 2014-12-13 06:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-12-20 00:17 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-12-19 08:54 - 2014-12-19 08:55 - 00000197 _____ () C:\Windows\system32\2014-12-19-07-54-58.083-AvastVBoxSVC.exe-3096.log
2014-12-18 11:00 - 2014-12-18 11:01 - 00000197 _____ () C:\Windows\system32\2014-12-18-10-00-38.089-AvastVBoxSVC.exe-3096.log
2014-12-18 08:12 - 2014-12-18 08:12 - 00000197 _____ () C:\Windows\system32\2014-12-18-07-12-21.041-AvastVBoxSVC.exe-2520.log
2014-12-17 16:44 - 2014-12-17 16:45 - 00000197 _____ () C:\Windows\system32\2014-12-17-15-44-51.051-AvastVBoxSVC.exe-2896.log
2014-12-17 06:48 - 2014-12-17 06:48 - 00000197 _____ () C:\Windows\system32\2014-12-17-05-48-02.066-AvastVBoxSVC.exe-3100.log
2014-12-16 22:05 - 2014-12-16 22:06 - 61292300 _____ () C:\Users\***\Desktop\Len-kun_Len_Kagamine_-_Shinkai_Shounen_German_Fandub_HD.mp4
2014-12-16 18:04 - 2014-12-16 18:04 - 00000247 _____ () C:\Windows\system32\2014-12-16-17-04-51.079-aswFe.exe-5912.log
2014-12-16 18:03 - 2014-12-16 18:04 - 00000247 _____ () C:\Windows\system32\2014-12-16-17-03-08.009-aswFe.exe-4796.log
2014-12-16 18:03 - 2014-12-16 18:03 - 00000197 _____ () C:\Windows\system32\2014-12-16-17-03-04.052-AvastVBoxSVC.exe-3796.log
2014-12-15 16:50 - 2014-12-15 16:51 - 00000197 _____ () C:\Windows\system32\2014-12-15-15-50-37.068-AvastVBoxSVC.exe-2872.log
2014-12-14 20:17 - 2014-12-14 20:17 - 00000197 _____ () C:\Windows\system32\2014-12-14-19-17-25.074-AvastVBoxSVC.exe-3088.log
2014-12-14 09:45 - 2014-12-14 09:45 - 00000600 _____ () C:\Windows\system32\TeamViewer10_Hooks.log
2014-12-14 09:44 - 2014-12-14 09:44 - 00000971 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk
2014-12-14 09:44 - 2014-12-14 09:44 - 00000959 _____ () C:\Users\Public\Desktop\TeamViewer 10.lnk
2014-12-14 08:50 - 2014-12-14 08:50 - 00000247 _____ () C:\Windows\system32\2014-12-14-07-50-18.067-aswFe.exe-5648.log
2014-12-14 08:48 - 2014-12-14 08:50 - 00000247 _____ () C:\Windows\system32\2014-12-14-07-48-27.068-aswFe.exe-6476.log
2014-12-14 08:48 - 2014-12-14 08:48 - 00000197 _____ () C:\Windows\system32\2014-12-14-07-48-24.030-AvastVBoxSVC.exe-2092.log
2014-12-14 08:36 - 2014-11-27 02:43 - 00389296 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-12-14 08:36 - 2014-11-27 02:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-12-14 08:36 - 2014-11-22 04:13 - 25059840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-12-14 08:36 - 2014-11-22 04:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-12-14 08:36 - 2014-11-22 04:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-12-14 08:36 - 2014-11-22 03:50 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-12-14 08:36 - 2014-11-22 03:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-12-14 08:36 - 2014-11-22 03:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-12-14 08:36 - 2014-11-22 03:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-12-14 08:36 - 2014-11-22 03:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-12-14 08:36 - 2014-11-22 03:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-12-14 08:36 - 2014-11-22 03:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-12-14 08:36 - 2014-11-22 03:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-12-14 08:36 - 2014-11-22 03:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-12-14 08:36 - 2014-11-22 03:34 - 06039552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-12-14 08:36 - 2014-11-22 03:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-12-14 08:36 - 2014-11-22 03:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-12-14 08:36 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-12-14 08:36 - 2014-11-22 03:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-12-14 08:36 - 2014-11-22 03:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-12-14 08:36 - 2014-11-22 03:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-12-14 08:36 - 2014-11-22 03:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-12-14 08:36 - 2014-11-22 03:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-12-14 08:36 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-12-14 08:36 - 2014-11-22 03:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-12-14 08:36 - 2014-11-22 03:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-12-14 08:36 - 2014-11-22 03:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-12-14 08:36 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-12-14 08:36 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-12-14 08:36 - 2014-11-22 02:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-12-14 08:36 - 2014-11-22 02:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-12-14 08:36 - 2014-11-22 02:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-12-14 08:36 - 2014-11-22 02:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-12-14 08:36 - 2014-11-22 02:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-12-14 08:36 - 2014-11-22 02:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-12-14 08:36 - 2014-11-22 02:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-12-14 08:36 - 2014-11-22 02:46 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-12-14 08:36 - 2014-11-22 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-12-14 08:36 - 2014-11-22 02:43 - 14412800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-12-14 08:36 - 2014-11-22 02:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-12-14 08:36 - 2014-11-22 02:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-12-14 08:36 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-12-14 08:36 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-12-14 08:36 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-12-14 08:36 - 2014-11-22 02:28 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-12-14 08:36 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-12-14 08:36 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-12-14 08:36 - 2014-11-22 02:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-12-14 08:36 - 2014-11-22 02:15 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-12-14 08:36 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-12-14 08:36 - 2014-11-22 02:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-12-14 08:36 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-12-14 08:36 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-12-14 08:36 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-12-14 08:36 - 2014-10-18 03:05 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-12-14 08:36 - 2014-10-18 02:33 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2014-12-14 08:36 - 2014-07-07 03:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2014-12-14 08:36 - 2014-07-07 03:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2014-12-14 08:36 - 2014-07-07 03:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2014-12-14 08:36 - 2014-07-07 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2014-12-14 08:36 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2014-12-14 08:36 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2014-12-14 08:36 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2014-12-14 08:36 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2014-12-14 08:35 - 2014-11-11 04:09 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-12-14 08:35 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-12-14 08:35 - 2014-11-11 02:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2014-12-14 08:35 - 2014-11-08 04:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-12-14 08:35 - 2014-11-08 03:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-12-14 08:35 - 2014-10-30 03:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe
2014-12-14 08:35 - 2014-10-30 02:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe
2014-12-14 08:35 - 2014-10-03 03:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2014-12-14 08:35 - 2014-10-03 03:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2014-12-14 08:35 - 2014-10-03 03:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2014-12-14 08:35 - 2014-10-03 03:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2014-12-14 08:35 - 2014-10-03 03:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2014-12-14 08:35 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2014-12-14 08:35 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2014-12-14 08:35 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2014-12-14 08:35 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2014-12-14 08:35 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2014-12-14 08:29 - 2014-12-14 08:30 - 00000197 _____ () C:\Windows\system32\2014-12-14-07-29-48.034-AvastVBoxSVC.exe-2128.log
2014-12-14 08:29 - 2014-12-14 08:29 - 00364512 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-12-14 08:29 - 2014-12-14 08:29 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-12-13 11:14 - 2014-12-13 11:14 - 00000197 _____ () C:\Windows\system32\2014-12-13-10-14-14.071-AvastVBoxSVC.exe-2932.log
2014-12-12 16:48 - 2014-12-12 16:48 - 00000197 _____ () C:\Windows\system32\2014-12-12-15-48-21.076-AvastVBoxSVC.exe-2064.log
2014-12-11 18:35 - 2014-12-11 18:35 - 00000000 ____D () C:\ProgramData\ATI
2014-12-11 18:34 - 2014-12-11 18:34 - 00053736 _____ () C:\Windows\SysWOW64\CCCInstall_201412111834482630.log
2014-12-11 18:34 - 2014-12-11 18:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2014-12-11 18:34 - 2014-12-11 18:34 - 00000000 ____D () C:\Program Files (x86)\AMD AVT
2014-12-11 18:34 - 2014-12-11 18:34 - 00000000 ____D () C:\Program Files (x86)\AMD
2014-12-11 18:27 - 2014-12-11 18:27 - 00000197 _____ () C:\Windows\system32\2014-12-11-17-27-02.003-AvastVBoxSVC.exe-3476.log
2014-12-10 18:11 - 2014-12-10 18:11 - 00000197 _____ () C:\Windows\system32\2014-12-10-17-11-19.023-AvastVBoxSVC.exe-3084.log
2014-12-09 19:34 - 2014-12-09 19:35 - 00000197 _____ () C:\Windows\system32\2014-12-09-18-34-56.010-AvastVBoxSVC.exe-2044.log
2014-12-05 16:52 - 2014-12-05 16:52 - 00000197 _____ () C:\Windows\system32\2014-12-05-15-52-20.078-AvastVBoxSVC.exe-2364.log
2014-12-04 18:31 - 2014-12-04 18:32 - 00000197 _____ () C:\Windows\system32\2014-12-04-17-31-32.061-AvastVBoxSVC.exe-3064.log
2014-12-03 18:24 - 2014-12-03 18:24 - 00000197 _____ () C:\Windows\system32\2014-12-03-17-24-00.025-AvastVBoxSVC.exe-2336.log
2014-12-03 00:02 - 2014-12-03 00:02 - 00000197 _____ () C:\Windows\system32\2014-12-02-23-02-26.042-AvastVBoxSVC.exe-2928.log
2014-12-02 16:28 - 2014-12-02 16:29 - 00000197 _____ () C:\Windows\system32\2014-12-02-15-28-42.066-AvastVBoxSVC.exe-3040.log
2014-12-02 06:16 - 2014-12-02 06:17 - 00000197 _____ () C:\Windows\system32\2014-12-02-05-16-49.055-AvastVBoxSVC.exe-2212.log
2014-12-01 21:26 - 2014-12-01 23:38 - 00000000 ____D () C:\Users\***\AppData\Roaming\Mumble
2014-12-01 21:25 - 2014-12-01 21:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mumble
2014-12-01 21:25 - 2014-12-01 21:25 - 00000000 ____D () C:\Program Files (x86)\Mumble
2014-12-01 17:51 - 2014-12-01 17:52 - 00000197 _____ () C:\Windows\system32\2014-12-01-16-51-44.007-AvastVBoxSVC.exe-2860.log
2014-11-30 22:34 - 2014-11-30 22:34 - 00001800 _____ () C:\Users\***\Desktop\mpc-hc.exe.lnk
2014-11-30 22:33 - 2014-11-30 22:33 - 00000714 _____ () C:\Users\***\Desktop\Videos-Anime.lnk
2014-11-30 22:32 - 2014-11-30 22:32 - 00000840 _____ () C:\Users\***\Desktop\Musik_Anime_Disny_Original.lnk
2014-11-30 22:15 - 2014-11-30 22:15 - 00001207 _____ () C:\Users\***\Desktop\FileZilla.lnk
2014-11-30 22:15 - 2014-11-30 22:15 - 00001022 _____ () C:\Users\***\Desktop\Vegas Pro 13.0 (64-bit).lnk
2014-11-30 16:37 - 2014-11-30 16:37 - 00000946 _____ () C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\osu!.lnk
2014-11-30 16:36 - 2014-12-13 20:35 - 00000000 ____D () C:\Users\***\AppData\Local\osu!
2014-11-30 11:02 - 2014-11-30 11:02 - 00000197 _____ () C:\Windows\system32\2014-11-30-10-02-38.005-AvastVBoxSVC.exe-2772.log
2014-11-30 10:45 - 2014-11-11 04:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-11-30 10:45 - 2014-11-11 04:08 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
2014-11-30 10:45 - 2014-11-11 03:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-11-30 10:45 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll
2014-11-30 10:41 - 2014-11-30 10:42 - 00000197 _____ () C:\Windows\system32\2014-11-30-09-41-54.059-AvastVBoxSVC.exe-2884.log
2014-11-29 21:05 - 2014-11-29 21:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MP4Joiner
2014-11-29 21:05 - 2014-11-29 21:05 - 00000000 ____D () C:\Program Files (x86)\MP4Joiner
2014-11-29 20:37 - 2014-11-29 20:37 - 00000000 ____D () C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
2014-11-29 20:37 - 2014-11-29 20:37 - 00000000 ____D () C:\Program Files (x86)\FreeTime
2014-11-29 20:14 - 2014-11-29 20:30 - 00000000 ____D () C:\Users\***\AppData\Roaming\HandBrake
2014-11-29 20:13 - 2014-11-29 20:13 - 00000000 ____D () C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Handbrake
2014-11-29 20:13 - 2014-11-29 20:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Handbrake
2014-11-29 20:13 - 2014-11-29 20:13 - 00000000 ____D () C:\Program Files (x86)\Handbrake
2014-11-29 19:00 - 2014-11-29 19:00 - 00000197 _____ () C:\Windows\system32\2014-11-29-18-00-47.016-AvastVBoxSVC.exe-2996.log
2014-11-29 10:39 - 2014-11-29 10:39 - 00000197 _____ () C:\Windows\system32\2014-11-29-09-39-50.075-AvastVBoxSVC.exe-3008.log
2014-11-28 17:36 - 2014-11-28 17:37 - 00000197 _____ () C:\Windows\system32\2014-11-28-16-36-29.054-AvastVBoxSVC.exe-2976.log
2014-11-27 18:01 - 2014-11-27 18:01 - 00000197 _____ () C:\Windows\system32\2014-11-27-17-01-36.084-AvastVBoxSVC.exe-2996.log
2014-11-27 06:40 - 2014-11-27 06:41 - 00000197 _____ () C:\Windows\system32\2014-11-27-05-40-36.003-AvastVBoxSVC.exe-2352.log
2014-11-26 19:22 - 2014-11-26 19:22 - 00000197 _____ () C:\Windows\system32\2014-11-26-18-22-05.087-AvastVBoxSVC.exe-2856.log
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-26 10:51 - 2014-02-15 00:19 - 00000000 ____D () C:\Users\***\AppData\Roaming\Skype
2014-12-26 10:50 - 2014-09-03 16:33 - 00020690 _____ () C:\Windows\setupact.log
2014-12-26 10:50 - 2014-07-29 20:11 - 00008192 _____ () C:\Windows\SysWOW64\WDPABKP.dat
2014-12-26 10:50 - 2014-02-15 11:18 - 00000000 ___RD () C:\Users\***\Dropbox
2014-12-26 10:50 - 2014-02-15 11:18 - 00000000 ____D () C:\Users\***\AppData\Roaming\Dropbox
2014-12-26 10:50 - 2014-02-14 15:58 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-12-26 10:50 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-26 10:49 - 2014-02-14 14:46 - 01369015 _____ () C:\Windows\WindowsUpdate.log
2014-12-26 10:49 - 2009-07-14 18:58 - 00700130 _____ () C:\Windows\system32\perfh007.dat
2014-12-26 10:49 - 2009-07-14 18:58 - 00149768 _____ () C:\Windows\system32\perfc007.dat
2014-12-26 10:49 - 2009-07-14 06:13 - 01622706 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-26 10:49 - 2009-07-14 05:45 - 00014944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-26 10:49 - 2009-07-14 05:45 - 00014944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-26 10:45 - 2014-11-01 20:48 - 00017794 _____ () C:\Windows\PFRO.log
2014-12-26 10:38 - 2014-05-03 11:10 - 00000000 ____D () C:\Program Files\CamStudio 2.7
2014-12-25 18:53 - 2014-02-14 15:58 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-12-25 18:28 - 2014-02-14 22:22 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-12-25 16:39 - 2014-02-14 14:45 - 00000000 ____D () C:\Users\***
2014-12-25 16:35 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default
2014-12-25 16:34 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2014-12-25 02:51 - 2014-05-03 11:14 - 00004546 _____ () C:\Users\***\AppData\Roaming\CamStudio.cfg
2014-12-25 02:51 - 2014-05-03 11:14 - 00000408 _____ () C:\Users\***\AppData\Roaming\CamShapes.ini
2014-12-25 02:51 - 2014-05-03 11:14 - 00000408 _____ () C:\Users\***\AppData\Roaming\CamLayout.ini
2014-12-25 02:51 - 2014-05-03 11:14 - 00000127 _____ () C:\Users\***\AppData\Roaming\Camdata.ini
2014-12-25 02:48 - 2014-05-03 11:10 - 00000096 _____ () C:\Users\***\AppData\Roaming\version2.xml
2014-12-25 02:40 - 2014-05-03 11:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CamStudio 2.7
2014-12-25 02:39 - 2014-06-14 19:31 - 00000000 ____D () C:\Users\***\AppData\Roaming\vlc
2014-12-25 02:22 - 2014-02-14 16:28 - 00007678 _____ () C:\Users\***\AppData\Local\Resmon.ResmonCfg
2014-12-25 01:47 - 2014-02-14 21:32 - 00001135 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-12-25 01:47 - 2014-02-14 21:32 - 00001135 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-12-24 09:57 - 2014-06-11 21:14 - 00000000 ____D () C:\Users\***\AppData\Roaming\FileZilla
2014-12-22 23:40 - 2014-02-14 22:40 - 00000600 _____ () C:\Users\***\AppData\Roaming\winscp.rnd
2014-12-22 23:38 - 2014-03-03 18:19 - 00000000 ____D () C:\Users\***\AppData\Roaming\Audacity
2014-12-22 23:21 - 2014-03-03 18:17 - 00000000 ____D () C:\Users\***\AppData\Roaming\foobar2000
2014-12-22 22:38 - 2014-09-08 17:52 - 00000000 ____D () C:\Users\***\AppData\Roaming\X-Chat 2
2014-12-22 17:02 - 2014-05-10 13:10 - 00000600 _____ () C:\Users\***\AppData\Local\PUTTY.RND
2014-12-21 12:00 - 2014-05-19 18:42 - 00000000 ____D () C:\Users\***\.VirtualBox
2014-12-21 09:32 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-12-21 09:29 - 2014-02-14 15:59 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-12-20 22:43 - 2014-03-29 18:37 - 00000000 ____D () C:\Users\***\dwhelper
2014-12-19 08:52 - 2009-07-14 06:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-12-18 18:36 - 2014-07-16 20:42 - 00000000 ____D () C:\Users\***\Desktop\JDownloader
2014-12-18 11:15 - 2014-11-17 20:07 - 00000000 ____D () C:\Users\***\AppData\Roaming\Foxit Software
2014-12-17 16:49 - 2014-06-10 18:11 - 00003850 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1402420282
2014-12-16 19:36 - 2014-05-29 06:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX
2014-12-16 19:36 - 2014-05-29 06:03 - 00000000 ____D () C:\ProgramData\DivX
2014-12-16 17:59 - 2014-02-15 11:18 - 00000000 ____D () C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-12-14 20:17 - 2014-02-14 15:17 - 00125192 _____ () C:\Users\***\AppData\Local\GDIPFONTCACHEV1.DAT
2014-12-14 20:17 - 2009-07-14 05:45 - 00435056 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-12-14 15:19 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-12-14 09:45 - 2014-06-11 19:34 - 00000000 ____D () C:\Program Files (x86)\TeamViewer
2014-12-14 08:43 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-12-14 08:39 - 2014-02-16 19:17 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-12-14 08:39 - 2014-02-14 17:23 - 00000000 ____D () C:\Windows\system32\MRT
2014-12-14 08:37 - 2014-02-14 17:23 - 112710672 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-12-14 08:29 - 2014-11-03 19:41 - 00001924 _____ () C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2014-12-14 08:29 - 2014-05-08 19:34 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-12-14 08:29 - 2014-02-14 15:58 - 01050432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2014-12-14 08:29 - 2014-02-14 15:58 - 00436624 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-12-14 08:29 - 2014-02-14 15:58 - 00267632 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-12-14 08:29 - 2014-02-14 15:58 - 00116728 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2014-12-14 08:29 - 2014-02-14 15:58 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-12-14 08:29 - 2014-02-14 15:58 - 00083280 _____ (AVAST Software) C:\Windows\system32\Drivers\aswmonflt.sys
2014-12-14 08:29 - 2014-02-14 15:58 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-12-13 19:49 - 2014-03-11 18:56 - 00000000 ____D () C:\Users\***\AppData\Roaming\TS3Client
2014-12-12 18:39 - 2014-02-14 22:22 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-12-12 18:39 - 2014-02-14 22:22 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-12-12 18:39 - 2014-02-14 22:22 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-12-12 18:38 - 2014-02-14 21:33 - 00002247 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-12-11 18:34 - 2014-02-14 16:03 - 00000000 ____D () C:\ProgramData\AMD
2014-12-11 18:33 - 2014-10-07 16:39 - 00000000 ____D () C:\Program Files\AMD
2014-12-11 18:30 - 2014-02-14 16:00 - 00000000 ____D () C:\AMD
2014-12-10 18:10 - 2014-02-14 21:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-12-09 21:06 - 2014-09-04 06:22 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-12-09 19:36 - 2014-11-17 20:00 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-12-06 09:09 - 2014-05-29 05:26 - 00000000 ____D () C:\Users\***\AppData\Roaming\Aegisub
2014-12-04 21:52 - 2014-09-19 20:37 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-12-04 21:52 - 2014-02-15 00:18 - 00000000 ____D () C:\ProgramData\Skype
2014-12-04 19:13 - 2014-11-17 20:08 - 00000000 ____D () C:\Users\Public\Foxit Software
2014-12-04 06:31 - 2014-09-10 19:04 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-11-30 22:24 - 2014-02-14 23:32 - 00000022 _____ () C:\Windows\GPU-Z.INI
2014-11-30 22:20 - 2014-02-14 23:14 - 00000890 _____ () C:\Users\Public\Desktop\CPUID HWMonitor.lnk
2014-11-29 23:23 - 2014-10-21 21:02 - 00000059 _____ () C:\Users\***\Desktop\Neues Textdokument.txt
2014-11-29 23:12 - 2014-09-12 19:47 - 00000000 ____D () C:\Users\***\AppData\Roaming\streamWriter
Some content of TEMP:
====================
C:\Users\***\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmplitpdw.dll
C:\Users\***\AppData\Local\Temp\Quarantine.exe
C:\Users\***\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-12-25 18:09
==================== End Of Log ============================ --- --- ---
additional Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-12-2014
Ran by *** at 2014-12-26 10:51:45
Running from E:\Users\***\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
3DMark (HKLM-x32\...\{e3d36b08-a0ac-41df-9119-86eba0d74dd8}) (Version: 1.4.778.0 - Futuremark)
3DMark (Version: 1.4.778.0 - Futuremark) Hidden
7-Zip 9.22 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0922-000001000000}) (Version: 9.22.00.0 - Igor Pavlov)
Adobe Flash Media Live Encoder 3.2 (HKLM-x32\...\{0659E943-DDF4-44FC-9FEE-A13B09F8BB08}) (Version: 3.2.0 - Adobe Systems Incorporated)
Adobe Flash Player 16 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 16.0.0.235 - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.235 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Aegisub 3.2.1 (HKLM-x32\...\{24BC8B57-716C-444F-B46B-A3349B9164C5}_is1) (Version: 3.2.1 - Aegisub Team)
Age of Chivalry: Hegemony 1.96 (HKLM-x32\...\Age of Chivalry: Hegemony) (Version: 1.96 - )
Amazon Music (HKU\S-1-5-21-1421196489-2289078169-999504329-1000\...\Amazon Amazon Music) (Version: 3.0.0.564 - Amazon Services LLC)
AMD Catalyst Install Manager (HKLM\...\{F2A7CE36-57BF-5C86-952D-90DBF3746D82}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
AMP WinOFF 5.0.1 (HKLM-x32\...\AMP WinOFF) (Version: 5.0.1 - Alberto Martinez Perez)
ANNO 1404 - Königsedition (HKLM-x32\...\{3D9CF3CA-3AB0-4A82-9853-D7C43FD1D775}) (Version: 3.10.0000 - Ubisoft)
ANNO 2070 (HKLM-x32\...\{B48E264C-C8CD-4617-B0BE-46E977BAD694}) (Version: 1.0.0.0 - Ubisoft)
Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Asmedia ASM106x SATA Host Controller Driver (HKLM-x32\...\{61942EF5-2CD8-47D4-869C-2E9A8BB085F1}) (Version: 1.3.4.001 - Asmedia Technology)
Audacity 2.0.5 (HKLM-x32\...\Audacity_is1) (Version: 2.0.5 - Audacity Team)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.0.2208 - AVAST Software)
AviSynth 2.5 (HKLM-x32\...\AviSynth) (Version: - )
CamStudio 2.7.2 (HKLM\...\{04B83666-3A62-452B-85D3-70F8117F2329}_is1) (Version: 2.7.2 - CamStudio Open Source)
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.3.4643 - CDBurnerXP)
CPUID CPU-Z 1.69 (HKLM\...\CPUID CPU-Z_is1) (Version: - )
CPUID HWMonitor 1.25 (HKLM\...\CPUID HWMonitor_is1) (Version: - )
Creative Smart Recorder (HKLM-x32\...\Smart Recorder) (Version: 2.20 - Creative Technology Limited)
Creative Systeminformationen (HKLM-x32\...\SysInfo) (Version: 1.10 - Creative Technology Limited)
CrystalDiskInfo 6.1.12 (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 6.1.12 - Crystal Dew World)
CyberLink BD_3D Advisor 2.0 (HKLM-x32\...\{2D2D8FE2-605C-4D3C-B706-36E981E7EEF0}) (Version: 2.0.6410 - CyberLink Corp.)
CyberLink Media Suite 10 (HKLM-x32\...\InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}) (Version: 10.0 - CyberLink Corp.)
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
Digieffects Phenomena Particle Effects (HKLM-x32\...\MAGIX_{B2D05F0A-841B-459F-8D2B-1802DB6449C8}) (Version: 1.0.0.1 - MAGIX AG)
Digieffects Phenomena Particle Effects (Version: 1.0.0.1 - MAGIX AG) Hidden
DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.7.0.31 - DivX, LLC)
Dragon's Prophet (HKLM-x32\...\{C31556D7-F2B9-4787-B223-F7A035067E89}_is1) (Version: 2.0.1315.20 - Infernum Productions AG)
Dropbox (HKU\S-1-5-21-1421196489-2289078169-999504329-1000\...\Dropbox) (Version: 3.0.3 - Dropbox, Inc.)
Elsword_DE (HKLM-x32\...\Elsword_DE_is1) (Version: - )
FileZilla Client 3.9.0.6 (HKLM-x32\...\FileZilla Client) (Version: 3.9.0.6 - Tim Kosse)
Firebird SQL Server - MAGIX Edition (HKLM-x32\...\{6C5F8503-55D2-4398-858C-362B7A7AF51C}) (Version: 2.1.31.0 - MAGIX AG)
FLAC 1.2.1b (remove only) (HKLM-x32\...\FLAC) (Version: 1.2.1b - Xiph.org)
foobar2000 v1.3.1 (HKLM-x32\...\foobar2000) (Version: 1.3.1 - Peter Pawlowski)
FormatFactory 3.5.0.0 (HKLM-x32\...\FormatFactory) (Version: 3.5.0.0 - Format Factory)
Foxit Cloud (HKLM-x32\...\{41914D8B-9D6E-4764-A1F9-BC43FB6782C1}_is1) (Version: 1.5.129.617 - Foxit Corporation)
Foxit PhantomPDF (HKLM-x32\...\{A33E42AC-6A09-4373-96AA-B2806431A938}) (Version: 6.1.5.624 - Foxit Corporation)
Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 6.1.5.624 - Foxit Corporation)
Fraps (remove only) (HKLM-x32\...\Fraps) (Version: - )
Free YouTube Download version 3.2.41.623 (HKLM-x32\...\Free YouTube Download_is1) (Version: 3.2.41.623 - DVDVideoSoft Ltd.)
Freemake Video Converter Version 4.1.3 (HKLM-x32\...\Freemake Video Converter_is1) (Version: 4.1.3 - Ellora Assets Corporation)
Futuremark SystemInfo (HKLM-x32\...\{E114E635-F06E-43B4-A800-74A22536B1B0}) (Version: 4.30.472.0 - Futuremark)
GameRanger (HKU\S-1-5-21-1421196489-2289078169-999504329-1000\...\GameRanger) (Version: - GameRanger Technologies)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 39.0.2171.95 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
HandBrake 0.10.0 (HKLM-x32\...\HandBrake) (Version: 0.10.0 - )
HD Tune 2.55 (HKLM-x32\...\HD Tune_is1) (Version: - EFD Software)
IndustrieGigant 2 - Gold Edition (HKLM-x32\...\{6910C412-A523-493C-BC22-0213CD7F4F3A}) (Version: 1.0.0 - JoWooD Productions Software AG)
Industry Empire (HKLM-x32\...\Steam App 291930) (Version: - Actalogic)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.14.1724 - Intel Corporation)
Intel(R) Network Connections 18.5.54.0 (HKLM\...\PROSetDX) (Version: 18.5.54.0 - Intel)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.0.1016 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 2.5.0.19 - Intel Corporation)
IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.38 - Irfan Skiljan)
Java 7 Update 67 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217067FF}) (Version: 7.0.670 - Oracle)
K-Lite Mega Codec Pack 10.5.5 (HKLM-x32\...\KLiteCodecPack_is1) (Version: 10.5.5 - )
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version: - )
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games )
League of Legends (x32 Version: 3.0.1 - Riot Games ) Hidden
LG ODD Auto Firmware Update (HKLM-x32\...\{6179550A-3E7C-499E-BCC9-9E8113E0A285}) (Version: 10.01.0712.01 - )
LinuxLive USB Creator (HKLM-x32\...\LinuxLive USB Creator) (Version: 2.8 - Thibaut Lauziere)
MAGIX Speed burnR (MSI) (HKLM-x32\...\MAGIX_{F115C413-A7CE-4E9C-8E6F-881A940CDBB8}) (Version: 7.0.2.6 - MAGIX AG)
MAGIX Speed burnR (MSI) (Version: 7.0.2.6 - MAGIX AG) Hidden
MAGIX Video deluxe 2013 Premium (HKLM-x32\...\MAGIX_{1B5AC129-F6CC-491E-84DE-1FF2996A0367}) (Version: 12.0.0.30 - MAGIX AG)
MAGIX Video deluxe 2013 Premium (Version: 12.0.0.30 - MAGIX AG) Hidden
MAGIX Video deluxe Premium 2013 Update (Version: 12.0.4.2 - MAGIX AG) Hidden
Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
MediaInfo Lite 0.7.67 (HKLM-x32\...\mediainfolite_is1) (Version: 0.7.67 - )
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft-Maus- und Tastatur-Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.3.145.0 - Microsoft Corporation)
MKVToolNix 7.3.0 (32bit) (HKLM-x32\...\MKVToolNix) (Version: 7.3.0 - Moritz Bunkus)
Mobile Broadband HL Service (HKLM-x32\...\Mobile Broadband HL Service) (Version: 22.001.21.00.03 - Huawei Technologies Co.,Ltd)
MobileWiFi (HKLM-x32\...\MobileWiFi) (Version: 1.12.01.414 - Huawei Technologies Co.,Ltd)
MotioninJoy Gamepad tool 0.7.1001 (HKLM\...\{330DAC67-5B62-452A-A0E4-6B4A5923940F}_is1) (Version: 0.7.1001 - www.motioninjoy.com)
Mozilla Firefox 34.0.5 (x86 de) (HKLM-x32\...\Mozilla Firefox 34.0.5 (x86 de)) (Version: 34.0.5 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0 - Mozilla)
Mozilla Thunderbird 31.3.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 31.3.0 (x86 de)) (Version: 31.3.0 - Mozilla)
MP4Joiner v2.1.2 (HKLM-x32\...\MP4Joiner_is1) (Version: - )
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
Müller Foto (HKLM-x32\...\Müller Foto) (Version: 5.1.6 - CEWE Stiftung u Co. KGaA)
Mumble 1.2.8 (HKLM-x32\...\{1BC144A3-20EF-49DD-8EBB-E421E128E30F}) (Version: 1.2.8 - Thorvald Natvig)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.6.3 - Notepad++ Team)
NVIDIA PhysX (HKLM-x32\...\{80407BA7-7763-4395-AB98-5233F1B34E65}) (Version: 9.13.1220 - NVIDIA Corporation)
Opera Stable 26.0.1656.60 (HKLM-x32\...\Opera 26.0.1656.60) (Version: 26.0.1656.60 - Opera Software ASA)
Oracle VM VirtualBox 4.3.12 (HKLM\...\{B5121457-0126-4E62-BCBF-6DC7C73D9E4A}) (Version: 4.3.12 - Oracle Corporation)
osu! (HKLM-x32\...\{fa41bad7-36d6-4448-ad6f-5f94ec237ed9}) (Version: latest - ppy Pty Ltd)
paint.net (HKLM\...\{F509C1F4-0029-49F9-B145-A4C4E8DF481A}) (Version: 4.0.3 - dotPDN LLC)
PCMark 7 (HKLM-x32\...\{75C3C9C0-6CE6-42FA-A0E9-658E8F539124}) (Version: 1.4.0 - Futuremark)
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Radio.fx (HKLM-x32\...\Tobit Radio.fx Server) (Version: - Tobit.Software)
Raptr (HKLM-x32\...\Raptr) (Version: - )
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7023 - Realtek Semiconductor Corp.)
ROCCAT Kone Pure Mouse Driver (HKLM-x32\...\{4905245D-56E7-4176-BE68-962728B803D6}) (Version: - Roccat GmbH)
Samsung Magician (HKLM-x32\...\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 4.3.0 - Samsung Electronics)
Skype™ 6.22 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.22.107 - Skype Technologies S.A.)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
StepMania v5.0 beta 3 (Nur entfernen) (HKLM-x32\...\StepMania 5) (Version: - StepMania Team)
streamWriter (HKLM-x32\...\streamWriter_is1) (Version: - )
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.15 - TeamSpeak Systems GmbH)
TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.36244 - TeamViewer)
TERRATEC GRABSTER AV 300 MX (64 Bit) (HKLM-x32\...\{D2496882-4944-4E17-8292-371F7C560544}) (Version: 1.0.8.30 - TERRATEC)
TERRATEC GRABSTER AV 300 MX (HKLM-x32\...\{AF2E0639-F692-4281-910D-8357C3430488}) (Version: 1.0.8.30 - )
The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version: - Bethesda Game Studios)
The Last Remnant (HKLM-x32\...\Steam App 23310) (Version: - SQUARE ENIX)
Tomb Raider (HKLM-x32\...\Steam App 203160) (Version: - Crystal Dynamics)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft)
Uplay (HKLM-x32\...\Uplay) (Version: 4.2 - Ubisoft)
USB Sound Blaster HD (HKLM-x32\...\{3BE06146-8ADC-47D7-9AD5-E5CABF1FF90C}) (Version: 1.0 - Creative Technology Limited)
Vasco da Gama 6 HD MAGIX Edition (HKLM-x32\...\{9432F8D1-09C7-4C78-8F68-B163206698CD}) (Version: 6.50.0000 - MotionStudios)
VC_CRT_x64 (Version: 1.02.0000 - Intel Corporation) Hidden
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
Vegas Pro 13.0 (64-bit) (HKLM\...\{386F5740-091D-11E4-B13E-F04DA23A5C58}) (Version: 13.0.373 - Sony)
Video Essentials IV for Magix (HKLM-x32\...\NewBlue Video Essentials IV for Magix) (Version: 3.0 - NewBlue)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN)
vMix (HKLM-x32\...\{93D664E9-E81E-4277-9E90-6CDABAC7208F}_is1) (Version: - StudioCoast)
WD Drive Utilities (HKLM-x32\...\{59E0381C-1047-45A3-B68A-57F586EAF3C2}) (Version: 1.1.0.51 - Western Digital Technologies, Inc.)
WD Security (HKLM-x32\...\{D338102B-BA1C-4CCA-B870-8690FA0F0433}) (Version: 1.1.0.51 - Western Digital Technologies, Inc.)
WD SmartWare (HKLM\...\{B7063C41-A5D1-482D-BE07-34750B26950B}) (Version: 2.1.0.11 - Western Digital Technologies, Inc.)
Windows 7 USB/DVD Download Tool (HKLM-x32\...\{CCF298AF-9CE1-4B26-B251-486E98A34789}) (Version: 1.0.30 - Microsoft Corporation)
Windows-Treiberpaket - TERRATEC (SMIGrabber3C) Media (02/23/2013 1.0.8.30) (HKLM\...\7E9494FD65A61C4AF6762FC49C6917408E9D230E) (Version: 02/23/2013 1.0.8.30 - TERRATEC )
WinSCP 5.5.1 (HKLM-x32\...\winscp3_is1) (Version: 5.5.1 - Martin Prikryl)
X-Chat 2.8.6-2 (HKLM-x32\...\X-Chat 2_is1) (Version: 2.8.6-2 - SilvereX)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-1421196489-2289078169-999504329-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\***\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1421196489-2289078169-999504329-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\***\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1421196489-2289078169-999504329-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\***\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1421196489-2289078169-999504329-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\***\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1421196489-2289078169-999504329-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\***\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1421196489-2289078169-999504329-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\***\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1421196489-2289078169-999504329-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\***\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1421196489-2289078169-999504329-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\***\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1421196489-2289078169-999504329-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\***\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
==================== Restore Points =========================
23-12-2014 12:09:01 Windows Update
25-12-2014 16:30:29 ComboFix created restore point
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:34 - 2014-12-25 16:34 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {108BE584-EF13-4ECB-A057-37D1A0BD4F7C} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-09-04] (Microsoft Corporation)
Task: {2B27D381-1314-4053-9A50-200C0CA413D0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-02-14] (Google Inc.)
Task: {63F829FB-214F-43B6-861E-BB9CF0B4985D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-02-14] (Google Inc.)
Task: {7BCC8C2A-B3DC-4076-A2DC-D041B35193F6} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-09-04] (Microsoft Corporation)
Task: {9CF6D4DC-093D-4FA2-A05B-DADF37BE81BA} - System32\Tasks\avastBCLRestartS-1-5-21-1421196489-2289078169-999504329-1000 => Firefox.exe
Task: {A050BCE6-071B-4806-9CF6-F304FF773037} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-12] (Adobe Systems Incorporated)
Task: {B5AE8253-7E7D-47B0-9B8C-3580C8C37C5C} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {B8374FCC-560A-4E19-AD13-7C86423C9CE9} - System32\Tasks\Opera scheduled Autoupdate 1402420282 => E:\Program Files (x86)\Opera\launcher.exe [2014-12-17] (Opera Software)
Task: {C1F2473D-56B4-4747-8DE6-47774F798B36} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-09-04] (Microsoft Corporation)
Task: {C29E1C4E-24AC-452B-B31F-7A399C58B4FC} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2013-09-04] (Microsoft)
Task: {E0952636-3AA8-4CF2-A94A-D9E111B5ED3B} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-12-14] (AVAST Software)
Task: {E8D4A38A-4194-45C5-8060-AD7799D24E45} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-09-04] (Microsoft Corporation)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2014-04-24 18:41 - 2009-10-16 12:12 - 00177664 _____ () C:\Windows\system32\spool\PRTPROCS\x64\lxdxdrpp.dll
2014-02-14 14:51 - 2013-05-07 08:45 - 00936728 ____N () C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe
2013-04-10 06:58 - 2013-04-10 06:58 - 00351824 _____ () C:\ProgramData\DatacardService\HWDeviceService64.exe
2014-12-14 08:29 - 2014-12-14 08:29 - 00388208 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxDDU.dll
2014-12-14 08:29 - 2014-12-14 08:29 - 05851328 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxRT.dll
2014-05-01 20:29 - 2014-05-01 20:29 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
2014-12-26 10:31 - 2014-12-26 10:31 - 02908160 _____ () C:\Program Files\AVAST Software\Avast\defs\14122501\algo.dll
2014-12-14 08:29 - 2014-12-14 08:29 - 04495336 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\x86\VBoxRT-x86.dll
2014-02-14 14:51 - 2014-12-26 10:50 - 00031744 _____ () C:\Program Files (x86)\ASUS\AXSP\1.01.02\PEbiosinterface32.dll
2014-02-14 14:51 - 2013-05-07 08:45 - 00104448 ____N () C:\Program Files (x86)\ASUS\AXSP\1.01.02\ATKEX.dll
2014-10-22 01:22 - 2014-10-22 01:22 - 00750080 _____ () C:\Users\***\AppData\Roaming\Dropbox\bin\libGLESv2.dll
2014-12-26 10:50 - 2014-12-26 10:50 - 00043008 _____ () c:\users\***\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmplitpdw.dll
2014-10-22 01:22 - 2014-10-22 01:22 - 00047616 _____ () C:\Users\***\AppData\Roaming\Dropbox\bin\libEGL.dll
2014-10-22 01:22 - 2014-10-22 01:22 - 00863744 _____ () C:\Users\***\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll
2014-10-22 01:22 - 2014-10-22 01:22 - 00200704 _____ () C:\Users\***\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll
2014-12-14 08:29 - 2014-12-14 08:29 - 38562088 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-10-04 15:55 - 2012-06-23 13:54 - 00061440 _____ () C:\Program Files (x86)\ROCCAT\Kone Pure Mouse\hiddriver.dll
2014-09-04 06:22 - 2014-12-09 21:06 - 03758192 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
MSCONFIG\Services: FirebirdServerMAGIXInstance => 3
MSCONFIG\Services: Futuremark SystemInfo Service => 3
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: lxdx_device => 2
MSCONFIG\Services: Mobile Broadband HL Service => 2
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: Radio.fx => 2
MSCONFIG\Services: Steam Client Service => 3
MSCONFIG\startupfolder: C:^Users^***^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^GameRanger.lnk => C:\Windows\pss\GameRanger.lnk.Startup
MSCONFIG\startupfolder: C:^Users^***^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Samsung Magician.lnk => C:\Windows\pss\Samsung Magician.lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Amazon Music => "C:\Users\***\AppData\Local\Amazon Music\Amazon Music Helper.exe"
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: BDRegion => C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
MSCONFIG\startupreg: Creative SB Monitoring Utility => RunDll32 sbavmon.dll,SBAVMonitor
MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: DivXMediaServer => E:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
MSCONFIG\startupreg: DivXUpdate => "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
MSCONFIG\startupreg: DriveUtilitiesHelper => C:\Program Files (x86)\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe
MSCONFIG\startupreg: LGODDFU => C:\Program Files (x86)\lg_fwupdate\lgfw.exe blrun
MSCONFIG\startupreg: Mobile Partner => D:\Program Files (x86)\MobileWiFi\MobileWiFi
MSCONFIG\startupreg: Onboard => C:\Program Files\Western Digital\WD SmartWare\BackupTask.exe /Onboard "C:\Program Files\Western Digital\WD SmartWare\WDSmartWare.exe"
MSCONFIG\startupreg: Raptr => C:\PROGRA~2\Raptr\raptrstub.exe --startup
MSCONFIG\startupreg: RemoteControl10 => "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
MSCONFIG\startupreg: rfxsrvtray => "E:\Tobit Radio.fx\Client\rfx-tray.exe"
MSCONFIG\startupreg: Steam => "F:\Program Files (x86)\Steam\Steam.exe" -silent
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: USB3MON => "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
MSCONFIG\startupreg: VolPanel => "C:\Program Files (x86)\Creative\USB Sound Blaster HD\Volume Panel\VolPanlu.exe" /r
MSCONFIG\startupreg: WD Drive Unlocker => C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe
MSCONFIG\startupreg: WD Quick View => C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe
========================= Accounts: ==========================
Administrator (S-1-5-21-1421196489-2289078169-999504329-500 - Administrator - Disabled)
Gast (S-1-5-21-1421196489-2289078169-999504329-501 - Limited - Enabled)
HomeGroupUser$ (S-1-5-21-1421196489-2289078169-999504329-1006 - Limited - Enabled)
*** (S-1-5-21-1421196489-2289078169-999504329-1000 - Administrator - Enabled) => C:\Users\***
==================== Faulty Device Manager Devices =============
Name: VirtualBox Host-Only Ethernet Adapter
Description: VirtualBox Host-Only Ethernet Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Oracle Corporation
Service: VBoxNetAdp
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
Name: TeamViewer VPN Adapter
Description: TeamViewer VPN Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: TeamViewer GmbH
Service: teamviewervpn
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
System errors:
=============
Error: (12/26/2014 10:50:22 AM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: ComputerstandardLokalAktivierung{BC50CF2A-E12C-4F18-90CE-714CC8600CEE}{BC50CF2A-E12C-4F18-90CE-714CC8600CEE}NT-AUTORITÄTLOKALER DIENSTS-1-5-19LocalHost (unter Verwendung von LRPC)
Microsoft Office Sessions:
=========================
CodeIntegrity Errors:
===================================
Date: 2014-12-25 16:34:16.742
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-12-25 16:34:16.702
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
==================== Memory info ===========================
Processor: Intel(R) Xeon(R) CPU E3-1230 v3 @ 3.30GHz
Percentage of memory in use: 16%
Total physical RAM: 16321.54 MB
Available physical RAM: 13580.3 MB
Total Pagefile: 16519.72 MB
Available Pagefile: 13592.61 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:209.5 GB) (Free:134.32 GB) NTFS
Drive d: (daten) (Fixed) (Total:1863.01 GB) (Free:710.57 GB) NTFS
Drive e: (programme_eigene_dateien) (Fixed) (Total:244.04 GB) (Free:89.86 GB) NTFS
Drive f: (spiele) (Fixed) (Total:352.03 GB) (Free:222.34 GB) NTFS
Drive h: (NAUSICAAE_BD) (CDROM) (Total:40.72 GB) (Free:0 GB) UDF
Drive m: (Anime) (Fixed) (Total:2794.39 GB) (Free:1330.85 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: 2F61EB3F)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=209.5 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 42C28CC2)
Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS)
========================================================
Disk: 2 (MBR Code: Windows 7 or 8) (Size: 596.2 GB) (Disk ID: C5014FA9)
Partition 1: (Not Active) - (Size=244 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=352 GB) - (Type=07 NTFS)
========================================================
Disk: 3 (MBR Code: Windows 7 or 8) (Size: 2794.5 GB) (Disk ID: 00000000)
Partition: GPT Partition Type.
==================== End Of Log ============================ |