Yannick123 | 04.02.2015 00:15 | Code:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 23:39 on 03/02/2015 (YannickReinhard)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=- --------------------------------------
-------------------------------------
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-02-2015
Ran by YannickReinhard (administrator) on YANNICKREINHARD on 03-02-2015 23:41:09
Running from C:\Users\YannickReinhard\Downloads
Loaded Profiles: YannickReinhard (Available profiles: YannickReinhard)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(COMPANYVERS_NAME) C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hbarsvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(ClientConnect Ltd.) C:\Program Files (x86)\Tbccint\ToolbarService\ToolbarService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\AppIntegrator64.exe
(Logitech Inc.) C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe
(VER_COMPANY_NAME) C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hbrmon.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(SRWare) C:\Program Files (x86)\SRWare Iron\iron.exe
(SRWare) C:\Program Files (x86)\SRWare Iron\iron.exe
(SRWare) C:\Program Files (x86)\SRWare Iron\iron.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(SRWare) C:\Program Files (x86)\SRWare Iron\iron.exe
(SRWare) C:\Program Files (x86)\SRWare Iron\iron.exe
(SRWare) C:\Program Files (x86)\SRWare Iron\iron.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 11.0\Reader\reader_sl.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13307496 2011-10-17] (Realtek Semiconductor)
HKLM\...\Run: [Allin1Convert Home Page Guard 64 bit] => C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\AppIntegrator64.exe [548936 2013-11-14] ()
HKLM\...\Run: [Launch LGDCore] => C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe [1783296 2006-07-23] (Logitech Inc.)
HKLM\...\Run: [Launch LCDMon] => "C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe"
HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2201032 2014-04-02] (NVIDIA Corporation)
HKLM-x32\...\Run: [Allin1Convert Search Scope Monitor] => C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hSrchMn.exe [44784 2013-11-14] (MindSpark)
HKLM-x32\...\Run: [Allin1Convert_8h Browser Plugin Loader] => C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hbrmon.exe [30096 2013-11-14] (VER_COMPANY_NAME)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2014-10-11] (Apple Inc.)
HKLM-x32\...\Run: [mobilegeni daemon] => C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKU\S-1-5-21-325977285-756268544-3411964983-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [1942720 2015-01-23] (Valve Corporation)
HKU\S-1-5-21-325977285-756268544-3411964983-1000\...\Run: [BackgroundContainerV2] => "C:\Windows\SysWOW64\Rundll32.exe" "C:\Users\YannickReinhard\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun
AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC64Loader.dll [253200 2015-01-28] (Client Connect LTD)
AppInit_DLLs-x32: C:\PROGRA~2\SEARCH~1\SEARCH~1\bin\VC32LO~1.DLL => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC32Loader.dll [219408 2015-01-28] ()
Startup: C:\Users\YannickReinhard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-325977285-756268544-3411964983-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-325977285-756268544-3411964983-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-325977285-756268544-3411964983-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
URLSearchHook: HKLM-x32 - NCH DE Toolbar - {b106b661-3e1b-4015-af5c-195e909f35c6} - C:\Users\YannickReinhard\AppData\LocalLow\NCH_DE\prxtbNCH2.dll (ClientConnect Ltd.)
URLSearchHook: HKU\S-1-5-21-325977285-756268544-3411964983-1000 - NCH DE Toolbar - {b106b661-3e1b-4015-af5c-195e909f35c6} - C:\Users\YannickReinhard\AppData\LocalLow\NCH_DE\prxtbNCH2.dll (ClientConnect Ltd.)
SearchScopes: HKLM -> {114DB5FA-0AFB-BB92-A75B-F44D3CE875CD} URL =
SearchScopes: HKLM-x32 -> {75b4241f-171e-44a3-bf44-23613b6e3e03} URL = hxxp://search.tb.ask.com/search/GGmain.jhtml?p2=^AYY^xdm070^YYA^de&si=flvrunner&ptb=AF7953BD-D92E-4D4D-9A3F-40971FF16898&ind=2013111311&n=77fda40f&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKU\S-1-5-21-325977285-756268544-3411964983-1000 -> DefaultScope {114DB5FA-0AFB-BB92-A75B-F44D3CE875CD} URL = hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3317209&octid=EB_ORIGINAL_CTID&ISID=ME73D48B0-EF65-4E7D-98CF-43DBB00B02CF&SearchSource=58&CUI=&UM=2&UP=SP2EA375C4-4A2A-41C3-8522-0F347001456D&q={searchTerms}&SSPV=
SearchScopes: HKU\S-1-5-21-325977285-756268544-3411964983-1000 -> {114DB5FA-0AFB-BB92-A75B-F44D3CE875CD} URL = hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3317209&octid=EB_ORIGINAL_CTID&ISID=ME73D48B0-EF65-4E7D-98CF-43DBB00B02CF&SearchSource=58&CUI=&UM=2&UP=SP2EA375C4-4A2A-41C3-8522-0F347001456D&q={searchTerms}&SSPV=
SearchScopes: HKU\S-1-5-21-325977285-756268544-3411964983-1000 -> {75b4241f-171e-44a3-bf44-23613b6e3e03} URL = hxxp://search.tb.ask.com/search/GGmain.jhtml?p2=^AYY^xdm070^YYA^de&si=flvrunner&ptb=AF7953BD-D92E-4D4D-9A3F-40971FF16898&ind=2013111311&n=77fda40f&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKU\S-1-5-21-325977285-756268544-3411964983-1000 -> {78562654-82B7-482A-85FB-2FFAAC49BF89} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3282494&CUI=UN58544550624669758&UM=2
BHO: No Name -> {41564952-412D-5637-00A7-7A786E7484D7} -> No File
BHO: DVDVideoSoft IE Extension -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Search Assistant BHO -> {a4c2fb10-84c3-44eb-9f9e-860fa1d9a797} -> C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hSrcAs.dll (MindSpark)
BHO-x32: NCH DE Toolbar -> {b106b661-3e1b-4015-af5c-195e909f35c6} -> C:\Users\YannickReinhard\AppData\LocalLow\NCH_DE\prxtbNCH2.dll (ClientConnect Ltd.)
BHO-x32: DVDVideoSoft IE Extension -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
BHO-x32: Toolbar BHO -> {fbcbc43a-dca9-4192-a4c8-b57fd0f77d4d} -> C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hbar.dll (MindSpark)
Toolbar: HKLM-x32 - Allin1Convert - {cd1a63ba-a08c-431b-9a34-f240aadc728d} - C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hbar.dll (MindSpark)
Toolbar: HKLM-x32 - NCH DE Toolbar - {b106b661-3e1b-4015-af5c-195e909f35c6} - C:\Users\YannickReinhard\AppData\LocalLow\NCH_DE\prxtbNCH2.dll (ClientConnect Ltd.)
Toolbar: HKU\S-1-5-21-325977285-756268544-3411964983-1000 -> No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Toolbar: HKU\S-1-5-21-325977285-756268544-3411964983-1000 -> No Name - {B106B661-3E1B-4015-AF5C-195E909F35C6} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\YannickReinhard\AppData\Roaming\Mozilla\Firefox\Profiles\ono270ir.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_296.dll ()
FF Plugin: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll ()
FF Plugin-x32: @Allin1Convert_8h.com/Plugin -> C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\NP8hStub.dll (MindSpark)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-325977285-756268544-3411964983-1000: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.trovi.com/?gd=&ctid=CT3322288&octid=EB_ORIGINAL_CTID&ISID=ME73D48B0-EF65-4E7D-98CF-43DBB00B02CF&SearchSource=55&CUI=&UM=6&UP=SP2EA375C4-4A2A-41C3-8522-0F347001456D&SSPV=
CHR StartupUrls: Default -> "hxxp://www.trovi.com/?gd=&ctid=CT3322288&octid=EB_ORIGINAL_CTID&ISID=ME73D48B0-EF65-4E7D-98CF-43DBB00B02CF&SearchSource=55&CUI=&UM=6&UP=SP2EA375C4-4A2A-41C3-8522-0F347001456D&SSPV="
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\YannickReinhard\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\YannickReinhard\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-06-06]
CHR Extension: (Google Drive) - C:\Users\YannickReinhard\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-06]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\YannickReinhard\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-06]
CHR Extension: (YouTube) - C:\Users\YannickReinhard\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-06]
CHR Extension: (Google-Suche) - C:\Users\YannickReinhard\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-06]
CHR Extension: (Avira SafeSearch) - C:\Users\YannickReinhard\AppData\Local\Google\Chrome\User Data\Default\Extensions\eglgfnfolcgijipffhlhbbnefdcbjbml [2014-08-16]
CHR Extension: (Google Wallet) - C:\Users\YannickReinhard\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-06]
CHR Extension: (Google Mail) - C:\Users\YannickReinhard\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-06]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 Allin1Convert_8hService; C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\8hbarsvc.exe [44752 2013-11-14] (COMPANYVERS_NAME)
S3 BRSptStub; C:\ProgramData\BitRaider\BRSptStub.exe [363208 2015-01-22] (BitRaider, LLC)
U2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1615192 2014-04-02] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [20541216 2014-04-02] (NVIDIA Corporation)
R2 TBSrv; C:\Program Files (x86)\Tbccint\ToolbarService\ToolbarService.exe [350528 2014-09-23] (ClientConnect Ltd.)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2013-11-20] ()
S3 BRDriver64_1_3_3_E02B25FC; C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [78088 2015-01-23] (BitRaider)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2013-11-20] ()
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-21] (NVIDIA Corporation)
R3 RTL8192cu; C:\Windows\System32\DRIVERS\RTL8192cu.sys [926824 2012-10-25] (Realtek Semiconductor Corporation )
R3 SaiK1713; C:\Windows\System32\DRIVERS\SaiK1713.sys [180544 2012-09-20] (Saitek)
R3 SaiMini; C:\Windows\System32\DRIVERS\SaiMini.sys [25120 2013-04-30] (Saitek)
R3 SaiNtBus; C:\Windows\System32\drivers\SaiBus.sys [52640 2013-04-30] (Saitek)
R3 SaiU1713; C:\Windows\System32\DRIVERS\SaiU1713.sys [47168 2012-09-20] (Saitek)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 SPPD; \??\C:\Windows\system32\drivers\SPPD.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-03 23:41 - 2015-02-03 23:41 - 00017342 _____ () C:\Users\YannickReinhard\Downloads\FRST.txt
2015-02-03 23:40 - 2015-02-03 23:41 - 00000000 ____D () C:\FRST
2015-02-03 23:40 - 2015-02-03 23:40 - 02131456 _____ (Farbar) C:\Users\YannickReinhard\Downloads\FRST64.exe
2015-02-03 23:39 - 2015-02-03 23:39 - 00000492 _____ () C:\Users\YannickReinhard\Desktop\defogger_disable.log
2015-02-03 23:39 - 2015-02-03 23:39 - 00000000 _____ () C:\Users\YannickReinhard\defogger_reenable
2015-02-03 23:38 - 2015-02-03 23:38 - 00000264 _____ () C:\Users\YannickReinhard\Downloads\defogger_enable.log
2015-02-03 23:37 - 2015-02-03 23:37 - 00050477 _____ () C:\Users\YannickReinhard\Downloads\Defogger (1).exe
2015-02-03 23:37 - 2015-02-03 23:37 - 00000492 _____ () C:\Users\YannickReinhard\Downloads\defogger_disable.log
2015-02-03 23:36 - 2015-02-03 23:36 - 00050477 _____ () C:\Users\YannickReinhard\Desktop\Defogger.exe
2015-02-03 23:05 - 2015-02-03 23:22 - 00000000 ___SD () C:\ComboFix
2015-02-03 22:56 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-02-03 22:56 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-02-03 22:56 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-02-03 22:56 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-02-03 22:56 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-02-03 22:56 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2015-02-03 22:56 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2015-02-03 22:56 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2015-02-03 22:48 - 2015-02-03 23:18 - 00000000 ____D () C:\Windows\erdnt
2015-02-03 22:48 - 2015-02-03 22:56 - 00000000 ____D () C:\Qoobox
2015-02-03 22:46 - 2015-02-03 23:03 - 05611380 ____R (Swearware) C:\Users\YannickReinhard\Downloads\ComboFix.exe
2015-02-03 22:44 - 2015-02-03 22:47 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2015-02-03 22:43 - 2015-02-03 22:43 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\YannickReinhard\Downloads\revosetup95.exe
2015-02-03 22:38 - 2015-02-03 22:38 - 00028732 _____ () C:\Users\YannickReinhard\Downloads\Combo.txt
2015-02-03 16:07 - 2015-02-03 16:35 - 00000000 ____D () C:\Users\YannickReinhard\AppData\Local\Conduit
2015-02-03 16:07 - 2015-02-03 16:07 - 00000000 ____D () C:\Program Files (x86)\Tbccint
2015-02-03 16:06 - 2015-02-03 16:06 - 00000000 ____D () C:\Users\YannickReinhard\AppData\Local\IAC
2015-02-03 15:40 - 2015-02-03 22:58 - 00000328 _____ () C:\Windows\Tasks\FreeFixer background scan.job
2015-02-03 15:40 - 2015-02-03 22:25 - 00000000 ____D () C:\Users\YannickReinhard\AppData\Roaming\FreeFixer
2015-02-03 15:40 - 2015-02-03 15:55 - 00000000 ____D () C:\Users\YannickReinhard\AppData\Local\FreeFixer
2015-02-03 15:40 - 2015-02-03 15:40 - 00003012 _____ () C:\Windows\System32\Tasks\FreeFixer background scan
2015-02-03 15:40 - 2015-02-03 15:40 - 00000000 ____D () C:\Users\YannickReinhard\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FreeFixer
2015-02-03 15:40 - 2015-02-03 15:40 - 00000000 ____D () C:\Program Files\FreeFixer
2015-02-03 15:39 - 2015-02-03 15:39 - 02666167 _____ (Kephyr) C:\Users\YannickReinhard\Downloads\freefixersetup1.12.exe
2015-02-03 11:52 - 2015-02-03 11:52 - 00001254 _____ () C:\Users\Public\Desktop\World of Warcraft.lnk
2015-02-03 11:20 - 2015-02-03 11:20 - 00001118 _____ () C:\Users\Public\Desktop\Battle.net.lnk
2015-02-03 11:20 - 2015-02-03 11:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
2015-02-03 11:20 - 2015-02-03 11:20 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2015-02-03 11:18 - 2015-02-03 11:18 - 02942368 _____ (Blizzard Entertainment) C:\Users\YannickReinhard\Downloads\World-of-Warcraft-Setup-deDE (1).exe
2015-02-03 11:15 - 2015-02-03 11:15 - 00010409 _____ () C:\Users\YannickReinhard\Documents\Uninstall STAR WARS The Old Republic.log
2015-02-03 11:07 - 2015-02-03 11:11 - 00000000 ____D () C:\Users\YannickReinhard\Desktop\Addons
2015-02-03 10:49 - 2015-02-03 10:49 - 00003550 _____ () C:\Windows\System32\Tasks\avaxvavya
2015-02-03 10:49 - 2015-02-03 10:49 - 00000000 ____D () C:\Users\YannickReinhard\AppData\Local\avaxvavya
2015-02-02 11:27 - 2015-02-02 11:27 - 00194217 _____ () C:\Users\YannickReinhard\Downloads\RCLootCouncil-1.7.0.zip
2015-01-22 23:22 - 2015-01-22 23:22 - 00000000 ____D () C:\Users\YannickReinhard\AppData\Local\SWTORPerf
2015-01-22 23:22 - 2015-01-22 23:22 - 00000000 ____D () C:\Users\Public\Documents\BitRaider
2015-01-22 23:22 - 2015-01-22 23:22 - 00000000 ____D () C:\ProgramData\BitRaider
2015-01-22 23:21 - 2015-01-22 23:21 - 00017360 _____ () C:\Users\YannickReinhard\Documents\Install STAR WARS The Old Republic.log
2015-01-22 23:21 - 2015-01-22 23:21 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts
2015-01-22 23:20 - 2015-01-22 23:20 - 29720272 _____ () C:\Users\YannickReinhard\Downloads\SWTOR_setup.exe
2015-01-15 22:30 - 2015-01-15 22:30 - 00013946 _____ () C:\Users\YannickReinhard\Downloads\TargetCharms (2).zip
2015-01-15 22:29 - 2015-01-15 22:29 - 00390145 _____ () C:\Users\YannickReinhard\Downloads\Recount-v6.0.3h_release.zip
2015-01-15 21:58 - 2015-01-15 21:58 - 00689258 _____ () C:\Users\YannickReinhard\Downloads\TidyPlates_6_15_3.zip
2015-01-15 20:45 - 2015-01-15 20:45 - 00577251 _____ () C:\Users\YannickReinhard\Downloads\Skada-1.4-27.zip
2015-01-14 09:59 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-14 09:59 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-14 09:59 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-14 09:59 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-01-14 09:59 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-01-14 09:59 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-01-14 09:59 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-01-14 09:59 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-01-14 09:59 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-01-14 09:59 - 2014-12-11 18:47 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-14 09:59 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-14 09:59 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-01-14 09:59 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-03 23:39 - 2013-11-13 23:33 - 00000000 ____D () C:\Users\YannickReinhard
2015-02-03 23:36 - 2009-07-14 05:45 - 00035136 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-03 23:36 - 2009-07-14 05:45 - 00035136 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-03 23:32 - 2013-11-13 23:27 - 01331501 _____ () C:\Windows\WindowsUpdate.log
2015-02-03 23:29 - 2014-10-10 19:54 - 00000000 ____D () C:\Users\YannickReinhard\AppData\Local\Deployment
2015-02-03 23:28 - 2014-06-06 00:16 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-03 23:28 - 2013-11-14 21:44 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-02-03 23:28 - 2013-11-13 23:49 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-02-03 23:28 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-03 23:28 - 2009-07-14 05:51 - 00229777 _____ () C:\Windows\setupact.log
2015-02-03 23:27 - 2014-10-10 19:54 - 00000000 ____D () C:\Users\YannickReinhard\AppData\Local\Apps\2.0
2015-02-03 23:19 - 2010-11-21 04:47 - 00292490 _____ () C:\Windows\PFRO.log
2015-02-03 23:18 - 2009-07-14 03:34 - 71565312 _____ () C:\Windows\system32\config\SOFTWARE.bak
2015-02-03 23:18 - 2009-07-14 03:34 - 19922944 _____ () C:\Windows\system32\config\SYSTEM.bak
2015-02-03 23:18 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak
2015-02-03 23:18 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\SAM.bak
2015-02-03 23:18 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\DEFAULT.bak
2015-02-03 23:17 - 2013-11-14 21:40 - 00000000 ____D () C:\Program Files (x86)\SearchProtect
2015-02-03 22:58 - 2013-11-23 11:15 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2015-02-03 22:55 - 2013-11-23 11:16 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2015-02-03 22:53 - 2013-11-14 00:43 - 00000000 ____D () C:\Program Files (x86)\Avira
2015-02-03 22:50 - 2014-06-06 00:16 - 00002175 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-02-03 22:50 - 2014-06-06 00:16 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-03 22:40 - 2014-08-25 21:55 - 00000000 ____D () C:\Users\YannickReinhard\AppData\Local\Battle.net
2015-02-03 22:29 - 2013-11-14 21:35 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-02-03 15:52 - 2013-11-14 22:44 - 00000000 ____D () C:\Program Files (x86)\World of Warcraft
2015-02-03 11:15 - 2009-07-14 06:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-02-02 20:21 - 2013-11-15 14:37 - 00000000 ____D () C:\Users\YannickReinhard\AppData\Roaming\TS3Client
2015-01-30 11:40 - 2014-12-29 22:11 - 00000000 ____D () C:\Users\YannickReinhard\AppData\Roaming\SimulationCraft
2015-01-24 22:29 - 2013-11-14 21:35 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-01-24 22:29 - 2013-11-14 21:35 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-24 22:29 - 2013-11-14 21:35 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-01-19 18:27 - 2014-01-19 21:03 - 00000000 ____D () C:\Windows\Minidump
2015-01-19 18:26 - 2014-01-19 21:03 - 743294109 _____ () C:\Windows\MEMORY.DMP
2015-01-14 12:15 - 2013-11-24 10:09 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-14 12:09 - 2013-11-24 10:09 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-12 09:52 - 2014-11-26 17:09 - 00000000 ____D () C:\Users\YannickReinhard\Documents\Bewerbungen
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-01-24 11:10
==================== End Of Log ============================ --- --- ---
-------------------------------
------------------------------- Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-02-2015
Ran by YannickReinhard at 2015-02-03 23:41:53
Running from C:\Users\YannickReinhard\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.296 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Allin1Convert Internet Explorer Toolbar (HKLM-x32\...\Allin1Convert_8hbar Uninstall Internet Explorer) (Version: - Mindspark Interactive Network) <==== ATTENTION
AMD Catalyst Install Manager (HKLM\...\{A00CC809-7137-B31B-D13D-401DA7BD962F}) (Version: 3.0.868.0 - Advanced Micro Devices, Inc.)
Apple Application Support (HKLM-x32\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
Belkin Connect Wireless USB Adapter (HKLM-x32\...\InstallShield_{08B73C99-D071-488F-8861-5DDA897C510D}) (Version: 1.0.0.3 - Belkin)
Belkin Connect Wireless USB Adapter (x32 Version: 1.0.0.3 - Belkin) Hidden
BitRaider Streaming Client (HKLM-x32\...\BitRaider Streaming Client) (Version: 1.3.3.4098 - BitRaider, LLC)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Call of Duty: Modern Warfare 2 - Multiplayer (HKLM-x32\...\Steam App 10190) (Version: - Infinity Ward)
Call of Duty: Modern Warfare 2 (HKLM-x32\...\Steam App 10180) (Version: - Infinity Ward)
Curse Client (HKU\S-1-5-21-325977285-756268544-3411964983-1000\...\101a9f93b8f0bb6f) (Version: 5.1.1.820 - Curse)
Etron USB3.0 Host Controller (HKLM-x32\...\InstallShield_{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}) (Version: 0.115 - Etron Technology)
Etron USB3.0 Host Controller (x32 Version: 0.115 - Etron Technology) Hidden
Free YouTube to MP3 Converter version 3.12.50.1122 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.50.1122 - DVDVideoSoft Ltd.)
FreeFixer (HKLM-x32\...\FreeFixer1.12) (Version: 1.12 - Kephyr)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 40.0.2214.94 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
iTunes (HKLM\...\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.)
Logitech G11 Keyboard Software 1.03 (HKLM\...\{59427B1F-852F-4AF1-8215-E5B12F966D89}) (Version: 1.3.166.0 - Logitech)
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISER) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{14297226-E0A0-3781-8911-E9D529552663}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
NCH DE Toolbar for IE (HKLM-x32\...\IECT3282494) (Version: 6.16.2.2 - NCH DE)
NVIDIA 3D Vision Controller-Treiber 335.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 335.21 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.0 - NVIDIA Corporation)
NVIDIA Grafiktreiber 335.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 335.23 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.30.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\...\{80407BA7-7763-4395-AB98-5233F1B34E65}) (Version: 9.13.1220 - NVIDIA Corporation)
NVIDIA Stereoscopic 3D Driver (HKLM-x32\...\NVIDIAStereo) (Version: 7.17.13.3523 - NVIDIA Corporation)
Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.7 - Pando Networks Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.44.421.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6482 - Realtek Semiconductor Corp.)
Risen 3 - Titan Lords (HKLM-x32\...\Steam App 249230) (Version: - Piranha Bytes)
Search Protect (HKLM-x32\...\SearchProtect) (Version: 2.20.2.12 - Client Connect LTD) <==== ATTENTION
SHIELD Streaming (Version: 1.8.323 - NVIDIA Corporation) Hidden
Simulationcraft(x64) version 6.0.3.20 (HKLM-x32\...\{AC025546-B7C5-45A7-B16A-80AE482CBB01}_is1) (Version: 6.0.3.20 - Simulationcraft)
SRWare Iron Version SRWare Iron 30.0.1650.0 (HKLM-x32\...\{C59CF2CE-B302-4833-AA35-E0E07D8EBC52}_is1) (Version: SRWare Iron 30.0.1650.0 - SRWare)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
Stronghold 3 (HKLM-x32\...\Steam App 47400) (Version: - FireFly Studios)
Stronghold Crusader 2 (HKLM-x32\...\Steam App 232890) (Version: - FireFly Studios)
Stronghold HD (HKLM-x32\...\Steam App 40950) (Version: - FireFly Studios)
TeamSpeak 3 Client (HKU\S-1-5-21-325977285-756268544-3411964983-1000\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
The Cursed Crusade (HKLM-x32\...\Steam App 106000) (Version: - Kylotonn Entertainment)
TP-LINK 300Mbps Wireless USB Adapter Treiber (HKLM-x32\...\{852E893E-E4FD-45BB-8B17-72ADDF686974}) (Version: 1.3.1 - TP-LINK)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISER_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft)
Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISER_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version: - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISER_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISER_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft)
VideoPad Videobearbeitungs-Software (HKLM-x32\...\VideoPad) (Version: - NCH Software)
World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-325977285-756268544-3411964983-1000_Classes\CLSID\{ae793a71-8a15-49b2-a212-25c89feb72ba}\InprocServer32 -> C:\Windows\system32\dfshim.dll (Microsoft Corporation)
==================== Restore Points =========================
26-01-2015 21:11:37 Geplanter Prüfpunkt
01-02-2015 19:00:06 Windows-Sicherung
03-02-2015 22:55:31 Windows Update
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:34 - 2015-02-03 23:18 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {229D6F8B-1555-47B6-8C33-99A0D189DA5E} - System32\Tasks\FreeFixer background scan => C:\Program Files\FreeFixer\freefixer.exe [2014-09-16] (Kephyr)
Task: {2DE42C54-E20B-49F3-B5BE-D6FC2E6425BD} - System32\Tasks\{D3207EF2-90BB-4F02-8BA1-A7F5906CE20A} => C:\Users\YannickReinhard\Downloads\midway_riseandfall.exe [2014-02-08] ()
Task: {4FB6F067-431C-438C-BBF8-4D52B96F029D} - System32\Tasks\{36A5AE87-EA05-411E-8597-E95176331FD0} => pcalua.exe -a C:\Users\YannickReinhard\Downloads\Range_MMO7_SD7_0_20_0_64Bit_Drivers.exe -d C:\Users\YannickReinhard\Downloads
Task: {694C9013-CC35-4B6C-9214-DF1B9490909C} - System32\Tasks\{18F2FDEE-A72A-4FB8-A264-313DB8DEF5E1} => pcalua.exe -a C:\Users\YannickReinhard\Downloads\midway_riseandfall.exe -d C:\Users\YannickReinhard\Downloads
Task: {7CCC0E7D-044C-4833-8722-59A4951837E6} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {93729F85-7B01-425C-8C86-8563C12C6661} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-24] (Adobe Systems Incorporated)
Task: {A86AE4CE-2D0F-4DDA-BBAD-35C58D557386} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-06-06] (Google Inc.)
Task: {AB4B4BAF-1C4C-43A2-9DDA-F567B6906139} - System32\Tasks\{96156D6C-36D9-413C-9D18-675E46A37772} => pcalua.exe -a C:\Users\YannickReinhard\Downloads\Range_MMO7_SD7_0_20_0_32Bit_Drivers.exe -d C:\Users\YannickReinhard\Downloads
Task: {C143452C-F82C-471A-BC66-E161407CD1C4} - System32\Tasks\{C5B1863E-54D5-473F-8A6D-1C74F9955A0D} => pcalua.exe -a "C:\Users\YannickReinhard\Downloads\midway_riseandfall (1).exe"
Task: {D1E52366-EF71-498B-B2C5-3D4F9B3B6F92} - System32\Tasks\avaxvavya => C:\Users\YannickReinhard\AppData\Local\avaxvavya\avaxvavya.exe [2015-01-28] ()
Task: {D610575F-53D6-4491-A38D-580EAD2E88F3} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {D9D70F11-4E91-4D75-AA4F-5CD52B5EFC4D} - System32\Tasks\{3FF9624A-8C76-41B2-93D6-98BFB9D4755D} => C:\Users\YannickReinhard\Downloads\midway_riseandfall.exe [2014-02-08] ()
Task: {EA040439-442B-40C8-81DD-A904131AF985} - System32\Tasks\{B345773F-69CD-4587-9776-499F9B8B01FF} => C:\Users\YannickReinhard\Downloads\midway_riseandfall.exe [2014-02-08] ()
Task: {EEF73241-27C6-40D1-B1B9-5B4B1692C074} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-06-06] (Google Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FreeFixer background scan.job => C:\Program Files\FreeFixer\freefixer.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2013-11-13 23:49 - 2014-03-04 14:05 - 00116056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2013-11-14 00:34 - 2013-11-14 00:34 - 00292424 _____ () C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\AppIntegratorStub64.dll
2013-11-14 00:34 - 2013-11-14 00:34 - 00548936 _____ () C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\AppIntegrator64.exe
2013-11-14 00:34 - 2013-11-14 00:34 - 00442952 _____ () C:\Program Files (x86)\Allin1Convert_8h\bar\1.bin\HPG64.DLL
2014-01-20 13:17 - 2014-01-20 13:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 12:05 - 2014-10-11 12:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2014-08-29 13:55 - 2014-12-01 22:31 - 02396672 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
2014-08-29 13:55 - 2014-12-01 22:31 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
2014-08-29 13:55 - 2014-12-01 22:31 - 00479744 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
2014-08-29 13:55 - 2014-12-01 22:31 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
2013-10-24 09:45 - 2014-11-11 19:47 - 00774656 _____ () C:\Program Files (x86)\Steam\SDL2.dll
2015-01-20 09:48 - 2014-12-02 01:29 - 05002752 _____ () C:\Program Files (x86)\Steam\v8.dll
2015-01-20 09:48 - 2014-12-02 01:29 - 01612800 _____ () C:\Program Files (x86)\Steam\icui18n.dll
2015-01-20 09:48 - 2014-12-02 01:29 - 01210368 _____ () C:\Program Files (x86)\Steam\icuuc.dll
2014-05-22 09:48 - 2015-01-23 23:34 - 02227904 _____ () C:\Program Files (x86)\Steam\video.dll
2014-08-29 13:55 - 2014-12-01 22:31 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
2013-10-30 11:25 - 2015-01-23 23:33 - 00696512 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
2013-10-23 12:07 - 2015-01-16 00:42 - 34641288 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll
2013-11-14 00:36 - 2013-10-05 21:22 - 00875008 _____ () C:\Program Files (x86)\SRWare Iron\libglesv2.dll
2013-11-14 00:36 - 2013-10-05 21:25 - 00102912 _____ () C:\Program Files (x86)\SRWare Iron\libegl.dll
2013-11-14 00:36 - 2013-10-05 20:12 - 00861696 _____ () C:\Program Files (x86)\SRWare Iron\ffmpegsumo.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
========================= Accounts: ==========================
Administrator (S-1-5-21-325977285-756268544-3411964983-500 - Administrator - Disabled)
Gast (S-1-5-21-325977285-756268544-3411964983-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-325977285-756268544-3411964983-1003 - Limited - Enabled)
YannickReinhard (S-1-5-21-325977285-756268544-3411964983-1000 - Administrator - Enabled) => C:\Users\YannickReinhard
==================== Faulty Device Manager Devices =============
Name: Programmable Root Enumerator
Description: Programming Support
Class Guid: {678dcf40-e2e6-11d5-8cd5-e960089ea00a}
Manufacturer: Mad Catz
Service: SaiNtBus
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver
==================== Event log errors: =========================
Application errors:
==================
Error: (02/03/2015 11:30:04 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/03/2015 11:21:03 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/03/2015 10:59:47 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/03/2015 05:08:02 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 16193
Error: (02/03/2015 05:08:02 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 16193
Error: (02/03/2015 05:08:02 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (02/03/2015 05:08:01 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15194
Error: (02/03/2015 05:08:01 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 15194
Error: (02/03/2015 05:08:01 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (02/03/2015 05:08:00 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 14196
System errors:
=============
Error: (02/03/2015 11:28:23 PM) (Source: Microsoft-Windows-TaskScheduler) (EventID: 413) (User: NT-AUTORITÄT)
Description: Beim Start des Aufgabenplanungsdiensts konnten Aufgaben nicht geladen werden. Zusätzliche Daten: Fehlerwert: 2147549183.
Error: (02/03/2015 11:28:22 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden.
Modulpfad: C:\Windows\system32\Rtlihvs.dll
Fehlercode: 126
Error: (02/03/2015 11:19:22 PM) (Source: Microsoft-Windows-TaskScheduler) (EventID: 413) (User: NT-AUTORITÄT)
Description: Beim Start des Aufgabenplanungsdiensts konnten Aufgaben nicht geladen werden. Zusätzliche Daten: Fehlerwert: 2147549183.
Error: (02/03/2015 11:19:21 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden.
Modulpfad: C:\Windows\system32\Rtlihvs.dll
Fehlercode: 126
Error: (02/03/2015 11:18:29 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (02/03/2015 11:18:24 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (02/03/2015 11:17:39 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: Aufgrund der Inkompatibilität mit diesem System wurde \??\C:\ComboFix\catchme.sys nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten.
Error: (02/03/2015 11:15:21 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (02/03/2015 10:58:15 PM) (Source: Microsoft-Windows-TaskScheduler) (EventID: 413) (User: NT-AUTORITÄT)
Description: Beim Start des Aufgabenplanungsdiensts konnten Aufgaben nicht geladen werden. Zusätzliche Daten: Fehlerwert: 2147549183.
Error: (02/03/2015 10:58:13 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden.
Modulpfad: C:\Windows\system32\Rtlihvs.dll
Fehlercode: 126
Microsoft Office Sessions:
=========================
CodeIntegrity Errors:
===================================
Date: 2015-02-03 23:17:39.016
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2015-02-03 23:17:38.990
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
==================== Memory info ===========================
Processor: AMD FX(tm)-6350 Six-Core Processor
Percentage of memory in use: 26%
Total physical RAM: 8148.74 MB
Available physical RAM: 6021.17 MB
Total Pagefile: 16295.66 MB
Available Pagefile: 13926.22 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:931.41 GB) (Free:716.51 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 04E7F4E0)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS)
==================== End Of Log ============================
-------------------------------
------------------------------- Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-02-03 23:52:22
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\00000063 ST1000LM rev.2AR1 931,51GB
Running: Gmer-19357.exe; Driver: C:\Users\YANNIC~1\AppData\Local\Temp\uxxdqpow.sys
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\Steam\Steam.exe[1652] C:\Windows\syswow64\psapi.dll!GetModuleFileNameExW + 17 0000000075921401 2 bytes JMP 7767b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Steam\Steam.exe[1652] C:\Windows\syswow64\psapi.dll!EnumProcessModules + 17 0000000075921419 2 bytes JMP 7767b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Steam\Steam.exe[1652] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 17 0000000075921431 2 bytes JMP 776f8ea9 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Steam\Steam.exe[1652] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 42 000000007592144a 2 bytes CALL 776548ad C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Steam\Steam.exe[1652] C:\Windows\syswow64\psapi.dll!EnumDeviceDrivers + 17 00000000759214dd 2 bytes JMP 776f87a2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Steam\Steam.exe[1652] C:\Windows\syswow64\psapi.dll!GetDeviceDriverBaseNameA + 17 00000000759214f5 2 bytes JMP 776f8978 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Steam\Steam.exe[1652] C:\Windows\syswow64\psapi.dll!QueryWorkingSetEx + 17 000000007592150d 2 bytes JMP 776f8698 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Steam\Steam.exe[1652] C:\Windows\syswow64\psapi.dll!GetDeviceDriverBaseNameW + 17 0000000075921525 2 bytes JMP 776f8a62 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Steam\Steam.exe[1652] C:\Windows\syswow64\psapi.dll!GetModuleBaseNameW + 17 000000007592153d 2 bytes JMP 7766fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Steam\Steam.exe[1652] C:\Windows\syswow64\psapi.dll!EnumProcesses + 17 0000000075921555 2 bytes JMP 776768ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Steam\Steam.exe[1652] C:\Windows\syswow64\psapi.dll!GetProcessMemoryInfo + 17 000000007592156d 2 bytes JMP 776f8f61 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Steam\Steam.exe[1652] C:\Windows\syswow64\psapi.dll!GetPerformanceInfo + 17 0000000075921585 2 bytes JMP 776f8ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Steam\Steam.exe[1652] C:\Windows\syswow64\psapi.dll!QueryWorkingSet + 17 000000007592159d 2 bytes JMP 776f865c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Steam\Steam.exe[1652] C:\Windows\syswow64\psapi.dll!GetModuleBaseNameA + 17 00000000759215b5 2 bytes JMP 7766fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Steam\Steam.exe[1652] C:\Windows\syswow64\psapi.dll!GetModuleFileNameExA + 17 00000000759215cd 2 bytes JMP 7767b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Steam\Steam.exe[1652] C:\Windows\syswow64\psapi.dll!GetProcessImageFileNameW + 20 00000000759216b2 2 bytes JMP 776f8e24 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Steam\Steam.exe[1652] C:\Windows\syswow64\psapi.dll!GetProcessImageFileNameW + 31 00000000759216bd 2 bytes JMP 776f85f1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Steam\bin\steamwebhelper.exe[3692] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075921401 2 bytes JMP 7767b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Steam\bin\steamwebhelper.exe[3692] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075921419 2 bytes JMP 7767b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Steam\bin\steamwebhelper.exe[3692] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075921431 2 bytes JMP 776f8ea9 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Steam\bin\steamwebhelper.exe[3692] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007592144a 2 bytes CALL 776548ad C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Steam\bin\steamwebhelper.exe[3692] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000759214dd 2 bytes JMP 776f87a2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Steam\bin\steamwebhelper.exe[3692] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000759214f5 2 bytes JMP 776f8978 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Steam\bin\steamwebhelper.exe[3692] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007592150d 2 bytes JMP 776f8698 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Steam\bin\steamwebhelper.exe[3692] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075921525 2 bytes JMP 776f8a62 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Steam\bin\steamwebhelper.exe[3692] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007592153d 2 bytes JMP 7766fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Steam\bin\steamwebhelper.exe[3692] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075921555 2 bytes JMP 776768ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Steam\bin\steamwebhelper.exe[3692] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007592156d 2 bytes JMP 776f8f61 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Steam\bin\steamwebhelper.exe[3692] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075921585 2 bytes JMP 776f8ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Steam\bin\steamwebhelper.exe[3692] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007592159d 2 bytes JMP 776f865c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Steam\bin\steamwebhelper.exe[3692] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000759215b5 2 bytes JMP 7766fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Steam\bin\steamwebhelper.exe[3692] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000759215cd 2 bytes JMP 7767b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Steam\bin\steamwebhelper.exe[3692] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000759216b2 2 bytes JMP 776f8e24 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Steam\bin\steamwebhelper.exe[3692] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000759216bd 2 bytes JMP 776f85f1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3992] C:\Windows\syswow64\psapi.dll!GetModuleFileNameExW + 17 0000000075921401 2 bytes JMP 7767b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3992] C:\Windows\syswow64\psapi.dll!EnumProcessModules + 17 0000000075921419 2 bytes JMP 7767b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3992] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 17 0000000075921431 2 bytes JMP 776f8ea9 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3992] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 42 000000007592144a 2 bytes CALL 776548ad C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3992] C:\Windows\syswow64\psapi.dll!EnumDeviceDrivers + 17 00000000759214dd 2 bytes JMP 776f87a2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3992] C:\Windows\syswow64\psapi.dll!GetDeviceDriverBaseNameA + 17 00000000759214f5 2 bytes JMP 776f8978 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3992] C:\Windows\syswow64\psapi.dll!QueryWorkingSetEx + 17 000000007592150d 2 bytes JMP 776f8698 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3992] C:\Windows\syswow64\psapi.dll!GetDeviceDriverBaseNameW + 17 0000000075921525 2 bytes JMP 776f8a62 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3992] C:\Windows\syswow64\psapi.dll!GetModuleBaseNameW + 17 000000007592153d 2 bytes JMP 7766fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3992] C:\Windows\syswow64\psapi.dll!EnumProcesses + 17 0000000075921555 2 bytes JMP 776768ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3992] C:\Windows\syswow64\psapi.dll!GetProcessMemoryInfo + 17 000000007592156d 2 bytes JMP 776f8f61 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3992] C:\Windows\syswow64\psapi.dll!GetPerformanceInfo + 17 0000000075921585 2 bytes JMP 776f8ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3992] C:\Windows\syswow64\psapi.dll!QueryWorkingSet + 17 000000007592159d 2 bytes JMP 776f865c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3992] C:\Windows\syswow64\psapi.dll!GetModuleBaseNameA + 17 00000000759215b5 2 bytes JMP 7766fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3992] C:\Windows\syswow64\psapi.dll!GetModuleFileNameExA + 17 00000000759215cd 2 bytes JMP 7767b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3992] C:\Windows\syswow64\psapi.dll!GetProcessImageFileNameW + 20 00000000759216b2 2 bytes JMP 776f8e24 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[3992] C:\Windows\syswow64\psapi.dll!GetProcessImageFileNameW + 31 00000000759216bd 2 bytes JMP 776f85f1 C:\Windows\syswow64\kernel32.dll
---- Threads - GMER 2.1 ----
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [5104:4804] 000007fefb752bf8
---- EOF - GMER 2.1 ---- |