der FRST log war zu lang, ich habe ihn als FRST.RAR angefügt. Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 16-05-2015 02
Ran by Erkan PC at 2015-05-19 14:46:43
Running from C:\Users\Erkan PC\Desktop
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-3241844552-6420410-4097038991-500 - Administrator - Disabled)
Erkan PC (S-1-5-21-3241844552-6420410-4097038991-1002 - Administrator - Enabled) => C:\Users\Erkan PC
Gast (S-1-5-21-3241844552-6420410-4097038991-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3241844552-6420410-4097038991-1004 - Limited - Enabled)
UpdatusUser (S-1-5-21-3241844552-6420410-4097038991-1001 - Limited - Enabled) => C:\Users\UpdatusUser
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avira Antivirus (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avira Antivirus (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Acer Backup Manager (HKLM-x32\...\InstallShield_{9DDDF20E-9FD1-4434-A43E-E7889DBC9420}) (Version: 4.0.0.0071 - NTI Corporation)
Acer Instant Update Service (HKLM\...\{8215A318-CC27-435E-B3EA-2E3443C8998C}) (Version: 1.00.3013 - Acer Incorporated)
Acer Power Management (HKLM\...\{91F52DE4-B789-42B0-9311-A349F10E5479}) (Version: 7.00.3011 - Acer Incorporated)
Acer Recovery Management (HKLM\...\{07F2005A-8CAC-4A4B-83A2-DA98A722CA61}) (Version: 6.00.3015 - Acer Incorporated)
AcerCloud (HKLM-x32\...\{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}) (Version: 2.01.3125 - Acer Incorporated)
AcerCloud Docs (HKLM-x32\...\{CA4FE8B0-298C-4E5D-A486-F33B126D6A0A}) (Version: 1.00.3204 - Acer Incorporated)
Adobe Acrobat 9 Pro Extended - English, Français, Deutsch (HKLM-x32\...\{AC76BA86-1033-F400-7761-000000000004}{AC76BA86-1033-F400-7761-000000000004}) (Version: 9.0.0 - Adobe Systems)
Adobe Acrobat 9 Pro Extended 64-bit Add-On (HKLM\...\{AC76BA86-1033-0000-0064-0003D0000004}) (Version: 9.0.0 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Apple Application Support (32-Bit) (HKLM-x32\...\{447CDCE5-F555-429B-BFA6-642C3C6D684F}) (Version: 3.1.2 - Apple Inc.)
Apple Application Support (64-Bit) (HKLM\...\{0DF7096B-715A-4233-8633-C7A16ED6D616}) (Version: 3.1.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: 8.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Avira (HKLM-x32\...\{b5675cc4-ab8b-4945-8c1d-4c5479556d6a}) (Version: 1.1.34.19732 - Avira Operations GmbH & Co. KG)
Avira (x32 Version: 1.1.34.19732 - Avira Operations GmbH & Co. KG) Hidden
Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.10.434 - Avira Operations GmbH & Co. KG)
Backup Manager v4 (x32 Version: 4.0.0.0071 - NTI Corporation) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Cisco AnyConnect Secure Mobility Client (HKLM-x32\...\Cisco AnyConnect Secure Mobility Client) (Version: 3.1.06073 - Cisco Systems, Inc.)
Cisco AnyConnect Secure Mobility Client (x32 Version: 3.1.06073 - Cisco Systems, Inc.) Hidden
clear.fi Media (HKLM-x32\...\{E9AF1707-3F3A-49E2-8345-4F2D629D0876}) (Version: 2.01.3112 - Acer Incorporated)
clear.fi Photo (HKLM-x32\...\{B5AD89F2-03D3-4206-8487-018298007DD0}) (Version: 2.01.3109 - Acer Incorporated)
clear.fi SDK - Video 2 (x32 Version: 2.1.2128 - CyberLink Corp.) Hidden
clear.fi SDK- Movie 2 (x32 Version: 2.1.2112 - CyberLink Corp.) Hidden
Dolby Advanced Audio v2 (HKLM-x32\...\{B9E70C7A-9F85-4A39-A4A3-BFA3C3BF7613}) (Version: 7.2.8000.16 - Dolby Laboratories Inc)
Dritek Radio Controller (HKLM-x32\...\RadioController) (Version: 2.02.2001.0803 - Dritek System Inc.)
EndNote X6 (HKLM-x32\...\{86B3F2D6-AC2B-0016-8AE1-F2F77F781B0C}) (Version: 16.0.1.6599 - Thomson Reuters)
HID Monitor (HKLM-x32\...\{697E8962-7610-4310-BFA9-A0591C65EC21}) (Version: 1.1.4 - Acer Incorporated)
Identity Card (HKLM-x32\...\{3D9CB654-99AD-4301-89C6-0D12A790767C}) (Version: 2.00.3004 - Acer Incorporated)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2867 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.5.4.1001 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
iTunes (HKLM\...\{D227565A-0033-40AD-89BA-653A205CDC11}) (Version: 12.1.1.4 - Apple Inc.)
Java 8 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation)
JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH)
Launch Manager (HKLM-x32\...\LManager) (Version: 7.0.10 - Acer Inc.)
Live Updater (HKLM-x32\...\{EE26E302-876A-48D9-9058-3129E5B99999}) (Version: 2.00.3006 - Acer Incorporated)
Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Sync Framework 2.0 Core Components (x86) ENU (HKLM-x32\...\{FF63121D-91C6-42CC-B341-F1AA729728E7}) (Version: 2.0.1578.0 - Microsoft Corporation)
Microsoft Sync Framework 2.0 Provider Services (x86) ENU (HKLM-x32\...\{D3A80508-CD83-4CA3-8671-914A1BC78B61}) (Version: 2.0.1578.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 38.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 38.0.1 (x86 de)) (Version: 38.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 37.0.2 - Mozilla)
MyWinLocker (Version: 4.0.14.35 - Egis Technology Inc.) Hidden
MyWinLocker 4 (x32 Version: 4.0.14.35 - Egis Technology Inc.) Hidden
MyWinLocker Suite (HKLM-x32\...\InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}) (Version: 4.0.14.24 - Egis Technology Inc.)
MyWinLocker Suite (x32 Version: 4.0.14.24 - Egis Technology Inc.) Hidden
NTI Media Maker 9 (HKLM-x32\...\InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}) (Version: 9.0.2.9014 - NTI Corporation)
NTI Media Maker 9 (x32 Version: 9.0.2.9014 - NTI Corporation) Hidden
NVIDIA Grafiktreiber 307.17 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 307.17 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.12.0613 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.0613 - NVIDIA Corporation)
NVIDIA Update 1.10.8 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.10.8 - NVIDIA Corporation)
Office Addin (HKLM-x32\...\{6D2BBE1D-E600-4695-BA37-0B0E605542CC}) (Version: 2.01.3202 - Acer)
Outils de vérification linguistique 2013 de Microsoft Office*- Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
PDF-Viewer (HKLM\...\{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: 2.5.312.1 - Tracker Software Products Ltd)
Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.0.216 - Qualcomm Atheros Communications)
Qualcomm Atheros WiFi Driver Installation (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 11.31 - Qualcomm Atheros)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.2.612.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6716 - Realtek Semiconductor Corp.)
Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.2.8400.27028 - Realtek Semiconductor Corp.)
ResearchSoft Direct Export Helper (HKLM-x32\...\ResearchSoft Direct Export Helper) (Version: - )
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{90150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUS_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version: - Microsoft)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (Version: - Microsoft) Hidden
Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
Shredder (Version: 2.0.8.9 - Egis Technology Inc.) Hidden
Shredder (x32 Version: 2.0.8.9 - Egis Technology Inc.) Hidden
Stardock Start8 (HKLM\...\Start8_is1) (Version: 1.30.1 - Stardock Software, Inc.)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.3.4.0 - Synaptics Incorporated)
SyncToy 2.1 (x86) (HKLM-x32\...\{A066194B-DC8F-449A-8E0F-B57BDD3A2072}) (Version: 2.1.0 - Microsoft)
Update for Skype for Business 2015 (KB2889853) 64-Bit Edition (HKLM\...\{90150000-012B-0407-1000-0000000FF1CE}_Office15.PROPLUS_{CBCC2FD8-7DFE-4752-95B5-2E447C226F45}) (Version: - Microsoft)
Visual Studio 2005 Tools for Office Second Edition Runtime (HKLM-x32\...\Microsoft Visual Studio 2005 Tools for Office Runtime) (Version: - Microsoft Corporation)
Visual Studio Tools for the Office system 3.0 Runtime (HKLM-x32\...\Visual Studio Tools for the Office system 3.0 Runtime) (Version: - Microsoft Corporation)
Visual Studio Tools for the Office system 3.0 Runtime Service Pack 1 (KB949258) (HKLM-x32\...\{8FB53850-246A-3507-8ADE-0060093FFEA6}.KB949258) (Version: 1 - Microsoft Corporation)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
WinRAR 5.01 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
==================== Restore Points =========================
08-05-2015 13:59:38 Windows Update
12-05-2015 09:35:13 Windows Update
15-05-2015 09:57:03 Windows Update
17-05-2015 13:50:36 Installed iTunes
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2012-07-26 07:26 - 2012-07-26 07:26 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {0307A090-2E31-43DA-9504-472A3A76E984} - System32\Tasks\iuEmailOutlookAgent => C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe [2012-08-23] ()
Task: {43669FA7-7C0C-47B4-8079-B7B4AC640022} - System32\Tasks\ALU => C:\Program Files (x86)\Acer\Live Updater\updater.exe [2012-11-06] ()
Task: {61F4F8C2-11AD-4FFB-BEF3-77614E838761} - System32\Tasks\ALUAgent => C:\Program Files (x86)\Acer\Live Updater\liveupdater_agent.exe [2012-06-21] ()
Task: {750C7467-3DDC-444D-87FF-9421BFBB9DA0} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-05-02] (Adobe Systems Incorporated)
Task: {97B6545F-A475-4BDD-B2B0-E5D2FDD7810E} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {9C6D898F-2277-44E4-831B-0419397165F2} - System32\Tasks\EgisUpdate => C:\Program Files\EgisTec IPS\EgisUpdate.exe [2012-07-12] (Egis Technology Inc.)
Task: {B648F56B-BF38-4F27-9D97-4E5189BFEF0B} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation)
Task: {C4E05C9A-DA25-4395-8892-E9E0732FD681} - System32\Tasks\PMMUpdate => C:\Program Files\EgisTec IPS\PMMUpdate.exe [2012-07-12] (Egis Technology Inc.)
Task: {C7B39504-FBF9-4862-8FE8-51F377F982BC} - System32\Tasks\HIDMonitor => C:\Program Files\Acer Incorporated\HID Monitor\HIDMonitor.exe
Task: {CE94CBA4-1793-4B8D-B770-DC1EE8AB5E91} - System32\Tasks\iuBrowserIEAgent => C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe [2012-08-23] ()
Task: {D4872F40-D0A0-488E-B609-CDDC95268376} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-05-13] (Microsoft Corporation)
Task: {DB5F7EE6-DCEB-4E81-A0E4-35E64F4C3F6F} - System32\Tasks\Power Management => C:\Program Files\Acer\Acer Power Management\ePowerTray.exe [2012-10-23] (Acer Incorporated)
Task: {E961803F-6466-4811-A7AA-AFB68B409817} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Loaded Modules (Whitelisted) ==============
2015-02-13 04:20 - 2015-02-13 04:20 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-02-13 04:20 - 2015-02-13 04:20 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2012-12-25 12:32 - 2012-10-23 20:37 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2012-08-23 01:04 - 2012-08-23 01:04 - 00025232 _____ () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe
2012-08-23 01:04 - 2012-08-23 01:04 - 00044176 _____ () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe
2014-11-19 17:36 - 2014-11-19 17:36 - 00063376 _____ () C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\zlib1.dll
2012-11-03 02:38 - 2012-11-03 02:38 - 00465384 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\sqlite3.dll
2012-11-03 02:37 - 2012-11-03 02:37 - 00125504 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\MailConverter32.dll
2012-11-03 02:38 - 2012-11-03 02:38 - 00155712 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\VolumeSnapshot.dll
2012-11-03 02:37 - 2012-11-03 02:37 - 00118336 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\Online.dll
2012-11-03 02:37 - 2012-11-03 02:37 - 01081408 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\ACE.dll
2012-11-03 02:37 - 2012-11-03 02:37 - 00052288 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\OsSettingPort.dll
2012-11-03 02:37 - 2012-11-03 02:37 - 00727616 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\OutlookShadow.dll
2013-02-02 09:52 - 2012-06-25 11:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver"
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, the associated entry will be removed from the registry.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3241844552-6420410-4097038991-1002\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\Web\Wallpaper\acer01.jpg
DNS Servers: 192.168.0.1
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
HKLM\...\StartupApproved\Run: => "BtPreLoad"
HKLM\...\StartupApproved\Run: => "iTunesHelper"
HKLM\...\StartupApproved\Run32: => "Acrobat Assistant 8.0"
HKLM\...\StartupApproved\Run32: => "Adobe Acrobat Speed Launcher"
HKLM\...\StartupApproved\Run32: => "mcpltui_exe"
HKLM\...\StartupApproved\Run32: => "Norton Online Backup"
HKLM\...\StartupApproved\Run32: => "RadioController"
HKLM\...\StartupApproved\Run32: => "Cisco AnyConnect Secure Mobility Agent for Windows"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{ADA96625-5DC8-4A5A-A3E6-BC4B41D66BBD}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{BED6ECE1-AF15-4346-8EB6-9766C259B94C}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{C20539F2-942C-4186-BC38-2F174D4E0C23}] => (Allow) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManager.exe
FirewallRules: [{5BF299D3-1876-468C-AD4A-DE84EC6154BC}] => (Allow) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
FirewallRules: [{1303A820-9B93-4118-92E3-1D8EF124036D}] => (Allow) C:\Program Files (x86)\NTI\Acer Backup Manager\FileExplorer.exe
FirewallRules: [{E614BEB4-8AA1-47E2-AD2A-54BA3EA8EB92}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{8B50EEE0-722C-4382-A596-7CDA77F664FD}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{61D5A218-6636-42D6-936F-FF59D0534516}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe
FirewallRules: [{DD8E3D55-98D2-4D6C-9C2D-DB16CE9F6773}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe
FirewallRules: [{74813F2E-6630-4D22-8F53-DE5F274B2B4D}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
FirewallRules: [{4DF0E89B-5978-457D-A7DA-6AD35B51020E}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
FirewallRules: [{103864FF-5EEB-409A-AC96-971C99E4528D}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Media\DMCDaemon.exe
FirewallRules: [{CD73B01B-D223-4676-B453-F5079BCCDF12}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Media\DMCDaemon.exe
FirewallRules: [{5D360960-D4CC-44ED-8945-3D7A8DB5DA29}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Media\WindowsUpnpMV.exe
FirewallRules: [{B5F1BFA1-621B-4A2A-BE10-93F7BDD1B434}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Media\WindowsUpnpMV.exe
FirewallRules: [{0FF4FFDD-9AEE-4394-A74C-4E8C567A508A}] => (Allow) C:\Program Files (x86)\Acer\clear.fi SDK21\Video\VideoPlayer.exe
FirewallRules: [{4F95CE79-EDE7-49FF-93AF-8590F39F48EF}] => (Allow) C:\Program Files (x86)\Acer\clear.fi SDK21\Video\MusicPlayer.exe
FirewallRules: [{1637E0A7-EC11-40C6-8DD8-9522EAA6D78D}] => (Allow) C:\Program Files (x86)\Acer\clear.fi SDK21\Movie\PlayMovie.exe
FirewallRules: [{50C1386F-A0B4-4B42-B561-D43ABE4575F9}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Photo\DMCDaemon.exe
FirewallRules: [{A916896E-E839-4046-897E-7A88F273E307}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Photo\DMCDaemon.exe
FirewallRules: [{D4B789CE-98E9-47B5-A5B4-E9C9F7F7A611}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Photo\WindowsUpnp.exe
FirewallRules: [{4B7DE4AF-56D3-4643-89A6-3D100B6CAD95}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Photo\WindowsUpnp.exe
FirewallRules: [{E97348C5-8313-43FD-B27B-6957EA474058}] => (Allow) C:\Program Files (x86)\Acer\Acer Cloud\ccd.exe
FirewallRules: [{32F4EDA8-13A0-4084-A437-15C922BAE7DC}] => (Allow) C:\Program Files (x86)\Acer\Acer Cloud\ccd.exe
FirewallRules: [{15E0E032-E558-4AA5-A872-B8D487823C42}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{75B7803F-6D9B-4B0E-A7C8-69A075206F88}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{920E42A1-987F-4EBB-9856-99768554AF16}] => (Allow) C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{9CB1A269-FB5A-4B8A-9F00-17B3F681D13F}] => (Allow) C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{20C175E5-8725-4ECC-9D1A-D710F90459C4}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{7C83C772-6DCF-42F1-A59A-99ACC941CF02}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{CBE52D21-96BE-4C91-BC9B-1B64BDAF0D16}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{338F64DC-D818-4F99-9829-517BFCA14691}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [TCP Query User{C5507669-4423-4B79-99B8-9DDAE3CAB36F}E:\desktop\sft\programme2\treiber\microsoft toolkit.exe] => (Allow) E:\desktop\sft\programme2\treiber\microsoft toolkit.exe
FirewallRules: [UDP Query User{F1588952-C92F-40C9-AB5B-59D2F56F5F92}E:\desktop\sft\programme2\treiber\microsoft toolkit.exe] => (Allow) E:\desktop\sft\programme2\treiber\microsoft toolkit.exe
FirewallRules: [{554D4C31-A99C-4AB2-9E0B-234C6E44FA89}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{B4D092E4-759D-4AFF-B643-59CAED416B53}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{25939AA8-6A6B-4894-8552-04889B535D42}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{1E645265-A1AC-44DE-BD54-006E18887B0C}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [TCP Query User{3BE69947-309B-46A1-A620-F576A1F743EE}C:\program files (x86)\java\jre1.8.0_45\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_45\bin\javaw.exe
FirewallRules: [UDP Query User{DA252943-659D-4AE1-965A-A7E2F4CADB06}C:\program files (x86)\java\jre1.8.0_45\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_45\bin\javaw.exe
FirewallRules: [TCP Query User{8F910B0E-13E2-40F5-93D1-7269342E5067}C:\users\erkan pc\appdata\local\hola\firefox\app\hola_plugin.exe] => (Allow) C:\users\erkan pc\appdata\local\hola\firefox\app\hola_plugin.exe
FirewallRules: [UDP Query User{4B0F9F44-D030-47CC-9BC3-339BC5DB0532}C:\users\erkan pc\appdata\local\hola\firefox\app\hola_plugin.exe] => (Allow) C:\users\erkan pc\appdata\local\hola\firefox\app\hola_plugin.exe
FirewallRules: [TCP Query User{3A07FC44-4398-43B5-8C3B-7CAB4FD0267B}C:\users\erkan pc\appdata\local\hola\firefox\app\hola_plugin.exe] => (Allow) C:\users\erkan pc\appdata\local\hola\firefox\app\hola_plugin.exe
FirewallRules: [UDP Query User{B24CD7E1-CA65-4269-9F8E-4516CD3FAA14}C:\users\erkan pc\appdata\local\hola\firefox\app\hola_plugin.exe] => (Allow) C:\users\erkan pc\appdata\local\hola\firefox\app\hola_plugin.exe
FirewallRules: [{02366853-1D8B-4DED-9B57-D61DEDB5763D}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{A7F8969C-DB29-4DDF-8A80-3E6F33B826FB}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{830F56DE-DE1F-4895-A4BA-1CD6E3D9506D}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{917CFE3F-26E1-43D0-945A-ED4F3A9AFDF2}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{AF6F2352-E142-43EF-A7D5-51D690FDA43C}] => (Allow) C:\Program Files\iTunes\iTunes.exe
==================== Faulty Device Manager Devices =============
Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: vpnva
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
Name: Bluetooth USB Module
Description: Bluetooth USB Module
Class Guid: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
Manufacturer: Qualcomm Atheros Communications
Service: BTHUSB
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (05/18/2015 03:14:05 PM) (Source: Avira Antivirus) (EventID: 4118) (User: NT-AUTORITÄT)
Description: AUSNAHMEFEHLER beim Aufruf der Funktion IThread(ProtocolSrvConThread)::run() für die Datei
unknown
[ACCESS_VIOLATION Exception!! EIP = 0x7312a271]
Bitte Avira informieren und die obige Datei übersenden!
Error: (05/16/2015 00:42:49 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: POWERPNT.EXE, Version: 15.0.4703.1000, Zeitstempel: 0x54e36607
Name des fehlerhaften Moduls: PenIMC.dll, Version: 3.0.6920.6418, Zeitstempel: 0x554089da
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000005d37
ID des fehlerhaften Prozesses: 0x%9
Startzeit der fehlerhaften Anwendung: 0xPOWERPNT.EXE0
Pfad der fehlerhaften Anwendung: POWERPNT.EXE1
Pfad des fehlerhaften Moduls: POWERPNT.EXE2
Berichtskennung: POWERPNT.EXE3
Vollständiger Name des fehlerhaften Pakets: POWERPNT.EXE4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: POWERPNT.EXE5
Error: (05/16/2015 11:22:50 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: rads_user_kernel.exe, Version: 0.0.0.0, Zeitstempel: 0x4e65c1ac
Name des fehlerhaften Moduls: MSVCR80.dll, Version: 8.0.50727.6910, Zeitstempel: 0x4fee68f0
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00012f4b
ID des fehlerhaften Prozesses: 0x15f8
Startzeit der fehlerhaften Anwendung: 0xrads_user_kernel.exe0
Pfad der fehlerhaften Anwendung: rads_user_kernel.exe1
Pfad des fehlerhaften Moduls: rads_user_kernel.exe2
Berichtskennung: rads_user_kernel.exe3
Vollständiger Name des fehlerhaften Pakets: rads_user_kernel.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: rads_user_kernel.exe5
Error: (05/16/2015 11:06:10 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: rads_user_kernel.exe, Version: 0.0.0.0, Zeitstempel: 0x4e65c1ac
Name des fehlerhaften Moduls: MSVCR80.dll, Version: 8.0.50727.6910, Zeitstempel: 0x4fee68f0
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00012f4b
ID des fehlerhaften Prozesses: 0x1768
Startzeit der fehlerhaften Anwendung: 0xrads_user_kernel.exe0
Pfad der fehlerhaften Anwendung: rads_user_kernel.exe1
Pfad des fehlerhaften Moduls: rads_user_kernel.exe2
Berichtskennung: rads_user_kernel.exe3
Vollständiger Name des fehlerhaften Pakets: rads_user_kernel.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: rads_user_kernel.exe5
Error: (05/16/2015 11:04:30 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: rads_user_kernel.exe, Version: 0.0.0.0, Zeitstempel: 0x4e65c1ac
Name des fehlerhaften Moduls: MSVCR80.dll, Version: 8.0.50727.6910, Zeitstempel: 0x4fee68f0
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00012f4b
ID des fehlerhaften Prozesses: 0x5b8
Startzeit der fehlerhaften Anwendung: 0xrads_user_kernel.exe0
Pfad der fehlerhaften Anwendung: rads_user_kernel.exe1
Pfad des fehlerhaften Moduls: rads_user_kernel.exe2
Berichtskennung: rads_user_kernel.exe3
Vollständiger Name des fehlerhaften Pakets: rads_user_kernel.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: rads_user_kernel.exe5
Error: (05/16/2015 11:04:24 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: rads_user_kernel.exe, Version: 0.0.0.0, Zeitstempel: 0x4e65c1ac
Name des fehlerhaften Moduls: MSVCR80.dll, Version: 8.0.50727.6910, Zeitstempel: 0x4fee68f0
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00012f4b
ID des fehlerhaften Prozesses: 0x17c4
Startzeit der fehlerhaften Anwendung: 0xrads_user_kernel.exe0
Pfad der fehlerhaften Anwendung: rads_user_kernel.exe1
Pfad des fehlerhaften Moduls: rads_user_kernel.exe2
Berichtskennung: rads_user_kernel.exe3
Vollständiger Name des fehlerhaften Pakets: rads_user_kernel.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: rads_user_kernel.exe5
Error: (05/16/2015 11:03:12 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: rads_user_kernel.exe, Version: 0.0.0.0, Zeitstempel: 0x4e65c1ac
Name des fehlerhaften Moduls: MSVCR80.dll, Version: 8.0.50727.6910, Zeitstempel: 0x4fee68f0
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00012f4b
ID des fehlerhaften Prozesses: 0x1578
Startzeit der fehlerhaften Anwendung: 0xrads_user_kernel.exe0
Pfad der fehlerhaften Anwendung: rads_user_kernel.exe1
Pfad des fehlerhaften Moduls: rads_user_kernel.exe2
Berichtskennung: rads_user_kernel.exe3
Vollständiger Name des fehlerhaften Pakets: rads_user_kernel.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: rads_user_kernel.exe5
Error: (05/16/2015 10:57:38 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: POWERPNT.EXE, Version: 15.0.4703.1000, Zeitstempel: 0x54e36607
Name des fehlerhaften Moduls: PenIMC.dll, Version: 3.0.6920.6418, Zeitstempel: 0x554089da
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000005d37
ID des fehlerhaften Prozesses: 0x%9
Startzeit der fehlerhaften Anwendung: 0xPOWERPNT.EXE0
Pfad der fehlerhaften Anwendung: POWERPNT.EXE1
Pfad des fehlerhaften Moduls: POWERPNT.EXE2
Berichtskennung: POWERPNT.EXE3
Vollständiger Name des fehlerhaften Pakets: POWERPNT.EXE4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: POWERPNT.EXE5
Error: (05/16/2015 10:43:43 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1511) (User: Erkan)
Description: Das lokale Benutzerprofil wurde nicht gefunden. Sie werden mit einem temporären Benutzerprofil angemeldet. Änderungen, die Sie am Benutzerprofil vornehmen, gehen bei der Abmeldung verloren.
Error: (05/16/2015 10:43:43 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1515) (User: Erkan)
Description: Dieses Benutzerprofil wurde gesichert. Bei der nächsten Anmeldung dieses Benutzers wird automatisch versucht, dieses gesicherte Profil zu verwenden.
System errors:
=============
Error: (05/19/2015 02:33:36 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "McAfee AP Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (05/19/2015 02:33:34 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "McAfee SiteAdvisor Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (05/19/2015 02:33:16 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Das System wurde zuvor am 19.05.2015 um 14:24:37 unerwartet heruntergefahren.
Error: (05/18/2015 04:18:26 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070001 fehlgeschlagen: German ESD Bundle Parent
Error: (05/18/2015 04:09:06 PM) (Source: DCOM) (EventID: 10016) (User: Erkan)
Description: AnwendungsspezifischLokalStart{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}ErkanErkan PCS-1-5-21-3241844552-6420410-4097038991-1002LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (05/18/2015 04:09:06 PM) (Source: DCOM) (EventID: 10016) (User: Erkan)
Description: AnwendungsspezifischLokalStart{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}ErkanErkan PCS-1-5-21-3241844552-6420410-4097038991-1002LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (05/18/2015 04:09:06 PM) (Source: DCOM) (EventID: 10016) (User: Erkan)
Description: AnwendungsspezifischLokalStart{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}ErkanErkan PCS-1-5-21-3241844552-6420410-4097038991-1002LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (05/18/2015 04:06:43 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "McAfee AP Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (05/18/2015 04:06:42 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "McAfee SiteAdvisor Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (05/18/2015 04:06:18 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Das System wurde zuvor am 18.05.2015 um 15:16:18 unerwartet heruntergefahren.
Microsoft Office Sessions:
=========================
Error: (05/18/2015 03:14:05 PM) (Source: Avira Antivirus) (EventID: 4118) (User: NT-AUTORITÄT)
Description: unknownACCESS_VIOLATION0x7312a271IThread(ProtocolSrvConThread)::run()
Error: (05/16/2015 00:42:49 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: POWERPNT.EXE15.0.4703.100054e36607PenIMC.dll3.0.6920.6418554089dac00000050000000000005d37
Error: (05/16/2015 11:22:50 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: rads_user_kernel.exe0.0.0.04e65c1acMSVCR80.dll8.0.50727.69104fee68f0c000000500012f4b15f801d08fb9e0686b14C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exeC:\WINDOWS\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6910_none_d089c358442de345\MSVCR80.dll1ef32810-fbad-11e4-be81-206a8af4aa7a
Error: (05/16/2015 11:06:10 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: rads_user_kernel.exe0.0.0.04e65c1acMSVCR80.dll8.0.50727.69104fee68f0c000000500012f4b176801d08fb78d6fb47fC:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exeC:\WINDOWS\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6910_none_d089c358442de345\MSVCR80.dllcb20e40d-fbaa-11e4-be80-206a8af4aa7a
Error: (05/16/2015 11:04:30 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: rads_user_kernel.exe0.0.0.04e65c1acMSVCR80.dll8.0.50727.69104fee68f0c000000500012f4b5b801d08fb751a37ed4C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exeC:\WINDOWS\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6910_none_d089c358442de345\MSVCR80.dll8f548739-fbaa-11e4-be80-206a8af4aa7a
Error: (05/16/2015 11:04:24 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: rads_user_kernel.exe0.0.0.04e65c1acMSVCR80.dll8.0.50727.69104fee68f0c000000500012f4b17c401d08fb74e2bf4c6C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exeC:\WINDOWS\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6910_none_d089c358442de345\MSVCR80.dll8bdc87ee-fbaa-11e4-be80-206a8af4aa7a
Error: (05/16/2015 11:03:12 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: rads_user_kernel.exe0.0.0.04e65c1acMSVCR80.dll8.0.50727.69104fee68f0c000000500012f4b157801d08fb722c274c7C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exeC:\WINDOWS\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6910_none_d089c358442de345\MSVCR80.dll60fc9acf-fbaa-11e4-be80-206a8af4aa7a
Error: (05/16/2015 10:57:38 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: POWERPNT.EXE15.0.4703.100054e36607PenIMC.dll3.0.6920.6418554089dac00000050000000000005d37
Error: (05/16/2015 10:43:43 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1511) (User: Erkan)
Description:
Error: (05/16/2015 10:43:43 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1515) (User: Erkan)
Description:
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i5-3337U CPU @ 1.80GHz
Percentage of memory in use: 38%
Total physical RAM: 3891.59 MB
Available physical RAM: 2383.24 MB
Total Pagefile: 6451.59 MB
Available Pagefile: 4630.08 MB
Total Virtual: 8192 MB
Available Virtual: 8191.77 MB
==================== Drives ================================
Drive c: (Acer) (Fixed) (Total:681.71 GB) (Free:371.91 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 698.6 GB) (Disk ID: 68B6A4DC)
Partition: GPT Partition Type.
==================== End Of Log ============================
Bei GMER tauchten folgende Probleme auf: http://www.imgbox.de/users/public/images/fujcAS9pJO.jpg Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-05-19 14:59:34
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\00000039 ST750LM022_HN-M750MBB rev.2AR10001 698,64GB
Running: Gmer-19357.exe; Driver: C:\Users\ERKANP~1\AppData\Local\Temp\pgloapow.sys
---- User code sections - GMER 2.1 ----
.text C:\WINDOWS\system32\dwm.exe[688] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8d13c1532 4 bytes [3C, D1, F8, 07]
.text C:\WINDOWS\system32\dwm.exe[688] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8d13c153a 4 bytes [3C, D1, F8, 07]
.text C:\WINDOWS\system32\dwm.exe[688] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8d13c165a 4 bytes [3C, D1, F8, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1132] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8d13c1532 4 bytes [3C, D1, F8, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1132] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8d13c153a 4 bytes [3C, D1, F8, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1132] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8d13c165a 4 bytes [3C, D1, F8, 07]
.text C:\WINDOWS\system32\nvvsvc.exe[1152] C:\WINDOWS\system32\MSIMG32.dll!GradientFill + 690 000007f8d13c1532 4 bytes [3C, D1, F8, 07]
.text C:\WINDOWS\system32\nvvsvc.exe[1152] C:\WINDOWS\system32\MSIMG32.dll!GradientFill + 698 000007f8d13c153a 4 bytes [3C, D1, F8, 07]
.text C:\WINDOWS\system32\nvvsvc.exe[1152] C:\WINDOWS\system32\MSIMG32.dll!TransparentBlt + 246 000007f8d13c165a 4 bytes [3C, D1, F8, 07]
.text C:\WINDOWS\system32\nvvsvc.exe[1152] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007f8d720177a 4 bytes [20, D7, F8, 07]
.text C:\WINDOWS\system32\nvvsvc.exe[1152] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007f8d7201782 4 bytes [20, D7, F8, 07]
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1540] C:\WINDOWS\SYSTEM32\WSOCK32.dll!recvfrom + 742 000007f8cc3b1b32 4 bytes [3B, CC, F8, 07]
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1540] C:\WINDOWS\SYSTEM32\WSOCK32.dll!recvfrom + 750 000007f8cc3b1b3a 4 bytes [3B, CC, F8, 07]
.text C:\WINDOWS\system32\mfevtps.exe[2260] C:\WINDOWS\system32\psapi.dll!GetProcessImageFileNameA + 306 000007f8d720177a 4 bytes [20, D7, F8, 07]
.text C:\WINDOWS\system32\mfevtps.exe[2260] C:\WINDOWS\system32\psapi.dll!GetProcessImageFileNameA + 314 000007f8d7201782 4 bytes [20, D7, F8, 07]
.text C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe[2500] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007f8d720177a 4 bytes [20, D7, F8, 07]
.text C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe[2500] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007f8d7201782 4 bytes [20, D7, F8, 07]
.text C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[2272] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8d13c1532 4 bytes [3C, D1, F8, 07]
.text C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[2272] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8d13c153a 4 bytes [3C, D1, F8, 07]
.text C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[2272] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8d13c165a 4 bytes [3C, D1, F8, 07]
.text C:\WINDOWS\system32\taskhostex.exe[1912] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8d13c1532 4 bytes [3C, D1, F8, 07]
.text C:\WINDOWS\system32\taskhostex.exe[1912] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8d13c153a 4 bytes [3C, D1, F8, 07]
.text C:\WINDOWS\system32\taskhostex.exe[1912] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8d13c165a 4 bytes [3C, D1, F8, 07]
.text C:\WINDOWS\Explorer.EXE[2976] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8d13c1532 4 bytes [3C, D1, F8, 07]
.text C:\WINDOWS\Explorer.EXE[2976] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8d13c153a 4 bytes [3C, D1, F8, 07]
.text C:\WINDOWS\Explorer.EXE[2976] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8d13c165a 4 bytes [3C, D1, F8, 07]
.text C:\WINDOWS\Explorer.EXE[2976] C:\WINDOWS\SYSTEM32\WSOCK32.dll!recvfrom + 742 000007f8cc3b1b32 4 bytes [3B, CC, F8, 07]
.text C:\WINDOWS\Explorer.EXE[2976] C:\WINDOWS\SYSTEM32\WSOCK32.dll!recvfrom + 750 000007f8cc3b1b3a 4 bytes [3B, CC, F8, 07]
.text C:\WINDOWS\system32\wbem\unsecapp.exe[3100] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8d13c1532 4 bytes [3C, D1, F8, 07]
.text C:\WINDOWS\system32\wbem\unsecapp.exe[3100] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8d13c153a 4 bytes [3C, D1, F8, 07]
.text C:\WINDOWS\system32\wbem\unsecapp.exe[3100] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8d13c165a 4 bytes [3C, D1, F8, 07]
.text C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[3132] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8d13c1532 4 bytes [3C, D1, F8, 07]
.text C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[3132] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8d13c153a 4 bytes [3C, D1, F8, 07]
.text C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[3132] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8d13c165a 4 bytes [3C, D1, F8, 07]
.text C:\Windows\system32\igfxext.exe[1072] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8d13c1532 4 bytes [3C, D1, F8, 07]
.text C:\Windows\system32\igfxext.exe[1072] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8d13c153a 4 bytes [3C, D1, F8, 07]
.text C:\Windows\system32\igfxext.exe[1072] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8d13c165a 4 bytes [3C, D1, F8, 07]
.text C:\Windows\System32\hkcmd.exe[4152] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8d13c1532 4 bytes [3C, D1, F8, 07]
.text C:\Windows\System32\hkcmd.exe[4152] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8d13c153a 4 bytes [3C, D1, F8, 07]
.text C:\Windows\System32\hkcmd.exe[4152] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8d13c165a 4 bytes [3C, D1, F8, 07]
.text C:\Windows\System32\igfxpers.exe[4172] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007f8d720177a 4 bytes [20, D7, F8, 07]
.text C:\Windows\System32\igfxpers.exe[4172] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007f8d7201782 4 bytes [20, D7, F8, 07]
.text C:\Windows\System32\igfxpers.exe[4172] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8d13c1532 4 bytes [3C, D1, F8, 07]
.text C:\Windows\System32\igfxpers.exe[4172] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8d13c153a 4 bytes [3C, D1, F8, 07]
.text C:\Windows\System32\igfxpers.exe[4172] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8d13c165a 4 bytes [3C, D1, F8, 07]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4216] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8d13c1532 4 bytes [3C, D1, F8, 07]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4216] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8d13c153a 4 bytes [3C, D1, F8, 07]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4216] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8d13c165a 4 bytes [3C, D1, F8, 07]
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4240] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8d13c1532 4 bytes [3C, D1, F8, 07]
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4240] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8d13c153a 4 bytes [3C, D1, F8, 07]
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4240] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8d13c165a 4 bytes [3C, D1, F8, 07]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4344] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007f8d720177a 4 bytes [20, D7, F8, 07]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4344] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007f8d7201782 4 bytes [20, D7, F8, 07]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4344] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8d13c1532 4 bytes [3C, D1, F8, 07]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4344] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8d13c153a 4 bytes [3C, D1, F8, 07]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4344] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8d13c165a 4 bytes [3C, D1, F8, 07]
.text C:\Dolby PCEE4\pcee4.exe[4484] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8d13c1532 4 bytes [3C, D1, F8, 07]
.text C:\Dolby PCEE4\pcee4.exe[4484] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8d13c153a 4 bytes [3C, D1, F8, 07]
.text C:\Dolby PCEE4\pcee4.exe[4484] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8d13c165a 4 bytes [3C, D1, F8, 07]
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4560] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007f8d720177a 4 bytes [20, D7, F8, 07]
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[4560] C:\WINDOWS\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007f8d7201782 4 bytes [20, D7, F8, 07]
.text C:\WINDOWS\system32\wbem\unsecapp.exe[3868] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8d13c1532 4 bytes [3C, D1, F8, 07]
.text C:\WINDOWS\system32\wbem\unsecapp.exe[3868] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8d13c153a 4 bytes [3C, D1, F8, 07]
.text C:\WINDOWS\system32\wbem\unsecapp.exe[3868] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8d13c165a 4 bytes [3C, D1, F8, 07]
.text C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe[3656] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8d13c1532 4 bytes [3C, D1, F8, 07]
.text C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe[3656] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8d13c153a 4 bytes [3C, D1, F8, 07]
.text C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe[3656] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8d13c165a 4 bytes [3C, D1, F8, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4068] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f8d13c1532 4 bytes [3C, D1, F8, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4068] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f8d13c153a 4 bytes [3C, D1, F8, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4068] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f8d13c165a 4 bytes [3C, D1, F8, 07]
---- Threads - GMER 2.1 ----
Thread C:\WINDOWS\system32\csrss.exe [788:1684] fffff960009525e8
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ---- |