Aktives Fenster wählt sich ab alleine Hallo,
bin neu hier und hab ein problem was wohl nirgends gelöst wird laut den ganzen foren :D
also seit neuesten deaktiviert sich einfach das fenster egal was ich mache selbst im game minimiert sich dann das game richtig ätzend, und wenn ich so schreibe auch muss ich bestimmt 10mal mit der maus das fenster anklicken damit ich weiter schreiben kann.
hablles probiert wie es in vielen foren stand alles nix gebracht, dann hab ich hier ein beitrag gesehen darauf konnte ich aber nicht antworten was dort steht hab ich mal gemacht hoffe mir kann jetzt endlich einer helfen :) http://www.trojaner-board.de/123916-...ogramm-ab.html
das ist der beitrag hier meine ergebnisse:
OTL: Code:
OTL logfile created on: 04.03.2014 11:50:06 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Chris\Downloads
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16518)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,00 Gb Total Physical Memory | 2,17 Gb Available Physical Memory | 72,45% Memory free
6,00 Gb Paging File | 4,91 Gb Available in Paging File | 81,92% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 931,51 Gb Total Space | 287,57 Gb Free Space | 30,87% Space Free | Partition Type: NTFS
Computer Name: CHRIS-PC | User Name: Chris | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014.03.04 11:48:50 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Chris\Downloads\OTL.exe
PRC - [2014.02.18 10:38:24 | 000,996,544 | ---- | M] (Kaspersky Lab ZAO) -- C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe
PRC - [2014.02.17 14:09:48 | 004,915,040 | ---- | M] (TeamViewer GmbH) -- C:\Programme\TeamViewer\Version9\TeamViewer_Service.exe
PRC - [2013.12.21 07:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013.12.20 20:04:27 | 001,496,576 | ---- | M] (Microsoft ® Windows ® Operating System) -- C:\Windows\System32\WinSecurity.exe
PRC - [2013.11.14 20:15:36 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2013.10.17 15:47:28 | 000,214,512 | ---- | M] (Kaspersky Lab ZAO) -- C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe
PRC - [2013.07.11 11:41:14 | 004,927,280 | ---- | M] (Native Instruments GmbH) -- C:\Programme\Common Files\Native Instruments\Hardware\NIHardwareService.exe
PRC - [2013.05.13 15:33:02 | 001,693,904 | ---- | M] (Microsoft Corporation) -- c:\Programme\Microsoft Mouse and Keyboard Center\ipoint.exe
PRC - [2013.05.13 15:33:02 | 001,113,296 | ---- | M] (Microsoft Corporation) -- c:\Programme\Microsoft Mouse and Keyboard Center\itype.exe
PRC - [2013.04.30 04:53:00 | 000,453,632 | ---- | M] (AMD) -- C:\Windows\System32\atieclxx.exe
PRC - [2013.04.30 04:52:26 | 000,217,088 | ---- | M] (AMD) -- C:\Windows\System32\atiesrxx.exe
PRC - [2013.04.29 23:24:04 | 000,291,840 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Programme\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
PRC - [2013.03.19 11:02:54 | 000,098,304 | ---- | M] (Firebird Project) -- C:\Programme\Firebird\Firebird_2_5\bin\fbguard.exe
PRC - [2013.03.19 11:02:32 | 003,784,704 | ---- | M] (Firebird Project) -- C:\Programme\Firebird\Firebird_2_5\bin\fbserver.exe
PRC - [2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010.11.20 22:29:49 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
========== Modules (No Company Name) ==========
MOD - [2014.02.12 03:13:50 | 000,260,096 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsForm0b574481#\1ab52f8951c2ab97592ec25830dd5165\WindowsFormsIntegration.ni.dll
MOD - [2014.02.12 03:12:25 | 019,693,056 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\24bf0c88c0465485f4b842df043b3f45\System.ServiceModel.ni.dll
MOD - [2014.02.12 03:11:21 | 000,190,976 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationTypes\75b6a68103e1b76063d9f69b8275ae61\UIAutomationTypes.ni.dll
MOD - [2014.02.12 03:11:18 | 000,018,944 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio49d6fefe#\47e7fc401facd4a5d3f2237f16948f36\PresentationFramework-SystemXml.ni.dll
MOD - [2014.02.12 03:06:42 | 001,889,792 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\3fe705796c6a41d4889d9001d1c56af8\System.Xaml.ni.dll
MOD - [2014.02.12 03:06:33 | 018,813,440 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\a4b45c44490c75bc2fb22780e7ef087d\PresentationFramework.ni.dll
MOD - [2014.02.12 03:06:18 | 011,025,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\a74542efbeb46445949a39026c501132\PresentationCore.ni.dll
MOD - [2014.02.12 03:06:08 | 003,950,080 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\acf97bfe2a931d4a47253b26b7218991\WindowsBase.ni.dll
MOD - [2014.02.12 03:06:08 | 000,470,528 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio1c9175f8#\75f8bc4cf08030c4a53b6d5e0ae20046\PresentationFramework.Aero.ni.dll
MOD - [2014.02.12 03:05:02 | 006,990,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\dce99d8de14d8a015313db98c72552ee\System.Core.ni.dll
MOD - [2014.02.12 03:05:01 | 007,662,080 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\bada32953bb6b16a53d653eae23d78dc\System.Xml.ni.dll
MOD - [2014.02.12 03:04:55 | 000,976,384 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\bbc48ec4245e502ae19b0601d3799c9e\System.Configuration.ni.dll
MOD - [2014.02.12 03:04:53 | 010,060,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ff26cc03e6d57d8abd13b990332e67c6\System.ni.dll
MOD - [2014.02.12 03:04:45 | 016,953,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\ce5f61c5754789df97be8dc991c47d07\mscorlib.ni.dll
MOD - [2013.10.16 18:01:34 | 002,601,328 | ---- | M] () -- C:\Programme\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x86.dll
MOD - [2013.08.07 20:25:24 | 000,093,696 | ---- | M] () -- C:\Programme\FileZilla FTP Client\fzshellext.dll
MOD - [2013.06.17 12:35:10 | 000,478,400 | ---- | M] () -- C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\dblite.dll
========== Services (SafeList) ==========
SRV - [2014.03.03 21:44:41 | 000,257,928 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014.02.17 14:09:48 | 004,915,040 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Programme\TeamViewer\Version9\TeamViewer_Service.exe -- (TeamViewer9)
SRV - [2014.02.15 07:47:14 | 000,118,896 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014.02.06 10:47:18 | 000,108,032 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV - [2013.12.21 07:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013.12.20 20:04:27 | 001,496,576 | ---- | M] (Microsoft ® Windows ® Operating System) [Auto | Running] -- C:\Windows\System32\WinSecurity.exe -- (WindowsSecurity)
SRV - [2013.12.11 20:40:36 | 000,569,768 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2013.10.23 11:53:56 | 000,018,360 | ---- | M] (Overwolf Ltd) [On_Demand | Stopped] -- C:\Programme\Overwolf\OverwolfUpdater.exe -- (OverwolfUpdaterService)
SRV - [2013.10.17 15:47:28 | 000,214,512 | ---- | M] (Kaspersky Lab ZAO) [Auto | Running] -- C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe -- (AVP)
SRV - [2013.08.22 14:10:14 | 000,032,568 | ---- | M] (The OpenVPN Project) [On_Demand | Stopped] -- C:\Programme\OpenVPN\bin\openvpnserv.exe -- (OpenVPNService)
SRV - [2013.07.11 11:41:14 | 004,927,280 | ---- | M] (Native Instruments GmbH) [Auto | Running] -- C:\Programme\Common Files\Native Instruments\Hardware\NIHardwareService.exe -- (NIHardwareService)
SRV - [2013.05.27 05:57:27 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2013.04.30 04:52:26 | 000,217,088 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2013.04.29 23:24:04 | 000,291,840 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV - [2013.03.19 11:02:54 | 000,098,304 | ---- | M] (Firebird Project) [Auto | Running] -- C:\Programme\Firebird\Firebird_2_5\bin\fbguard.exe -- (FirebirdGuardianDefaultInstance)
SRV - [2013.03.19 11:02:32 | 003,784,704 | ---- | M] (Firebird Project) [On_Demand | Running] -- C:\Programme\Firebird\Firebird_2_5\bin\fbserver.exe -- (FirebirdServerDefaultInstance)
SRV - [2010.11.20 22:29:49 | 001,121,792 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Programme\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2010.02.19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Programme\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009.07.14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 02:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009.07.14 02:15:33 | 000,029,696 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\iprip.dll -- (iprip)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\RTKVHDA.sys -- (IntcAzAudAddService)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\EagleXNt.sys -- (EagleXNt)
DRV - [2014.03.01 16:18:37 | 000,050,728 | ---- | M] (Eugene V. Muzychenko) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vrtaucbl.sys -- (EuMusDesignVirtualAudioCableWdm)
DRV - [2014.02.18 10:38:43 | 000,025,184 | ---- | M] (Kaspersky Lab ZAO) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\klkbdflt.sys -- (klkbdflt)
DRV - [2014.02.18 10:38:42 | 000,576,096 | ---- | M] (Kaspersky Lab ZAO) [File_System | System | Running] -- C:\Windows\System32\drivers\klif.sys -- (KLIF)
DRV - [2014.02.18 10:38:42 | 000,094,304 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\klflt.sys -- (klflt)
DRV - [2014.01.04 11:55:05 | 000,243,128 | ---- | M] (Disc Soft Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2013.12.19 12:47:51 | 000,144,992 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\Windows\System32\drivers\kneps.sys -- (kneps)
DRV - [2013.11.14 22:31:28 | 000,135,776 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\kl1.sys -- (kl1)
DRV - [2013.10.28 01:12:12 | 000,182,680 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudmdm.sys -- (ssudmdm)
DRV - [2013.10.28 01:12:12 | 000,087,064 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudbus.sys -- (dg_ssudbus)
DRV - [2013.10.17 15:47:26 | 000,025,696 | ---- | M] (Kaspersky Lab ZAO) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\klmouflt.sys -- (klmouflt)
DRV - [2013.10.17 15:47:26 | 000,025,696 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\Windows\System32\drivers\klim6.sys -- (KLIM6)
DRV - [2013.10.02 01:42:31 | 000,049,152 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2013.08.22 13:40:22 | 000,035,288 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tap0901.sys -- (tap0901)
DRV - [2013.05.14 17:34:44 | 000,045,024 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\Windows\System32\drivers\kltdi.sys -- (kltdi)
DRV - [2013.04.30 05:14:44 | 010,070,016 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2013.04.30 05:14:44 | 010,070,016 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag)
DRV - [2013.04.30 03:47:52 | 000,290,304 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap)
DRV - [2013.04.12 15:34:48 | 000,014,432 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\Windows\System32\drivers\klpd.sys -- (klpd)
DRV - [2012.08.23 15:46:55 | 000,024,064 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\terminpt.sys -- (terminpt)
DRV - [2012.08.23 15:44:32 | 000,014,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2012.08.23 15:41:34 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV - [2012.05.14 07:12:28 | 000,086,656 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AtihdW73.sys -- (AtiHDAudioService)
DRV - [2010.11.20 22:29:03 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2010.11.20 22:29:03 | 000,112,640 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tsusbhub.sys -- (tsusbhub)
DRV - [2010.11.20 22:29:03 | 000,077,184 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Synth3dVsc.sys -- (Synth3dVsc)
DRV - [2010.11.20 22:29:03 | 000,062,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\dmvsc.sys -- (dmvsc)
DRV - [2010.11.20 22:29:03 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010.11.20 22:29:03 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010.11.20 22:29:03 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2010.11.20 22:29:03 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010.11.20 22:29:03 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010.08.12 12:07:48 | 000,298,216 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvmf6232.sys -- (NVNET)
DRV - [2010.02.18 09:18:22 | 000,037,944 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\amdiox86.sys -- (amdiox86)
DRV - [2009.07.13 23:02:52 | 000,347,264 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nvm62x32.sys -- (NVENETFD)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.dell.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.dell.com
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
========== FireFox ==========
FF - prefs.js..CT3312807.browser.search.defaultthis.engineName: "true"
FF - prefs.js..browser.search.defaultenginename: "Conduit Search"
FF - prefs.js..browser.search.defaultthis.engineName: "Fun Media Bar V11 Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3312807&CUI=UN93255172636127723&UM=1&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Ask Search"
FF - prefs.js..browser.search.selectedEngine: "Conduit Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "https://www.google.de/"
FF - prefs.js..extensions.enabledAddons: %7Bb9db16a4-6edc-47ec-a1f4-b86292ed211d%7D:4.9.21
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:27.0.1
FF - prefs.js..keyword.URL: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3312807&SearchSource=2&CUI=UN93255172636127723&UM=1&q="
FF - prefs.js..network.proxy.autoconfig_url: "file:///C:/Users/Chris/Desktop/putty.exe%20-N%20-L%201234:localhost:1234%20proxy@cs-sys.de"
FF - prefs.js..network.proxy.backup.ftp: "localhost"
FF - prefs.js..network.proxy.backup.ftp_port: 1234
FF - prefs.js..network.proxy.backup.socks: "localhost"
FF - prefs.js..network.proxy.backup.socks_port: 1234
FF - prefs.js..network.proxy.backup.ssl: "localhost"
FF - prefs.js..network.proxy.backup.ssl_port: 1234
FF - prefs.js..network.proxy.ftp: "localhost"
FF - prefs.js..network.proxy.ftp_port: 1234
FF - prefs.js..network.proxy.http: "localhost"
FF - prefs.js..network.proxy.http_port: 1234
FF - prefs.js..network.proxy.no_proxies_on: "C:\\Users\\CS-SYS\\Desktop\\putty.exe -N -L 1234:localhost:1234 proxy@cs-sys.de"
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "localhost"
FF - prefs.js..network.proxy.socks_port: 1234
FF - prefs.js..network.proxy.ssl: "localhost"
FF - prefs.js..network.proxy.ssl_port: 1234
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_70.dll ()
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/npbattlelog,version=2.3.2: C:\Program Files\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@ngm.nexoneu.com/NxGame: C:\ProgramData\NexonEU\NGM\npNxGameEU.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\url_advisor@kaspersky.com: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2014.02.18 10:39:20 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\virtual_keyboard@kaspersky.com: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014.02.18 10:39:20 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\content_blocker@kaspersky.com: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2014.02.18 10:39:20 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\anti_banner@kaspersky.com: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2014.02.18 10:39:20 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\online_banking@kaspersky.com: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2014.02.18 10:39:20 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 27.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 27.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 24.3.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 24.3.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 27.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 27.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 24.3.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 24.3.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2013.11.14 19:31:37 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Chris\AppData\Roaming\mozilla\Extensions
[2014.01.30 17:40:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Chris\AppData\Roaming\mozilla\Firefox\Profiles\v5p5rn11.default\extensions
[2013.12.20 21:52:24 | 000,000,000 | ---D | M] (Fun Media Bar V11) -- C:\Users\Chris\AppData\Roaming\mozilla\Firefox\Profiles\v5p5rn11.default\extensions\{21bd831c-5f59-432d-9c58-c3162b161816}
[2013.11.21 16:25:07 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Chris\AppData\Roaming\mozilla\Firefox\Profiles\v5p5rn11.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2014.01.30 17:40:36 | 000,000,000 | ---D | M] ("Plus-HD-1.3") -- C:\Users\Chris\AppData\Roaming\mozilla\Firefox\Profiles\v5p5rn11.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com
[2014.01.30 17:40:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Chris\AppData\Roaming\mozilla\Firefox\Profiles\v5p5rn11.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData
[2014.01.30 17:40:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Chris\AppData\Roaming\mozilla\Firefox\Profiles\v5p5rn11.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\plugins
[2014.01.30 17:40:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Chris\AppData\Roaming\mozilla\Firefox\Profiles\v5p5rn11.default\extensions\509508ef-0b14-4616-a557-0d58601be33d@c4a581e9-0ea6-46db-a185-58e021ee138c.com\extensionData\userCode
[2013.12.16 18:31:15 | 000,002,661 | ---- | M] () -- C:\Users\Chris\AppData\Roaming\mozilla\firefox\profiles\v5p5rn11.default\searchplugins\ask-search.xml
[2014.02.20 16:23:40 | 000,000,969 | ---- | M] () -- C:\Users\Chris\AppData\Roaming\mozilla\firefox\profiles\v5p5rn11.default\searchplugins\conduit-search.xml
[2013.12.17 14:35:04 | 000,001,011 | ---- | M] () -- C:\Users\Chris\AppData\Roaming\mozilla\firefox\profiles\v5p5rn11.default\searchplugins\conduit.xml
[2014.02.15 07:47:10 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\browser\extensions
[2014.02.15 07:47:14 | 000,000,000 | ---D | M] (Default) -- C:\Programme\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - homepage:
CHR - plugin: Error reading preferences file
CHR - Extension: Google Docs = C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google-Suche = C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Modul zur Link-Untersuchung = C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj\14.0.0.4651_0\
CHR - Extension: Beach in the Maldives = C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\ddicfadfciaeikknlkcldgockejldhek\1_0\
CHR - Extension: Sicherer Zahlungsverkehr = C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh\14.0.0.4651_0\
CHR - Extension: Modul zum Sperren von gefährlichen Webseiten = C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail\14.0.0.4651_0\
CHR - Extension: Plus-HD-1.3 = C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhlmghjmomaoodfgjeikphfdljhpcpkl\1.26.131_0\crossrider
CHR - Extension: Plus-HD-1.3 = C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhlmghjmomaoodfgjeikphfdljhpcpkl\1.26.131_0\
CHR - Extension: Virtuelle Tastatur = C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh\14.0.0.4873_0\
CHR - Extension: Google Wallet = C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Google Mail = C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
CHR - Extension: Anti-Banner = C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman\14.0.0.4651_0\
O1 HOSTS File: ([2009.06.10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Content Blocker Plugin) - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (Virtual Keyboard Plugin) - {73455575-E40C-433C-9784-C78DC7761455} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O2 - BHO: (Safe Money Plugin) - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
O2 - BHO: (URL Advisor Plugin) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: Zu Anti-Banner hinzufügen - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ie_banner_deny.htm ()
O9 - Extra Button: Virtuelle Tastatur - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
O9 - Extra Button: Link-Untersuchung - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Programme\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2F0F6FB5-ACF4-4FC0-9D8A-A85ED5CC34F5}: DhcpNameServer = 192.168.2.1 192.168.2.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{92e28e6b-74e1-11e3-996e-002185194ef1}\Shell - "" = AutoRun
O33 - MountPoints2\{92e28e6b-74e1-11e3-996e-002185194ef1}\Shell\AutoRun\command - "" = E:\Autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {25FFAAD0-F4A3-4164-95FF-4461E9F35D51} - .NET Framework
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4903D172-DCCB-392F-93A3-34CA9D47FE3D} - .NET Framework
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -UserConfig
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files\Google\Chrome\Application\33.0.1750.146\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
MsConfig - StartUpFolder: C:^Users^Chris^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk - C:\Users\Chris\AppData\Roaming\Dropbox\bin\Dropbox.exe - (Dropbox, Inc.)
MsConfig - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg: AdobeAAMUpdater-1.0 - hkey= - key= - C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg: AdobeBridge - hkey= - key= - File not found
MsConfig - StartUpReg: AdobeCS6ServiceManager - hkey= - key= - C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg: AMD AVT - hkey= - key= - File not found
MsConfig - StartUpReg: APSDaemon - hkey= - key= - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
MsConfig - StartUpReg: DAEMON Tools Lite - hkey= - key= - C:\Program Files\DAEMON Tools Lite\DTLite.exe (Disc Soft Ltd)
MsConfig - StartUpReg: icq - hkey= - key= - C:\Users\Chris\AppData\Roaming\ICQM\icq.exe (ICQ)
MsConfig - StartUpReg: KPeerNexonEU - hkey= - key= - C:\Nexon\NEXON_EU_Downloader\nxEULauncher.exe (NEXON Inc.)
MsConfig - StartUpReg: LiveZilla - hkey= - key= - C:\Program Files\LiveZilla\LiveZilla.exe (LiveZilla GmbH)
MsConfig - StartUpReg: Overwolf - hkey= - key= - C:\Program Files\Overwolf\Overwolf.exe (Overwolf)
MsConfig - StartUpReg: QuickTime Task - hkey= - key= - C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
MsConfig - StartUpReg: Sidebar - hkey= - key= - C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
MsConfig - StartUpReg: Spotify - hkey= - key= - C:\Users\Chris\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd)
MsConfig - StartUpReg: Spotify Web Helper - hkey= - key= - C:\Users\Chris\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
MsConfig - StartUpReg: StartCCC - hkey= - key= - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
MsConfig - StartUpReg: SwitchBoard - hkey= - key= - C:\Programme\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2014.03.03 22:16:18 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2014.03.01 19:11:01 | 1967,289,647 | ---- | C] (Nexon) -- C:\Users\Chris\Documents\Combatarms_eu.exe
[2014.03.01 18:31:38 | 000,000,000 | ---D | C] -- C:\Users\Chris\AppData\Local\Diagnostics
[2014.03.01 16:18:37 | 000,050,728 | ---- | C] (Eugene V. Muzychenko) -- C:\Windows\System32\drivers\vrtaucbl.sys
[2014.03.01 16:18:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Virtual Audio Cable
[2014.03.01 16:18:36 | 000,000,000 | ---D | C] -- C:\Program Files\Virtual Audio Cable
[2014.03.01 16:15:49 | 000,000,000 | ---D | C] -- C:\Users\Chris\Documents\Virtual Audio Cable 4.10
[2014.02.27 16:13:55 | 000,000,000 | ---D | C] -- C:\Users\Chris\Documents\ILS-SimV4
[2014.02.26 14:15:39 | 000,000,000 | ---D | C] -- C:\Users\Chris\AppData\Roaming\CAE_Report_Generator
[2014.02.26 14:15:39 | 000,000,000 | ---D | C] -- C:\Users\Chris\AppData\Local\CAE_Report_Generator
[2014.02.26 14:15:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CAE Report Generator
[2014.02.26 14:15:26 | 000,000,000 | ---D | C] -- C:\Program Files\BandiMPEG1
[2014.02.26 14:15:22 | 000,000,000 | ---D | C] -- C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5
[2014.02.26 14:15:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth 2.5
[2014.02.26 14:15:22 | 000,000,000 | ---D | C] -- C:\Program Files\AviSynth 2.5
[2014.02.26 14:15:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\x264vfw
[2014.02.26 14:15:04 | 000,000,000 | ---D | C] -- C:\Program Files\CAE Report Generator
[2014.02.24 22:55:38 | 000,000,000 | ---D | C] -- C:\ProgramData\MVH
[2014.02.24 22:48:44 | 000,000,000 | ---D | C] -- C:\Users\Chris\AppData\Roaming\MVH
[2014.02.21 18:08:22 | 000,000,000 | ---D | C] -- C:\Users\Chris\Desktop\CB-Desings
[2014.02.20 20:51:58 | 000,000,000 | R--D | C] -- C:\Users\Chris\Dropbox
[2014.02.20 20:50:49 | 000,000,000 | ---D | C] -- C:\Users\Chris\AppData\Roaming\DropboxMaster
[2014.02.20 20:50:23 | 000,000,000 | ---D | C] -- C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2014.02.20 20:49:00 | 000,000,000 | ---D | C] -- C:\Users\Chris\AppData\Roaming\Dropbox
[2014.02.20 16:21:16 | 000,000,000 | ---D | C] -- C:\Users\Chris\AppData\Roaming\TuneUp Software
[2014.02.20 16:19:24 | 000,000,000 | ---D | C] -- C:\ProgramData\TuneUp Software
[2014.02.20 16:19:11 | 000,000,000 | -HSD | C] -- C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
[2014.02.20 16:19:11 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2014.02.20 16:15:19 | 000,000,000 | ---D | C] -- C:\Users\Chris\AppData\Roaming\OpenCandy
[2014.02.18 17:28:00 | 000,000,000 | ---D | C] -- C:\Users\Chris\Desktop\Filme Download
[2014.02.15 07:47:08 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2014.02.15 06:30:01 | 000,000,000 | ---D | C] -- C:\Program Files\Scanner Recorder
[2014.02.13 22:59:09 | 000,000,000 | ---D | C] -- C:\Users\Chris\Desktop\Filme Dome
[2014.02.13 18:25:22 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Thunderbird
[2014.02.11 17:14:28 | 000,000,000 | ---D | C] -- C:\Users\Chris\Desktop\SD-Karte
[2014.02.09 17:58:29 | 000,000,000 | ---D | C] -- C:\Users\Chris\AppData\Roaming\TeamViewer
[2014.02.08 10:06:27 | 000,000,000 | ---D | C] -- C:\Users\Chris\Documents\Native Instruments
[2014.02.08 10:06:02 | 000,000,000 | -H-D | C] -- C:\ProgramData\{E54DB1D4-CC7D-414E-8BED-584C447836EA}
[2014.02.08 10:00:36 | 000,000,000 | -H-D | C] -- C:\ProgramData\{9477ED15-E4A3-4984-9B76-31F573D8EAAF}
[2014.02.08 09:59:43 | 000,000,000 | -H-D | C] -- C:\ProgramData\{F2610326-6A40-4BBC-9FBC-7F05356A912A}
[2014.02.08 09:59:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments
[2014.02.08 09:59:40 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Native Instruments
[2014.02.08 09:59:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Native Instruments
[2014.02.08 09:59:39 | 000,000,000 | ---D | C] -- C:\Program Files\Native Instruments
[2014.02.08 09:45:25 | 000,000,000 | ---D | C] -- C:\Users\Chris\Documents\Native Instruments Traktor Scratch Pro 2.v2.6.3
[2014.02.07 23:50:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Serato
[2014.02.07 23:50:21 | 000,000,000 | ---D | C] -- C:\Program Files\Serato
[2014.02.07 23:50:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Package Cache
[2014.02.07 23:29:51 | 000,000,000 | ---D | C] -- C:\Users\Chris\Desktop\Bild 2
[2014.02.04 18:03:49 | 000,000,000 | -H-D | C] -- C:\Program Files\Temp
[2014.02.03 18:55:35 | 000,000,000 | ---D | C] -- C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SAM Broadcaster
[2014.02.03 18:20:08 | 000,000,000 | ---D | C] -- C:\Users\Chris\AppData\Local\SpacialAudio
[2014.02.03 18:20:08 | 000,000,000 | ---D | C] -- C:\ProgramData\firebird
[2014.02.03 18:17:28 | 000,552,960 | ---- | C] (Firebird Project) -- C:\Windows\System32\GDS32.DLL
[2014.02.03 18:17:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firebird 2.5 (Win32)
[2014.02.03 18:16:56 | 000,000,000 | ---D | C] -- C:\Program Files\Firebird
[2014.02.03 18:16:11 | 000,000,000 | ---D | C] -- C:\Program Files\SpacialAudio
[2014.02.03 17:18:57 | 000,000,000 | ---D | C] -- C:\Users\Chris\AppData\Local\IsolatedStorage
[2014.02.03 17:18:44 | 000,000,000 | ---D | C] -- C:\Program Files\OpenPlsInWMP
[2014.02.03 17:00:25 | 000,000,000 | ---D | C] -- C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SHOUTcast DNAS
[2014.02.03 17:00:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SHOUTcast DNAS
[2014.02.03 17:00:25 | 000,000,000 | ---D | C] -- C:\Program Files\SHOUTcast
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2014.03.04 11:45:00 | 000,001,096 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014.03.04 11:44:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014.03.04 11:41:16 | 000,025,648 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014.03.04 11:41:16 | 000,025,648 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014.03.04 11:34:14 | 000,002,080 | ---- | M] () -- C:\Windows\tasks\Plus-HD-1.3-firefoxinstaller.job
[2014.03.04 11:34:14 | 000,001,952 | ---- | M] () -- C:\Windows\tasks\Plus-HD-1.3-chromeinstaller.job
[2014.03.04 11:34:14 | 000,001,316 | ---- | M] () -- C:\Windows\tasks\Plus-HD-1.3-updater.job
[2014.03.04 11:34:14 | 000,001,218 | ---- | M] () -- C:\Windows\tasks\Plus-HD-1.3-codedownloader.job
[2014.03.04 11:34:14 | 000,001,118 | ---- | M] () -- C:\Windows\tasks\Plus-HD-1.3-enabler.job
[2014.03.04 11:34:14 | 000,001,092 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014.03.04 11:33:50 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014.03.04 11:33:45 | 2415,419,392 | -HS- | M] () -- C:\hiberfil.sys
[2014.03.04 11:31:57 | 000,001,094 | ---- | M] () -- C:\Users\Public\Desktop\Kaspersky Internet Security.lnk
[2014.03.04 11:25:44 | 257,813,336 | ---- | M] () -- C:\Users\Chris\Documents\kis14.0.0.4651de-de.exe
[2014.03.04 09:53:09 | 000,002,121 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014.03.03 21:25:06 | 000,000,965 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2014.03.02 02:08:04 | 000,001,630 | ---- | M] () -- C:\Users\Public\Desktop\Combat Arms EU.lnk
[2014.03.01 19:47:05 | 1967,289,647 | ---- | M] (Nexon) -- C:\Users\Chris\Documents\Combatarms_eu.exe
[2014.03.01 16:18:37 | 000,050,728 | ---- | M] (Eugene V. Muzychenko) -- C:\Windows\System32\drivers\vrtaucbl.sys
[2014.03.01 16:13:41 | 001,323,708 | ---- | M] () -- C:\Users\Chris\Documents\VIRTUAL_AUDIO_CABLE_4.10.RAR
[2014.03.01 15:28:49 | 000,976,332 | ---- | M] () -- C:\Users\Chris\Desktop\Unbenannt.png
[2014.02.26 14:45:06 | 000,699,416 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2014.02.26 14:45:06 | 000,654,254 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2014.02.26 14:45:06 | 000,149,556 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2014.02.26 14:45:06 | 000,122,126 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2014.02.26 14:15:30 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\CAE Report Generator.lnk
[2014.02.25 17:08:17 | 001,369,088 | ---- | M] () -- C:\Users\Chris\Desktop\MVH Loader.exe
[2014.02.24 22:45:03 | 001,106,766 | ---- | M] () -- C:\Users\Chris\Desktop\MVH Loader.zip
[2014.02.20 20:51:58 | 000,001,039 | ---- | M] () -- C:\Users\Chris\Desktop\Dropbox.lnk
[2014.02.20 17:57:42 | 000,000,132 | ---- | M] () -- C:\Users\Chris\AppData\Roaming\Adobe CS6-PNG-Format - Voreinstellungen
[2014.02.20 16:16:17 | 000,000,000 | ---- | M] () -- C:\END
[2014.02.18 10:38:43 | 000,025,184 | ---- | M] (Kaspersky Lab ZAO) -- C:\Windows\System32\drivers\klkbdflt.sys
[2014.02.18 10:38:42 | 000,576,096 | ---- | M] (Kaspersky Lab ZAO) -- C:\Windows\System32\drivers\klif.sys
[2014.02.18 10:38:42 | 000,094,304 | ---- | M] (Kaspersky Lab ZAO) -- C:\Windows\System32\drivers\klflt.sys
[2014.02.09 11:47:34 | 003,771,384 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2014.02.08 13:33:50 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2014.02.08 13:33:50 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2014.02.08 10:05:48 | 000,001,002 | ---- | M] () -- C:\Users\Public\Desktop\Traktor 2.lnk
[2014.02.08 10:00:33 | 000,001,094 | ---- | M] () -- C:\Users\Public\Desktop\Controller Editor.lnk
[2014.02.08 09:59:42 | 000,001,059 | ---- | M] () -- C:\Users\Public\Desktop\Service Center.lnk
[2014.02.05 20:45:06 | 000,000,600 | ---- | M] () -- C:\Users\Chris\AppData\Local\PUTTY.RND
[2014.02.04 18:05:47 | 000,000,000 | -H-- | M] () -- C:\ProgramData\DP45977C.lfl
[2014.02.03 18:55:35 | 000,001,974 | ---- | M] () -- C:\Users\Chris\Desktop\SAM Broadcaster.lnk
[2014.02.03 18:18:07 | 000,004,988 | ---- | M] () -- C:\ProgramData\qiwmnyln.lsb
[2014.02.02 15:48:16 | 000,001,253 | ---- | M] () -- C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
[2014.02.02 13:03:25 | 000,001,361 | ---- | M] () -- C:\Users\Chris\Desktop\ILS-SimV4.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014.03.04 11:20:23 | 257,813,336 | ---- | C] () -- C:\Users\Chris\Documents\kis14.0.0.4651de-de.exe
[2014.03.02 02:08:04 | 000,001,630 | ---- | C] () -- C:\Users\Public\Desktop\Combat Arms EU.lnk
[2014.03.01 16:13:39 | 001,323,708 | ---- | C] () -- C:\Users\Chris\Documents\VIRTUAL_AUDIO_CABLE_4.10.RAR
[2014.03.01 15:28:31 | 000,976,332 | ---- | C] () -- C:\Users\Chris\Desktop\Unbenannt.png
[2014.02.26 14:15:30 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\CAE Report Generator.lnk
[2014.02.24 22:46:53 | 001,369,088 | ---- | C] () -- C:\Users\Chris\Desktop\MVH Loader.exe
[2014.02.24 22:45:01 | 001,106,766 | ---- | C] () -- C:\Users\Chris\Desktop\MVH Loader.zip
[2014.02.20 20:51:58 | 000,001,039 | ---- | C] () -- C:\Users\Chris\Desktop\Dropbox.lnk
[2014.02.19 00:07:20 | 000,000,965 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2014.02.15 06:30:02 | 000,002,917 | ---- | C] () -- C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Scanner Recorder.lnk
[2014.02.08 13:33:50 | 000,000,000 | RHS- | C] () -- C:\MSDOS.SYS
[2014.02.08 13:33:50 | 000,000,000 | RHS- | C] () -- C:\IO.SYS
[2014.02.08 10:05:48 | 000,001,002 | ---- | C] () -- C:\Users\Public\Desktop\Traktor 2.lnk
[2014.02.08 10:00:33 | 000,001,094 | ---- | C] () -- C:\Users\Public\Desktop\Controller Editor.lnk
[2014.02.08 09:59:42 | 000,001,059 | ---- | C] () -- C:\Users\Public\Desktop\Service Center.lnk
[2014.02.04 18:05:47 | 000,000,000 | -H-- | C] () -- C:\ProgramData\DP45977C.lfl
[2014.02.03 18:55:35 | 000,001,974 | ---- | C] () -- C:\Users\Chris\Desktop\SAM Broadcaster.lnk
[2014.02.03 18:18:07 | 000,004,988 | ---- | C] () -- C:\ProgramData\qiwmnyln.lsb
[2014.02.02 13:03:25 | 000,001,361 | ---- | C] () -- C:\Users\Chris\Desktop\ILS-SimV4.lnk
[2014.01.08 22:36:13 | 000,000,132 | ---- | C] () -- C:\Users\Chris\AppData\Roaming\Adobe CS6-PNG-Format - Voreinstellungen
[2013.12.20 23:40:20 | 000,139,032 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2013.12.20 23:40:14 | 000,290,184 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2013.12.20 23:40:07 | 000,076,888 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2013.12.20 17:42:20 | 000,007,634 | ---- | C] () -- C:\Users\Chris\AppData\Local\Resmon.ResmonCfg
[2013.12.13 16:34:00 | 000,000,062 | ---- | C] () -- C:\Windows\wininit.ini
[2013.12.08 22:49:32 | 144,752,885 | ---- | C] () -- C:\Users\Chris\AppData\Local\ACCCx2_2_1_260(1).zip
[2013.12.08 22:37:54 | 144,752,885 | ---- | C] () -- C:\Users\Chris\AppData\Local\ACCCx2_2_1_260.zip
[2013.12.08 01:11:00 | 000,011,164 | ---- | C] () -- C:\Windows\System32\drivers\nvphy.bin
[2013.11.28 21:27:51 | 000,000,528 | R--- | C] () -- C:\Users\Chris\MediaID.bin
[2013.11.21 19:07:46 | 000,000,600 | ---- | C] () -- C:\Users\Chris\AppData\Roaming\winscp.rnd
[2013.11.20 22:41:53 | 000,000,600 | ---- | C] () -- C:\Users\Chris\AppData\Local\PUTTY.RND
[2013.11.15 10:52:34 | 000,138,056 | ---- | C] () -- C:\Users\Chris\AppData\Roaming\PnkBstrK.sys
[2013.11.15 03:02:41 | 000,699,416 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2013.11.15 03:02:41 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2013.11.15 03:02:41 | 000,149,556 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2013.11.15 03:02:41 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2013.11.14 18:06:49 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2013.04.30 03:30:54 | 000,204,952 | ---- | C] () -- C:\Windows\System32\ativvsvl.dat
[2013.04.30 03:30:54 | 000,157,144 | ---- | C] () -- C:\Windows\System32\ativvsva.dat
[2013.04.29 23:36:28 | 000,159,232 | ---- | C] () -- C:\Windows\System32\clinfo.exe
[2012.07.02 21:11:02 | 000,016,384 | ---- | C] () -- C:\Windows\System32\theowl.dll
[2012.04.18 19:39:06 | 000,028,672 | ---- | C] () -- C:\Windows\System32\kdbsdk32.dll
[2012.03.06 18:59:32 | 000,618,823 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2005.04.24 18:14:00 | 000,025,896 | -H-- | C] () -- C:\Users\Chris\AppData\Roaming\Chrislog.dat
========== ZeroAccess Check ==========
[2009.07.14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013.07.26 02:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 22:29:20 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.07.14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013.12.03 17:58:31 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Audacity
[2014.02.26 14:15:39 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\CAE_Report_Generator
[2013.12.12 20:21:14 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2014.01.25 01:13:23 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\DAEMON Tools Lite
[2014.01.19 13:26:21 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Dealply
[2014.03.03 11:17:53 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Dropbox
[2014.02.20 20:51:58 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\DropboxMaster
[2014.02.25 16:29:43 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\DVDVideoSoft
[2014.03.03 21:28:16 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\FileZilla
[2013.12.08 22:43:17 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\flightgear.org
[2013.12.03 16:45:29 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\FlowStone
[2013.12.24 00:47:29 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\FT_Software
[2014.01.14 21:52:27 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\ICQ-Profile
[2014.01.14 16:15:58 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\ICQM
[2013.12.03 16:45:55 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Image-Line
[2013.12.08 22:11:15 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\iSafe
[2013.11.24 14:32:11 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\IsolatedStorage
[2013.11.16 09:43:16 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\KY-Programming
[2014.02.24 22:48:44 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\MVH
[2014.01.16 22:52:19 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\newnext.me
[2013.11.21 20:37:51 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Notepad++
[2014.02.20 16:15:19 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\OpenCandy
[2013.11.19 22:51:56 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\OpenOffice
[2013.11.15 07:14:09 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Origin
[2014.02.20 16:26:06 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Solvusoft
[2013.11.16 19:37:52 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\SoundSpectrum
[2014.02.08 13:14:56 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Spotify
[2013.12.20 20:21:27 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\svchost.exe
[2014.03.01 15:55:31 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Systweak
[2014.02.09 18:03:56 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\TeamViewer
[2013.11.14 21:06:28 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\Thunderbird
[2014.03.04 11:40:50 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\TS3Client
[2014.02.20 16:21:16 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\TuneUp Software
[2014.02.02 00:10:00 | 000,000,000 | -HSD | M] -- C:\Users\Chris\AppData\Roaming\wyUpdate AU
[2013.12.28 19:47:42 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\XMedia Recode
[2013.11.14 21:17:19 | 000,000,000 | ---D | M] -- C:\Users\Chris\AppData\Roaming\YaTQA
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*. >
[2014.01.19 17:04:01 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin
[2013.11.28 21:12:25 | 000,000,000 | ---D | M] -- C:\8ebf41383ee3e18591c24b16c6d795
[2013.11.28 21:16:34 | 000,000,000 | ---D | M] -- C:\AMD
[2013.11.15 03:03:46 | 000,000,000 | -HSD | M] -- C:\Boot
[2014.03.04 11:32:20 | 000,000,000 | -HSD | M] -- C:\Config.Msi
[2013.12.28 14:13:36 | 000,000,000 | ---D | M] -- C:\dell
[2009.07.14 05:53:55 | 000,000,000 | -HSD | M] -- C:\Documents and Settings
[2013.11.14 19:25:49 | 000,000,000 | -HSD | M] -- C:\Dokumente und Einstellungen
[2013.11.16 21:20:21 | 000,000,000 | ---D | M] -- C:\Download
[2013.11.15 03:03:25 | 000,000,000 | ---D | M] -- C:\Drivers
[2013.11.15 03:03:25 | 000,000,000 | ---D | M] -- C:\Hotfix
[2014.03.02 02:05:03 | 000,000,000 | ---D | M] -- C:\Nexon
[2009.07.14 03:37:05 | 000,000,000 | ---D | M] -- C:\PerfLogs
[2014.03.03 21:23:10 | 000,000,000 | R--D | M] -- C:\Program Files
[2014.03.04 11:32:30 | 000,000,000 | -H-D | M] -- C:\ProgramData
[2013.11.14 19:25:49 | 000,000,000 | -HSD | M] -- C:\Programme
[2013.11.14 19:25:49 | 000,000,000 | -HSD | M] -- C:\Recovery
[2013.11.24 14:29:35 | 000,000,000 | ---D | M] -- C:\Spacekace
[2014.03.04 11:52:46 | 000,000,000 | -HSD | M] -- C:\System Volume Information
[2013.12.08 11:48:21 | 000,000,000 | R--D | M] -- C:\Users
[2014.03.03 22:19:30 | 000,000,000 | ---D | M] -- C:\Windows
< %PROGRAMFILES%\*.exe >
< %LOCALAPPDATA%\*.exe >
< %systemroot%\*. /mp /s >
< C:\Windows\system32\*.tsp >
[2009.07.14 02:14:11 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\hidphone.tsp
[2009.07.14 02:14:11 | 000,038,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\kmddsp.tsp
[2009.07.14 02:14:11 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\ndptsp.tsp
[2009.07.14 02:14:11 | 000,082,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\remotesp.tsp
[2010.11.20 22:29:06 | 000,281,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\unimdm.tsp
[2009.07.14 05:53:46 | 000,032,634 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2009.07.14 05:53:47 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2013.11.14 19:33:46 | 000,000,884 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
[2013.11.14 21:28:54 | 000,001,092 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2013.11.14 21:28:56 | 000,001,096 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2013.12.13 07:23:37 | 000,001,952 | ---- | C] () -- C:\Windows\Tasks\Plus-HD-1.3-chromeinstaller.job
[2013.12.13 07:24:18 | 000,002,080 | ---- | C] () -- C:\Windows\Tasks\Plus-HD-1.3-firefoxinstaller.job
[2013.12.13 07:24:35 | 000,001,218 | ---- | C] () -- C:\Windows\Tasks\Plus-HD-1.3-codedownloader.job
[2013.12.13 07:24:40 | 000,001,118 | ---- | C] () -- C:\Windows\Tasks\Plus-HD-1.3-enabler.job
[2013.12.13 07:24:45 | 000,001,316 | ---- | C] () -- C:\Windows\Tasks\Plus-HD-1.3-updater.job
< MD5 for: AGP440.SYS >
[2009.07.14 02:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\drivers\AGP440.sys
[2009.07.14 02:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\AGP440.sys
[2009.07.14 02:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_bc1a57271cf2f285\AGP440.sys
< MD5 for: ATAPI.SYS >
[2009.07.14 02:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\drivers\atapi.sys
[2009.07.14 02:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_a5025d31bee4647c\atapi.sys
[2009.07.14 02:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\atapi.sys
[2009.07.14 02:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_df3f92057fcbe7a7\atapi.sys
[2009.07.14 02:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7601.18231_none_df26d4d57fdef5b0\atapi.sys
[2009.07.14 02:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7601.22414_none_dfc9143c98e9a6c4\atapi.sys
< MD5 for: CNGAUDIT.DLL >
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\System32\cngaudit.dll
[2009.07.14 02:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
< MD5 for: EXPLORER.EXE >
[2011.02.26 06:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2010.11.20 22:29:20 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\explorer.exe
[2011.02.25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
< MD5 for: IASTORV.SYS >
[2011.03.11 06:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\System32\drivers\iaStorV.sys
[2011.03.11 06:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_0bcee2057afcc090\iaStorV.sys
[2011.03.11 06:38:51 | 000,332,160 | ---- | M] (Intel Corporation) MD5=5CD5F9A5444E6CDCB0AC89BD62D8B76E -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_b0daddb9e6380745\iaStorV.sys
[2011.03.11 06:28:00 | 000,332,160 | ---- | M] (Intel Corporation) MD5=778D0E6D7D9EBA0C403BADBAAD41DB20 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_b152a892ff64119f\iaStorV.sys
[2010.11.20 22:29:03 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_668286aa35d55928\iaStorV.sys
[2010.11.20 22:29:03 | 000,332,160 | ---- | M] (Intel Corporation) MD5=A3CAE5D281DB4CFF7CFF8233507EE5AD -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_b118bc63e60a139a\iaStorV.sys
< MD5 for: NETLOGON.DLL >
[2010.11.20 22:29:12 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\System32\netlogon.dll
[2010.11.20 22:29:12 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_ffbf212e963c0162\netlogon.dll
< MD5 for: NVSTOR.SYS >
[2011.03.11 06:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\System32\drivers\nvstor.sys
[2011.03.11 06:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_0276fc3b3ea60d41\nvstor.sys
[2011.03.11 06:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=4380E59A170D88C4F1022EFF6719A8A4 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_3ba44e691d6eb11d\nvstor.sys
[2011.03.11 06:28:10 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=66D468654A58594F5F3BA63D5AD5B1AF -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_3c1c1942369abb77\nvstor.sys
[2010.11.20 22:29:03 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_dd659ed032d28a14\nvstor.sys
[2010.11.20 22:29:03 | 000,143,744 | ---- | M] (NVIDIA Corporation) MD5=9283C58EBAA2618F93482EB5DABCEC82 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_3be22d131d40bd72\nvstor.sys
< MD5 for: SCECLI.DLL >
[2010.11.20 22:29:07 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\System32\scecli.dll
[2010.11.20 22:29:07 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_3a154c47375d881d\scecli.dll
< MD5 for: USER32.DLL >
[2010.11.20 22:29:20 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- C:\Windows\System32\user32.dll
[2010.11.20 22:29:20 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll
< MD5 for: USERINIT.EXE >
[2010.11.20 22:29:06 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\System32\userinit.exe
[2010.11.20 22:29:06 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
< MD5 for: WINLOGON.EXE >
[2010.11.20 22:29:06 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\System32\winlogon.exe
[2010.11.20 22:29:06 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
< MD5 for: WS2IFSL.SYS >
[2009.07.14 00:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\System32\drivers\ws2ifsl.sys
[2009.07.14 00:55:02 | 000,016,384 | ---- | M] (Microsoft Corporation) MD5=6DB3276587B853BF886B69528FDB048C -- C:\Windows\winsxs\x86_microsoft-windows-w..rastructure-ws2ifsl_31bf3856ad364e35_6.1.7600.16385_none_4f5cf6f829213bb2\ws2ifsl.sys
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2013.11.14 22:31:28 | 000,135,776 | ---- | M] (Kaspersky Lab ZAO) Unable to obtain MD5 -- C:\Windows\system32\drivers\kl1.sys
[2014.02.18 10:38:42 | 000,094,304 | ---- | M] (Kaspersky Lab ZAO) Unable to obtain MD5 -- C:\Windows\system32\drivers\klflt.sys
[2014.02.18 10:38:42 | 000,576,096 | ---- | M] (Kaspersky Lab ZAO) Unable to obtain MD5 -- C:\Windows\system32\drivers\klif.sys
[2013.10.17 15:47:26 | 000,025,696 | ---- | M] (Kaspersky Lab ZAO) Unable to obtain MD5 -- C:\Windows\system32\drivers\klim6.sys
[2014.02.18 10:38:43 | 000,025,184 | ---- | M] (Kaspersky Lab ZAO) Unable to obtain MD5 -- C:\Windows\system32\drivers\klkbdflt.sys
[2013.10.17 15:47:26 | 000,025,696 | ---- | M] (Kaspersky Lab ZAO) Unable to obtain MD5 -- C:\Windows\system32\drivers\klmouflt.sys
[2013.04.12 15:34:48 | 000,014,432 | ---- | M] (Kaspersky Lab ZAO) Unable to obtain MD5 -- C:\Windows\system32\drivers\klpd.sys
[2013.05.14 17:34:44 | 000,045,024 | ---- | M] (Kaspersky Lab ZAO) Unable to obtain MD5 -- C:\Windows\system32\drivers\kltdi.sys
[2013.12.19 12:47:51 | 000,144,992 | ---- | M] (Kaspersky Lab ZAO) Unable to obtain MD5 -- C:\Windows\system32\drivers\kneps.sys
< %systemroot%\System32\config\*.sav >
< %systemroot%\system32\*.dll /lockedfiles >
< %USERPROFILE%\*.* >
[2013.12.08 11:48:22 | 000,000,000 | ---- | M] () -- C:\Users\Chris\daemonprocess.txt
[2013.11.28 21:27:51 | 000,000,528 | R--- | M] () -- C:\Users\Chris\MediaID.bin
[2014.03.04 12:18:32 | 003,670,016 | -HS- | M] () -- C:\Users\Chris\ntuser.dat
[2014.03.04 12:18:32 | 000,262,144 | -HS- | M] () -- C:\Users\Chris\ntuser.dat.LOG1
[2013.11.14 19:26:02 | 000,000,000 | -HS- | M] () -- C:\Users\Chris\ntuser.dat.LOG2
[2013.11.14 19:26:02 | 000,065,536 | -HS- | M] () -- C:\Users\Chris\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
[2013.11.14 19:26:02 | 000,524,288 | -HS- | M] () -- C:\Users\Chris\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
[2013.11.14 19:26:02 | 000,524,288 | -HS- | M] () -- C:\Users\Chris\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
[2014.01.25 07:16:54 | 000,065,536 | -HS- | M] () -- C:\Users\Chris\ntuser.dat{d217c682-850a-11e3-bbc9-002185194ef1}.TM.blf
[2014.01.25 07:16:54 | 000,524,288 | -HS- | M] () -- C:\Users\Chris\ntuser.dat{d217c682-850a-11e3-bbc9-002185194ef1}.TMContainer00000000000000000001.regtrans-ms
[2014.01.25 07:16:54 | 000,524,288 | -HS- | M] () -- C:\Users\Chris\ntuser.dat{d217c682-850a-11e3-bbc9-002185194ef1}.TMContainer00000000000000000002.regtrans-ms
[2013.11.14 19:26:02 | 000,000,020 | -HS- | M] () -- C:\Users\Chris\ntuser.ini
< %USERPROFILE%\Local Settings\Temp\*.exe >
< %USERPROFILE%\Local Settings\Temp\*.dll >
< %USERPROFILE%\Application Data\*.exe >
< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems|Windows /rs >
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Required: DebugWindows [binary data]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\\Windows: %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
========== Files - Unicode (All) ==========
[2014.02.24 07:09:01 | 001,343,488 | ---- | M] ()(C:\Windows\System32\????????????????????????????????) -- C:\Windows\System32\㩣灜潲牧浡慤慴歜獡数獲祫氠扡慜灶㐱〮〮摜瑡屡潭畤敬彳湩敶瑮牯慤
[2013.11.23 15:35:40 | 001,343,488 | ---- | C] ()(C:\Windows\System32\????????????????????????????????) -- C:\Windows\System32\㩣灜潲牧浡慤慴歜獡数獲祫氠扡慜灶㐱〮〮摜瑡屡潭畤敬彳湩敶瑮牯慤
< End of report > Exras: Code:
OTL Extras logfile created on: 04.03.2014 11:50:06 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Chris\Downloads
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16518)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,00 Gb Total Physical Memory | 2,17 Gb Available Physical Memory | 72,45% Memory free
6,00 Gb Paging File | 4,91 Gb Available in Paging File | 81,92% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 931,51 Gb Total Space | 287,57 Gb Free Space | 30,87% Space Free | Partition Type: NTFS
Computer Name: CHRIS-PC | User Name: Chris | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] -- Reg Error: Key error. File not found
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- Reg Error: Key error.
htmlfile [opennew] -- Reg Error: Key error.
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] -- C:\Program Files\Adobe\Adobe Bridge CS6\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- Reg Error: Key error.
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Key error.
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{12997831-6BEB-48F0-9E4E-CDEE6D89FE6A}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{253FD525-3219-404A-BF74-DD4437A6F617}" = lport=139 | protocol=6 | dir=in | app=system |
"{362D59F3-CEA2-41B2-ADFA-B782D1D47B96}" = rport=445 | protocol=6 | dir=out | app=system |
"{45B43115-695E-4CC3-9448-3083FA42E630}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{51CA24CB-5953-4FB5-A303-6A54B7F7DEC6}" = rport=138 | protocol=17 | dir=out | app=system |
"{53AEFDDD-01A5-4464-83A4-27E45FCBCAA8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{5CDF08D9-F1A9-4013-9063-286737043805}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework\v4.0.30319\smsvchost.exe |
"{65A3B10C-928A-4A09-9DBF-EAE6155E7D0C}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{7EB0BA99-DA0A-49BD-A84E-06CD26198AA3}" = lport=137 | protocol=17 | dir=in | app=system |
"{9068133E-E233-4587-B025-E6BDB4681102}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{95E05BA2-56FF-4CF6-855E-45C82AB7A773}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{A2F553DF-BA70-47CA-92E7-0CAFE76A7B73}" = lport=138 | protocol=17 | dir=in | app=system |
"{A4C5BAA6-E06D-4C1E-B43E-CADC3D47B01F}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{B62ECB5A-FAB2-4858-A766-776CA3DED7E5}" = lport=10243 | protocol=6 | dir=in | app=system |
"{BD992055-9E23-42CC-B850-C3F4FC357709}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{BF1D8653-8ACC-454C-903E-D474900FE4A1}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D28B56B0-FA55-4A1F-8CB4-EE08DF03722A}" = rport=139 | protocol=6 | dir=out | app=system |
"{D372ECE4-20D5-423E-A2E6-3BD41A139B06}" = rport=10243 | protocol=6 | dir=out | app=system |
"{DA8ACEA7-F578-4C28-8B41-5D416D5DD4FF}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{FD0E75DA-2F8F-4FC1-B401-83A0F2ACEF13}" = lport=2869 | protocol=6 | dir=in | app=system |
"{FE327B06-5652-481D-B284-F982CB6C6DC9}" = rport=137 | protocol=17 | dir=out | app=system |
"{FECEEB85-ADC7-4772-987F-9275C1D66E72}" = lport=445 | protocol=6 | dir=in | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0387BE3E-5302-47A5-9DD3-2E9401D4067C}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{0818E383-187E-42A5-9B9D-1672AD0239EB}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\counter-strike global offensive\csgo.exe |
"{0C03850B-7FDD-48CB-9EB9-FC24F659AD95}" = protocol=6 | dir=in | app=c:\program files\steam\steam.exe |
"{0E7508D7-16B7-4AE7-803A-D9E1D2BC6A80}" = protocol=17 | dir=in | app=c:\program files\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{0FDAAF00-5639-4544-9B8D-770AA9926B7F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{1003CE41-2BC8-4AB1-B276-3F39EDE1A91E}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{1BEE3657-1D04-4AA9-A578-3C9540FB0EE2}" = protocol=17 | dir=in | app=c:\users\chris\appdata\roaming\dropbox\bin\dropbox.exe |
"{239E317C-29CA-4D41-8451-B9D1EBEE3517}" = protocol=6 | dir=in | app=c:\nexon\combat arms eu\nmservice.exe |
"{28401590-2985-4963-AE34-FBE37D329D42}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{2AF60912-751C-4373-A430-81B7019F6616}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{2F8F4D1B-14B2-48E1-B273-4A96932860E8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{30298EFF-EB39-4687-8801-B6448066C6F0}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{3C0F3749-8E40-4813-A36C-AE7F4FBA7B56}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version9\teamviewer.exe |
"{3E93199D-9FEB-4D34-A99A-4F2FAFAA35E2}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{4D3082DA-8429-4FED-841E-743FD01030F7}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version9\teamviewer_service.exe |
"{52D9E9E1-1142-4FF7-88F9-6AB832462A50}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{5678A7DB-5779-4B0D-A551-52FE4E2B153A}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{56C9F0B7-D313-438D-A1AD-EC8D5340AE3F}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{5820BC58-BC0E-44CB-B41D-1C25342DC9FC}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{58BE2F42-709C-48E0-908E-C0F8EB1F899B}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{58E8D33B-99B3-4482-9248-322EE8697EBB}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\railworks\railworks.exe |
"{5BAC8378-0514-4426-BF95-D61F78EB0798}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\euro truck simulator\eurotrucks.exe |
"{5D972DED-FD96-4B6C-8909-84126E077452}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\counter-strike global offensive\csgo.exe |
"{5DD94AA1-03BF-4DF1-A8C7-F2A1CE144CC3}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\counter-strike global offensive\csgo.exe |
"{5F0E5084-A25E-4F82-ABF3-4C376D7D6312}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{621CEAF7-D0CA-4EBE-9FD2-BCA050BB2C36}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\railworks\railworks.exe |
"{62F0023B-B794-4D3B-B69D-F5631E6FD8C3}" = protocol=6 | dir=out | app=system |
"{70073E45-D233-43D6-A3C2-E60403336F00}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{7C292CA6-B6D4-49D5-B523-0C7A97931F26}" = protocol=17 | dir=in | app=c:\programdata\nexoneu\ngm\ngm.exe |
"{862413C0-9B7B-4633-ABC8-3B8AEE757A5E}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\counter-strike global offensive\csgo.exe |
"{88A8BE23-1255-4184-BB69-3AF08E7D24BC}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{925F0368-E378-43E5-8511-2AC48524081D}" = protocol=6 | dir=in | app=c:\programdata\nexoneu\ngm\ngm.exe |
"{A40CAA0C-10E0-4935-880E-04732E148C39}" = protocol=17 | dir=in | app=c:\program files\steam\steam.exe |
"{A5996292-7FA1-49A0-87D5-945BA500A2B1}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version9\teamviewer_service.exe |
"{A89CB780-2EF7-48D5-99D6-33541403F48C}" = protocol=17 | dir=in | app=c:\users\chris\appdata\roaming\icqm\icq.exe |
"{A8DC0B66-6395-4321-A098-7292816F6E17}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\euro truck simulator\eurotrucks.exe |
"{BBDC0E56-BBDC-445C-B7DB-54185D6C9296}" = protocol=6 | dir=in | app=c:\program files\origin games\battlefield 3\bf3.exe |
"{BDE240F9-CC02-43D1-9C9A-5C9A823626AE}" = protocol=6 | dir=in | app=c:\users\chris\appdata\roaming\dropbox\bin\dropbox.exe |
"{D111F2B7-D6C5-48B4-A429-46C5681BAA88}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{D740B318-1332-4736-9A2C-696B646EAEF8}" = protocol=6 | dir=in | app=c:\program files\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
"{DC12ED60-D0CA-492F-9150-B1AB1787E0E4}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{E24EBAF1-A82B-4CA1-BC41-C1AC7D83A27D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{E6C5ABF1-1253-41D5-B280-E7D01BD89C4F}" = protocol=17 | dir=in | app=c:\program files\origin games\battlefield 3\bf3.exe |
"{EC628071-14EB-4E6F-A617-91ACA324611F}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{EDBACFB7-1E0A-418B-A0D6-FD5EDDBF1176}" = protocol=17 | dir=in | app=c:\nexon\combat arms eu\nmservice.exe |
"{EE9EA8E1-92F3-43DE-B100-499D6A22EBFF}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{F08BD54B-7C62-4E72-9033-D8A5766A534E}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version9\teamviewer.exe |
"{F83AC32D-BE8A-47D1-BE0D-D415ED92A308}" = protocol=6 | dir=in | app=c:\users\chris\appdata\roaming\icqm\icq.exe |
"{FC868FEE-4F6B-4C6C-9370-49E59B1E9260}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"TCP Query User{4987910B-F199-4465-85AF-D745B73A5600}C:\users\chris\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\chris\appdata\roaming\spotify\spotify.exe |
"TCP Query User{747F59E0-65EF-49F7-9C30-DA785EA5A823}C:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe" = protocol=6 | dir=in | app=c:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe |
"UDP Query User{115538E1-C9A7-440C-A5D5-820B17873D6F}C:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe" = protocol=17 | dir=in | app=c:\nexon\nexon_eu_downloader\nexon_eu_downloader_engine.exe |
"UDP Query User{B6F893DB-F8DC-4543-9598-FA496A352356}C:\users\chris\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\chris\appdata\roaming\spotify\spotify.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00F14E5B-E07A-2A1E-6788-580773CE1486}" = CCC Help English
"{0886900B-B2F3-452C-B580-60F1253F7F80}" = Native Instruments Controller Editor
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0A036215-0A8D-6FBE-7EA3-7AED4F9E162A}" = CCC Help Turkish
"{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}" = OpenOffice 4.0.1
"{0B8565BA-BAD5-4732-B122-5FD78EFC50A9}" = Native Instruments Service Center
"{15A05AAA-37E7-D516-5BE9-C960C2170403}" = CCC Help Czech
"{1d86c014-f03a-43a1-be1b-3001da2b1aa6}" = Serato DJ 1.1
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{21E9850E-58C2-FA88-D5AD-B64D253B8F82}" = CCC Help Thai
"{23F20D12-1D01-4806-8AA8-AC79055109DE}" = VirtualDJ PRO Full
"{25A7270E-1B63-DFD1-ACBC-88852A305398}" = CCC Help Chinese Traditional
"{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1" = ConvertHelper 2.2
"{2E376AD9-5C49-4F7D-A0BA-6A44E8FA5A3B}" = Next Generation Visualisations
"{2E69E784-F84A-9A18-7D8E-4EB8504EEE1E}" = CCC Help Danish
"{362614E4-9ABB-E7A7-CDDC-239AB168060A}" = CCC Help Japanese
"{3BBFD444-5FAB-49F6-98B1-A1954E831399}" = Die Sims™ 3 Showtime
"{3DE92282-CB49-434F-81BF-94E5B380E889}" = Die Sims™ 3 Jahreszeiten
"{3DF7D356-6225-8717-AFC2-91D5C1521036}" = AMD Media Foundation Decoders
"{45057FCE-5784-48BE-8176-D9D00AF56C3C}" = Die Sims™ 3 Late Night
"{4745F6F8-09DA-CC39-EC19-0E8D764CF2B7}" = CCC Help Chinese Standard
"{4903D172-DCCB-392F-93A3-34CA9D47FE3D}" = Microsoft .NET Framework 4.5.1
"{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}" = Google Earth Plug-in
"{4B60A7A4-49F6-4D2A-8AE7-BCBAFA6224CE}" = Simulationsprogramm Integrierte Leitstelle V4
"{4E623953-A936-5114-5702-08A609BA509C}" = HydraVision
"{4FA31DE2-B613-24BB-1738-B655C00B1C9D}" = CCC Help Hungarian
"{52E225FC-FCB4-41F7-837B-6E37FB05BD7B}" = Adobe AIR
"{58771CF6-F212-CC4D-61B1-45CC70B6375C}" = CCC Help Dutch
"{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}" = Apple Application Support
"{5D222DF2-1428-48A6-AB3F-1C7DE57D019C}" = Serato DJ 1.1
"{5D30F159-FFB9-458F-8A03-1747DDE499D8}" = Overwolf
"{6D5CE5F1-CBB0-9ED4-1A1E-91DDCD6225FD}" = CCC Help Italian
"{6F6873E3-5C92-4049-B511-231A138DD090}" = Kaspersky Internet Security
"{707210B0-29F1-C550-BA96-6ECDA245CF24}" = CCC Help Spanish
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{72EF03F5-0507-4861-9A44-D99FD4C41417}" = Paint.NET v3.5.11
"{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}" = Adobe Photoshop CS6
"{76285C16-411A-488A-BCE3-C83CB933D8CF}" = Battlefield 3™
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7F644A4B-C9A7-E419-BFD9-75DFA0EE57DB}" = AMD Accelerated Video Transcoding
"{812B956B-37AB-24B9-4527-78A6D3ECE7F8}" = CCC Help Korean
"{83293709-B863-0EF6-00DA-B026D486E8B5}" = CCC Help Polish
"{8694B919-8C39-41FB-875E-0FC8E3EE3216}_is1" = Werkfeuerwehr Simulator 2014 Version 1.2
"{88B2ABCF-9C00-47C1-8FC4-369B98845DD7}" = Catalyst Control Center - Branding
"{8D5B19AA-3D3A-5870-C9A0-346EBC5DB21E}" = ccc-utility
"{910F4A29-1134-49E0-AD8B-56E4A3152BD1}" = Die Sims™ 3 Traumkarrieren
"{911904DE-EBB6-BC8E-D5BD-762B7DB42C46}" = CCC Help Greek
"{914928E5-4BA3-4809-9280-9C3DC20B993D}" = Scanner Recorder
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031" = Microsoft .NET Framework 4.5.1 (Deutsch)
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1
"{9903011B-5F1D-A2A1-8078-EE62B3324CCE}" = CCC Help Portuguese
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A4C534E-431F-4A17-97D4-D1682B19A054}" = Emergency4
"{9A7F1628-2126-34A5-852D-2B93328BCF3F}" = CCC Help German
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9E871D09-064D-3BC9-963B-3AB8ABE1273D}" = Microsoft .NET Framework 4.5.1 (DEU)
"{9FE75E68-96A2-48F3-90AB-34E6B8C9989D}" = Microsoft-Maus- und Tastatur-Center
"{A25FF1C0-80B6-4B8B-A551-DC525697A408}" = AMD APP SDK Runtime
"{A8D93648-9F7F-407D-915C-62044644C3DA}" = MSI to redistribute MS VS2005 CRT libraries
"{A8EC0CC0-AD8D-4244-B080-424EDF7A7634}" = Native Instruments Traktor 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1031-7B44-AB0000000001}" = Adobe Reader XI (11.0.06) - Deutsch
"{ACEF85BD-2489-BE0E-9965-CE2F661260AA}" = AMD Fuel
"{AE6C422B-DADB-D547-411C-E9E56DF03D16}" = CCC Help Russian
"{B09567CC-E43F-10F1-752D-549AC7FB0C43}" = CCC Help Finnish
"{B170B91D-E8E3-A6A3-D129-D8E36FEA8A0B}" = CCC Help Norwegian
"{B67BAFBA-4C9F-48FA-9496-933E3B255044}" = QuickTime
"{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}" = Die Sims™ 3 Reiseabenteuer
"{BD96ABD3-D1D4-5513-6C60-11476D6DCFC5}" = Catalyst Control Center Localization All
"{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}" = PDF Settings CS6
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = Die Sims™ 3
"{C39C7876-4D21-8A38-0A42-B5C8858EC6C7}" = CCC Help French
"{C4C91E02-D4E2-481E-BCBA-7D90CC8D43E1}" = LiveZilla
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D4236B82-213F-679E-09A2-9AEB5EF4CADC}" = Catalyst Control Center Graphics Previews Common
"{DB21639E-FE55-432C-BCA2-0C5249E3F79E}" = Die Sims™ 3 Inselparadies
"{DBA18992-B9F3-950D-E973-6ED23422EA73}" = AMD Drag and Drop Transcoding
"{DDA3C325-47B2-4730-9672-BF3771C08799}_is1" = XMedia Recode Version 3.1.7.6
"{E15BC10F-04AA-0AFD-A6C9-476730195F8B}" = Adobe Download Assistant
"{e3ca9788-c318-4024-98c3-68c04a735fbf}_is1" = Funkspiel-Forum
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E43B4909-141E-DFF3-8C58-62B5E4D66BBA}" = AMD Catalyst Install Manager
"{E6B88BD6-E4B2-4701-A648-B6DAC6E491CC}" = Die Sims™ 3 Lebensfreude
"{EBBD4FE6-91DA-C397-6D56-FE85DBF24FCF}" = AMD VISION Engine Control Center
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F26DE8EF-F2CF-40DC-8CDA-CC0D82D11B36}" = Die Sims™ 3 Wildes Studentenleben
"{F7849D41-0A46-457D-827D-00FF47AF2D85}_is1" = CAE Report Generator v1.1
"{F868C16D-75F8-4EE8-BCBF-422D0833415D}_is1" = Open PLS in Windows Media Player 2.3.0
"{FCEFDA6B-63CD-BB17-B845-478A42E24D39}" = CCC Help Swedish
"{RTS-Wegberg-2-0}_is1" = RTS Wegberg Version 2.0
"{Wegberg-Modifikation-6-0}_is1" = Feuer- und Notfallsimulation Wegberg Version 6.0
"5513-1208-7298-9440" = JDownloader 0.9
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 12 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 12 Plugin
"ASIO4ALL" = ASIO4ALL
"Audacity_is1" = Audacity 2.0.5
"AviSynth" = AviSynth 2.5
"BandiMPEG1" = Bandisoft MPEG-1 Decoder
"Battlelog Web Plugins" = Battlelog Web Plugins
"CCleaner" = CCleaner
"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant
"Combat Arms EU" = Combat Arms EU
"DAEMON Tools Lite" = DAEMON Tools Lite
"ESN Sonar-0.70.4" = ESN Sonar
"ExpressBurn" = Express Burn
"FBDBServer_2_5_is1" = Firebird 2.5.2.26540 (Win32)
"FileZilla Client" = FileZilla Client 3.7.3
"FL Studio 11" = FL Studio 11
"FlowStone" = FlowStone FL 3.0
"Free YouTube Download_is1" = Free YouTube Download version 3.2.23.219
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.12.26.224
"Google Chrome" = Google Chrome
"InstallWIX_{6F6873E3-5C92-4049-B511-231A138DD090}" = Kaspersky Internet Security
"LAME_is1" = LAME v3.99.3 (for Windows)
"LiveZilla" = LiveZilla
"Microsoft Mouse and Keyboard Center" = Microsoft-Maus- und Tastatur-Center
"MixPad" = MixPad Audiodatei-Mixer
"Mixxx (1.11.0)" = Mixxx 1.11.0
"Mozilla Firefox 27.0.1 (x86 de)" = Mozilla Firefox 27.0.1 (x86 de)
"Mozilla Thunderbird 24.3.0 (x86 de)" = Mozilla Thunderbird 24.3.0 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Native Instruments Controller Editor" = Native Instruments Controller Editor
"Native Instruments Service Center" = Native Instruments Service Center
"Native Instruments Traktor 2" = Native Instruments Traktor 2
"NAVIGON Fresh" = NAVIGON Fresh 3.5.1
"Notepad++" = Notepad++
"NVIDIA Drivers" = NVIDIA Drivers
"OpenVPN" = OpenVPN 2.3.2-I003
"Origin" = Origin
"SAM3" = SAM Broadcaster v4
"SCDNAS" = SHOUTcast DNAS (remove only)
"Steam" = Steam
"Steam App 232010" = Euro Truck Simulator
"Steam App 24010" = Train Simulator 2014
"Steam App 550" = Left 4 Dead 2
"Steam App 730" = Counter-Strike: Global Offensive
"TAP-Windows" = TAP-Windows 9.9.2
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"TeamViewer 9" = TeamViewer 9
"Virtual Audio Cable 4.10" = Virtual Audio Cable 4.10
"WavePad" = WavePad Audio-Editor
"WhiteCap" = WhiteCap
"WinRAR archiver" = WinRAR 5.00 (32-Bit)
"winscp3_is1" = WinSCP 5.1.7
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"ICQ" = ICQ 8.2 (build 6901)
"Spotify" = Spotify
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 03.03.2014 20:12:45 | Computer Name = Chris-PC | Source = WinSecurity.exe | ID = 0
Description =
Error - 03.03.2014 20:12:45 | Computer Name = Chris-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: WinSecurity.exe, Version: 1.0.0.70,
Zeitstempel: 0x522949f5 Name des fehlerhaften Moduls: WinSecurity.exe, Version:
1.0.0.70, Zeitstempel: 0x522949f5 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000052bf
ID
des fehlerhaften Prozesses: 0x13b0 Startzeit der fehlerhaften Anwendung: 0x01cf373e6f252209
Pfad
der fehlerhaften Anwendung: C:\Windows\System32\WinSecurity.exe Pfad des fehlerhaften
Moduls: C:\Windows\System32\WinSecurity.exe Berichtskennung: b5af92b8-a331-11e3-8c31-002185194ef1
Error - 03.03.2014 20:12:47 | Computer Name = Chris-PC | Source = WinSecurity.exe | ID = 0
Description =
Error - 03.03.2014 20:13:00 | Computer Name = Chris-PC | Source = WinSecurity.exe | ID = 0
Description =
Error - 03.03.2014 20:13:00 | Computer Name = Chris-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: WinSecurity.exe, Version: 1.0.0.70,
Zeitstempel: 0x522949f5 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247,
Zeitstempel: 0x521ea91c Ausnahmecode: 0xc0000005 Fehleroffset: 0x00046a62 ID des fehlerhaften
Prozesses: 0x1408 Startzeit der fehlerhaften Anwendung: 0x01cf373e78220570 Pfad der
fehlerhaften Anwendung: C:\Windows\System32\WinSecurity.exe Pfad des fehlerhaften
Moduls: C:\Windows\SYSTEM32\ntdll.dll Berichtskennung: be7a3e98-a331-11e3-8c31-002185194ef1
Error - 03.03.2014 20:13:01 | Computer Name = Chris-PC | Source = WinSecurity.exe | ID = 0
Description =
Error - 03.03.2014 20:13:19 | Computer Name = Chris-PC | Source = WinSecurity.exe | ID = 0
Description =
Error - 03.03.2014 20:13:19 | Computer Name = Chris-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: WinSecurity.exe, Version: 1.0.0.70,
Zeitstempel: 0x522949f5 Name des fehlerhaften Moduls: WinSecurity.exe, Version:
1.0.0.70, Zeitstempel: 0x522949f5 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0003b327
ID
des fehlerhaften Prozesses: 0x12a8 Startzeit der fehlerhaften Anwendung: 0x01cf373e80ecb150
Pfad
der fehlerhaften Anwendung: C:\Windows\System32\WinSecurity.exe Pfad des fehlerhaften
Moduls: C:\Windows\System32\WinSecurity.exe Berichtskennung: c99b58b6-a331-11e3-8c31-002185194ef1
Error - 03.03.2014 20:13:20 | Computer Name = Chris-PC | Source = WinSecurity.exe | ID = 0
Description =
Error - 03.03.2014 20:13:33 | Computer Name = Chris-PC | Source = WinSecurity.exe | ID = 0
Description =
[ Media Center Events ]
Error - 07.01.2014 11:00:31 | Computer Name = Chris-PC | Source = MCUpdate | ID = 0
Description = 16:00:31 - Fehler beim Herstellen der Internetverbindung. 16:00:31
- Serververbindung konnte nicht hergestellt werden..
Error - 07.01.2014 11:01:12 | Computer Name = Chris-PC | Source = MCUpdate | ID = 0
Description = 16:00:38 - Fehler beim Herstellen der Internetverbindung. 16:00:38
- Serververbindung konnte nicht hergestellt werden..
[ System Events ]
Error - 03.03.2014 20:21:53 | Computer Name = Chris-PC | Source = Service Control Manager | ID = 7031
Description = Der Dienst "WINDOWS SECURITY COMPONEMENT" wurde unerwartet beendet.
Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden
durchgeführt: Neustart des Diensts.
Error - 03.03.2014 20:22:07 | Computer Name = Chris-PC | Source = Service Control Manager | ID = 7031
Description = Der Dienst "WINDOWS SECURITY COMPONEMENT" wurde unerwartet beendet.
Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden
durchgeführt: Neustart des Diensts.
Error - 03.03.2014 20:22:26 | Computer Name = Chris-PC | Source = Service Control Manager | ID = 7031
Description = Der Dienst "WINDOWS SECURITY COMPONEMENT" wurde unerwartet beendet.
Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden
durchgeführt: Neustart des Diensts.
Error - 03.03.2014 20:22:41 | Computer Name = Chris-PC | Source = Service Control Manager | ID = 7031
Description = Der Dienst "WINDOWS SECURITY COMPONEMENT" wurde unerwartet beendet.
Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden
durchgeführt: Neustart des Diensts.
Error - 03.03.2014 20:23:01 | Computer Name = Chris-PC | Source = Service Control Manager | ID = 7031
Description = Der Dienst "WINDOWS SECURITY COMPONEMENT" wurde unerwartet beendet.
Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden
durchgeführt: Neustart des Diensts.
Error - 03.03.2014 20:23:16 | Computer Name = Chris-PC | Source = Service Control Manager | ID = 7031
Description = Der Dienst "WINDOWS SECURITY COMPONEMENT" wurde unerwartet beendet.
Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden
durchgeführt: Neustart des Diensts.
Error - 03.03.2014 20:23:30 | Computer Name = Chris-PC | Source = Service Control Manager | ID = 7031
Description = Der Dienst "WINDOWS SECURITY COMPONEMENT" wurde unerwartet beendet.
Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden
durchgeführt: Neustart des Diensts.
Error - 03.03.2014 20:23:44 | Computer Name = Chris-PC | Source = Service Control Manager | ID = 7031
Description = Der Dienst "WINDOWS SECURITY COMPONEMENT" wurde unerwartet beendet.
Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden
durchgeführt: Neustart des Diensts.
Error - 03.03.2014 20:24:03 | Computer Name = Chris-PC | Source = Service Control Manager | ID = 7031
Description = Der Dienst "WINDOWS SECURITY COMPONEMENT" wurde unerwartet beendet.
Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden
durchgeführt: Neustart des Diensts.
Error - 03.03.2014 20:24:22 | Computer Name = Chris-PC | Source = Service Control Manager | ID = 7031
Description = Der Dienst "WINDOWS SECURITY COMPONEMENT" wurde unerwartet beendet.
Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden
durchgeführt: Neustart des Diensts.
< End of report > hoffe ihr könnt endlich helfen ich wäre so dankbar weil das echt ätzend ist... |