CrashOver | 15.10.2014 01:33 | Log AdwCleaner: Code:
# AdwCleaner v4.000 - Bericht erstellt am 15/10/2014 um 02:09:03
# DB v2014-10-14.6
# Aktualisiert 12/10/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername : CrashOverwrite - CRASHDESKTOP
# Gestartet von : C:\Users\CrashOverwrite\Desktop\AdwCleaner_4.000.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}
Schlüssel Gelöscht : HKCU\Software\OCS
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17280
-\\ Mozilla Firefox v32.0.3 (x86 de)
-\\ Google Chrome v37.0.2062.124
*************************
AdwCleaner[R0].txt - [1008 octets] - [15/10/2014 02:07:16]
AdwCleaner[S0].txt - [877 octets] - [15/10/2014 02:09:03]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [936 octets] ########## Log Antimalware: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 15.10.2014
Suchlauf-Zeit: 02:13:23
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.3.1025
Malware Datenbank: v2014.10.14.12
Rootkit Datenbank: v2014.10.14.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: CrashOverwrite
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 326346
Verstrichene Zeit: 4 Min, 15 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente erkannt)
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 0
(Keine schädliche Elemente erkannt)
Registrierungswerte: 0
(Keine schädliche Elemente erkannt)
Registrierungsdaten: 0
(Keine schädliche Elemente erkannt)
Ordner: 0
(Keine schädliche Elemente erkannt)
Dateien: 0
(Keine schädliche Elemente erkannt)
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end) Log FRST:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-10-2014
Ran by CrashOverwrite (administrator) on CRASHDESKTOP on 15-10-2014 02:30:04
Running from C:\Users\CrashOverwrite\Desktop
Loaded Profiles: CrashOverwrite & (Available profiles: CrashOverwrite)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apache Software Foundation) F:\xampp\apache\bin\httpd.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files (x86)\Livedrive\VSSService.exe
() F:\xampp\mysql\bin\mysqld.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
() C:\Users\CrashOverwrite\AppData\Local\Amazon Music\Amazon Music Helper.exe
(Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
(Livedrive Internet Ltd) C:\Program Files (x86)\Livedrive\Livedrive.exe
(Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL3\KHALMNPR.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Dropbox, Inc.) C:\Users\CrashOverwrite\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Apache Software Foundation) F:\xampp\apache\bin\httpd.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13671792 2014-03-14] (Realtek Semiconductor)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3100440 2014-05-19] (Logitech, Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2014-02-21] (Intel Corporation)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-04-17] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [703736 2014-10-14] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [AdobeCS5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [406992 2010-02-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [44128 2013-05-08] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [642664 2013-05-08] (Adobe Systems Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [WSHelperSetup.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2020192 2014-06-25] (Wondershare)
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2020192 2014-06-25] (Wondershare)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-08-01] (Apple Inc.)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [165168 2014-09-23] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-1736619863-4178959946-3952721437-1000\...\Run: [Amazon Music] => C:\Users\CrashOverwrite\AppData\Local\Amazon Music\Amazon Music Helper.exe [3356480 2014-07-22] ()
HKU\S-1-5-21-1736619863-4178959946-3952721437-1000\...\Run: [WSHelperSetup.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2020192 2014-06-25] (Wondershare)
HKU\S-1-5-21-1736619863-4178959946-3952721437-1000\...\Run: [Livedrive] => C:\Program Files (x86)\Livedrive\Livedrive.exe [1842840 2014-07-24] (Livedrive Internet Ltd)
HKU\S-1-5-21-1736619863-4178959946-3952721437-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [22027880 2014-08-27] (Skype Technologies S.A.)
HKU\S-1-5-21-1736619863-4178959946-3952721437-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Amazon Music] => C:\Users\CrashOverwrite\AppData\Local\Amazon Music\Amazon Music Helper.exe [3356480 2014-07-22] ()
HKU\S-1-5-21-1736619863-4178959946-3952721437-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [WSHelperSetup.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2020192 2014-06-25] (Wondershare)
HKU\S-1-5-21-1736619863-4178959946-3952721437-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Livedrive] => C:\Program Files (x86)\Livedrive\Livedrive.exe [1842840 2014-07-24] (Livedrive Internet Ltd)
HKU\S-1-5-21-1736619863-4178959946-3952721437-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [22027880 2014-08-27] (Skype Technologies S.A.)
Startup: C:\Users\CrashOverwrite\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\CrashOverwrite\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
SSODL-x32: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)
ShellIconOverlayIdentifiers: [BackupOverlay] -> {B44A5D93-1351-41A1-BD91-5E92435D8ECD} => C:\Program Files (x86)\Livedrive\Extensions.dll (Livedrive Internet Ltd)
ShellIconOverlayIdentifiers: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\Windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
ShellIconOverlayIdentifiers: [LivedriveDownloadOverlay] -> {CBCDB610-6B68-4EE9-B7A2-1282FD0C9292} => C:\Program Files (x86)\Livedrive\Extensions.dll (Livedrive Internet Ltd)
ShellIconOverlayIdentifiers: [LivedriveSharedOverlay] -> {84CEF1E4-1356-4063-845F-05047F4DD52C} => C:\Program Files (x86)\Livedrive\Extensions.dll (Livedrive Internet Ltd)
ShellIconOverlayIdentifiers: [LivedriveSyncedOverlay] -> {42058329-2FBF-4B33-8E52-3BE5754DE0C1} => C:\Program Files (x86)\Livedrive\Extensions.dll (Livedrive Internet Ltd)
ShellIconOverlayIdentifiers: [LivedriveUploadOverlay] -> {39A1715A-E4CD-4F1E-B5C4-36B5DB80124E} => C:\Program Files (x86)\Livedrive\Extensions.dll (Livedrive Internet Ltd)
ShellIconOverlayIdentifiers-x32: [EldosIconOverlay] -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x76757EA7FD8FCF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll (Logitech, Inc.)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll (Logitech, Inc.)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\CrashOverwrite\AppData\Roaming\Mozilla\Firefox\Profiles\qpjhjcjj.default
FF NewTab: hxxp://www.google.com/
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF NetworkProxy: "autoconfig_url", "https://secure.premiumize.me/004a15a2d95d27cb072db5bd3cb22346/proxy.pac"
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @esn/npbattlelog,version=2.5.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.0\npbattlelogx64.dll No File
FF Plugin: @esn/npbattlelog,version=2.5.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelogx64.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @esn/npbattlelog,version=2.4.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll No File
FF Plugin-x32: @esn/npbattlelog,version=2.5.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: LastPass - C:\Users\CrashOverwrite\AppData\Roaming\Mozilla\Firefox\Profiles\qpjhjcjj.default\Extensions\support@lastpass.com [2014-06-25]
FF Extension: Firebug - C:\Users\CrashOverwrite\AppData\Roaming\Mozilla\Firefox\Profiles\qpjhjcjj.default\Extensions\firebug@software.joehewitt.com.xpi [2014-08-05]
FF Extension: Premiumize.me - C:\Users\CrashOverwrite\AppData\Roaming\Mozilla\Firefox\Profiles\qpjhjcjj.default\Extensions\jid1-sirVJT0BXhkuJg@jetpack.xpi [2014-06-26]
FF Extension: Web Developer - C:\Users\CrashOverwrite\AppData\Roaming\Mozilla\Firefox\Profiles\qpjhjcjj.default\Extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi [2014-07-12]
FF Extension: Adblock Plus - C:\Users\CrashOverwrite\AppData\Roaming\Mozilla\Firefox\Profiles\qpjhjcjj.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-06-26]
FF Extension: Pixlr Grabber - C:\Users\CrashOverwrite\AppData\Roaming\Mozilla\Firefox\Profiles\qpjhjcjj.default\Extensions\{d47a9f51-8281-43fa-f450-f28ef8735e9a}.xpi [2014-08-22]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2014-06-25]
FF Extension: No Name - {F003DA68-8256-4b37-A6C4-350FA04494DF} [Not Found]
Chrome:
=======
CHR Profile: C:\Users\CrashOverwrite\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\CrashOverwrite\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-06-25]
CHR Extension: (Google Drive) - C:\Users\CrashOverwrite\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-25]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\CrashOverwrite\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-08-28]
CHR Extension: (YouTube) - C:\Users\CrashOverwrite\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-25]
CHR Extension: (Adblock Plus) - C:\Users\CrashOverwrite\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-06-26]
CHR Extension: (Google-Suche) - C:\Users\CrashOverwrite\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-25]
CHR Extension: (Premiumize.me) - C:\Users\CrashOverwrite\AppData\Local\Google\Chrome\User Data\Default\Extensions\lojbjecfjcnaledoelddkcjlifhhfebm [2014-07-06]
CHR Extension: (Google Wallet) - C:\Users\CrashOverwrite\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-25]
CHR Extension: (Google Mail) - C:\Users\CrashOverwrite\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-25]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-10-14] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-10-14] (Avira Operations GmbH & Co. KG)
R2 Apache2.2; F:\xampp\apache\bin\httpd.exe [24640 2009-08-06] (Apache Software Foundation) [File not signed]
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [160560 2014-09-23] (Avira Operations GmbH & Co. KG)
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [651720 2014-06-25] (Macrovision Europe Ltd.) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [887232 2014-01-31] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [154584 2014-03-20] (Intel Corporation)
R2 LivedriveVSSService; C:\Program Files (x86)\Livedrive\VSSService.exe [210584 2014-07-24] ()
R2 MySQL; F:\xampp\mysql\bin\mysqld.exe [5497856 2009-08-06] () [File not signed]
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-08-10] ()
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-14] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-10-14] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-06-17] (Avira Operations GmbH & Co. KG)
R1 cbfs3; C:\Windows\system32\drivers\cbfs3.sys [352008 2012-11-10] (EldoS Corporation)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [118272 2014-03-20] (Intel Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 gdrv; \??\C:\Windows\gdrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-10-15 02:30 - 2014-10-15 02:30 - 00019138 _____ () C:\Users\CrashOverwrite\Desktop\FRST.txt
2014-10-15 02:29 - 2014-10-15 02:29 - 00000000 ____D () C:\Users\CrashOverwrite\Desktop\FRST-OlderVersion
2014-10-15 02:28 - 2014-10-15 02:28 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-10-15 02:25 - 2014-10-15 02:25 - 00005153 _____ () C:\zoek-results.log
2014-10-15 02:24 - 2014-10-15 02:24 - 00000000 ____D () C:\zoek_backup
2014-10-15 02:22 - 2014-10-15 02:22 - 01290752 _____ () C:\Users\CrashOverwrite\Desktop\zoek.exe
2014-10-15 02:12 - 2014-10-15 02:12 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-10-15 02:12 - 2014-10-15 02:12 - 00001123 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-10-15 02:12 - 2014-10-15 02:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-10-15 02:12 - 2014-10-15 02:12 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-10-15 02:12 - 2014-10-15 02:12 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-10-15 02:12 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-10-15 02:12 - 2014-10-01 11:11 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-10-15 02:12 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-10-15 02:11 - 2014-10-15 02:11 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\CrashOverwrite\Desktop\mbam-setup-2.0.3.1025.exe
2014-10-15 02:07 - 2014-10-15 02:09 - 00000000 ____D () C:\AdwCleaner
2014-10-15 02:05 - 2014-10-15 02:05 - 01976320 _____ () C:\Users\CrashOverwrite\Desktop\AdwCleaner_4.000.exe
2014-10-12 13:29 - 2014-10-12 13:29 - 00024928 _____ () C:\ComboFix.txt
2014-10-12 13:24 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-10-12 13:24 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-10-12 13:24 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-10-12 13:24 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-10-12 13:24 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-10-12 13:24 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-10-12 13:24 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-10-12 13:24 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-10-12 13:22 - 2014-10-12 13:29 - 00000000 ____D () C:\Windows\erdnt
2014-10-12 13:22 - 2014-10-12 13:29 - 00000000 ____D () C:\Qoobox
2014-10-12 13:22 - 2014-10-12 13:22 - 05582481 ____R (Swearware) C:\Users\CrashOverwrite\Desktop\ComboFix.exe
2014-10-12 11:29 - 2014-10-12 11:29 - 00380416 _____ () C:\Users\CrashOverwrite\Downloads\c36ftsxg.exe
2014-10-12 11:26 - 2014-10-12 11:26 - 00034462 _____ () C:\Users\CrashOverwrite\Downloads\Addition.txt
2014-10-12 11:25 - 2014-10-15 02:30 - 00000000 ____D () C:\FRST
2014-10-12 11:25 - 2014-10-15 02:29 - 02110464 _____ (Farbar) C:\Users\CrashOverwrite\Desktop\FRST64.exe
2014-10-12 11:25 - 2014-10-12 11:26 - 00028311 _____ () C:\Users\CrashOverwrite\Downloads\FRST.txt
2014-10-12 11:22 - 2014-10-12 11:22 - 00050477 _____ () C:\Users\CrashOverwrite\Downloads\Defogger.exe
2014-10-12 11:22 - 2014-10-12 11:22 - 00000490 _____ () C:\Users\CrashOverwrite\Downloads\defogger_disable.log
2014-10-12 11:22 - 2014-10-12 11:22 - 00000000 _____ () C:\Users\CrashOverwrite\defogger_reenable
2014-10-12 10:59 - 2014-10-12 10:59 - 04714656 _____ (Avira Operations GmbH & Co. KG) C:\Users\CrashOverwrite\Downloads\avira_de_av_4502000269__ws.exe
2014-10-09 18:19 - 2014-10-09 18:19 - 00000000 ____D () C:\ProgramData\mediDOK
2014-10-08 01:31 - 2014-10-08 01:31 - 00000000 ____D () C:\Users\CrashOverwrite\AppData\Roaming\AMD
2014-10-06 09:08 - 2014-10-06 09:08 - 00000000 ____D () C:\ProgramData\ATI
2014-10-05 22:44 - 2014-10-05 22:44 - 00000000 ____D () C:\AMD
2014-10-01 09:01 - 2014-09-25 04:08 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-10-01 09:01 - 2014-09-25 03:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2014-09-24 08:48 - 2014-09-10 00:11 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-09-24 08:48 - 2014-09-09 23:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-09-23 23:47 - 2014-10-03 21:04 - 00000000 ____D () C:\Arco Video
2014-09-23 08:56 - 2014-09-23 08:56 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-09-23 08:56 - 2014-09-23 08:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-09-20 21:55 - 2014-09-20 21:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Livedrive
2014-09-20 21:55 - 2014-09-20 21:55 - 00000000 ____D () C:\Program Files (x86)\Livedrive
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-10-15 02:28 - 2014-07-07 09:23 - 00000000 ____D () C:\Users\CrashOverwrite\AppData\Local\Livedrive
2014-10-15 02:28 - 2014-06-25 10:41 - 00000000 ____D () C:\Users\CrashOverwrite\AppData\Roaming\Skype
2014-10-15 02:28 - 2014-06-25 01:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-10-15 02:28 - 2014-06-25 00:35 - 01671942 _____ () C:\Windows\WindowsUpdate.log
2014-10-15 02:17 - 2009-07-14 06:45 - 00025328 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-10-15 02:17 - 2009-07-14 06:45 - 00025328 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-10-15 02:15 - 2009-07-14 19:58 - 00699092 _____ () C:\Windows\system32\perfh007.dat
2014-10-15 02:15 - 2009-07-14 19:58 - 00149232 _____ () C:\Windows\system32\perfc007.dat
2014-10-15 02:15 - 2009-07-14 07:13 - 01619284 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-10-15 02:13 - 2014-06-25 01:03 - 00001126 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-10-15 02:12 - 2014-06-25 01:25 - 00044077 _____ () C:\Windows\SysWOW64\Gms.log
2014-10-15 02:10 - 2014-06-27 23:09 - 00000000 ____D () C:\Users\CrashOverwrite\AppData\Roaming\Dropbox
2014-10-15 02:10 - 2014-06-25 01:23 - 00141376 _____ () C:\Windows\PFRO.log
2014-10-15 02:10 - 2014-06-25 01:03 - 00001122 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-10-15 02:10 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-15 02:10 - 2009-07-14 06:51 - 00114119 _____ () C:\Windows\setupact.log
2014-10-14 14:56 - 2014-07-01 15:01 - 00043064 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-10-14 14:56 - 2014-06-25 09:02 - 00131608 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-10-14 14:56 - 2014-06-25 09:02 - 00119272 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-10-12 13:29 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-10-12 13:28 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-10-12 13:27 - 2014-06-25 09:42 - 00000000 ____D () C:\Users\CrashOverwrite\AppData\Local\Adobe
2014-10-12 11:54 - 2014-06-28 02:41 - 00000000 ____D () C:\ProgramData\FLEXnet
2014-10-12 11:54 - 2014-06-25 12:48 - 00000000 ____D () C:\Users\CrashOverwrite\AppData\Roaming\IrfanView
2014-10-12 11:54 - 2014-06-25 11:43 - 00000000 ____D () C:\Users\CrashOverwrite\AppData\Roaming\Battle.net
2014-10-12 11:54 - 2014-06-25 11:43 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2014-10-12 11:54 - 2014-06-25 01:51 - 00000000 ____D () C:\Users\CrashOverwrite\AppData\Roaming\Adobe
2014-10-12 11:54 - 2014-06-25 01:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2014-10-12 11:54 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration
2014-10-12 11:53 - 2014-06-25 01:20 - 00000000 ____D () C:\Program Files (x86)\AMD AVT
2014-10-12 11:22 - 2014-06-25 00:35 - 00000000 ____D () C:\Users\CrashOverwrite
2014-10-12 10:59 - 2014-09-09 09:05 - 00001154 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-10-12 10:59 - 2014-06-25 09:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-10-12 10:59 - 2014-06-25 09:02 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-10-12 10:59 - 2014-06-25 01:00 - 00000000 ____D () C:\ProgramData\Package Cache
2014-10-10 01:50 - 2014-06-25 15:46 - 00004887 _____ () C:\Users\CrashOverwrite\AppData\Roaming\com.living-e.timeEdition.plist
2014-10-10 01:49 - 2014-06-29 01:16 - 00000000 ____D () C:\Users\CrashOverwrite\AppData\Roaming\FileZilla
2014-10-10 01:30 - 2014-06-25 15:27 - 00001456 _____ () C:\Users\CrashOverwrite\AppData\Local\Adobe Für Web speichern 12.0 Prefs
2014-10-09 13:15 - 2014-06-25 11:43 - 00000000 ____D () C:\Users\CrashOverwrite\AppData\Local\Battle.net
2014-10-05 22:46 - 2014-06-25 01:20 - 00000000 ____D () C:\ProgramData\AMD
2014-10-05 22:46 - 2014-06-25 01:18 - 00000000 ____D () C:\Program Files\ATI Technologies
2014-09-25 14:22 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-09-23 08:56 - 2014-06-25 10:41 - 00000000 ____D () C:\ProgramData\Skype
2014-09-23 08:55 - 2009-07-14 07:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-09-22 09:14 - 2014-06-25 01:51 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-22 09:14 - 2014-06-25 01:51 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-09-20 21:55 - 2014-07-07 09:23 - 00000000 __SHD () C:\Windows\SysWOW64\AI_RecycleBin
2014-09-20 21:54 - 2014-06-27 23:09 - 00000000 ____D () C:\Users\CrashOverwrite\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
Some content of TEMP:
====================
C:\Users\CrashOverwrite\AppData\Local\Temp\avgnt.exe
C:\Users\CrashOverwrite\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpbozyqn.dll
C:\Users\CrashOverwrite\AppData\Local\Temp\Quarantine.exe
C:\Users\CrashOverwrite\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-10-06 11:41
==================== End Of Log ============================ --- --- ---
Log Addition Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-10-2014
Ran by CrashOverwrite at 2014-10-15 02:30:17
Running from C:\Users\CrashOverwrite\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - )
Adobe Acrobat 9 Pro - English, Français, Deutsch (HKLM-x32\...\{AC76BA86-1033-F400-7760-000000000004}{AC76BA86-1033-F400-7760-000000000004}) (Version: 9.5.5 - Adobe Systems)
Adobe Acrobat 9 Pro - English, Français, Deutsch (x32 Version: 9.5.5 - Adobe Systems) Hidden
Adobe Acrobat 9.5.5 - CPSID_83708 (HKLM-x32\...\{AC76BA86-1033-F400-7760-000000000004}_955) (Version: - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.3.9120 - Adobe Systems Inc.)
Adobe AIR (x32 Version: 1.5.3.9120 - Adobe Systems Inc.) Hidden
Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.0.0.400 - Adobe Systems Incorporated)
Adobe Community Help (x32 Version: 3.0.0 - Adobe Systems Incorporated) Hidden
Adobe Creative Suite 5 Master Collection (HKLM-x32\...\{2A65343E-A598-49BA-BB4B-D320F7370B6D}) (Version: 5.0 - Adobe Systems Incorporated)
Adobe Flash Player 10 ActiveX (HKLM-x32\...\{6E9EF98E-259E-416D-B5F8-0ABDB99942CE}) (Version: 10.1.52.14 - Adobe Systems, Inc.)
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated)
Adobe Media Player (HKLM-x32\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.8 - Adobe Systems Incorporated)
Adobe Media Player (x32 Version: 1.8 - Adobe Systems Incorporated) Hidden
Amazon Music (HKCU\...\Amazon Amazon Music) (Version: 3.2.0.591 - Amazon Services LLC)
AMD Accelerated Video Transcoding (Version: 13.30.100.40417 - Advanced Micro Devices, Inc.) Hidden
AMD Catalyst Control Center (x32 Version: 2014.0417.2226.38446 - Ihr Firmenname) Hidden
AMD Catalyst Install Manager (HKLM\...\{6119B3A6-3603-9695-0398-CDF2AF0A13F8}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
AMD Drag and Drop Transcoding (Version: 2.00.0000 - Advanced Micro Devices, Inc.) Hidden
AMD Wireless Display v3.0 (Version: 1.0.0.15 - Advanced Micro Devices, Inc.) Hidden
Apple Application Support (HKLM-x32\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{6AF2AC2A-3532-43FD-9F4D-BDC9C0D724C7}) (Version: 7.1.2.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Avira (HKLM-x32\...\{9bd9b85e-7792-483b-a318-cc51ff0877ed}) (Version: 1.1.22.50000 - Avira Operations GmbH & Co. KG)
Avira (x32 Version: 1.1.22.50000 - Avira Operations GmbH & Co. KG) Hidden
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.7.306 - Avira)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
Battlefield 4™ (HKLM-x32\...\{ABADE36E-EC37-413B-8179-B432AD3FACE7}) (Version: 1.3.2.3825 - Electronic Arts)
Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.5.1 - EA Digital Illusions CE AB)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Call of Duty: Black Ops (HKLM-x32\...\Steam App 42700) (Version: - Treyarch)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2014.0417.2226.38446 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2014.0417.2226.38446 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2014.0417.2226.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (x32 Version: 2014.0417.2225.38446 - Advanced Micro Devices, Inc.) Hidden
ccc-utility64 (Version: 2014.0417.2226.38446 - Advanced Micro Devices, Inc.) Hidden
Crysis®3 (HKLM-x32\...\{4198AE83-A3C6-4C41-85C8-EC63E990696E}) (Version: 1.0.0.0 - Electronic Arts)
Crysis®3 Digital Deluxe Edition Content (HKLM-x32\...\{2A8C5AE3-2772-4EB1-8206-D5E53D111A61}) (Version: 1.0.0.0 - Electronic Arts)
Dropbox (HKCU\...\Dropbox) (Version: 2.10.30 - Dropbox, Inc.)
FileZilla Client 3.8.1 (HKLM-x32\...\FileZilla Client) (Version: 3.8.1 - Tim Kosse)
Free YouTube to MP3 Converter version 3.12.42.716 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.42.716 - DVDVideoSoft Ltd.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 37.0.2062.124 - Google Inc.)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
HIS iTurbo (HKLM-x32\...\HIS iTurbo) (Version: - )
Intel(R) Chipset Device Software (Version: 10.0.13 - Intel Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 10.0.0.1204 - Intel Corporation)
Intel(R) Management Engine Components (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) Management Engine Components (Version: 10.0.0.1204 - Intel Corporation) Hidden
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 3.0.0.16 - Intel Corporation)
Intel® Chipsatz-Gerätesoftware (x32 Version: 10.0.13 - Intel(R) Corporation) Hidden
Intel® Trusted Connect Service Client (Version: 1.35.127.1 - Intel Corporation) Hidden
IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.37 - Irfan Skiljan)
iTunes (HKLM\...\{77DE5105-D05E-448C-96CB-7FA381903753}) (Version: 11.3.1.2 - Apple Inc.)
Left 4 Dead 2 (HKLM-x32\...\Steam App 550) (Version: - Valve)
Livedrive (HKLM\...\{7D2E0E90-3BBA-43B1-894D-EC39A4E18748}) (Version: 1.15.2.0 - Livedrive Internet Limited)
Logitech SetPoint 6.65 (HKLM\...\sp6) (Version: 6.65.62 - Logitech)
Malwarebytes Anti-Malware Version 2.0.3.1025 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.3.1025 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft_VC80_ATL_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053 - Adobe) Hidden
Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000 - Adobe) Hidden
Mozilla Firefox 33.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 33.0 (x86 de)) (Version: 33.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 24.6.0 - Mozilla)
Mozilla Thunderbird 24.6.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.6.0 (x86 de)) (Version: 24.6.0 - Mozilla)
MPC-HC 1.7.5 (HKLM-x32\...\{2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1) (Version: 1.7.5 - MPC-HC Team)
OpenOffice 4.1.0 (HKLM-x32\...\{E19483E2-6C18-494D-A307-D4498BCFD2C7}) (Version: 4.10.9764 - Apache Software Foundation)
Origin (HKLM-x32\...\Origin) (Version: 9.4.11.2806 - Electronic Arts, Inc.)
PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.)
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Realtek Ethernet Controller All-In-One Windows Driver (HKLM-x32\...\{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}) (Version: 7.78.1218.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7200 - Realtek Semiconductor Corp.)
Skype™ 6.20 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.20.104 - Skype Technologies S.A.)
Team Fortress 2 (HKLM-x32\...\Steam App 440) (Version: - Valve)
Wing Commander III (HKLM-x32\...\{F96B9930-E22A-44D6-81B5-6C8E92C21B4B}) (Version: 2.0.0.2 - Electronic Arts)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-1736619863-4178959946-3952721437-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\CrashOverwrite\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1736619863-4178959946-3952721437-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\CrashOverwrite\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1736619863-4178959946-3952721437-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\CrashOverwrite\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1736619863-4178959946-3952721437-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\CrashOverwrite\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1736619863-4178959946-3952721437-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\CrashOverwrite\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1736619863-4178959946-3952721437-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\CrashOverwrite\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1736619863-4178959946-3952721437-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\CrashOverwrite\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1736619863-4178959946-3952721437-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\CrashOverwrite\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1736619863-4178959946-3952721437-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\CrashOverwrite\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
==================== Restore Points =========================
20-09-2014 19:55:10 Livedrive wird installiert
24-09-2014 14:56:19 Windows Update
01-10-2014 23:38:55 Windows Update
05-10-2014 20:45:53 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727
05-10-2014 20:45:57 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727
12-10-2014 11:24:32 ComboFix created restore point
15-10-2014 00:25:08 zoek.exe restore point
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 04:34 - 2014-10-12 13:27 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {0818B8AD-5F11-4306-91E1-94AD4168AA2A} - System32\Tasks\AdobeAAMUpdater-1.0-CrashDesktop-CrashOverwrite => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06] (Adobe Systems Incorporated)
Task: {5520726D-1A21-4446-8FBD-63AD7C55FB17} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-06-25] (Google Inc.)
Task: {5BCFBD5D-FC2B-48C4-8F70-627EEE88C00A} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {C9021B54-8F5F-4E8B-A9A9-B34DFEA43A07} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-06-25] (Google Inc.)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2014-07-24 16:05 - 2014-07-24 16:05 - 00210584 _____ () C:\Program Files (x86)\Livedrive\VSSService.exe
2008-08-04 15:41 - 2009-08-06 00:00 - 05497856 _____ () F:\xampp\mysql\bin\mysqld.exe
2014-08-10 21:38 - 2014-08-10 21:38 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-05-01 21:29 - 2014-05-01 21:29 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
2014-08-03 11:53 - 2014-07-22 22:46 - 03356480 _____ () C:\Users\CrashOverwrite\AppData\Local\Amazon Music\Amazon Music Helper.exe
2007-12-21 04:00 - 2009-08-06 00:00 - 00032768 _____ () F:\xampp\apache\modules\mod_autoindex_color.so
2009-10-19 00:51 - 2009-08-06 00:00 - 00852025 _____ () F:\xampp\perl\bin\perl510.dll
2009-10-19 00:53 - 2009-08-06 00:00 - 00127072 _____ () F:\xampp\apache\modules\mod_perl.so
2008-08-04 15:45 - 2009-08-06 00:00 - 01689600 _____ () F:\xampp\apache\bin\LIBMYSQL.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00020583 _____ () F:\xampp\perl\site\lib\auto\ModPerl\Util\Util.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00041075 _____ () F:\xampp\perl\site\lib\auto\Apache2\RequestRec\RequestRec.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00032881 _____ () F:\xampp\perl\site\lib\auto\Apache2\RequestIO\RequestIO.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00032885 _____ () F:\xampp\perl\site\lib\auto\Apache2\RequestUtil\RequestUtil.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00024677 _____ () F:\xampp\perl\site\lib\auto\Apache2\Log\Log.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00028785 _____ () F:\xampp\perl\site\lib\auto\Apache2\ServerRec\ServerRec.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00024691 _____ () F:\xampp\perl\site\lib\auto\Apache2\ServerUtil\ServerUtil.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00028787 _____ () F:\xampp\perl\site\lib\auto\Apache2\Connection\Connection.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00020585 _____ () F:\xampp\perl\site\lib\auto\Apache2\Const\Const.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00020581 _____ () F:\xampp\perl\site\lib\auto\APR\Const\Const.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00028773 _____ () F:\xampp\perl\site\lib\auto\APR\Table\Table.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00024683 _____ () F:\xampp\perl\site\lib\auto\Apache2\Access\Access.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00024683 _____ () F:\xampp\perl\site\lib\auto\Apache2\Module\Module.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00024687 _____ () F:\xampp\perl\site\lib\auto\Apache2\Response\Response.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00024691 _____ () F:\xampp\perl\site\lib\auto\Apache2\SubRequest\SubRequest.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00028779 _____ () F:\xampp\perl\site\lib\auto\Apache2\Filter\Filter.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00020583 _____ () F:\xampp\perl\site\lib\auto\Apache2\Util\Util.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00020581 _____ () F:\xampp\perl\site\lib\auto\Apache2\URI\URI.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00020579 _____ () F:\xampp\perl\site\lib\auto\APR\Date\Date.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00024675 _____ () F:\xampp\perl\site\lib\auto\APR\Pool\Pool.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00024673 _____ () F:\xampp\perl\site\lib\auto\APR\URI\URI.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00020579 _____ () F:\xampp\perl\site\lib\auto\APR\Util\Util.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00028777 _____ () F:\xampp\perl\site\lib\auto\APR\Brigade\Brigade.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00028775 _____ () F:\xampp\perl\site\lib\auto\APR\Bucket\Bucket.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00024646 _____ () F:\xampp\perl\lib\auto\Fcntl\Fcntl.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00020583 _____ () F:\xampp\perl\site\lib\auto\APR\Status\Status.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00020587 _____ () F:\xampp\perl\site\lib\auto\ModPerl\Global\Global.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00024683 _____ () F:\xampp\perl\lib\auto\Digest\MD5\MD5.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00020579 _____ () F:\xampp\perl\lib\auto\Cwd\Cwd.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00032881 _____ () F:\xampp\perl\lib\auto\Data\Dumper\Dumper.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00024681 _____ () F:\xampp\perl\lib\auto\Time\HiRes\HiRes.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00032846 _____ () F:\xampp\perl\lib\auto\SDBM_File\SDBM_File.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00024666 _____ () F:\xampp\perl\lib\auto\IO\IO.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00028786 _____ () F:\xampp\perl\lib\auto\List\Util\Util.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00024649 _____ () F:\xampp\perl\lib\auto\File\Glob\Glob.dll
2009-10-19 00:51 - 2009-08-06 00:00 - 00106619 _____ () F:\xampp\perl\lib\auto\Compress\Raw\Zlib\Zlib.dll
2014-04-23 16:05 - 2014-04-23 16:05 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-04-23 16:04 - 2014-04-23 16:04 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2014-08-05 20:34 - 2014-06-25 10:13 - 01457664 _____ () C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\DAQExp.dll
2014-08-05 20:34 - 2014-05-19 17:19 - 00137728 _____ () C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\CBSCreateVC.dll
2014-07-24 15:58 - 2014-07-24 15:58 - 00816128 _____ () C:\Program Files (x86)\Livedrive\Localisation.dll
2011-07-28 16:20 - 2011-07-28 16:20 - 00270336 _____ () C:\Program Files (x86)\Livedrive\AlphaFS.dll
2014-07-24 16:05 - 2014-07-24 16:05 - 00068760 _____ () C:\Program Files (x86)\Livedrive\Native.dll
2014-10-15 02:10 - 2014-10-15 02:10 - 00043008 _____ () c:\Users\CrashOverwrite\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpbozyqn.dll
2013-08-23 21:01 - 2013-08-23 21:01 - 25100288 _____ () C:\Users\CrashOverwrite\AppData\Roaming\Dropbox\bin\libcef.dll
2014-07-20 04:00 - 2009-02-27 16:39 - 00019968 _____ () C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.deu
2014-03-20 11:43 - 2014-03-20 11:43 - 01241560 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2014-10-15 02:28 - 2014-10-15 02:28 - 03649648 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2014-06-25 02:02 - 2014-06-25 02:02 - 01020928 _____ () C:\Users\CrashOverwrite\AppData\Roaming\Mozilla\Firefox\Profiles\qpjhjcjj.default\extensions\support@lastpass.com\platform\WINNT_x86-msvc\components\lpxpcom.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\Users\CrashOverwrite\Lokale Einstellungen:ouxGQNoX0uZVHQDIiC
AlternateDataStreams: C:\Users\CrashOverwrite\Lokale Einstellungen:wM5TuWMyoyhCWu36Vf7tOIKmHb
AlternateDataStreams: C:\Users\CrashOverwrite\AppData\Local:ouxGQNoX0uZVHQDIiC
AlternateDataStreams: C:\Users\CrashOverwrite\AppData\Local:wM5TuWMyoyhCWu36Vf7tOIKmHb
AlternateDataStreams: C:\Users\CrashOverwrite\AppData\Local\Anwendungsdaten:ouxGQNoX0uZVHQDIiC
AlternateDataStreams: C:\Users\CrashOverwrite\AppData\Local\Anwendungsdaten:wM5TuWMyoyhCWu36Vf7tOIKmHb
AlternateDataStreams: C:\Users\CrashOverwrite\AppData\Local\Temp:Hq9YF8TrqCqbyPCH5o2Ch
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
========================= Accounts: ==========================
Administrator (S-1-5-21-1736619863-4178959946-3952721437-500 - Administrator - Disabled)
CrashOverwrite (S-1-5-21-1736619863-4178959946-3952721437-1000 - Administrator - Enabled) => C:\Users\CrashOverwrite
Gast (S-1-5-21-1736619863-4178959946-3952721437-501 - Limited - Enabled)
HomeGroupUser$ (S-1-5-21-1736619863-4178959946-3952721437-1002 - Limited - Enabled)
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (10/14/2014 05:29:04 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 4009
Error: (10/14/2014 05:29:04 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 4009
Error: (10/14/2014 05:29:04 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (10/14/2014 05:29:03 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 3010
Error: (10/14/2014 05:29:03 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 3010
Error: (10/14/2014 05:29:03 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (10/14/2014 05:29:02 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 2012
Error: (10/14/2014 05:29:02 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 2012
Error: (10/14/2014 05:29:02 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (10/14/2014 05:29:01 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1014
System errors:
=============
Error: (10/15/2014 02:09:27 AM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Der Dienst "Apache2.2" wurde mit folgendem dienstspezifischem Fehler beendet: %%1.
Error: (10/14/2014 01:09:07 AM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Der Dienst "Apache2.2" wurde mit folgendem dienstspezifischem Fehler beendet: %%1.
Error: (10/13/2014 08:17:55 AM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Der Dienst "Apache2.2" wurde mit folgendem dienstspezifischem Fehler beendet: %%1.
Error: (10/13/2014 00:43:10 AM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Der Dienst "Apache2.2" wurde mit folgendem dienstspezifischem Fehler beendet: %%1.
Error: (10/12/2014 03:12:28 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}
Error: (10/12/2014 01:28:11 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Der Dienst "Apache2.2" wurde mit folgendem dienstspezifischem Fehler beendet: %%1.
Error: (10/12/2014 01:27:55 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (10/12/2014 01:27:37 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: Aufgrund der Inkompatibilität mit diesem System wurde \??\C:\ComboFix\catchme.sys nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten.
Error: (10/12/2014 01:26:10 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (10/12/2014 01:25:10 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "MySQL" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Microsoft Office Sessions:
=========================
Error: (10/14/2014 05:29:04 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 4009
Error: (10/14/2014 05:29:04 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 4009
Error: (10/14/2014 05:29:04 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (10/14/2014 05:29:03 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 3010
Error: (10/14/2014 05:29:03 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 3010
Error: (10/14/2014 05:29:03 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (10/14/2014 05:29:02 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 2012
Error: (10/14/2014 05:29:02 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 2012
Error: (10/14/2014 05:29:02 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (10/14/2014 05:29:01 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1014
CodeIntegrity Errors:
===================================
Date: 2014-10-12 13:27:37.082
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-10-12 13:27:37.035
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
==================== Memory info ===========================
Processor: Intel(R) Xeon(R) CPU E3-1231 v3 @ 3.40GHz
Percentage of memory in use: 18%
Total physical RAM: 16305.24 MB
Available physical RAM: 13211.54 MB
Total Pagefile: 32608.66 MB
Available Pagefile: 28964.66 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
==================== Drives ================================
Drive c: (SSD 250 GB System) (Fixed) (Total:232.79 GB) (Free:79.26 GB) NTFS
Drive e: (500 GB SATA 2) (Fixed) (Total:465.75 GB) (Free:63.21 GB) NTFS
Drive f: (500 GB SATA 1) (Fixed) (Total:465.75 GB) (Free:87.39 GB) NTFS
Drive g: (500 GB SATA Mac) (Fixed) (Total:465.76 GB) (Free:303 GB) NTFS
Drive j: (SSD 75 GB) (Fixed) (Total:74.53 GB) (Free:21.93 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: 53A46647)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=232.8 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: 8FD73621)
Partition 1: (Active) - (Size=465.7 GB) - (Type=07 NTFS)
========================================================
Disk: 2 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: ADF7E9F5)
Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS)
========================================================
Disk: 3 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: 4C9F97E8)
Partition 1: (Active) - (Size=465.7 GB) - (Type=07 NTFS)
========================================================
Disk: 4 (MBR Code: Windows 7 or 8) (Size: 74.5 GB) (Disk ID: D6E414CB)
Partition 1: (Not Active) - (Size=74.5 GB) - (Type=07 NTFS)
==================== End Of Log ============================ Mein Rechner is doch sauber hm? ;) |