clemicool | 05.11.2014 15:48 | Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 03.11.2014
Suchlauf-Zeit: 21:22:56
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.3.1025
Malware Datenbank: v2014.11.03.09
Rootkit Datenbank: v2014.11.01.02
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8
CPU: x64
Dateisystem: NTFS
Benutzer: Clemens
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 323281
Verstrichene Zeit: 5 Min, 59 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente erkannt)
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 0
(Keine schädliche Elemente erkannt)
Registrierungswerte: 0
(Keine schädliche Elemente erkannt)
Registrierungsdaten: 0
(Keine schädliche Elemente erkannt)
Ordner: 0
(Keine schädliche Elemente erkannt)
Dateien: 0
(Keine schädliche Elemente erkannt)
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end) Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.5 (10.31.2014:1)
OS: Windows 8 x64
Ran by Clemens on 05.11.2014 at 15:44:59,45
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 05.11.2014 at 15:46:24,87
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
# AdwCleaner v4.002 - Bericht erstellt am 05/11/2014 um 15:37:57
# DB v2014-11-02.1
# Aktualisiert 27/10/2014 von Xplode
# Betriebssystem : Windows 8 (64 bits)
# Benutzername : Clemens - CLEMENS-PC
# Gestartet von : C:\Users\Clemens\Desktop\AdwCleaner_4.002.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\Clemens\AppData\Local\CrashRpt
Datei Gelöscht : C:\Windows\System32\roboot64.exe
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\Tune
Schlüssel Gelöscht : HKLM\SOFTWARE\systweak
Schlüssel Gelöscht : HKLM\SOFTWARE\Tune
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GoogleUpdate.exe
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16537
-\\ Google Chrome v38.0.2125.111
*************************
AdwCleaner[R0].txt - [1152 octets] - [03/11/2014 21:31:16]
AdwCleaner[R1].txt - [1212 octets] - [05/11/2014 15:34:31]
AdwCleaner[R2].txt - [1272 octets] - [05/11/2014 15:35:54]
AdwCleaner[S0].txt - [1138 octets] - [05/11/2014 15:37:57]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1198 octets] ########## FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-11-2014
Ran by Clemens (administrator) on CLEMENS-PC on 05-11-2014 15:49:16
Running from C:\Users\Clemens\Desktop
Loaded Profile: Clemens (Available profiles: Clemens)
Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 10
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(AVG Technologies) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(AVG Technologies) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2462536 2014-10-16] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-09-12] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKU\S-1-5-21-957755645-4260464881-2478257714-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [1938624 2014-10-21] (Valve Corporation)
HKU\S-1-5-21-957755645-4260464881-2478257714-1001\...\Run: [Akamai NetSession Interface] => C:\Users\Clemens\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.)
HKU\S-1-5-21-957755645-4260464881-2478257714-1001\...\Run: [TBPanel] => C:\Program Files (x86)\EXPERTool\TBPanel.exe [2195240 2014-02-17] (Gainward Co. Ltd.)
HKU\S-1-5-21-957755645-4260464881-2478257714-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-957755645-4260464881-2478257714-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {9C112D7C-1165-4661-8C0C-570CC04BAECD} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASBJS
SearchScopes: HKLM-x32 - {9C112D7C-1165-4661-8C0C-570CC04BAECD} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASBJS
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
Chrome:
=======
CHR HomePage: Default -> hxxp://www.trovi.com/?gd=&ctid=CT3314958&octid=EB_ORIGINAL_CTID&ISID=M18CEBFDC-E1D6-4F55-A93D-1C20C3016816&SearchSource=55&CUI=&UM=6&UP=SP7A3DCEFA-5B80-459B-8FDB-C5C7F2D6883D&SSPV=
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\Clemens\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (ProxFlow) - C:\Users\Clemens\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek [2014-09-14]
CHR Extension: (Google Präsentationen) - C:\Users\Clemens\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-14]
CHR Extension: (Google Docs) - C:\Users\Clemens\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-07]
CHR Extension: (Google Drive) - C:\Users\Clemens\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-07]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Clemens\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-14]
CHR Extension: (YouTube) - C:\Users\Clemens\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-07]
CHR Extension: (Adblock Plus) - C:\Users\Clemens\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-09-14]
CHR Extension: (Google-Suche) - C:\Users\Clemens\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-07]
CHR Extension: (Google Play Music) - C:\Users\Clemens\AppData\Local\Google\Chrome\User Data\Default\Extensions\fahmaaghhglfmonjliepjlchgpgfmobi [2014-09-14]
CHR Extension: (Google Tabellen) - C:\Users\Clemens\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-14]
CHR Extension: (AdBlock) - C:\Users\Clemens\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-09-14]
CHR Extension: (Google Wallet) - C:\Users\Clemens\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-14]
CHR Extension: (Google Mail) - C:\Users\Clemens\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-07]
CHR Profile: C:\Users\Clemens\AppData\Local\Google\Chrome\User Data\Profile 1
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148744 2014-10-16] (NVIDIA Corporation)
S3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [43520 2012-07-26] (Microsoft Corporation)
S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [634368 2012-07-26] (Microsoft Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1795912 2014-10-16] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19439944 2014-10-16] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-06-23] ()
S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18432 2012-07-26] (Microsoft Corporation)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2589496 2014-10-17] (AVG Technologies)
R2 UxTuneUp; C:\Windows\System32\uxtuneup.dll [42808 2014-10-17] (AVG Technologies)
R2 UxTuneUp; C:\Windows\SysWOW64\uxtuneup.dll [35640 2014-10-17] (AVG Technologies)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 Apowersoft_AudioDevice; C:\Windows\system32\drivers\Apowersoft_AudioDevice.sys [31920 2014-04-09] (Wondershare)
U5 AppMgmt; C:\Windows\system32\svchost.exe [29696 2012-09-20] (Microsoft Corporation)
R3 AU8168; C:\Windows\system32\DRIVERS\au630x64.sys [792648 2013-09-23] (Realtek )
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-06-08] (Disc Soft Ltd)
S3 GameKB; C:\Windows\system32\drivers\GameKB.sys [27648 2012-05-11] () [File not signed]
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19272 2014-10-16] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38048 2014-09-04] (NVIDIA Corporation)
S3 RTL8187B; C:\Windows\system32\DRIVERS\RTL8187B.sys [458384 2012-05-31] (Realtek Semiconductor Corporation )
R3 RtlWlanu; C:\Windows\system32\DRIVERS\rtwlanu.sys [1576080 2012-09-17] (Realtek Semiconductor Corporation )
S3 taphss6; C:\Windows\system32\DRIVERS\taphss6.sys [42184 2014-01-14] (Anchorfree Inc.)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [14112 2014-08-28] (TuneUp Software)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 FairplayKD; \??\C:\ProgramData\MTA San Andreas All\Common\temp\FairplayKD.sys [X]
S3 wolfkr; \??\C:\AeriaGames\WolfTeam-DE\avital\wolfk64.sys [X]
S3 XFDriver64; \??\C:\Program Files (x86)\Xfire2\XFDriver64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-05 15:46 - 2014-11-05 15:46 - 00000684 _____ () C:\Users\Clemens\Desktop\JRT.txt
2014-11-05 15:43 - 2014-11-05 15:43 - 01706359 _____ (Thisisu) C:\Users\Clemens\Desktop\JRT.exe
2014-11-05 15:42 - 2014-11-05 15:43 - 01706359 _____ (Thisisu) C:\Users\Clemens\Downloads\JRT.exe
2014-11-04 18:11 - 2014-11-04 20:42 - 418816834 _____ () C:\Users\Clemens\Downloads\sovepr37.rar
2014-11-04 18:08 - 2014-11-04 18:08 - 00001668 _____ () C:\Users\Clemens\Downloads\Sony_Vegas_Pro_v13-xa61ydnok5ml.dlc
2014-11-03 21:31 - 2014-11-05 15:37 - 00000000 ___DC () C:\AdwCleaner
2014-11-03 21:30 - 2014-11-03 21:30 - 00001189 _____ () C:\Users\Clemens\Desktop\mbam.txt
2014-11-03 21:30 - 2014-11-03 21:24 - 01998336 _____ () C:\Users\Clemens\Desktop\AdwCleaner_4.002.exe
2014-11-03 21:23 - 2014-11-03 21:24 - 01998336 _____ () C:\Users\Clemens\Downloads\AdwCleaner_4.002.exe
2014-11-03 21:18 - 2014-11-03 21:22 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-11-03 21:18 - 2014-11-03 21:18 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-11-03 21:18 - 2014-11-03 21:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-11-03 21:18 - 2014-11-03 21:18 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-11-03 21:18 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-11-03 21:18 - 2014-10-01 11:11 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-11-03 21:18 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-11-03 20:34 - 2014-11-03 20:41 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Clemens\Downloads\mbam-setup-2.0.3.1025.exe
2014-11-03 20:26 - 2014-11-03 20:26 - 00139117 _____ (Malwarebytes Corporation ) C:\Users\Clemens\Downloads\Nicht bestätigt 443938.crdownload
2014-11-02 21:54 - 2014-11-02 21:55 - 04833640 _____ () C:\Users\Clemens\Downloads\Timecyc_dezor.rar
2014-11-02 21:49 - 2014-11-02 21:51 - 05826479 _____ () C:\Users\Clemens\Downloads\435_Overdose_Effect(2).rar
2014-11-02 16:37 - 2014-11-02 16:37 - 00034185 _____ () C:\Users\Clemens\Desktop\Addition.txt
2014-11-02 16:36 - 2014-11-05 15:49 - 00013525 _____ () C:\Users\Clemens\Desktop\FRST.txt
2014-11-02 16:36 - 2014-11-05 15:49 - 00000000 ___DC () C:\FRST
2014-11-02 16:36 - 2014-11-02 16:35 - 02114560 _____ (Farbar) C:\Users\Clemens\Desktop\FRST64.exe
2014-11-02 16:34 - 2014-11-02 16:35 - 02114560 _____ (Farbar) C:\Users\Clemens\Downloads\FRST64.exe
2014-11-01 23:50 - 2014-11-01 23:49 - 05643950 _____ () C:\Users\Clemens\Desktop\Deaglepack.rar
2014-11-01 23:48 - 2014-11-01 23:47 - 02259057 _____ () C:\Users\Clemens\Desktop\LayzieBoneByYures.rar
2014-11-01 23:47 - 2014-11-01 23:49 - 05643950 _____ () C:\Users\Clemens\Downloads\Deaglepack.rar
2014-11-01 23:47 - 2014-11-01 23:47 - 02259057 _____ () C:\Users\Clemens\Downloads\LayzieBoneByYures.rar
2014-11-01 23:42 - 2014-11-01 23:42 - 00352856 _____ () C:\Users\Clemens\Downloads\M4.zip
2014-11-01 17:48 - 2014-10-17 11:34 - 00042808 _____ (AVG Technologies) C:\Windows\system32\uxtuneup.dll
2014-11-01 17:48 - 2014-10-17 11:34 - 00035640 _____ (AVG Technologies) C:\Windows\SysWOW64\uxtuneup.dll
2014-10-31 21:55 - 2014-10-31 21:55 - 00073771 _____ () C:\Users\Clemens\Downloads\deagle-fisco.zip
2014-10-30 21:03 - 2014-10-30 21:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Atari
2014-10-30 21:01 - 2014-10-30 21:01 - 00000000 ____D () C:\Program Files (x86)\Atari
2014-10-30 19:54 - 2014-10-30 19:54 - 00907989 _____ () C:\Users\Clemens\Downloads\meowy.zip
2014-10-30 19:54 - 2014-10-30 19:49 - 01574912 _____ () C:\Users\Clemens\Desktop\m4.txd
2014-10-30 19:54 - 2014-10-30 19:49 - 00417792 _____ () C:\Users\Clemens\Desktop\m4.dff
2014-10-30 13:51 - 2014-10-30 13:58 - 00000000 ____D () C:\Windows\system32\AutoUpdateLicense
2014-10-30 13:47 - 2014-10-22 04:34 - 00010777 _____ () C:\Windows\system32\AutoconfigV2.cab
2014-10-30 13:47 - 2014-10-22 04:33 - 00581016 _____ (Microsoft Corporation) C:\Windows\system32\AutoUpdate.exe
2014-10-30 13:47 - 2014-10-22 04:33 - 00462760 _____ (Microsoft Corporation) C:\Windows\system32\NotificationUI.exe
2014-10-30 13:47 - 2014-10-22 02:08 - 00568832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2014-10-30 13:47 - 2014-10-22 02:08 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-30 13:47 - 2014-10-22 02:01 - 00695808 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2014-10-30 13:47 - 2014-10-22 02:01 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll
2014-10-30 13:47 - 2014-10-22 02:01 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-30 13:47 - 2014-10-22 02:00 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2014-10-26 13:50 - 2014-10-26 13:54 - 05261442 _____ () C:\Users\Clemens\Downloads\jana.rar
2014-10-26 13:05 - 2014-10-26 17:01 - 00006684 _____ () C:\Users\Clemens\Desktop\ggVIo.txt
2014-10-26 11:11 - 2014-10-16 13:27 - 00614544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2014-10-26 11:09 - 2014-10-16 17:54 - 31890064 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2014-10-26 11:09 - 2014-10-16 17:54 - 24555840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2014-10-26 11:09 - 2014-10-16 17:54 - 20922696 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2014-10-26 11:09 - 2014-10-16 17:54 - 19966856 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2014-10-26 11:09 - 2014-10-16 17:54 - 18499648 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2014-10-26 11:09 - 2014-10-16 17:54 - 17260864 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2014-10-26 11:09 - 2014-10-16 17:54 - 16886168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2014-10-26 11:09 - 2014-10-16 17:54 - 14029400 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2014-10-26 11:09 - 2014-10-16 17:54 - 13942368 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2014-10-26 11:09 - 2014-10-16 17:54 - 13190288 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2014-10-26 11:09 - 2014-10-16 17:54 - 11395672 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2014-10-26 11:09 - 2014-10-16 17:54 - 11333848 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2014-10-26 11:09 - 2014-10-16 17:54 - 04289856 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2014-10-26 11:09 - 2014-10-16 17:54 - 04009672 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2014-10-26 11:09 - 2014-10-16 17:54 - 02849224 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2014-10-26 11:09 - 2014-10-16 17:54 - 01876296 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6434448.dll
2014-10-26 11:09 - 2014-10-16 17:54 - 01539272 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6434448.dll
2014-10-26 11:09 - 2014-10-16 17:54 - 00962376 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2014-10-26 11:09 - 2014-10-16 17:54 - 00931984 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2014-10-26 11:09 - 2014-10-16 17:54 - 00921928 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2014-10-26 11:09 - 2014-10-16 17:54 - 00895176 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2014-10-26 11:09 - 2014-10-16 17:54 - 00870112 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2014-10-26 11:09 - 2014-10-16 17:54 - 00500880 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2014-10-26 11:09 - 2014-10-16 17:54 - 00418112 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2014-10-26 11:09 - 2014-10-16 17:54 - 00392008 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2014-10-26 11:09 - 2014-10-16 17:54 - 00352016 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2014-10-26 11:09 - 2014-10-16 17:54 - 00348488 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2014-10-26 11:09 - 2014-10-16 17:54 - 00303600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2014-10-26 11:09 - 2014-10-16 17:54 - 00174856 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2014-10-26 11:09 - 2014-10-16 17:54 - 00156840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2014-10-26 03:01 - 2014-10-26 04:48 - 306270552 _____ (NVIDIA Corporation) C:\Users\Clemens\Downloads\344.48-desktop-win8-win7-winvista-64bit-international-whql.exe
2014-10-22 12:02 - 2014-10-22 12:02 - 00000000 ____D () C:\Users\Clemens\AppData\Roaming\Obsidian Entertainment
2014-10-22 12:02 - 2014-10-22 12:02 - 00000000 ____D () C:\ProgramData\Obsidian Entertainment
2014-10-21 12:05 - 2014-10-21 12:05 - 00000967 _____ () C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2014-10-21 12:05 - 2014-10-21 12:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2014-10-21 12:05 - 2014-10-21 12:05 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client
2014-10-21 11:50 - 2014-10-21 12:01 - 30014480 _____ (TeamSpeak Systems GmbH) C:\Users\Clemens\Downloads\TeamSpeak3-Client-win64-3.0.16.exe
2014-10-20 21:18 - 2014-10-20 21:18 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-10-20 21:18 - 2014-10-20 21:18 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-10-20 21:18 - 2014-10-20 21:18 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-10-20 21:18 - 2014-10-20 21:18 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-10-20 21:18 - 2014-10-20 21:18 - 00000000 ____D () C:\Program Files (x86)\Java
2014-10-17 21:36 - 2014-10-31 01:17 - 00000000 ____D () C:\Users\Clemens\Desktop\kills
2014-10-17 15:59 - 2014-09-27 01:08 - 152401496 _____ () C:\Users\Clemens\Downloads\KOHA (ESKK2 K.rar
2014-10-17 15:58 - 2014-09-27 03:46 - 152401623 _____ () C:\Users\Clemens\Downloads\EO HAAK451LR .rar
2014-10-17 14:39 - 2014-10-17 15:34 - 152401750 _____ () C:\Users\Clemens\Downloads\)AA5 (2A00ER(.rar
2014-10-17 11:52 - 2014-10-17 12:36 - 124065566 _____ () C:\Users\Clemens\Downloads\Shi-F_VCKB1TCHeSG37M0N3Y(DLXVER)(2014).rar
2014-10-17 02:21 - 2014-10-17 02:59 - 108152640 _____ () C:\Users\Clemens\Downloads\Hdry5hm.rar
2014-10-17 00:39 - 2014-10-17 00:42 - 03395206 _____ () C:\Users\Clemens\Downloads\17. Oktober.rar
2014-10-17 00:11 - 2014-10-17 00:11 - 00000000 ____D () C:\Users\Clemens\Downloads\thumbs
2014-10-17 00:06 - 2014-10-17 00:06 - 01019904 _____ (www.byphry.de.vu) C:\Users\Clemens\Downloads\ThumbsDbExtractor.exe
2014-10-16 23:22 - 2014-09-13 07:24 - 02233152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-10-16 23:22 - 2014-09-06 01:46 - 00389176 _____ () C:\Windows\system32\ApnDatabase.xml
2014-10-16 23:22 - 2014-09-03 03:48 - 00457728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll
2014-10-16 23:22 - 2014-09-03 03:48 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2014-10-16 23:22 - 2014-09-03 03:22 - 00188928 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2014-10-16 23:22 - 2014-09-03 03:21 - 00623104 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2014-10-16 23:22 - 2014-09-03 03:21 - 00212992 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll
2014-10-16 23:22 - 2014-08-29 05:17 - 02043392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2014-10-16 23:22 - 2014-08-29 05:17 - 00227328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2014-10-16 23:22 - 2014-08-29 05:04 - 02837504 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2014-10-16 23:22 - 2014-08-29 05:04 - 00309248 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2014-10-16 23:22 - 2014-08-28 07:04 - 00499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FXSCOMEX.dll
2014-10-16 23:22 - 2014-08-28 07:04 - 00227840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FXSAPI.dll
2014-10-16 23:22 - 2014-08-28 06:59 - 00616448 _____ (Microsoft Corporation) C:\Windows\system32\FXSAPI.dll
2014-10-16 23:22 - 2014-08-28 06:59 - 00609280 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOMEX.dll
2014-10-16 23:22 - 2014-08-28 06:59 - 00432640 _____ (Microsoft Corporation) C:\Windows\system32\FXSTIFF.dll
2014-10-16 23:22 - 2014-08-28 06:59 - 00254976 _____ (Microsoft Corporation) C:\Windows\system32\FXST30.dll
2014-10-16 23:22 - 2014-07-24 14:12 - 00328512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys
2014-10-16 23:06 - 2014-10-16 23:06 - 00000000 ____D () C:\Program Files (x86)\Microsoft ASP.NET
2014-10-16 23:02 - 2014-07-07 06:53 - 01125376 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-10-16 23:02 - 2014-07-07 06:52 - 03248128 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-10-16 23:02 - 2014-07-07 06:52 - 00724992 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-10-16 23:02 - 2014-07-07 06:52 - 00300544 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2014-10-16 23:02 - 2014-07-07 06:51 - 05982208 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-10-16 23:02 - 2014-07-07 05:01 - 01049600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2014-10-16 23:02 - 2014-07-07 05:01 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winsta.dll
2014-10-16 23:02 - 2014-07-07 05:00 - 05095424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-10-16 23:02 - 2014-07-07 04:59 - 00269312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2014-10-16 23:00 - 2014-10-10 05:47 - 00693248 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-10-16 23:00 - 2014-10-10 05:47 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-10-16 23:00 - 2014-10-08 05:26 - 00556544 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-10-16 22:59 - 2014-09-13 06:29 - 00079360 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-10-16 22:59 - 2014-09-13 05:02 - 00068096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-10-16 22:59 - 2014-09-03 03:48 - 00510464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
2014-10-16 22:59 - 2014-09-03 03:21 - 00585728 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2014-10-16 22:58 - 2014-09-28 05:18 - 04068352 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-10-16 22:57 - 2014-09-18 00:24 - 02416128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-10-16 22:57 - 2014-09-17 23:56 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-10-16 22:02 - 2014-10-16 22:02 - 00069827 _____ () C:\Users\Clemens\Downloads\1220357907_SAStreamMemFix2.0.rar
2014-10-15 14:09 - 2014-10-15 14:09 - 00002762 _____ () C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013
2014-10-13 20:37 - 2014-10-13 20:37 - 00003704 _____ () C:\Windows\System32\Tasks\Java(TM) Platform SE Auto Updater
2014-10-13 20:27 - 2014-10-17 11:34 - 00040248 _____ (AVG Technologies) C:\Windows\system32\TURegOpt.exe
2014-10-13 20:27 - 2014-10-17 11:34 - 00029496 _____ (AVG Technologies) C:\Windows\system32\authuitu.dll
2014-10-13 20:27 - 2014-10-17 11:34 - 00025400 _____ (AVG Technologies) C:\Windows\SysWOW64\authuitu.dll
2014-10-13 20:27 - 2014-10-13 20:27 - 00002225 _____ () C:\Users\Public\Desktop\AVG 1-Klick-Wartung.lnk
2014-10-13 20:27 - 2014-10-13 20:27 - 00002213 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp 2015.lnk
2014-10-13 20:27 - 2014-10-13 20:27 - 00002201 _____ () C:\Users\Public\Desktop\AVG PC TuneUp 2015.lnk
2014-10-13 20:27 - 2014-10-13 20:27 - 00000000 ____D () C:\Users\Clemens\AppData\Roaming\AVG
2014-10-13 20:27 - 2014-10-13 20:27 - 00000000 ____D () C:\Users\Clemens\AppData\Local\Avg
2014-10-13 20:26 - 2014-10-13 20:26 - 00000000 ____D () C:\Program Files (x86)\AVG
2014-10-13 20:24 - 2014-10-25 02:35 - 00000000 ____D () C:\ProgramData\AVG
2014-10-13 20:20 - 2014-10-13 20:24 - 87520056 _____ (AVG Technologies) C:\Users\Clemens\Downloads\avg_tuht_stf_all_2015_105.exe
2014-10-13 19:51 - 2014-10-13 19:57 - 03482976 _____ (tuneuppro.com ) C:\Users\Clemens\Downloads\tuppsetup_2005.exe
2014-10-13 19:15 - 2014-10-13 19:15 - 00006218 _____ () C:\Users\Clemens\Downloads\timecyc (6).zip
2014-10-13 19:11 - 2014-10-13 19:15 - 08097996 _____ () C:\Users\Clemens\Downloads\Timecyc (5).zip
2014-10-13 19:09 - 2014-10-13 19:10 - 01681961 _____ () C:\Users\Clemens\Downloads\1413149069_REVOFX M4 MOD.rar
2014-10-13 19:09 - 2014-10-13 19:09 - 00011423 _____ () C:\Users\Clemens\Downloads\Standard-Timecyc.rar
2014-10-13 19:06 - 2014-10-13 19:08 - 04113030 _____ () C:\Users\Clemens\Downloads\1405084687_Pack_de_Armas_BlueLine.rar
2014-10-11 10:42 - 2014-10-11 10:45 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-10-11 09:55 - 2014-10-11 09:55 - 00002011 _____ () C:\Users\Clemens\Downloads\b78293_4bdec333e91aa.zip
2014-10-10 17:12 - 2014-10-10 17:13 - 04336037 _____ () C:\Users\Clemens\Downloads\DetailedRadarModLabels.zip
2014-10-09 14:50 - 2014-10-09 15:32 - 119200175 _____ () C:\Users\Clemens\Downloads\39.rar
2014-10-08 15:29 - 2014-10-08 15:29 - 00000196 _____ () C:\Users\Clemens\Downloads\1e035a17-26a8-4fad-aace-7739ee27a807 (1).htm
2014-10-08 15:28 - 2014-10-08 15:28 - 00165072 _____ () C:\Users\Clemens\Downloads\installer_jdownloader_two.exe
2014-10-08 15:28 - 2014-10-08 15:28 - 00000196 _____ () C:\Users\Clemens\Downloads\1e035a17-26a8-4fad-aace-7739ee27a807.htm
2014-10-08 15:04 - 2014-10-08 15:23 - 52807729 _____ () C:\Users\Clemens\Downloads\Premium Database Script.rar
2014-10-07 17:59 - 2014-10-07 18:53 - 153287081 _____ () C:\Users\Clemens\Downloads\Kurdo - Slum Dog Millionaer [Premium Edition] (2014).rar
2014-10-06 18:28 - 2014-10-06 18:29 - 416569824 _____ () C:\Users\Clemens\Desktop\gta3.rar
2014-10-06 18:27 - 2014-10-06 18:29 - 05051435 _____ () C:\Users\Clemens\Downloads\grp.cc.rar
2014-10-06 14:43 - 2014-10-06 15:32 - 140717223 _____ () C:\Users\Clemens\Downloads\#8468#.rar
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-05 15:45 - 2012-07-26 11:27 - 00828878 _____ () C:\Windows\system32\perfh007.dat
2014-11-05 15:45 - 2012-07-26 11:27 - 00188018 _____ () C:\Windows\system32\perfc007.dat
2014-11-05 15:45 - 2012-07-26 08:28 - 01949496 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-11-05 15:44 - 2014-09-15 14:48 - 00000000 ____D () C:\Windows\ERUNT
2014-11-05 15:41 - 2013-12-07 11:35 - 00001136 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-05 15:38 - 2014-01-19 19:07 - 00090136 _____ () C:\Windows\PFRO.log
2014-11-05 15:38 - 2013-12-09 18:02 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-11-05 15:38 - 2012-07-26 08:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-11-04 23:16 - 2013-12-07 11:35 - 00001140 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-11-04 23:00 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\system32\sru
2014-11-03 22:17 - 2013-12-07 12:47 - 00000000 ____D () C:\Users\Clemens\AppData\Roaming\TS3Client
2014-11-03 21:52 - 2014-01-15 15:28 - 01562452 _____ () C:\Windows\WindowsUpdate.log
2014-11-02 19:04 - 2014-09-26 14:37 - 04433408 ___SH () C:\Users\Clemens\Desktop\Thumbs.db
2014-11-02 16:33 - 2013-12-13 19:54 - 00007598 _____ () C:\Users\Clemens\AppData\Local\Resmon.ResmonCfg
2014-11-02 13:33 - 2014-09-23 17:59 - 00019456 ____H () C:\Users\Clemens\Desktop\photothumb.db
2014-11-01 23:44 - 2014-01-07 18:48 - 00000000 ____D () C:\Users\Clemens\AppData\Roaming\vlc
2014-11-01 17:39 - 2013-12-07 11:35 - 00004112 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-11-01 17:39 - 2013-12-07 11:35 - 00003876 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-10-30 22:04 - 2014-01-11 10:36 - 00000000 ____D () C:\Users\Clemens\AppData\Local\CrashDumps
2014-10-30 21:46 - 2014-02-08 12:52 - 00459630 _____ () C:\Windows\DirectX.log
2014-10-30 21:06 - 2013-12-07 11:16 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-10-30 17:47 - 2014-06-25 21:08 - 00000000 ___DC () C:\Fraps
2014-10-30 15:01 - 2014-01-03 15:22 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-10-30 15:00 - 2014-09-15 14:56 - 00000000 ____D () C:\Users\Clemens\Desktop\trojanerboard
2014-10-30 15:00 - 2014-06-08 19:43 - 00000000 ___RD () C:\Users\Clemens\Desktop\Alles
2014-10-30 15:00 - 2013-12-28 18:58 - 00000000 ___RD () C:\Users\Clemens\Desktop\Tools
2014-10-30 14:57 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\rescache
2014-10-30 13:52 - 2012-07-26 08:59 - 00000000 ____D () C:\Windows\CbsTemp
2014-10-30 13:52 - 2012-07-26 06:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-10-30 13:51 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\WinStore
2014-10-30 12:25 - 2013-12-09 18:17 - 00275080 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-10-26 15:07 - 2014-06-16 15:44 - 00000000 ____D () C:\Users\Clemens\Documents\Rockstar Games
2014-10-26 11:12 - 2014-03-17 18:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2014-10-26 11:12 - 2014-02-15 12:54 - 00007522 _____ () C:\Windows\setupact.log
2014-10-26 11:12 - 2013-12-09 18:01 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-10-25 13:20 - 2014-02-08 12:38 - 00000000 ____D () C:\Program Files (x86)\Activision
2014-10-25 10:53 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\system32\NDF
2014-10-25 02:37 - 2014-01-17 23:13 - 00000000 ____D () C:\Users\Clemens\AppData\Roaming\Skype
2014-10-22 12:16 - 2014-01-17 23:13 - 00000000 ____D () C:\ProgramData\Skype
2014-10-22 12:15 - 2014-01-12 11:58 - 00000000 ____D () C:\ProgramData\Ubisoft
2014-10-22 12:12 - 2014-04-04 13:38 - 00000000 ____D () C:\Program Files (x86)\Sony
2014-10-22 12:12 - 2014-03-03 17:00 - 00000000 ____D () C:\Users\Clemens\AppData\Local\Sony
2014-10-22 12:12 - 2014-03-03 16:59 - 00000000 ____D () C:\ProgramData\Sony
2014-10-22 12:04 - 2014-01-07 20:30 - 00000000 ____D () C:\Program Files (x86)\QuickTime
2014-10-22 12:03 - 2014-01-03 16:17 - 00000000 ____D () C:\Users\Clemens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2014-10-22 10:23 - 2014-01-13 22:23 - 00003584 _____ () C:\Users\Clemens\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-10-20 21:18 - 2013-12-12 16:47 - 00000000 ____D () C:\ProgramData\Oracle
2014-10-17 19:02 - 2014-10-05 19:58 - 00000000 ____D () C:\Users\Clemens\Desktop\Crosshair
2014-10-17 01:11 - 2014-01-12 12:08 - 00000000 ____D () C:\Users\Clemens\AppData\Local\Ubisoft Game Launcher
2014-10-17 00:02 - 2014-01-17 23:14 - 02260992 _____ () C:\Program Files (x86)\Thumbs.db
2014-10-16 23:26 - 2014-07-10 15:17 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-10-16 23:25 - 2012-07-26 09:12 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-10-16 23:13 - 2014-09-07 11:56 - 00287608 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-16 23:11 - 2012-07-26 09:12 - 00000000 ___RD () C:\Windows\ToastData
2014-10-16 23:10 - 2013-12-09 17:32 - 00000000 ____D () C:\Windows\system32\MRT
2014-10-16 23:06 - 2013-12-09 17:32 - 103265616 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-10-16 17:54 - 2014-07-31 21:28 - 01715224 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2014-10-16 17:54 - 2014-07-31 21:28 - 01291280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2014-10-16 17:54 - 2014-07-31 21:23 - 00027024 _____ () C:\Windows\system32\nvinfo.pb
2014-10-16 17:54 - 2014-03-17 18:32 - 02800296 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2014-10-16 17:54 - 2014-03-17 18:32 - 02197680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2014-10-16 17:54 - 2014-03-17 18:29 - 00987008 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2014-10-16 17:54 - 2013-12-09 18:02 - 00072904 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2014-10-16 17:54 - 2013-12-09 18:02 - 00060560 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2014-10-16 17:54 - 2013-10-27 09:12 - 03237528 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2014-10-16 17:54 - 2012-07-25 21:22 - 20968040 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2014-10-16 15:11 - 2013-12-09 18:02 - 06883136 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2014-10-16 15:11 - 2013-12-09 18:02 - 03533632 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2014-10-16 15:11 - 2013-12-09 18:02 - 02559808 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2014-10-16 15:11 - 2013-12-09 18:02 - 00933064 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2014-10-16 15:11 - 2013-12-09 18:02 - 00384200 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2014-10-16 15:11 - 2013-12-09 18:02 - 00061640 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2014-10-15 14:12 - 2013-12-07 11:10 - 00000000 ____D () C:\Users\Clemens\AppData\Local\VirtualStore
2014-10-15 01:48 - 2014-06-08 19:22 - 04047877 _____ () C:\Windows\system32\nvcoproc.bin
2014-10-14 17:35 - 2013-12-07 11:17 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-957755645-4260464881-2478257714-1001
2014-10-13 20:41 - 2013-12-31 13:54 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-10-13 20:37 - 2014-03-03 16:59 - 00000000 ____D () C:\Users\Clemens\AppData\Roaming\Sony
2014-10-13 20:35 - 2014-06-08 19:33 - 00003006 _____ () C:\Windows\System32\Tasks\EXPERTool
2014-10-13 20:32 - 2014-01-01 19:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
2014-10-13 20:32 - 2013-12-14 18:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-10-13 20:00 - 2013-12-31 13:54 - 00003774 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-10-12 19:02 - 2014-10-03 16:15 - 01017856 _____ () C:\Users\Clemens\Desktop\bikdrug.txd
2014-10-12 19:02 - 2014-10-03 16:15 - 00483328 _____ () C:\Users\Clemens\Desktop\bikdrug.dff
2014-10-11 10:45 - 2014-01-03 18:38 - 00000000 ____D () C:\ProgramData\Origin
2014-10-10 17:04 - 2013-12-09 20:49 - 00621568 ___SH () C:\Users\Clemens\Downloads\Thumbs.db
Some content of TEMP:
====================
C:\Users\Clemens\AppData\Local\Temp\drm_dyndata_7410004.dll
C:\Users\Clemens\AppData\Local\Temp\nvStInst.exe
C:\Users\Clemens\AppData\Local\Temp\Quarantine.exe
C:\Users\Clemens\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-10-27 17:29
==================== End Of Log ============================ --- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-11-2014
Ran by Clemens at 2014-11-02 16:37:09
Running from C:\Users\Clemens\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.152 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.09) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated)
Akamai NetSession Interface (HKCU\...\Akamai) (Version: - Akamai Technologies, Inc)
AVG PC TuneUp 2015 (de-DE) (x32 Version: 15.0.1001.185 - AVG Technologies) Hidden
AVG PC TuneUp 2015 (HKLM-x32\...\AVG PC TuneUp) (Version: 15.0.1001.185 - AVG Technologies)
AVG PC TuneUp 2015 (x32 Version: 15.0.1001.185 - AVG Technologies) Hidden
Borderlands (HKLM-x32\...\{52B65911-1559-4ED5-9461-46957FDD48CD}) (Version: 1.0.295 - 2K Games)
Borderlands 2 (HKLM-x32\...\Borderlands 2_is1) (Version: - )
Call of Duty(R) 4 - Modern Warfare(TM) (HKLM-x32\...\InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}) (Version: 1.7 - Activision)
Call of Duty(R) 4 - Modern Warfare(TM) (x32 Version: 1.6 - Activision) Hidden
Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch (x32 Version: - ) Hidden
Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch (x32 Version: 1.7 - Activision) Hidden
Call of Duty: Black Ops - Multiplayer (HKLM-x32\...\Steam App 42710) (Version: - Treyarch)
Call of Duty: Black Ops (HKLM-x32\...\Steam App 42700) (Version: - Treyarch)
Camtasia Studio 8 (HKLM-x32\...\{F5C9BE9A-04C3-4A72-8CD0-BB67C722D608}) (Version: 8.1.2.1344 - TechSmith Corporation)
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
EXPERTool v9.1 (HKLM-x32\...\{551D9481-9487-4D0C-9A1D-6BC3E7B6D991}_is1) (Version: 9.1.0.2 - Gainward Co. Ltd.)
Far Cry 3 (HKLM-x32\...\{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}) (Version: 1.00 - Ubisoft)
Far Cry 3 Blood Dragon (HKLM-x32\...\{A071F478-73E0-4143-AE55-4DD6BABD74F5}) (Version: 1.00 - Ubisoft)
Far Cry 3 Deutsch Patch Fix-TokZic 1.00 (HKLM-x32\...\Far Cry 3 Deutsch Patch Fix-TokZic 1.00) (Version: 1.00 - TokZic)
Far Cry 3 Deutsch Patch-TokZic 1.00 (HKLM-x32\...\Far Cry 3 Deutsch Patch-TokZic 1.00) (Version: 1.00 - TokZic)
Fotogalerie (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Fraps (remove only) (HKLM-x32\...\Fraps) (Version: - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 38.0.2125.111 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.5 - Google Inc.) Hidden
Grand Theft Auto San Andreas (HKLM-x32\...\{086BADF8-9B1F-4E89-B207-2EDA520972D6}) (Version: 1.00.00001 - Rockstar Games)
Grand Theft Auto: Episodes From Liberty City (HKLM-x32\...\{61B8B2F9-D8DA-4B24-89A9-DB09F38A4899}) (Version: 1.1.0.0 - Rockstar Games)
Grand Theft Auto: Episodes from Liberty City (x32 Version: 1.0.0003.135 - Rockstar Games Inc.) Hidden
Hitman Absolution (HKLM-x32\...\Hitman Absolution_is1) (Version: - )
Java 7 Update 45 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417045FF}) (Version: 7.0.450 - Oracle)
Java 7 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
Mafia II (HKLM-x32\...\Mafia II_is1) (Version: 1.0 - Take-Two Interactive Software, Inc.)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{42AA4CA8-DCD8-4308-BCAB-0B6D75856A9D}) (Version: 3.5.95.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (HKLM-x32\...\{8e70e4e1-06d7-470b-9f74-a51bef21088e}) (Version: 11.0.51106.1 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
MSVCRT Redists (Version: 1.0 - Sony Creative Software Inc.) Hidden
MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden
MTA:SA v1.3.5 (HKLM-x32\...\MTA:SA 1.3) (Version: v1.3.5 - Multi Theft Auto)
MTA:SA v1.4.0 (HKLM-x32\...\MTA:SA 1.4) (Version: v1.4.0 - Multi Theft Auto)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.6.6 - Notepad++ Team)
NVIDIA 3D Vision Controller-Treiber 344.46 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 344.46 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 344.48 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 344.48 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.1.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.3 - NVIDIA Corporation)
NVIDIA Grafiktreiber 344.48 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 344.48 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.32.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.32.1 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.14.0702 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation)
Orcs Must Die! (HKLM-x32\...\Orcs Must Die!_is1) (Version: - )
Photo Common (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Photo Gallery (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
PhotoScape (HKLM-x32\...\PhotoScape) (Version: - )
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.)
SHIELD Streaming (Version: 3.1.1000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 16.13.56 - NVIDIA Corporation) Hidden
Sniper Elite: Zombie Army 2 (HKLM-x32\...\Steam App 247930) (Version: - Rebellion)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
Uplay (HKLM-x32\...\Uplay) (Version: 2.0 - Ubisoft)
VLC media player 2.1.2 (HKLM-x32\...\VLC media player) (Version: 2.1.2 - VideoLAN)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WinRAR 5.01 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
==================== Restore Points =========================
20-10-2014 20:17:52 Installed Java 7 Update 71
22-10-2014 11:01:23 Removed Apple Application Support
24-10-2014 14:40:00 Installiert Stronghold 2
26-10-2014 10:12:20 DirectX wurde installiert
30-10-2014 12:51:19 Windows Update
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2012-07-26 06:26 - 2014-09-14 11:40 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {2A67E660-0914-4E8C-8118-E938D8F37469} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2014-10-16] (Microsoft Corporation)
Task: {4E89B4B0-CC85-46ED-B4E8-3F3CA78FCCC4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-07] (Google Inc.)
Task: {722F2DA5-3D75-4B8B-A706-616B7C64A5E9} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe
Task: {744E0A84-6F53-48A1-8682-6CD9292E97D0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-07] (Google Inc.)
Task: {74726EC3-B4FB-426A-AB83-FEBA960459AA} - System32\Tasks\Java(TM) Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-09-26] (Oracle Corporation)
Task: {8063572F-4A3D-4740-BAAA-BC079BF24584} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-09] (Adobe Systems Incorporated)
Task: {8137EEC6-4F9E-41EB-A185-B5F3AC76CC73} - System32\Tasks\Microsoft\Windows\Setup\8.1 auto install v2 => C:\Windows\system32\AutoUpdate.exe [2014-10-22] (Microsoft Corporation)
Task: {836ABE6E-E11C-4E82-96A8-985A05C32049} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
Task: {A52DD622-67F6-4085-81AD-A913C14E8419} - System32\Tasks\Microsoft\Windows\Setup\8.1 auto install ping => C:\Windows\system32\AutoUpdate.exe [2014-10-22] (Microsoft Corporation)
Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {C1D3BA93-9266-4E75-A302-6DED7458A7E1} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\AVG\AVG PC TuneUp\OneClick.exe [2014-10-17] (AVG Technologies)
Task: {C4A2FA10-F036-4824-9D0C-1800F17E6AB9} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {EBD8D9D1-EE7A-404D-BB8C-4619D14EEB36} - System32\Tasks\EXPERTool => C:\Program Files (x86)\EXPERTool\TBPanel.exe [2014-02-17] (Gainward Co. Ltd.)
Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2013-12-09 18:20 - 2014-06-23 14:49 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-10-17 11:34 - 2014-10-17 11:34 - 00699704 _____ () C:\Program Files (x86)\AVG\AVG PC TuneUp\avgrepliba.dll
2014-10-17 11:34 - 2014-10-17 11:34 - 00835896 _____ () C:\Program Files (x86)\AVG\AVG PC TuneUp\tulnga.dll
2014-02-28 10:14 - 2014-02-28 10:14 - 00173568 _____ () C:\Program Files\TeamSpeak 3 Client\quazip.dll
2014-02-27 15:51 - 2014-02-27 15:51 - 01080832 _____ () C:\Program Files\TeamSpeak 3 Client\platforms\qwindows.dll
2014-02-27 15:51 - 2014-02-27 15:51 - 00833024 _____ () C:\Program Files\TeamSpeak 3 Client\sqldrivers\qsqlite.dll
2014-08-04 14:43 - 2014-08-04 14:43 - 00102344 _____ () C:\Program Files\TeamSpeak 3 Client\soundbackends\directsound_win64.dll
2014-08-04 14:43 - 2014-08-04 14:43 - 00108488 _____ () C:\Program Files\TeamSpeak 3 Client\soundbackends\windowsaudiosession_win64.dll
2014-02-27 15:51 - 2014-02-27 15:51 - 00030208 _____ () C:\Program Files\TeamSpeak 3 Client\imageformats\qgif.dll
2014-02-27 15:51 - 2014-02-27 15:51 - 00233984 _____ () C:\Program Files\TeamSpeak 3 Client\imageformats\qjpeg.dll
2014-08-04 14:46 - 2014-08-04 14:46 - 00563656 _____ () C:\Program Files\TeamSpeak 3 Client\plugins\clientquery_plugin.dll
2014-08-04 14:46 - 2014-08-04 14:46 - 00579016 _____ () C:\Program Files\TeamSpeak 3 Client\plugins\teamspeak_control_plugin.dll
2014-02-27 15:51 - 2014-02-27 15:51 - 00159232 _____ () C:\Program Files\TeamSpeak 3 Client\accessible\qtaccessiblewidgets.dll
2014-10-27 20:16 - 2014-10-22 05:04 - 01042760 _____ () C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\libglesv2.dll
2014-10-27 20:16 - 2014-10-22 05:04 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\libegl.dll
2014-10-27 20:16 - 2014-10-22 05:04 - 08910664 _____ () C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\pdf.dll
2014-10-27 20:16 - 2014-10-22 05:04 - 01681224 _____ () C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\ffmpegsumo.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\ProgramData:$SS_DESCRIPTOR_NBVUV6PKDVBGTLPHJKBUK1R0WTPLY2LB3W2PHDEX6J5T4BW9V4DLNNH2V1UY71VU5VVVVVJVTVVJVT
AlternateDataStreams: C:\ProgramData:NT
AlternateDataStreams: C:\ProgramData:NT2
AlternateDataStreams: C:\Users\All Users:$SS_DESCRIPTOR_NBVUV6PKDVBGTLPHJKBUK1R0WTPLY2LB3W2PHDEX6J5T4BW9V4DLNNH2V1UY71VU5VVVVVJVTVVJVT
AlternateDataStreams: C:\Users\All Users:NT
AlternateDataStreams: C:\Users\All Users:NT2
AlternateDataStreams: C:\ProgramData\Anwendungsdaten:$SS_DESCRIPTOR_NBVUV6PKDVBGTLPHJKBUK1R0WTPLY2LB3W2PHDEX6J5T4BW9V4DLNNH2V1UY71VU5VVVVVJVTVVJVT
AlternateDataStreams: C:\ProgramData\Anwendungsdaten:NT
AlternateDataStreams: C:\ProgramData\Anwendungsdaten:NT2
AlternateDataStreams: C:\ProgramData\Application Data:$SS_DESCRIPTOR_NBVUV6PKDVBGTLPHJKBUK1R0WTPLY2LB3W2PHDEX6J5T4BW9V4DLNNH2V1UY71VU5VVVVVJVTVVJVT
AlternateDataStreams: C:\ProgramData\Application Data:NT
AlternateDataStreams: C:\ProgramData\Application Data:NT2
AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT
AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT2
AlternateDataStreams: C:\Users\Clemens\Anwendungsdaten:NT
AlternateDataStreams: C:\Users\Clemens\Anwendungsdaten:NT2
AlternateDataStreams: C:\Users\Clemens\AppData\Roaming:NT
AlternateDataStreams: C:\Users\Clemens\AppData\Roaming:NT2
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
MSCONFIG\Services: AdobeARMservice => 2
HKLM\...\StartupApproved\Run: => "NvBackend"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKLM\...\StartupApproved\Run32: => "Aeria Ignite"
HKLM\...\StartupApproved\Run32: => "APSDaemon"
HKLM\...\StartupApproved\Run32: => "QuickTime Task"
HKLM\...\StartupApproved\Run32: => "Adobe ARM"
HKCU\...\StartupApproved\StartupFolder: => "MFBot.url"
HKCU\...\StartupApproved\Run: => "EA Core"
HKCU\...\StartupApproved\Run: => "Steam"
HKCU\...\StartupApproved\Run: => "Skype"
HKCU\...\StartupApproved\Run: => "Akamai NetSession Interface"
HKCU\...\StartupApproved\Run: => "DAEMON Tools Lite"
HKCU\...\StartupApproved\Run: => "Overwolf"
========================= Accounts: ==========================
Administrator (S-1-5-21-957755645-4260464881-2478257714-500 - Administrator - Disabled)
Clemens (S-1-5-21-957755645-4260464881-2478257714-1001 - Administrator - Enabled) => C:\Users\Clemens
Gast (S-1-5-21-957755645-4260464881-2478257714-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-957755645-4260464881-2478257714-1003 - Limited - Enabled)
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (11/02/2014 03:52:10 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: CLEMENS-PC)
Description: Das Paket „winstore_1.0.0.0_neutral_neutral_cw5n1h2txyewy“ wurde beendet, da das Anhalten zu lange dauerte.
Error: (11/02/2014 03:52:11 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm WWAHost.exe, Version 6.2.9200.16420 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: fec
Startzeit: 01cff6ac824815dd
Endzeit: 4294967295
Anwendungspfad: C:\Windows\System32\WWAHost.exe
Berichts-ID: d2d21e49-629f-11e4-bf8d-60a44c3287ba
Vollständiger Name des fehlerhaften Pakets: winstore_1.0.0.0_neutral_neutral_cw5n1h2txyewy
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Windows.Store
Error: (11/02/2014 03:48:02 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2486) (User: CLEMENS-PC)
Description: Die App „winstore_cw5n1h2txyewy!Windows.Store“ wurde nicht innerhalb der vorgesehenen Zeit gestartet.
Error: (10/30/2014 10:04:52 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: EFLC.exe, Version: 1.1.0.0, Zeitstempel: 0x4b87a71e
Name des fehlerhaften Moduls: DSOUND.dll, Version: 6.2.9200.17046, Zeitstempel: 0x53b485c4
Ausnahmecode: 0xc0000142
Fehleroffset: 0x00078c9e
ID des fehlerhaften Prozesses: 0x64
Startzeit der fehlerhaften Anwendung: 0xEFLC.exe0
Pfad der fehlerhaften Anwendung: EFLC.exe1
Pfad des fehlerhaften Moduls: EFLC.exe2
Berichtskennung: EFLC.exe3
Vollständiger Name des fehlerhaften Pakets: EFLC.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: EFLC.exe5
Error: (10/30/2014 10:04:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: EFLC.exe, Version: 1.1.0.0, Zeitstempel: 0x4b87a71e
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.2.9200.16864, Zeitstempel: 0x531d2be6
Ausnahmecode: 0x0eedfade
Fehleroffset: 0x00010f22
ID des fehlerhaften Prozesses: 0x64
Startzeit der fehlerhaften Anwendung: 0xEFLC.exe0
Pfad der fehlerhaften Anwendung: EFLC.exe1
Pfad des fehlerhaften Moduls: EFLC.exe2
Berichtskennung: EFLC.exe3
Vollständiger Name des fehlerhaften Pakets: EFLC.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: EFLC.exe5
Error: (10/30/2014 03:39:54 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm ts3client_win64.exe, Version 3.0.16.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: e74
Startzeit: 01cff44f515102a7
Endzeit: 3
Anwendungspfad: C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe
Berichts-ID: 9a9f021c-6042-11e4-bf84-60a44c3287ba
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (10/30/2014 03:33:09 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm ts3client_win64.exe, Version 3.0.16.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: f70
Startzeit: 01cff44e5cc77f99
Endzeit: 2
Anwendungspfad: C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe
Berichts-ID: a871210c-6041-11e4-bf83-60a44c3287ba
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (10/27/2014 10:00:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: GFWLClient.exe, Version: 3.5.67.0, Zeitstempel: 0x52178fb2
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x059cbfd5
ID des fehlerhaften Prozesses: 0x13ec
Startzeit der fehlerhaften Anwendung: 0xGFWLClient.exe0
Pfad der fehlerhaften Anwendung: GFWLClient.exe1
Pfad des fehlerhaften Moduls: GFWLClient.exe2
Berichtskennung: GFWLClient.exe3
Vollständiger Name des fehlerhaften Pakets: GFWLClient.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: GFWLClient.exe5
Error: (10/27/2014 10:00:37 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: GFWLClient.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet.
Ausnahmeinformationen: System.NullReferenceException
Stapel:
bei Microsoft.GamesForWindows.LiveClient.Messaging.CommandPipe.IsDownloadAndInstallationQueueDrained()
bei Microsoft.GamesForWindows.LiveClient.Messaging.CommandPipe.Shutdown()
bei Microsoft.GamesForWindows.LiveClient.Messaging.CommandPipe.ListenerThread()
bei System.Threading.ThreadHelper.ThreadStart_Context(System.Object)
bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
bei System.Threading.ThreadHelper.ThreadStart()
Error: (10/26/2014 11:58:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: GFWLClient.exe, Version: 3.5.67.0, Zeitstempel: 0x52178fb2
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0581a97d
ID des fehlerhaften Prozesses: 0x6fc
Startzeit der fehlerhaften Anwendung: 0xGFWLClient.exe0
Pfad der fehlerhaften Anwendung: GFWLClient.exe1
Pfad des fehlerhaften Moduls: GFWLClient.exe2
Berichtskennung: GFWLClient.exe3
Vollständiger Name des fehlerhaften Pakets: GFWLClient.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: GFWLClient.exe5
System errors:
=============
Error: (11/02/2014 03:45:24 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "NVIDIA Network Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (11/02/2014 03:44:22 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden.
Modulpfad: C:\Windows\system32\Rtlihvs.dll
Fehlercode: 126
Error: (11/02/2014 03:40:32 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden.
Modulpfad: C:\Windows\system32\Rtlihvs.dll
Fehlercode: 126
Error: (11/02/2014 03:25:41 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden.
Modulpfad: C:\Windows\system32\Rtlihvs.dll
Fehlercode: 126
Error: (11/02/2014 00:29:18 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden.
Modulpfad: C:\Windows\system32\Rtlihvs.dll
Fehlercode: 126
Error: (11/02/2014 01:51:20 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden.
Modulpfad: C:\Windows\system32\Rtlihvs.dll
Fehlercode: 126
Error: (11/01/2014 05:50:12 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden.
Modulpfad: C:\Windows\system32\Rtlihvs.dll
Fehlercode: 126
Error: (11/01/2014 05:48:16 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "AVG Designerweiterung" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1083
Error: (11/01/2014 00:50:29 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden.
Modulpfad: C:\Windows\system32\Rtlihvs.dll
Fehlercode: 126
Error: (10/31/2014 09:14:27 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: NT-AUTORITÄT)
Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden.
Modulpfad: C:\Windows\system32\Rtlihvs.dll
Fehlercode: 126
Microsoft Office Sessions:
=========================
Error: (11/02/2014 03:52:10 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: CLEMENS-PC)
Description: winstore_1.0.0.0_neutral_neutral_cw5n1h2txyewy
Error: (11/02/2014 03:52:11 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: WWAHost.exe6.2.9200.16420fec01cff6ac824815dd4294967295C:\Windows\System32\WWAHost.exed2d21e49-629f-11e4-bf8d-60a44c3287bawinstore_1.0.0.0_neutral_neutral_cw5n1h2txyewyWindows.Store
Error: (11/02/2014 03:48:02 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2486) (User: CLEMENS-PC)
Description: winstore_cw5n1h2txyewy!Windows.Store
Error: (10/30/2014 10:04:52 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: EFLC.exe1.1.0.04b87a71eDSOUND.dll6.2.9200.1704653b485c4c000014200078c9e6401cff48521a672f0C:\Program Files (x86)\Rockstar Games\EFLC\EFLC.exeDSOUND.dll63c2742f-6078-11e4-bf85-60a44c3287ba
Error: (10/30/2014 10:04:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: EFLC.exe1.1.0.04b87a71eKERNELBASE.dll6.2.9200.16864531d2be60eedfade00010f226401cff48521a672f0C:\Program Files (x86)\Rockstar Games\EFLC\EFLC.exeC:\Windows\SYSTEM32\KERNELBASE.dll5fbe3dfe-6078-11e4-bf85-60a44c3287ba
Error: (10/30/2014 03:39:54 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: ts3client_win64.exe3.0.16.0e7401cff44f515102a73C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe9a9f021c-6042-11e4-bf84-60a44c3287ba
Error: (10/30/2014 03:33:09 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: ts3client_win64.exe3.0.16.0f7001cff44e5cc77f992C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exea871210c-6041-11e4-bf83-60a44c3287ba
Error: (10/27/2014 10:00:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: GFWLClient.exe3.5.67.052178fb2unknown0.0.0.000000000c0000005059cbfd513ec01cff227ae4dba3cC:\Program Files (x86)\Microsoft Games for Windows - LIVE\Client\GFWLClient.exeunknown4c96a8e9-5e1c-11e4-bf7f-60a44c3287ba
Error: (10/27/2014 10:00:37 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: GFWLClient.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet.
Ausnahmeinformationen: System.NullReferenceException
Stapel:
bei Microsoft.GamesForWindows.LiveClient.Messaging.CommandPipe.IsDownloadAndInstallationQueueDrained()
bei Microsoft.GamesForWindows.LiveClient.Messaging.CommandPipe.Shutdown()
bei Microsoft.GamesForWindows.LiveClient.Messaging.CommandPipe.ListenerThread()
bei System.Threading.ThreadHelper.ThreadStart_Context(System.Object)
bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
bei System.Threading.ThreadHelper.ThreadStart()
Error: (10/26/2014 11:58:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: GFWLClient.exe3.5.67.052178fb2unknown0.0.0.000000000c00000050581a97d6fc01cff16827a863d0C:\Program Files (x86)\Microsoft Games for Windows - LIVE\Client\GFWLClient.exeunknown9e248af0-5d63-11e4-bf7e-60a44c3287ba
CodeIntegrity Errors:
===================================
Date: 2014-09-14 12:39:53.357
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2014-07-22 01:09:17.420
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Clemens\AppData\Local\Temp\EverestDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2014-07-22 01:09:17.264
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64 because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2014-05-18 18:01:37.838
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Clemens\AppData\Local\Temp\EverestDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2014-05-18 18:01:37.784
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64 because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i3-3220 CPU @ 3.30GHz
Percentage of memory in use: 17%
Total physical RAM: 12224.28 MB
Available physical RAM: 10035.02 MB
Total Pagefile: 13952.28 MB
Available Pagefile: 11074.14 MB
Total Virtual: 8192 MB
Available Virtual: 8191.77 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:931.51 GB) (Free:694.52 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (EFLC_DISC1) (CDROM) (Total:7.85 GB) (Free:0 GB) UDF
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 2DF6D47D)
Partition 1: (Active) - (Size=931.5 GB) - (Type=07 NTFS)
==================== End Of Log ============================ |