Kaspersky Rescue Disc 10 Scan Code:
Untersuchung von Objekten: wurde abgeschlossen vor weniger als einer Minute (Ereignis: 61, Objekte: 1053751, Zeit: 01:39:47)
19.03.15 00:43 Aufgabe wurde abgeschlossen
19.03.15 00:43 Nicht desinfizierte Objekte: HEUR:Trojan.Win32.Generic D:/Sicherung alter PC/E/Worms Armageddon/DXMfc.dll Vom Benutzer übersprungen
19.03.15 00:43 Gefunden: HEUR:Trojan.Win32.Generic D:/Sicherung alter PC/E/Worms Armageddon/DXMfc.dll
19.03.15 00:43 Nicht desinfizierte Objekte: HEUR:Trojan.Win32.Generic D:/Sicherung alter PC/E/Worms Armageddon/DXMfc.backup.dll Vom Benutzer übersprungen
19.03.15 00:43 Gefunden: HEUR:Trojan.Win32.Generic D:/Sicherung alter PC/E/Worms Armageddon/DXMfc.backup.dll
19.03.15 00:42 Nicht desinfizierte Objekte: Trojan-Downloader.Win32.Genome.pgwt C:/Program Files (x86)/Panda Security/Panda Security Protection/LostandFound/components2_1 Vom Benutzer übersprungen
19.03.15 00:42 Gefunden: Trojan-Downloader.Win32.Genome.pgwt C:/Program Files (x86)/Panda Security/Panda Security Protection/LostandFound/components2_1
19.03.15 00:42 Nicht desinfizierte Objekte: Trojan-Dropper.MSIL.Agent.auvh C:/Program Files (x86)/Panda Security/Panda Security Protection/LostandFound/components2 Vom Benutzer übersprungen
19.03.15 00:42 Gefunden: Trojan-Dropper.MSIL.Agent.auvh C:/Program Files (x86)/Panda Security/Panda Security Protection/LostandFound/components2
19.03.15 00:42 Gelöscht: Trojan.Win32.Fsysna.bdnd /mnt/MountedDevices/PD-D2AB1056-0000000006500000/Users/Phillip/AppData/Roaming/Windows Services/services.exe
19.03.15 00:42 Gefunden: Trojan.Win32.Fsysna.bdnd /mnt/MountedDevices/PD-D2AB1056-0000000006500000/Users/Phillip/AppData/Roaming/Windows Services/services.exe
19.03.15 00:42 Gelöscht: Trojan.MSIL.Disfa.boi /mnt/MountedDevices/PD-D2AB1056-0000000006500000/Users/Phillip/AppData/Local/Temp/explorer.exe
19.03.15 00:41 Gefunden: Trojan.MSIL.Disfa.boi /mnt/MountedDevices/PD-D2AB1056-0000000006500000/Users/Phillip/AppData/Local/Temp/explorer.exe
19.03.15 00:41 Nicht desinfizierte Objekte: Trojan.MSIL.Disfa.boi C:/Users/Phillip/AppData/Local/Temp/explorer.exe Zurückgestellt
19.03.15 00:41 Gefunden: Trojan.MSIL.Disfa.boi C:/Users/Phillip/AppData/Local/Temp/explorer.exe
19.03.15 00:41 Nicht desinfizierte Objekte: Trojan.Win32.Fsysna.bdnd C:/Users/Phillip/AppData/Roaming/Windows Services/services.exe Zurückgestellt
19.03.15 00:40 Gefunden: Trojan.Win32.Fsysna.bdnd C:/Users/Phillip/AppData/Roaming/Windows Services/services.exe
19.03.15 00:29 Verarbeitungsfehler D:/GameZ/LOTROEU_Enedwaith_DE_Installer/lotrosetup.exe Lesefehler
18.03.15 23:56 Nicht desinfizierte Objekte: HEUR:Trojan.Win32.Generic D:/Sicherung alter PC/E/Worms Armageddon/DXMfc.backup.dll Zurückgestellt
18.03.15 23:56 Nicht desinfizierte Objekte: HEUR:Trojan.Win32.Generic D:/Sicherung alter PC/E/Worms Armageddon/DXMfc.dll Zurückgestellt
18.03.15 23:56 Gefunden: HEUR:Trojan.Win32.Generic D:/Sicherung alter PC/E/Worms Armageddon/DXMfc.backup.dll
18.03.15 23:56 Gefunden: HEUR:Trojan.Win32.Generic D:/Sicherung alter PC/E/Worms Armageddon/DXMfc.dll
18.03.15 23:45 Nicht desinfizierte Objekte: Trojan.MSIL.Disfa.boi /mnt/MountedDevices/PD-D2AB1056-0000000006500000/Users/Phillip/AppData/Local/Temp/explorer.exe Zurückgestellt
18.03.15 23:45 Gefunden: Trojan.MSIL.Disfa.boi /mnt/MountedDevices/PD-D2AB1056-0000000006500000/Users/Phillip/AppData/Local/Temp/explorer.exe
18.03.15 23:44 Nicht desinfizierte Objekte: Trojan.Win32.Fsysna.bdnd /mnt/MountedDevices/PD-D2AB1056-0000000006500000/Users/Phillip/AppData/Roaming/Windows Services/services.exe Zurückgestellt
18.03.15 23:44 Gefunden: Trojan.Win32.Fsysna.bdnd /mnt/MountedDevices/PD-D2AB1056-0000000006500000/Users/Phillip/AppData/Roaming/Windows Services/services.exe
18.03.15 23:42 Nicht desinfizierte Objekte: Trojan.MSIL.Disfa.boi /mnt/MountedDevices/PD-D2AB1056-0000000006500000/Users/Phillip/AppData/Local/Temp/explorer.exe Zurückgestellt
18.03.15 23:42 Gefunden: Trojan.MSIL.Disfa.boi /mnt/MountedDevices/PD-D2AB1056-0000000006500000/Users/Phillip/AppData/Local/Temp/explorer.exe
18.03.15 23:41 Nicht desinfizierte Objekte: Trojan.Win32.Fsysna.bdnd /mnt/MountedDevices/PD-D2AB1056-0000000006500000/Users/Phillip/AppData/Roaming/Windows Services/services.exe Zurückgestellt
18.03.15 23:41 Gefunden: Trojan.Win32.Fsysna.bdnd /mnt/MountedDevices/PD-D2AB1056-0000000006500000/Users/Phillip/AppData/Roaming/Windows Services/services.exe
18.03.15 23:20 Nicht desinfizierte Objekte: Trojan.MSIL.Disfa.boi /mnt/MountedDevices/PD-D2AB1056-0000000006500000/Users/Phillip/AppData/Local/Temp/explorer.exe Zurückgestellt
18.03.15 23:20 Gefunden: Trojan.MSIL.Disfa.boi /mnt/MountedDevices/PD-D2AB1056-0000000006500000/Users/Phillip/AppData/Local/Temp/explorer.exe
18.03.15 23:18 Nicht desinfizierte Objekte: Trojan.Win32.Fsysna.bdnd C:/Users/Phillip/AppData/Roaming/Windows Services/services.exe Zurückgestellt
18.03.15 23:18 Gefunden: Trojan.Win32.Fsysna.bdnd C:/Users/Phillip/AppData/Roaming/Windows Services/services.exe
18.03.15 23:17 Nicht desinfizierte Objekte: Trojan.MSIL.Disfa.boi C:/Users/Phillip/AppData/Local/Temp/explorer.exe Zurückgestellt
18.03.15 23:17 Gefunden: Trojan.MSIL.Disfa.boi C:/Users/Phillip/AppData/Local/Temp/explorer.exe
18.03.15 23:15 Nicht desinfizierte Objekte: Trojan.Win32.Fsysna.bdnd /mnt/MountedDevices/PD-D2AB1056-0000000006500000/Users/Phillip/AppData/Roaming/Windows Services/services.exe Zurückgestellt
18.03.15 23:15 Gefunden: Trojan.Win32.Fsysna.bdnd /mnt/MountedDevices/PD-D2AB1056-0000000006500000/Users/Phillip/AppData/Roaming/Windows Services/services.exe
18.03.15 23:11 Nicht desinfizierte Objekte: Trojan-Downloader.Win32.Genome.pgwt C:/Program Files (x86)/Panda Security/Panda Security Protection/LostandFound/components2_1 Zurückgestellt
18.03.15 23:11 Gefunden: Trojan-Downloader.Win32.Genome.pgwt C:/Program Files (x86)/Panda Security/Panda Security Protection/LostandFound/components2_1
18.03.15 23:11 Nicht desinfizierte Objekte: Trojan-Dropper.MSIL.Agent.auvh C:/Program Files (x86)/Panda Security/Panda Security Protection/LostandFound/components2 Zurückgestellt
18.03.15 23:11 Gefunden: Trojan-Dropper.MSIL.Agent.auvh C:/Program Files (x86)/Panda Security/Panda Security Protection/LostandFound/components2
18.03.15 23:09 Nicht desinfizierte Objekte: Trojan.MSIL.Disfa.boi /mnt/MountedDevices/PD-D2AB1056-0000000006500000/Users/Phillip/AppData/Local/Temp/explorer.exe Zurückgestellt
18.03.15 23:09 Gefunden: Trojan.MSIL.Disfa.boi /mnt/MountedDevices/PD-D2AB1056-0000000006500000/Users/Phillip/AppData/Local/Temp/explorer.exe
18.03.15 23:08 Nicht desinfizierte Objekte: Trojan.Win32.Fsysna.bdnd /mnt/MountedDevices/PD-D2AB1056-0000000006500000/Users/Phillip/AppData/Roaming/Windows Services/services.exe Zurückgestellt
18.03.15 23:08 Gefunden: Trojan.Win32.Fsysna.bdnd /mnt/MountedDevices/PD-D2AB1056-0000000006500000/Users/Phillip/AppData/Roaming/Windows Services/services.exe
18.03.15 23:06 Nicht desinfizierte Objekte: Trojan.MSIL.Disfa.boi /mnt/MountedDevices/PD-D2AB1056-0000000006500000/Users/Phillip/AppData/Local/Temp/explorer.exe Zurückgestellt
18.03.15 23:06 Gefunden: Trojan.MSIL.Disfa.boi /mnt/MountedDevices/PD-D2AB1056-0000000006500000/Users/Phillip/AppData/Local/Temp/explorer.exe
18.03.15 23:05 Nicht desinfizierte Objekte: Trojan.Win32.Fsysna.bdnd /mnt/MountedDevices/PD-D2AB1056-0000000006500000/Users/Phillip/AppData/Roaming/Windows Services/services.exe Zurückgestellt
18.03.15 23:05 Gefunden: Trojan.Win32.Fsysna.bdnd /mnt/MountedDevices/PD-D2AB1056-0000000006500000/Users/Phillip/AppData/Roaming/Windows Services/services.exe
18.03.15 23:04 Aufgabe wurde gestartet FRST
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
Ran by Phillip (administrator) on PHILLIP-PC on 20-03-2015 13:23:42
Running from C:\Users\Phillip\Desktop
Loaded Profiles: Phillip (Available profiles: Phillip)
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\BCMWLTRY.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Kingsoft Corporation) C:\Program Files (x86)\cmcm\Clean Master\cmcore.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe
() C:\Program Files\ASUS Xonar U7 Audio\CPL\ASUSXonarU7_x64.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [12697368 2014-10-14] (Logitech Inc.)
HKLM\...\Run: [GamecomSound] => C:\Program Files\ASUS Xonar U7 Audio\CPL\ASUSXonarU7_x64.exe [2453504 2013-08-06] ()
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-21] (Intel Corporation)
HKLM-x32\...\Run: [Dolby Home Theater v4] => C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [508656 2012-08-31] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [PSUAMain] => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe [37624 2014-10-16] (Panda Security, S.L.)
HKLM\...\Winlogon: [Userinit] C:\Windows\SysWOW64\userinit.exe,
HKU\S-1-5-21-3639536685-2187574041-2537157961-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2874048 2015-02-19] (Valve Corporation)
HKU\S-1-5-21-3639536685-2187574041-2537157961-1000\...\Run: [Windows Services] => C:\Users\Phillip\AppData\Roaming\Windows Services\services.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2013-05-20] (Microsoft Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKU\S-1-5-21-3639536685-2187574041-2537157961-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll [2014-10-18] (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-10-18] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Winsock: Catalog9 01 C:\Windows\system32\abengine.dll File Not found ()
Winsock: Catalog9 02 C:\Windows\system32\abengine.dll File Not found ()
Winsock: Catalog9 03 C:\Windows\system32\abengine.dll File Not found ()
Winsock: Catalog9 04 C:\Windows\system32\abengine.dll File Not found ()
Winsock: Catalog9 12 C:\Windows\system32\abengine.dll File Not found ()
Winsock: Catalog9-x64 01 C:\Windows\system32\abengine64.dll File Not found ()
Winsock: Catalog9-x64 02 C:\Windows\system32\abengine64.dll File Not found ()
Winsock: Catalog9-x64 03 C:\Windows\system32\abengine64.dll File Not found ()
Winsock: Catalog9-x64 04 C:\Windows\system32\abengine64.dll File Not found ()
Winsock: Catalog9-x64 12 C:\Windows\system32\abengine64.dll File Not found ()
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Phillip\AppData\Roaming\Mozilla\Firefox\Profiles\raf60uc3.default
FF Homepage: hxxp://www.t-online.de/
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll [2015-03-16] ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-05-26] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelogx64.dll [2015-01-13] (EA Digital Illusions CE AB)
FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2014-10-18] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-10-18] (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2014-05-26] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @videolan.org/vlc,version=2.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.7 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-16] ()
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-05-26] (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @esn/esnlaunch,version=2.1.4 -> C:\Program Files (x86)\Battlelog Web Plugins\2.1.4\npesnlaunch.dll No File
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll No File
FF Plugin-x32: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelog.dll [2015-01-13] (EA Digital Illusions CE AB)
FF Plugin-x32: @live.heroesandgenerals.com/npretox -> D:\Spiele\Heroes & Generals\live\npretox-1.0.6.1\npretoxlive-1.0.6.1.dll [2014-11-28] (Reto-Moto ApS)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-05-26] (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-3639536685-2187574041-2537157961-1000: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2014-05-26] (Tracker Software Products (Canada) Ltd.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll [2014-05-26] (Tracker Software Products (Canada) Ltd.)
FF Extension: ProxTube - C:\Users\Phillip\AppData\Roaming\Mozilla\Firefox\Profiles\raf60uc3.default\Extensions\ich@maltegoetz.de.xpi [2014-09-11]
FF Extension: NoSquint - C:\Users\Phillip\AppData\Roaming\Mozilla\Firefox\Profiles\raf60uc3.default\Extensions\nosquint@urandom.ca.xpi [2013-12-14]
FF Extension: Session Manager - C:\Users\Phillip\AppData\Roaming\Mozilla\Firefox\Profiles\raf60uc3.default\Extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}.xpi [2014-06-04]
FF Extension: {61ff6d5b-b16e-4d4f-867d-a53a3edebcdc} - C:\Users\Phillip\AppData\Roaming\Mozilla\Firefox\Profiles\raf60uc3.default\Extensions\{61ff6d5b-b16e-4d4f-867d-a53a3edebcdc}.xpi [2015-01-12]
FF Extension: YouTube High Definition - C:\Users\Phillip\AppData\Roaming\Mozilla\Firefox\Profiles\raf60uc3.default\Extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi [2014-08-05]
FF Extension: Adblock Plus - C:\Users\Phillip\AppData\Roaming\Mozilla\Firefox\Profiles\raf60uc3.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-12-14]
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\Phillip\AppData\Local\Google\Chrome\User Data\Default
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [814464 2015-02-21] ()
R2 cmcore; c:\program files (x86)\cmcm\Clean Master\cmcore.exe [315240 2014-11-02] (Kingsoft Corporation)
R2 NanoServiceMain; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe [142072 2014-10-13] (Panda Security, S.L.)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1910640 2015-03-16] (Electronic Arts)
R2 PandaAgent; C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe [66808 2014-10-09] (Panda Security, S.L.)
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2014-12-02] ()
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2015-02-27] ()
R2 PSUAService; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe [38136 2014-10-16] (Panda Security, S.L.)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 wltrysvc; C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\bcmwltry.exe [5821952 2013-05-20] (Broadcom Corporation) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 ASUSU7; C:\Windows\System32\DRIVERS\ASUSU7.SYS [406016 2013-08-01] (C-Media Inc.)
S3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [134696 2011-11-03] (Broadcom Corporation.)
S3 BTWDPAN; C:\Windows\System32\DRIVERS\btwdpan.sys [89640 2011-05-21] (Broadcom Corporation.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-10-18] (Disc Soft Ltd)
R3 hidusbf; C:\Windows\System32\DRIVERS\hidusbf.sys [7808 2012-08-07] (SweetLow) [File not signed]
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [26528 2014-12-12] (REALiX(tm))
R3 ksapi64; C:\Windows\system32\drivers\ksapi64.sys [56680 2014-11-02] (Kingsoft Corporation)
R3 LGPBTDD; C:\Windows\System32\Drivers\LGPBTDD.sys [30728 2009-07-01] (Logitech Inc.)
R1 NNSALPC; C:\Windows\System32\DRIVERS\NNSAlpc.sys [96800 2014-06-04] (Panda Security, S.L.)
R1 NNSHTTP; C:\Windows\System32\DRIVERS\NNSHttp.sys [162336 2014-06-18] (Panda Security, S.L.)
R1 NNSHTTPS; C:\Windows\System32\DRIVERS\NNSHttps.sys [112160 2014-06-04] (Panda Security, S.L.)
R1 NNSIDS; C:\Windows\System32\DRIVERS\NNSIds.sys [115232 2014-06-04] (Panda Security, S.L.)
R1 NNSPICC; C:\Windows\System32\DRIVERS\NNSPicc.sys [95776 2014-06-04] (Panda Security, S.L.)
R1 NNSPIHSW; C:\Windows\System32\DRIVERS\NNSPihsw.sys [70176 2014-06-04] (Panda Security, S.L.)
R1 NNSPOP3; C:\Windows\System32\DRIVERS\NNSPop3.sys [125984 2014-06-04] (Panda Security, S.L.)
R1 NNSPROT; C:\Windows\System32\DRIVERS\NNSProt.sys [306720 2014-06-04] (Panda Security, S.L.)
R1 NNSPRV; C:\Windows\System32\DRIVERS\NNSPrv.sys [169504 2014-06-04] (Panda Security, S.L.)
R1 NNSSMTP; C:\Windows\System32\DRIVERS\NNSSmtp.sys [115744 2014-06-04] (Panda Security, S.L.)
R1 NNSSTRM; C:\Windows\System32\DRIVERS\NNSStrm.sys [261152 2014-06-04] (Panda Security, S.L.)
R1 NNSTLSC; C:\Windows\System32\DRIVERS\NNSTlsc.sys [109088 2014-06-04] (Panda Security, S.L.)
R2 PSINAflt; C:\Windows\System32\DRIVERS\PSINAflt.sys [163088 2014-10-13] (Panda Security, S.L.)
R2 PSINFile; C:\Windows\System32\DRIVERS\PSINFile.sys [121616 2014-10-13] (Panda Security, S.L.)
R1 PSINKNC; C:\Windows\System32\DRIVERS\psinknc.sys [195616 2014-07-24] (Panda Security, S.L.)
R2 PSINProc; C:\Windows\System32\DRIVERS\PSINProc.sys [122400 2014-07-24] (Panda Security, S.L.)
R2 PSINProt; C:\Windows\System32\DRIVERS\PSINProt.sys [132128 2014-07-24] (Panda Security, S.L.)
R2 PSINReg; C:\Windows\System32\DRIVERS\PSINReg.sys [107792 2014-10-13] (Panda Security, S.L.)
R3 PSKMAD; C:\Windows\System32\DRIVERS\PSKMAD.sys [60400 2014-03-25] (Panda Security, S.L.)
S3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [13368 2013-03-11] ()
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2012-12-13] (Apple, Inc.) [File not signed]
S3 ALSysIO; \??\C:\Users\Phillip\AppData\Local\Temp\ALSysIO64.sys [X]
S3 btwampfl; \??\C:\Windows\system32\drivers\btwampfl.sys [X]
S3 btwaudio; system32\drivers\btwaudio.sys [X]
S3 btwavdt; system32\DRIVERS\btwavdt.sys [X]
S3 btwl2cap; system32\DRIVERS\btwl2cap.sys [X]
S3 btwrchid; system32\DRIVERS\btwrchid.sys [X]
S3 IntcAzAudAddService; system32\drivers\RTKVHD64.sys [X]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
S4 NVHDA; system32\drivers\nvhda64v.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 taphss6; system32\DRIVERS\taphss6.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 WinRing0_1_2_0; \??\C:\Program Files (x86)\Corsair\Corsair Link\CorsairLINK_HardwareMonitor.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-20 13:23 - 2015-03-20 13:23 - 00016950 _____ () C:\Users\Phillip\Desktop\FRST.txt
2015-03-20 13:23 - 2015-03-20 13:23 - 00000000 ____D () C:\FRST
2015-03-20 13:23 - 2015-03-20 00:41 - 02095616 _____ (Farbar) C:\Users\Phillip\Desktop\FRST64.exe
2015-03-20 13:19 - 2015-03-20 13:19 - 00000000 ____D () C:\ProgramData\Kingsoft
2015-03-18 22:27 - 2015-03-18 22:27 - 00003570 _____ () C:\Windows\System32\Tasks\PNPGLZVDA
2015-03-18 22:27 - 2015-03-18 22:27 - 00003148 _____ () C:\Windows\System32\Tasks\SidebarExecute
2015-03-18 22:27 - 2015-03-18 22:27 - 00003090 _____ () C:\Windows\System32\Tasks\trik3004
2015-03-18 21:46 - 2015-03-18 21:46 - 00000000 ____D () C:\Program Files\Common Files\Lavasoft
2015-03-16 15:12 - 2015-03-20 13:15 - 00001411 _____ () C:\Windows\setupact.log
2015-03-16 15:12 - 2015-03-16 15:12 - 00000352 _____ () C:\Windows\PFRO.log
2015-03-16 15:12 - 2015-03-16 15:12 - 00000000 _____ () C:\Windows\setuperr.log
2015-03-16 09:59 - 2015-03-16 09:59 - 00000000 ____D () C:\Users\Phillip\AppData\Roaming\timgquxs
2015-03-16 09:55 - 2014-03-11 16:48 - 00040480 _____ (Panda Security, S.L.) C:\Windows\system32\Drivers\PsBoot.sys
2015-03-16 09:27 - 2015-03-19 01:42 - 00000000 _RSHD () C:\Users\Phillip\AppData\Roaming\Windows Services
2015-03-16 00:54 - 2015-03-16 00:54 - 00000000 ____D () C:\Users\Phillip\AppData\Roaming\NVIDIA
2015-03-16 00:43 - 2015-03-16 00:43 - 00000218 _____ () C:\Users\Phillip\Desktop\Counter-Strike.url
2015-03-10 18:28 - 2015-03-10 18:28 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-03-10 18:27 - 2015-03-10 18:27 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation
2015-03-10 18:27 - 2015-02-05 22:01 - 32106640 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 25460880 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 24768144 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 20466496 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 18575880 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 17253848 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 16017040 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 14119744 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 13294528 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 13208200 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 10773704 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 10713256 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 10284872 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2015-03-10 18:27 - 2015-02-05 22:01 - 03610768 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 03299512 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 03247248 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 02902784 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 01895240 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6434752.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 01557648 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6434752.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 00995248 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 00969872 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 00943760 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 00929936 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 00908104 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 00877816 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 00496272 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 00399504 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 00390472 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 00353224 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 00345744 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 00305136 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 00177624 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 00164752 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 00074056 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 00060560 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2015-03-10 18:27 - 2015-02-05 22:01 - 00027441 _____ () C:\Windows\system32\nvinfo.pb
2015-03-10 18:27 - 2015-02-05 20:07 - 06861128 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2015-03-10 18:27 - 2015-02-05 20:07 - 03517584 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2015-03-10 18:27 - 2015-02-05 20:07 - 02558792 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2015-03-10 18:27 - 2015-02-05 20:07 - 00935056 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2015-03-10 18:27 - 2015-02-05 20:07 - 00062792 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2015-03-10 18:27 - 2015-02-05 20:06 - 00385168 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2015-03-10 18:27 - 2015-02-05 13:50 - 04236870 _____ () C:\Windows\system32\nvcoproc.bin
2015-03-06 15:49 - 2015-03-16 14:55 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-02-28 20:31 - 2015-02-28 20:31 - 00001592 _____ () C:\Users\Phillip\AppData\Local\recently-used.xbel
2015-02-28 15:33 - 2015-02-28 15:54 - 00000000 ____D () C:\Users\Phillip\AppData\Local\UmmyVideoDownloader
2015-02-23 13:04 - 2015-02-23 13:04 - 00000000 ____D () C:\Program Files (x86)\Microsoft Chart Controls
2015-02-21 15:02 - 2015-02-21 15:02 - 00000000 ____D () C:\Users\Phillip\AppData\Local\Steam
2015-02-18 13:44 - 2015-03-20 13:13 - 00289015 _____ () C:\Windows\WindowsUpdate.log
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-20 13:18 - 2009-07-14 05:45 - 00020992 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-03-20 13:18 - 2009-07-14 05:45 - 00020992 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-03-20 13:16 - 2009-07-14 18:58 - 00674610 _____ () C:\Windows\system32\perfh007.dat
2015-03-20 13:16 - 2009-07-14 18:58 - 00139750 _____ () C:\Windows\system32\perfc007.dat
2015-03-20 13:16 - 2009-07-14 06:13 - 01556210 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-03-20 13:15 - 2015-02-09 15:07 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-03-20 13:11 - 2009-07-14 06:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-03-20 13:11 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-03-19 22:29 - 2013-07-09 10:50 - 00000029 _____ () C:\Users\Phillip\AppData\Roaming\Network Meter_Usage.ini
2015-03-19 22:27 - 2013-11-19 20:40 - 00000000 ____D () C:\Users\Phillip\AppData\Roaming\TS3Client
2015-03-18 22:39 - 2013-05-24 10:31 - 00000000 ____D () C:\Users\Phillip\AppData\Roaming\vlc
2015-03-18 22:24 - 2013-05-19 10:12 - 00000000 ____D () C:\Program Files (x86)\MSI Afterburner
2015-03-18 21:04 - 2014-03-23 11:35 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-03-18 18:13 - 2013-05-19 12:36 - 00003146 _____ () C:\Windows\System32\Tasks\FRAPS
2015-03-16 16:05 - 2013-12-30 00:35 - 00003030 _____ () C:\Windows\System32\Tasks\MSIAfterburner
2015-03-16 09:23 - 2013-06-02 12:55 - 00000021 _____ () C:\Users\Phillip\AppData\Roaming\config_data.dat
2015-03-16 08:34 - 2014-12-21 15:48 - 00000000 ____D () C:\Users\Phillip\AppData\Roaming\Corsair
2015-03-16 02:15 - 2013-05-19 10:17 - 00000000 ____D () C:\ProgramData\Origin
2015-03-16 02:15 - 2013-05-19 10:17 - 00000000 ____D () C:\Program Files (x86)\Origin
2015-03-16 01:50 - 2014-03-23 11:35 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-03-16 01:50 - 2013-05-17 20:05 - 00778928 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-03-16 01:50 - 2013-05-17 20:05 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-03-16 01:37 - 2014-08-14 16:08 - 00000596 __RSH () C:\ProgramData\ntuser.pol
2015-03-10 18:27 - 2013-07-11 13:07 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2015-03-10 18:27 - 2013-05-17 20:35 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2015-03-10 18:27 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Help
2015-03-08 00:32 - 2014-03-14 17:39 - 00000000 ____D () C:\Users\Phillip\AppData\Roaming\Skype
2015-03-06 14:36 - 2014-02-23 14:07 - 00000000 ____D () C:\Users\Phillip\AppData\Local\DayZ
2015-03-02 15:47 - 2013-05-19 20:25 - 00280856 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2015-03-02 15:47 - 2013-05-19 20:25 - 00280856 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2015-03-01 21:39 - 2013-05-19 13:36 - 00000000 ____D () C:\Program Files\CCleaner
2015-02-28 20:31 - 2015-01-16 20:17 - 00000000 ____D () C:\Users\Phillip\.gimp-2.8
2015-02-28 20:30 - 2015-01-16 21:10 - 00000000 ____D () C:\Users\Phillip\AppData\Local\gtk-2.0
2015-02-28 15:34 - 2013-06-02 16:07 - 00000000 ____D () C:\Users\Phillip\AppData\Roaming\DVDVideoSoft
2015-02-27 22:45 - 2013-05-19 20:25 - 00280792 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2015-02-27 22:45 - 2013-05-19 20:24 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2015-02-22 17:11 - 2014-06-30 18:57 - 00000000 ____D () C:\Users\Phillip\AppData\Local\Arma 3
2015-02-22 17:10 - 2013-10-04 20:45 - 00000000 ____D () C:\ProgramData\Package Cache
2015-02-18 13:33 - 2013-05-17 20:09 - 00007626 _____ () C:\Users\Phillip\AppData\Local\resmon.resmoncfg
==================== Files in the root of some directories =======
2014-09-09 11:00 - 2015-01-11 13:03 - 0000302 _____ () C:\Users\Phillip\AppData\Roaming\BreakingPoint_Login.ini
2014-09-09 11:02 - 2015-01-11 13:12 - 0001408 _____ () C:\Users\Phillip\AppData\Roaming\BreakingPoint_Options.ini
2014-11-02 15:18 - 2014-11-02 16:22 - 0000127 _____ () C:\Users\Phillip\AppData\Roaming\Camdata.ini
2014-11-02 15:18 - 2014-11-02 16:22 - 0000408 _____ () C:\Users\Phillip\AppData\Roaming\CamLayout.ini
2014-11-02 15:18 - 2014-11-02 16:22 - 0000408 _____ () C:\Users\Phillip\AppData\Roaming\CamShapes.ini
2014-11-02 15:18 - 2014-11-02 16:22 - 0004574 _____ () C:\Users\Phillip\AppData\Roaming\CamStudio.cfg
2013-06-02 12:55 - 2015-03-16 09:23 - 0000021 _____ () C:\Users\Phillip\AppData\Roaming\config_data.dat
2014-01-31 08:04 - 2014-10-20 11:52 - 0001154 _____ () C:\Users\Phillip\AppData\Roaming\Network Meter_Settings.ini
2013-07-09 10:50 - 2015-03-19 22:29 - 0000029 _____ () C:\Users\Phillip\AppData\Roaming\Network Meter_Usage.ini
2014-11-02 15:16 - 2014-11-02 16:16 - 0000096 _____ () C:\Users\Phillip\AppData\Roaming\version2.xml
2015-02-28 20:31 - 2015-02-28 20:31 - 0001592 _____ () C:\Users\Phillip\AppData\Local\recently-used.xbel
2013-05-17 20:09 - 2015-02-18 13:33 - 0007626 _____ () C:\Users\Phillip\AppData\Local\resmon.resmoncfg
2014-10-18 19:26 - 2014-10-18 19:26 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
testsigning: ==> testsigning is on. Check for possible unsigned rootkit driver <===== ATTENTION!
LastRegBack: 2015-03-18 19:38
==================== End Of Log ============================ --- --- ---
Addition Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-03-2015
Ran by Phillip at 2015-03-20 13:23:56
Running from C:\Users\Phillip\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Panda Free Antivirus (Enabled - Up to date) {3456760B-FDAA-FFFD-06C2-7BB528D2066C}
AS: Panda Free Antivirus (Enabled - Up to date) {8F3797EF-DB90-F073-3C72-40C753554CD1}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Panda Firewall (Disabled) {0C6DF72E-B7C5-FEA5-2D9D-D280D6014117}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.134 - Adobe Systems Incorporated)
Arma 3 (HKLM-x32\...\Steam App 107410) (Version: - Bohemia Interactive)
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.14.3.0 - Asmedia Technology)
ASUS Xonar U7 Audio (HKLM-x32\...\{71B53BA8-4BE3-49AF-BC3E-07F39206632A}) (Version: - ASUSTeK Computer Inc.)
Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.6.0.0 - Electronic Arts)
Battlefield 4™ (HKLM-x32\...\{ABADE36E-EC37-413B-8179-B432AD3FACE7}) (Version: 1.4.2.25648 - Electronic Arts)
Battlefield: Bad Company™ 2 (HKLM-x32\...\{3AC8457C-0385-4BEA-A959-E095F05D6D67}) (Version: 1.0.0.0 - Electronic Arts)
Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.6.2 - EA Digital Illusions CE AB)
BeamNG.drive (HKU\S-1-5-21-3639536685-2187574041-2537157961-1000\...\BeamNG.drive) (Version: 0.3.1.0 - beamng.com)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Broadcom Wireless Utility (HKLM\...\Broadcom Wireless Utility) (Version: 5.100.82.97 - Broadcom Corporation)
CCleaner (HKLM\...\CCleaner) (Version: 5.03 - Piriform)
Cisco EAP-FAST Module (x32 Version: 2.2.14 - Cisco Systems, Inc.) Hidden
Cisco LEAP Module (x32 Version: 1.0.19 - Cisco Systems, Inc.) Hidden
Cisco PEAP Module (x32 Version: 1.1.6 - Cisco Systems, Inc.) Hidden
Clean Master (HKLM-x32\...\Clean Master) (Version: 1.0 - Cheetah Mobile)
Corsair Link (HKLM-x32\...\{658EFB3F-8606-4576-8FEC-B0CED48F1E68}) (Version: 2.4.4948 - Corsair)
Corsair Link(TM) USB Dongle (Driver Removal) (HKLM-x32\...\CMIUSB&1B1C&1C00) (Version: - Corsair Memory, Inc.)
Corsair Link(TM) USB Dongle (Driver Removal) (HKLM-x32\...\SIUSBXP&1B1C&1C00) (Version: - Corsair Memory, Inc.)
Counter-Strike (HKLM-x32\...\Steam App 10) (Version: - Valve)
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve)
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
DayZ (HKLM-x32\...\Steam App 221100) (Version: - Bohemia Interactive)
Dolby Home Theater v4 (HKLM-x32\...\{B26438B4-BF51-49C3-9567-7F14A5E40CB9}) (Version: 7.2.8000.17 - Dolby Laboratories Inc)
Driver Sweeper Version 3.2.0 (HKLM-x32\...\{5A67D2EA-FB70-4033-A6F3-606AD85B2015}_is1) (Version: 3.2.0 - Phyxion.net)
Fraps (remove only) (HKLM-x32\...\Fraps) (Version: - )
GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team)
Grand Theft Auto IV (HKLM-x32\...\Steam App 12210) (Version: - Rockstar North)
Grand Theft Auto IV (x32 Version: 1.0.0013.131 - Rockstar Games Inc.) Hidden
Grand Theft Auto: Episodes from Liberty City (HKLM-x32\...\Steam App 12220) (Version: - Rockstar North / Toronto)
Grand Theft Auto: Episodes from Liberty City (x32 Version: 1.0.0002.135 - Rockstar Games Inc.) Hidden
Heroes & Generals (HKLM-x32\...\Heroes & Generals) (Version: 1.0.6.1 - Reto-Moto)
HWiNFO64 Version 4.48 (HKLM\...\HWiNFO64_is1) (Version: 4.48 - Martin Malík - REALiX)
Intel(R) Network Connections Drivers (HKLM\...\PROSet) (Version: 16.1 - Intel)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.5.235 - Intel Corporation)
Java 8 Update 25 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418025F0}) (Version: 8.0.250 - Oracle Corporation)
Logitech Gaming Software 8.57 (HKLM\...\Logitech Gaming Software) (Version: 8.57.145 - Logitech Inc.)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Extended DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Chart Controls for Microsoft .NET Framework 3.5 (HKLM-x32\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.0.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE (HKLM-x32\...\{F97E3841-CA9D-4964-9D64-26066241D26F}) (Version: 3.3.24.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{42AA4CA8-DCD8-4308-BCAB-0B6D75856A9D}) (Version: 3.5.95.0 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Mozilla Firefox 36.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 36.0.1 (x86 de)) (Version: 36.0.1 - Mozilla)
MSI Afterburner 4.1.0 (HKLM-x32\...\Afterburner) (Version: 4.1.0 - MSI Co., LTD)
NetSpeedMonitor 2.5.4.0 x64 (HKLM\...\{88F41EE2-949B-4B52-933D-C7F8F67BC1D2}) (Version: 2.5.4.0 - Florian Gilles)
NVIDIA Grafiktreiber 347.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 347.52 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.14.0702 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation)
Origin (HKLM-x32\...\Origin) (Version: 9.1.15.109 - Electronic Arts, Inc.)
Panda Cloud Cleaner (HKLM-x32\...\{92B2B132-C7F0-43DC-921A-4493C04F78A4}_is1) (Version: 1.0.104 - Panda Security)
Panda Devices Agent (HKLM-x32\...\Panda Devices Agent) (Version: 1.03.04 - Panda Security)
Panda Devices Agent (x32 Version: 1.05.00 - Panda Security) Hidden
Panda Free Antivirus (HKLM-x32\...\Panda Universal Agent Endpoint) (Version: 15.00.04.0000 - Panda Security)
Panda Free Antivirus (Version: 7.23.00.0000 - Panda Security) Hidden
PDF24 Creator 6.9.2 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org)
PDF-Viewer (HKLM\...\{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: 2.5.308.0 - Tracker Software Products Ltd)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.992 - Even Balance, Inc.)
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Rising Storm/Red Orchestra 2 Multiplayer (HKLM-x32\...\Steam App 35450) (Version: - Tripwire Interactive)
RivaTuner Statistics Server 6.3.0 (HKLM-x32\...\RTSS) (Version: 6.3.0 - Unwinder)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version: - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version: - Microsoft) Hidden
Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.15 - TeamSpeak Systems GmbH)
UmmyVideoDownloader (HKLM-x32\...\{E028DBDA-EEE7-48A0-ADF7-D250589A02C5}_is1) (Version: 1.2.1.1 - )
Vegas Pro 12.0 (64-bit) (HKLM\...\{BE94768F-5232-11E3-BD78-F04DA23A5C58}) (Version: 12.0.770 - Sony)
Vegas Pro 13.0 (64-bit) (HKLM\...\{386F5740-091D-11E4-B13E-F04DA23A5C58}) (Version: 13.0.373 - Sony)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.0 - VideoLAN)
War Thunder Launcher 1.0.1.467 (HKLM-x32\...\{ed8deea4-29fa-3932-9612-e2122d8a62d9}}_is1) (Version: - Gaijin Entertainment)
WinRAR 4.20 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-3639536685-2187574041-2537157961-1000_Classes\CLSID\{07474513-7B58-45c7-B3E6-13A3669B1AFD}\InprocServer32 -> C:\Windows\SYSTEM32\mscoree.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3639536685-2187574041-2537157961-1000_Classes\CLSID\{25815CC0-43F4-3C75-8C3A-A139D9ADE740}\InprocServer32 -> C:\Windows\SYSTEM32\mscoree.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3639536685-2187574041-2537157961-1000_Classes\CLSID\{2F5DA951-82C6-471e-90BD-CAB15552A932}\InprocServer32 -> C:\Windows\SYSTEM32\mscoree.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3639536685-2187574041-2537157961-1000_Classes\CLSID\{56FDF344-FD6D-11d0-958A-006097C9A090}\InprocServer32 -> C:\Users\Phillip\AppData\Roaming\timgquxs\tivesen.dll () <==== ATTENTION
CustomCLSID: HKU\S-1-5-21-3639536685-2187574041-2537157961-1000_Classes\CLSID\{85A0641D-324D-4b47-9E5C-D2F33CCB14C3}\InprocServer32 -> C:\Windows\SYSTEM32\mscoree.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3639536685-2187574041-2537157961-1000_Classes\CLSID\{97D17A04-4438-4C8E-BAC7-BC21B8B9E999}\InprocServer32 -> C:\Windows\SYSTEM32\mscoree.dll (Microsoft Corporation)
==================== Restore Points =========================
ATTENTION: System Restore is disabled.
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {144AC2C2-0891-4258-94C4-9748496BAD7B} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-02-19] (Piriform Ltd)
Task: {23B3186F-73A0-45DE-8196-D3F0EDDC0D4C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-03-16] (Adobe Systems Incorporated)
Task: {2CB8659F-569B-4A0B-B442-C113B406FC36} - System32\Tasks\FRAPS => D:\FRAPS\fraps.exe [2013-02-26] (Beepa P/L)
Task: {40247C15-39D6-4059-A974-E9AAAA72C24A} - System32\Tasks\PNPGLZVDA => C:\ProgramData\0dfcafffadba49a298b588510cb87bf9\0dfcafffadba49a298b588510cb87bf9.exe
Task: {61423804-DAF7-4E7C-BFC5-9F76AA458B57} - System32\Tasks\HWiNFO => C:\Program Files\HWiNFO64\HWiNFO64.EXE [2014-11-26] (REALiX)
Task: {80B3C200-534C-4F27-9A5B-F4FA4E88F309} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {B2F73501-C532-4DA0-BF3C-7D69C01CD7F8} - \Start CorsairLINK Hardware Monitor No Task File <==== ATTENTION
Task: {B3EE32CC-D2B6-4DD9-8F3D-D79185654F54} - System32\Tasks\trik3004 => C:\PROGRA~2\TabNav\trik3004.exe
Task: {CB17C761-ABD2-4628-B7B1-78F70617F00C} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe [2014-12-06] ()
Task: {CF1E8D14-A304-4535-B913-D355D0A349AB} - \Start Corsair Link No Task File <==== ATTENTION
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Loaded Modules (whitelisted) ==============
2015-03-10 18:27 - 2015-02-05 20:07 - 00117576 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2013-05-19 20:24 - 2015-02-27 22:45 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2015-03-16 09:59 - 2015-03-16 09:59 - 00157696 _____ () C:\Users\Phillip\AppData\Roaming\timgquxs\tivesen.dll
2014-12-25 12:52 - 2013-08-06 11:34 - 02453504 ____N () C:\Program Files\ASUS Xonar U7 Audio\CPL\ASUSXonarU7_x64.exe
2013-04-12 18:23 - 2013-04-12 18:23 - 00612664 _____ () C:\Program Files (x86)\Panda Security\Panda Security Protection\SQLite3.dll
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NanoServiceMain => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSUAService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NanoServiceMain => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PSUAService => ""="Service"
==================== EXE Association (whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3639536685-2187574041-2537157961-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Phillip\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.178.1
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== Accounts: =============================
Administrator (S-1-5-21-3639536685-2187574041-2537157961-500 - Administrator - Disabled)
Gast (S-1-5-21-3639536685-2187574041-2537157961-501 - Limited - Enabled)
HomeGroupUser$ (S-1-5-21-3639536685-2187574041-2537157961-1002 - Limited - Enabled)
Phillip (S-1-5-21-3639536685-2187574041-2537157961-1000 - Administrator - Enabled) => C:\Users\Phillip
==================== Faulty Device Manager Devices =============
Name: PCI-Kommunikationscontroller (einfach)
Description: PCI-Kommunikationscontroller (einfach)
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (03/20/2015 01:11:55 PM) (Source: Schedule) (EventID: 0) (User: )
Description: Schedule error: 10106Initialize call failed, bailing out
Error: (03/20/2015 01:11:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: LCore.exe, Version: 8.57.145.0, Zeitstempel: 0x543d6bf8
Name des fehlerhaften Moduls: Qt5Network.dll, Version: 5.1.1.0, Zeitstempel: 0x53695429
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000078280
ID des fehlerhaften Prozesses: 0xcfc
Startzeit der fehlerhaften Anwendung: 0xLCore.exe0
Pfad der fehlerhaften Anwendung: LCore.exe1
Pfad des fehlerhaften Moduls: LCore.exe2
Berichtskennung: LCore.exe3
Error: (03/20/2015 01:11:38 PM) (Source: Schedule) (EventID: 0) (User: )
Description: Schedule error: 10106Initialize call failed, bailing out
Error: (03/19/2015 10:28:46 PM) (Source: Schedule) (EventID: 0) (User: )
Description: Schedule error: 10106Initialize call failed, bailing out
Error: (03/19/2015 10:28:36 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: LCore.exe, Version: 8.57.145.0, Zeitstempel: 0x543d6bf8
Name des fehlerhaften Moduls: Qt5Network.dll, Version: 5.1.1.0, Zeitstempel: 0x53695429
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000078280
ID des fehlerhaften Prozesses: 0xd04
Startzeit der fehlerhaften Anwendung: 0xLCore.exe0
Pfad der fehlerhaften Anwendung: LCore.exe1
Pfad des fehlerhaften Moduls: LCore.exe2
Berichtskennung: LCore.exe3
Error: (03/19/2015 10:28:30 PM) (Source: Schedule) (EventID: 0) (User: )
Description: Schedule error: 10106Initialize call failed, bailing out
Error: (03/19/2015 10:12:58 PM) (Source: Schedule) (EventID: 0) (User: )
Description: Schedule error: 10106Initialize call failed, bailing out
Error: (03/19/2015 10:12:48 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: LCore.exe, Version: 8.57.145.0, Zeitstempel: 0x543d6bf8
Name des fehlerhaften Moduls: Qt5Network.dll, Version: 5.1.1.0, Zeitstempel: 0x53695429
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000078280
ID des fehlerhaften Prozesses: 0xe40
Startzeit der fehlerhaften Anwendung: 0xLCore.exe0
Pfad der fehlerhaften Anwendung: LCore.exe1
Pfad des fehlerhaften Moduls: LCore.exe2
Berichtskennung: LCore.exe3
Error: (03/19/2015 10:12:41 PM) (Source: Schedule) (EventID: 0) (User: )
Description: Schedule error: 10106Initialize call failed, bailing out
Error: (03/19/2015 00:46:21 AM) (Source: Schedule) (EventID: 0) (User: )
Description: Schedule error: 10106Initialize call failed, bailing out
System errors:
=============
Error: (03/20/2015 01:15:33 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "IPsec-Richtlinien-Agent" wurde mit folgendem Fehler beendet:
%%10106
Error: (03/20/2015 01:15:24 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "IPsec-Richtlinien-Agent" wurde mit folgendem Fehler beendet:
%%10106
Error: (03/20/2015 01:15:24 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "IPsec-Richtlinien-Agent" wurde mit folgendem Fehler beendet:
%%10106
Error: (03/20/2015 01:13:41 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "Windows Update" wurde mit folgendem Fehler beendet:
%%-2147014790
Error: (03/20/2015 01:13:40 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: Der Dienst "Intelligenter Hintergrundübertragungsdienst" wurde mit folgendem dienstspezifischem Fehler beendet: %%-2147014790.
Error: (03/20/2015 01:13:40 PM) (Source: Microsoft-Windows-Bits-Client) (EventID: 16392) (User: NT-AUTORITÄT)
Description: Fehler beim Starten des BITS-Dienstes. Fehler: 2147952506.
Error: (03/20/2015 01:12:19 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "Superfetch" wurde mit folgendem Fehler beendet:
%%2
Error: (03/20/2015 01:11:52 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "IPsec-Richtlinien-Agent" wurde mit folgendem Fehler beendet:
%%10106
Error: (03/20/2015 01:11:49 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuche-Ressourcenveröffentlichung" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%-2147014854
Error: (03/20/2015 01:11:49 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "Funktionssuche-Ressourcenveröffentlichung" wurde mit folgendem Fehler beendet:
%%-2147014854
Microsoft Office Sessions:
=========================
Error: (03/20/2015 01:11:55 PM) (Source: Schedule) (EventID: 0) (User: )
Description: Schedule error: 10106Initialize call failed, bailing out
Error: (03/20/2015 01:11:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: LCore.exe8.57.145.0543d6bf8Qt5Network.dll5.1.1.053695429c00000050000000000078280cfc01d0630706dd52bcC:\Program Files\Logitech Gaming Software\LCore.exeC:\Program Files\Logitech Gaming Software\Qt5Network.dll466e1dac-cefa-11e4-b26f-08606ee7ef88
Error: (03/20/2015 01:11:38 PM) (Source: Schedule) (EventID: 0) (User: )
Description: Schedule error: 10106Initialize call failed, bailing out
Error: (03/19/2015 10:28:46 PM) (Source: Schedule) (EventID: 0) (User: )
Description: Schedule error: 10106Initialize call failed, bailing out
Error: (03/19/2015 10:28:36 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: LCore.exe8.57.145.0543d6bf8Qt5Network.dll5.1.1.053695429c00000050000000000078280d0401d0628ba71de712C:\Program Files\Logitech Gaming Software\LCore.exeC:\Program Files\Logitech Gaming Software\Qt5Network.dlle66bdba7-ce7e-11e4-8897-08606ee7ef88
Error: (03/19/2015 10:28:30 PM) (Source: Schedule) (EventID: 0) (User: )
Description: Schedule error: 10106Initialize call failed, bailing out
Error: (03/19/2015 10:12:58 PM) (Source: Schedule) (EventID: 0) (User: )
Description: Schedule error: 10106Initialize call failed, bailing out
Error: (03/19/2015 10:12:48 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: LCore.exe8.57.145.0543d6bf8Qt5Network.dll5.1.1.053695429c00000050000000000078280e4001d0628971fbe418C:\Program Files\Logitech Gaming Software\LCore.exeC:\Program Files\Logitech Gaming Software\Qt5Network.dllb1421060-ce7c-11e4-918e-08606ee7ef88
Error: (03/19/2015 10:12:41 PM) (Source: Schedule) (EventID: 0) (User: )
Description: Schedule error: 10106Initialize call failed, bailing out
Error: (03/19/2015 00:46:21 AM) (Source: Schedule) (EventID: 0) (User: )
Description: Schedule error: 10106Initialize call failed, bailing out
CodeIntegrity Errors:
===================================
Date: 2015-02-10 12:46:26.652
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-02-10 12:34:38.908
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-02-09 14:57:39.300
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-02-09 12:33:48.326
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-02-09 12:01:19.115
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-02-09 11:54:59.813
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-02-09 11:28:09.849
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-02-09 11:13:39.543
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-02-09 11:13:07.190
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-02-09 10:35:56.252
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i5-3570K CPU @ 3.40GHz
Percentage of memory in use: 17%
Total physical RAM: 8134.84 MB
Available physical RAM: 6686.64 MB
Total Pagefile: 10181.03 MB
Available Pagefile: 8639.57 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:232.79 GB) (Free:73.57 GB) NTFS
Drive d: () (Fixed) (Total:596.16 GB) (Free:263.42 GB) NTFS
Drive e: () (Fixed) (Total:596.17 GB) (Free:338.72 GB) NTFS
Drive h: () (Removable) (Total:0.49 GB) (Free:0.48 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596.2 GB) (Disk ID: A5D5DC5A)
Partition 1: (Not Active) - (Size=596.2 GB) - (Type=OF Extended)
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 596.2 GB) (Disk ID: 5B2FBDC9)
Partition 1: (Not Active) - (Size=596.2 GB) - (Type=OF Extended)
========================================================
Disk: 2 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: D2AB1056)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=232.8 GB) - (Type=07 NTFS)
========================================================
Disk: 3 (Size: 503.3 MB) (Disk ID: 01B10499)
Partition 1: (Active) - (Size=503 MB) - (Type=0B)
==================== End Of Log ============================
Schönen Freitag wünsche ich :) |