DamnedRecon | 10.06.2015 16:04 | Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 10.06.2015
Suchlauf-Zeit: 16:45:10
Logdatei: MBAM LOG(DamnedRecon).txt
Administrator: Ja
Version: 2.01.6.1022
Malware Datenbank: v2015.06.10.03
Rootkit Datenbank: v2015.06.02.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Dennis
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 354742
Verstrichene Zeit: 3 Min, 54 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 3
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\POLICIES\GOOGLE\UPDATE, In Quarantäne, [ad5e6a4f256580b6d3b38bfc1bea04fc],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{1146AC44-2F03-4431-B4FD-889BC837521F}{cae99edb}, In Quarantäne, [39d27d3ce5a5e94dac2f0b7a06ff36ca],
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\WOW6432NODE\POLICIES\GOOGLE\UPDATE, In Quarantäne, [3ccf4d6ceaa0f541dda9820533d202fe],
Registrierungswerte: 2
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\POLICIES\GOOGLE\UPDATE|DisableAutoUpdateChecksCheckboxValue, 1, In Quarantäne, [ad5e6a4f256580b6d3b38bfc1bea04fc]
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\WOW6432NODE\POLICIES\GOOGLE\UPDATE|DisableAutoUpdateChecksCheckboxValue, 1, In Quarantäne, [3ccf4d6ceaa0f541dda9820533d202fe]
Registrierungsdaten: 0
(Keine schädliche Elemente gefunden)
Ordner: 2
PUP.Optional.PullUpdate.A, C:\ProgramData\IZHIwLSvfp\dat, In Quarantäne, [1fecb900c9c1b185d803c8b25bab659b],
PUP.Optional.PullUpdate.A, C:\ProgramData\IZHIwLSvfp, In Quarantäne, [1fecb900c9c1b185d803c8b25bab659b],
Dateien: 14
PUP.Optional.BreakingNewsAlert.A, C:\ProgramData\IZHIwLSvfp\dat\UnNlAJwfQ.exe, In Quarantäne, [a3683d7cf79369cdba646bca8979d12f],
PUP.Optional.OurSeaching.A, C:\Users\Dennis\AppData\Local\Temp\smt_oursurfing.exe, In Quarantäne, [3bd0506978129e989359b1c6c93d867a],
PUP.Optional.Infonaut.A, C:\Users\Dennis\AppData\Local\Temp\is-OMKI4.tmp\infonauts_bitkible.exe, In Quarantäne, [7c8fc5f442488aacf888116719ed19e7],
PUP.Optional.Vitruvian.A, C:\Users\Dennis\AppData\Local\Temp\vitruvian-installer-hardwareprofile-v0001, In Quarantäne, [9378ffbae0aa76c0bb44690e47be7c84],
PUP.Optional.Vitruvian.A, C:\Users\Dennis\AppData\Local\Temp\vitruvian-installer-install-v0003, In Quarantäne, [f417368391f92b0b35ca0a6dc73e54ac],
PUP.Optional.Vitruvian.A, C:\Users\Dennis\AppData\Local\Temp\vitruvian-installer-processes-v0002, In Quarantäne, [33d89c1d8109350142bd2f48e61f21df],
PUP.Optional.Vitruvian.A, C:\Users\Dennis\AppData\Local\Temp\vitruvian-installer-scheduledtasks-v0001, In Quarantäne, [c3486e4b7c0efe38d629393e14f1ad53],
PUP.Optional.Vitruvian.A, C:\Users\Dennis\AppData\Local\Temp\vitruvian-installer-softwareregkeys-v0002, In Quarantäne, [f219bcfd3357e15548b7096e5ca9e917],
PUP.Optional.Vitruvian.A, C:\Users\Dennis\AppData\Local\Temp\vitruvian-installer-uninstall-v0002, In Quarantäne, [6e9dc2f7e0aa47efe6190a6d32d348b8],
PUP.Optional.PullUpdate.A, C:\ProgramData\IZHIwLSvfp\dat\qKGwHGBl.exe.config, In Quarantäne, [1fecb900c9c1b185d803c8b25bab659b],
PUP.Optional.PullUpdate.A, C:\ProgramData\IZHIwLSvfp\dat\UnNlAJwfQ.exe.config, In Quarantäne, [1fecb900c9c1b185d803c8b25bab659b],
PUP.Optional.PullUpdate.A, C:\ProgramData\IZHIwLSvfp\info.dat, In Quarantäne, [1fecb900c9c1b185d803c8b25bab659b],
PUP.Optional.PullUpdate.A, C:\ProgramData\IZHIwLSvfp\ioioMsPeVkV.dat, In Quarantäne, [1fecb900c9c1b185d803c8b25bab659b],
PUP.Optional.PullUpdate.A, C:\ProgramData\IZHIwLSvfp\ioioMsPeVkV.exe.config, In Quarantäne, [1fecb900c9c1b185d803c8b25bab659b],
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.9.1 (06.08.2015:1)
OS: Windows 8.1 x64
Ran by Dennis on 10.06.2015 at 16:58:31,38
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] C:\ProgramData\14842413286407222954
~~~ FireFox
~~~ Chrome
[C:\Users\Dennis\appdata\local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
[C:\Users\Dennis\appdata\local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
[C:\Users\Dennis\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
[C:\Users\Dennis\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 10.06.2015 at 17:01:33,39
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:08-06-2015
Ran by Dennis (administrator) on GOSDZINSKI on 10-06-2015 17:03:01
Running from D:\Dennis\Downloads
Loaded Profiles: Dennis (Available Profiles: Dennis)
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\afwServ.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2014-05-28] (Intel Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2673296 2015-04-09] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8447192 2015-04-13] (Realtek Semiconductor)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [163520 2015-04-09] (IvoSoft)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-05-11] (Avast Software s.r.o.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => E:\hamachi-2-ui.exe [3978600 2015-03-30] (LogMeIn Inc.)
HKU\S-1-5-21-3748175176-1344429532-2253105022-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2892992 2015-06-04] (Valve Corporation)
HKU\S-1-5-21-3748175176-1344429532-2253105022-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [28785792 2015-06-02] (Skype Technologies S.A.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-05-05] (Avast Software s.r.o.)
ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2015-04-09] (IvoSoft)
ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll [2015-04-09] (IvoSoft)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=sp-006&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-3748175176-1344429532-2253105022-1001\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?trackid=sp-006&q={searchTerms}
HKU\S-1-5-21-3748175176-1344429532-2253105022-1001\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006
HKU\S-1-5-21-3748175176-1344429532-2253105022-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp
HKU\S-1-5-21-3748175176-1344429532-2253105022-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3748175176-1344429532-2253105022-1001 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = https://www.google.com/search?trackid=sp-006&q={searchTerms}
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2015-04-09] (IvoSoft)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-05-06] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-05-05] (Avast Software s.r.o.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-05-06] (Oracle Corporation)
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2015-04-09] (IvoSoft)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2015-04-09] (IvoSoft)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-05-05] (Avast Software s.r.o.)
BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2015-04-09] (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2015-04-09] (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2015-04-09] (IvoSoft)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\upwbv0xo.default
FF Homepage: google.com
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_188.dll [2015-05-21] ()
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-05-06] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-05-06] (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_188.dll [2015-05-21] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2014-04-29] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2014-04-29] (Intel Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-04-08] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-04-08] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-29] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-03-17] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3748175176-1344429532-2253105022-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-05-09] ()
FF Extension: Avira Browser Safety - C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\upwbv0xo.default\Extensions\abs@avira.com [2015-05-24]
FF Extension: Adblock Plus - C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\upwbv0xo.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-05-06]
FF Extension: Greasemonkey - C:\Users\Dennis\AppData\Roaming\Mozilla\Firefox\Profiles\upwbv0xo.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2015-05-26]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-05-05]
Chrome:
=======
CHR Profile: C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-05-29]
CHR Extension: (Google Docs) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-05-29]
CHR Extension: (Google Drive) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-05-29]
CHR Extension: (YouTube) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-05-29]
CHR Extension: (Google Search) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-05-29]
CHR Extension: (Avast SafePrice) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2015-05-29]
CHR Extension: (Google Sheets) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-05-29]
CHR Extension: (Avira Browser Safety) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2015-05-29]
CHR Extension: (Avast Online Security) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-05-29]
CHR Extension: (agar.io server browser) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\hongpdkjnjhijmdnogoicadboadgllhi [2015-05-29]
CHR Extension: (Google Wallet) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-05-29]
CHR Extension: (Gmail) - C:\Users\Dennis\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-29]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-05-05]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-05-05]
Opera:
=======
OPR Extension: (Adblock Plus) - C:\Users\Dennis\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2015-05-30]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe [936728 2014-01-28] ()
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-05-05] (Avast Software s.r.o.)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [107448 2015-05-21] (Avast Software s.r.o.)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation)
S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [238376 2015-06-07] (EasyAntiCheat Ltd)
S2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152144 2015-04-09] (NVIDIA Corporation)
S2 Hamachi2Svc; E:\hamachi-2.exe [2490216 2015-03-30] (LogMeIn Inc.)
S2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [16232 2014-05-28] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [887232 2014-01-31] (Intel(R) Corporation)
S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [154584 2014-04-29] (Intel Corporation)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
S2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1878672 2015-04-09] (NVIDIA Corporation)
S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [22995600 2015-04-09] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1931632 2015-05-09] (Electronic Arts)
S2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2015-05-09] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2014-01-28] ()
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-05-05] ()
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28144 2015-05-21] (Avast Software s.r.o.)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [89944 2015-05-05] (Avast Software s.r.o.)
R0 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [449896 2015-05-21] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-05-05] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-05-05] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-05-05] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-05-05] (Avast Software s.r.o.)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [137288 2015-05-05] (Avast Software s.r.o.)
S3 aswTap; C:\Windows\system32\DRIVERS\aswTap.sys [44640 2015-05-05] (The OpenVPN Project)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [272248 2015-05-05] ()
R3 e1dexpress; C:\Windows\system32\DRIVERS\e1d64x64.sys [394520 2014-09-29] (Intel Corporation)
R3 Hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [44296 2015-03-30] (LogMeIn Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-06-10] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-04-14] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [129312 2014-09-30] (Intel Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-04-09] (NVIDIA Corporation)
R3 NVVADARM; C:\Windows\system32\drivers\nvvadarm.sys [39056 2015-04-09] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38032 2015-04-09] (NVIDIA Corporation)
R3 RtlWlanu; C:\Windows\system32\DRIVERS\rtwlanu.sys [1975000 2013-07-31] (Realtek Semiconductor Corporation )
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-10 17:01 - 2015-06-10 17:01 - 00001277 _____ C:\Users\Dennis\Desktop\JRT.txt
2015-06-10 16:58 - 2015-06-10 16:58 - 00000207 _____ C:\Windows\tweaking.com-regbackup-GOSDZINSKI-Windows-8.1-(64-bit).dat
2015-06-10 16:58 - 2015-06-10 16:58 - 00000000 ____D C:\RegBackup
2015-06-10 16:44 - 2015-06-10 16:51 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-06-10 16:44 - 2015-06-10 16:44 - 00001118 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-06-10 16:44 - 2015-06-10 16:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-06-10 16:44 - 2015-06-10 16:44 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-06-10 16:44 - 2015-06-10 16:44 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-06-10 16:44 - 2015-04-14 09:38 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-06-10 16:44 - 2015-04-14 09:37 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-06-10 16:44 - 2015-04-14 09:37 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-06-10 15:29 - 2015-06-10 17:03 - 00000000 ____D C:\FRST
2015-06-10 13:59 - 2015-05-27 16:35 - 24917504 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-06-10 13:59 - 2015-05-27 16:08 - 19607040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-06-10 13:59 - 2015-05-23 05:15 - 00503808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-06-10 13:59 - 2015-05-23 05:14 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-06-10 13:59 - 2015-05-23 05:10 - 02278912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-06-10 13:59 - 2015-05-23 05:05 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-06-10 13:59 - 2015-05-23 05:04 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-06-10 13:59 - 2015-05-23 04:48 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-06-10 13:59 - 2015-05-23 04:47 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-06-10 13:59 - 2015-05-23 04:47 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-06-10 13:59 - 2015-05-23 04:47 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2015-06-10 13:59 - 2015-05-23 04:43 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2015-06-10 13:59 - 2015-05-23 04:38 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-06-10 13:59 - 2015-05-23 04:38 - 00327168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-06-10 13:59 - 2015-05-23 04:37 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-06-10 13:59 - 2015-05-23 04:28 - 12829696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-06-10 13:59 - 2015-05-23 04:28 - 01042944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2015-06-10 13:59 - 2015-05-23 04:20 - 01950720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-06-10 13:59 - 2015-05-23 04:16 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-06-10 13:59 - 2015-05-23 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-06-10 13:59 - 2015-05-22 21:00 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-06-10 13:59 - 2015-05-22 21:00 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-06-10 13:59 - 2015-05-22 21:00 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-06-10 13:59 - 2015-05-22 20:52 - 06026240 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-06-10 13:59 - 2015-05-22 20:48 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-06-10 13:59 - 2015-05-22 20:47 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-06-10 13:59 - 2015-05-22 20:47 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-06-10 13:59 - 2015-05-22 20:24 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-06-10 13:59 - 2015-05-22 20:23 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2015-06-10 13:59 - 2015-05-22 20:21 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-06-10 13:59 - 2015-05-22 20:15 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-06-10 13:59 - 2015-05-22 20:09 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-06-10 13:59 - 2015-05-22 20:08 - 00374272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-06-10 13:59 - 2015-05-22 20:06 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-06-10 13:59 - 2015-05-22 20:05 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-06-10 13:59 - 2015-05-22 19:57 - 14404096 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-06-10 13:59 - 2015-05-22 19:50 - 02426880 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-06-10 13:59 - 2015-05-22 19:49 - 02865152 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2015-06-10 13:59 - 2015-05-22 19:38 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-06-10 13:59 - 2015-05-22 19:26 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-06-10 13:58 - 2015-05-25 15:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-06-10 13:58 - 2015-05-25 15:07 - 01430528 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-06-10 13:58 - 2015-05-22 15:08 - 00700416 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-06-10 13:58 - 2015-05-21 15:08 - 01119232 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-06-10 13:58 - 2015-05-21 15:08 - 01020928 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-06-10 13:58 - 2015-05-21 15:08 - 00756736 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-06-10 13:58 - 2015-05-21 15:08 - 00422912 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-06-10 13:58 - 2015-05-21 15:08 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-06-10 13:58 - 2015-05-21 15:08 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-06-10 13:58 - 2015-04-17 00:07 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-06-10 13:58 - 2015-04-09 00:41 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rgb9rast.dll
2015-06-10 13:58 - 2015-04-09 00:07 - 00410336 _____ C:\Windows\system32\ApnDatabase.xml
2015-06-10 13:58 - 2015-04-02 00:42 - 03097600 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
2015-06-10 13:58 - 2015-04-02 00:30 - 02483712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll
2015-06-10 13:58 - 2015-03-20 05:49 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\compstui.dll
2015-06-10 13:58 - 2015-03-20 05:08 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\puiobj.dll
2015-06-10 13:58 - 2015-03-20 04:37 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\puiobj.dll
2015-06-10 13:58 - 2015-03-20 04:07 - 01091072 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2015-06-10 13:58 - 2015-03-02 03:43 - 00222208 _____ (Microsoft Corporation) C:\Windows\system32\rastapi.dll
2015-06-10 13:58 - 2015-03-02 03:21 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastapi.dll
2015-06-10 13:57 - 2015-04-25 04:34 - 00653824 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2015-06-10 13:57 - 2015-04-25 04:33 - 00549888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2015-06-10 13:57 - 2015-04-16 08:17 - 00325464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBXHCI.SYS
2015-06-10 13:57 - 2015-04-14 00:37 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\authz.dll
2015-06-10 13:57 - 2015-04-14 00:34 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authz.dll
2015-06-10 13:57 - 2015-04-10 02:40 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\UIAutomationCore.dll
2015-06-10 13:57 - 2015-04-10 02:17 - 01018880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAutomationCore.dll
2015-06-10 13:57 - 2015-04-01 06:21 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2015-06-10 13:57 - 2015-04-01 06:18 - 00468480 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2015-06-10 13:57 - 2015-04-01 06:17 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2015-06-10 13:57 - 2015-04-01 06:08 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2015-06-10 13:57 - 2015-04-01 05:46 - 03633664 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2015-06-10 13:57 - 2015-04-01 05:17 - 02551808 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2015-06-10 13:57 - 2015-04-01 05:17 - 00903168 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2015-06-10 13:57 - 2015-04-01 04:53 - 00391680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2015-06-10 13:57 - 2015-04-01 04:53 - 00272896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2015-06-10 13:57 - 2015-04-01 04:45 - 02749952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2015-06-10 13:57 - 2015-04-01 04:45 - 00699392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2015-06-10 13:57 - 2015-04-01 04:14 - 01920000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2015-06-10 13:57 - 2015-04-01 04:12 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2015-06-10 13:56 - 2015-05-21 18:47 - 04177920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-06-09 15:32 - 2015-06-09 15:32 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\ParadoxInteractive
2015-06-07 14:49 - 2015-06-07 14:49 - 00000000 ____D C:\Users\Dennis\AppData\Local\SR22.1.7
2015-06-03 21:47 - 2015-06-03 21:47 - 00000000 ____D C:\Users\Dennis\AppData\Local\LogMeIn
2015-06-03 21:47 - 2015-06-03 21:47 - 00000000 ____D C:\ProgramData\LogMeIn
2015-06-03 21:38 - 2015-06-10 16:51 - 00000000 ____D C:\Users\Dennis\AppData\Local\LogMeIn Hamachi
2015-06-03 21:37 - 2015-06-03 21:37 - 00000451 _____ C:\Users\Public\Desktop\LogMeIn Hamachi.lnk
2015-06-03 21:37 - 2015-06-03 21:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2015-06-01 16:42 - 2015-06-01 16:42 - 00000000 ____D C:\Users\Dennis\AppData\Local\Black_Tree_Gaming
2015-06-01 13:04 - 2015-06-10 16:51 - 00000000 ___RD C:\Users\Dennis\OneDrive
2015-06-01 12:20 - 2015-06-01 12:20 - 00000000 ____D C:\Users\Dennis\AppData\Local\GWX
2015-05-29 18:52 - 2015-05-29 18:52 - 00000000 ____D C:\Users\Dennis\AppData\Local\My Games
2015-05-29 18:09 - 2015-06-10 14:13 - 00002195 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-05-29 18:09 - 2015-05-29 18:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-05-29 18:08 - 2015-06-10 16:51 - 00001128 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-05-29 18:08 - 2015-06-10 16:13 - 00001132 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-05-29 18:08 - 2015-05-29 18:09 - 00000000 ____D C:\Users\Dennis\AppData\Local\Google
2015-05-29 18:08 - 2015-05-29 18:09 - 00000000 ____D C:\Program Files (x86)\Google
2015-05-29 18:08 - 2015-05-29 18:08 - 00004104 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-05-29 18:08 - 2015-05-29 18:08 - 00003868 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-05-27 16:22 - 2015-06-08 18:54 - 00000080 _____ C:\Users\Dennis\AppData\Local剜捯獫慴慇敭屳呇⁁屖湥楴汴浥湥湩潦
2015-05-26 18:27 - 2015-06-04 22:33 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Awesomium
2015-05-26 15:25 - 2015-05-26 15:25 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\SpaceEngineers
2015-05-24 17:41 - 2015-05-24 17:41 - 00003848 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1432482065
2015-05-24 17:41 - 2015-05-24 17:41 - 00001151 _____ C:\Users\Public\Desktop\Opera.lnk
2015-05-24 17:41 - 2015-05-24 17:41 - 00001151 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2015-05-24 13:46 - 2015-06-10 16:09 - 00000000 ____D C:\ProgramData\Avira
2015-05-24 13:46 - 2015-06-10 16:09 - 00000000 ____D C:\Program Files (x86)\Avira
2015-05-24 13:29 - 2015-05-24 13:29 - 00001175 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-05-24 13:29 - 2015-05-24 13:29 - 00001163 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-05-24 13:29 - 2015-05-24 13:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-05-24 13:29 - 2015-05-24 13:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-05-21 14:24 - 2015-05-21 14:24 - 00000000 ____D C:\ProgramData\Gecuenogloxut
2015-05-21 14:23 - 2015-05-21 14:23 - 00001998 _____ C:\Users\Public\Desktop\Avast SafeZone.lnk
2015-05-21 14:23 - 2015-05-21 14:23 - 00001938 _____ C:\Users\Public\Desktop\Avast Internet Security.lnk
2015-05-21 14:23 - 2015-05-21 14:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-05-21 14:22 - 2015-05-21 14:22 - 00449896 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswNdisFlt.sys
2015-05-21 14:22 - 2015-05-21 14:22 - 00028144 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswKbd.sys
2015-05-21 14:22 - 2015-05-05 18:18 - 00364472 _____ (Avast Software s.r.o.) C:\Windows\system32\aswBoot.exe
2015-05-20 21:40 - 2015-05-20 21:40 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2015-05-20 13:59 - 2015-06-10 16:16 - 00000000 ____D C:\AdwCleaner
2015-05-18 17:24 - 2015-06-07 17:28 - 00238376 _____ (EasyAntiCheat Ltd) C:\Windows\SysWOW64\EasyAntiCheat.exe
2015-05-17 19:54 - 2015-06-10 16:14 - 00000000 ____D C:\Program Files (x86)\Opera
2015-05-17 19:54 - 2015-05-24 17:41 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Opera Software
2015-05-17 19:54 - 2015-05-24 17:41 - 00000000 ____D C:\Users\Dennis\AppData\Local\Opera Software
2015-05-15 01:42 - 2015-05-15 01:42 - 00000899 _____ C:\Users\Public\Desktop\Dragon Age Origins.lnk
2015-05-15 01:42 - 2015-05-15 01:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dragon Age Origins
2015-05-14 17:30 - 2015-05-14 17:30 - 00000000 ____D C:\Program Files (x86)\Microsoft XNA
2015-05-14 15:40 - 2015-05-01 01:05 - 00429568 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-05-14 15:40 - 2015-05-01 00:48 - 00358912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-05-14 15:40 - 2015-04-21 18:13 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2015-05-14 15:40 - 2015-04-21 17:49 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-05-14 15:40 - 2015-04-21 17:28 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-05-14 15:40 - 2015-04-10 03:00 - 01996800 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-05-14 15:40 - 2015-04-10 02:50 - 01387008 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-05-14 15:40 - 2015-04-10 02:34 - 02256896 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2015-05-14 15:40 - 2015-04-10 02:26 - 01560576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2015-05-14 15:40 - 2015-04-10 02:11 - 01943040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2015-05-14 15:40 - 2015-04-09 00:55 - 00410128 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2015-05-14 15:40 - 2015-03-30 07:47 - 00561928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-05-14 15:40 - 2015-03-27 05:27 - 00445440 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2015-05-14 15:40 - 2015-03-27 04:50 - 00324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2015-05-14 15:40 - 2015-03-27 04:48 - 01441792 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-05-14 03:06 - 2015-04-30 22:35 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-14 03:06 - 2015-04-30 22:35 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-10 17:02 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\sru
2015-06-10 16:59 - 2015-05-05 18:21 - 00000000 ____D C:\Users\Dennis\AppData\Local\ClassicShell
2015-06-10 16:57 - 2015-05-05 11:06 - 01780340 _____ C:\Windows\system32\PerfStringBackup.INI
2015-06-10 16:57 - 2013-08-23 01:24 - 00765378 _____ C:\Windows\system32\perfh007.dat
2015-06-10 16:57 - 2013-08-23 01:24 - 00159696 _____ C:\Windows\system32\perfc007.dat
2015-06-10 16:56 - 2015-05-05 11:07 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3748175176-1344429532-2253105022-1001
2015-06-10 16:53 - 2015-05-05 11:16 - 00006464 _____ C:\Windows\SysWOW64\Gms.log
2015-06-10 16:51 - 2015-05-06 14:57 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Skype
2015-06-10 16:51 - 2015-05-06 14:53 - 00000000 ____D C:\Program Files (x86)\Steam
2015-06-10 16:51 - 2013-08-22 16:46 - 00028214 _____ C:\Windows\setupact.log
2015-06-10 16:50 - 2015-05-05 12:17 - 00000000 ____D C:\ProgramData\NVIDIA
2015-06-10 16:50 - 2015-05-05 10:56 - 00202894 _____ C:\Windows\PFRO.log
2015-06-10 16:50 - 2013-08-22 16:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-06-10 16:09 - 2013-08-22 16:44 - 00338016 _____ C:\Windows\system32\FNTCACHE.DAT
2015-06-10 16:08 - 2015-05-05 17:53 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-06-10 16:08 - 2015-05-05 17:53 - 00000000 ____D C:\Windows\system32\appraiser
2015-06-10 16:08 - 2015-05-05 11:02 - 01835061 _____ C:\Windows\WindowsUpdate.log
2015-06-10 16:08 - 2013-08-22 17:36 - 00000000 ___RD C:\Windows\ToastData
2015-06-10 16:08 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-06-10 16:08 - 2013-08-22 15:25 - 00262144 ___SH C:\Windows\system32\config\BBI
2015-06-10 16:06 - 2015-05-06 15:32 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-06-10 15:05 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\AppReadiness
2015-06-10 15:02 - 2015-05-08 11:37 - 00000000 ____D C:\Program Files (x86)\Rockstar Games
2015-06-10 15:02 - 2015-05-08 11:36 - 00000000 ____D C:\Program Files\Rockstar Games
2015-06-10 14:36 - 2013-08-22 17:20 - 00000000 ____D C:\Windows\CbsTemp
2015-06-10 14:19 - 2015-05-05 11:08 - 00000000 ____D C:\ProgramData\Package Cache
2015-06-10 13:43 - 2015-05-05 13:49 - 00003942 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{5E764A5A-7CAF-44D4-B1EA-40815D08292E}
2015-06-09 14:46 - 2015-05-06 18:59 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2015-06-05 14:41 - 2015-05-05 11:02 - 00000000 ____D C:\Users\Dennis\AppData\Local\Packages
2015-06-05 12:01 - 2015-05-06 14:57 - 00000000 ____D C:\ProgramData\Skype
2015-06-03 20:20 - 2015-05-06 19:54 - 00168006 _____ C:\Windows\DirectX.log
2015-06-03 18:18 - 2013-08-22 17:38 - 00792568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-06-03 18:18 - 2013-08-22 17:38 - 00178168 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-06-02 21:09 - 2015-05-05 11:02 - 00000000 ____D C:\Users\Dennis
2015-06-01 17:30 - 2015-05-06 15:38 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\.minecraft
2015-05-29 22:07 - 2015-05-09 04:25 - 00000000 ____D C:\ProgramData\Origin
2015-05-27 14:50 - 2015-05-06 15:05 - 00000000 ____D C:\Users\Dennis\AppData\Local\ftblauncher
2015-05-21 17:22 - 2015-05-06 15:32 - 00003772 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-05-21 14:22 - 2015-05-05 18:19 - 00003924 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2015-05-20 16:34 - 2015-05-05 17:53 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2015-05-20 16:34 - 2015-05-05 17:53 - 00000000 ___SD C:\Windows\system32\GWX
2015-05-20 13:53 - 2015-05-06 14:58 - 00000000 ____D C:\Users\Dennis\Tracing
2015-05-18 12:47 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\LiveKernelReports
2015-05-15 15:15 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\rescache
2015-05-15 01:43 - 2015-05-09 04:25 - 00000000 ____D C:\ProgramData\Electronic Arts
2015-05-15 01:43 - 2015-05-06 15:39 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\NVIDIA
2015-05-15 00:15 - 2015-05-09 04:26 - 00000000 ____D C:\Users\Dennis\AppData\Roaming\Origin
2015-05-14 19:51 - 2013-08-23 01:26 - 00000000 ____D C:\Program Files\Windows Journal
2015-05-14 03:06 - 2015-05-05 15:04 - 00000000 ____D C:\Windows\system32\MRT
2015-05-14 03:05 - 2015-05-05 15:04 - 140425016 ____N (Microsoft Corporation) C:\Windows\system32\MRT.exe
==================== Files in the root of some directories =======
2015-05-05 11:09 - 2015-05-05 11:09 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some files in TEMP:
====================
C:\Users\Dennis\AppData\Local\Temp\avgnt.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-06-10 14:34
==================== End of log ============================ [CODE]Additional
FRST Logfile: Code:
scan result of Farbar Recovery Scan Tool (x64) Version:08-06-2015
Ran by Dennis at 2015-06-10 17:03:14
Running from D:\Dennis\Downloads
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-3748175176-1344429532-2253105022-500 - Administrator - Disabled)
Dennis (S-1-5-21-3748175176-1344429532-2253105022-1001 - Administrator - Enabled) => C:\Users\Dennis
Gast (S-1-5-21-3748175176-1344429532-2253105022-501 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.007.20033 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.188 - Adobe Systems Incorporated)
AdVenture Capitalist (HKLM-x32\...\Steam App 346900) (Version: - Hyper Hippo Games)
Avast Internet Security (HKLM-x32\...\Avast) (Version: 10.2.2218 - AVAST Software)
Besiege (HKLM-x32\...\Steam App 346010) (Version: - Spiderling Studios)
Borderlands 2 (HKLM-x32\...\Steam App 49520) (Version: - Gearbox Software)
BOSS (HKLM-x32\...\BOSS) (Version: 2.1.1 - BOSS Development Team)
Call of Duty: Black Ops II - Multiplayer (HKLM-x32\...\Steam App 202990) (Version: - Treyarch)
Call of Duty: Black Ops II - Zombies (HKLM-x32\...\Steam App 212910) (Version: - )
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.4.5143 - CDBurnerXP)
Cheat Engine 6.4 (HKLM-x32\...\Cheat Engine 6.4_is1) (Version: - Cheat Engine)
Classic Shell (HKLM\...\{7C129CF8-199F-4269-AAEE-60B5D8D716E2}) (Version: 4.2.1 - IvoSoft)
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve)
Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version: - Valve)
Don't Starve Together Beta (HKLM-x32\...\Steam App 322330) (Version: - Klei Entertainment)
Dota 2 (HKLM-x32\...\Steam App 570) (Version: - Valve)
Dragon Age: Origins (HKLM-x32\...\{AEC81925-9C76-4707-84A9-40696C613ED3}) (Version: 1.05.0.0 - Electronic Arts)
Duke Nukem Forever (HKLM-x32\...\Steam App 57900) (Version: - Gearbox Software)
Dying Light (HKLM-x32\...\Steam App 239140) (Version: - Techland)
Far Cry® 3 (HKLM-x32\...\Steam App 220240) (Version: - Ubisoft Montreal, Massive Entertainment, and Ubisoft Shanghai)
Fraps (remove only) (HKLM-x32\...\Fraps) (Version: - )
Game Dev Tycoon (HKLM-x32\...\Steam App 239820) (Version: - Greenheart Games)
Garry's Mod (HKLM-x32\...\Steam App 4000) (Version: - Facepunch Studios)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.124 - Google Inc.)
Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden
Grand Theft Auto V (HKLM-x32\...\Steam App 271590) (Version: - Rockstar North)
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 10.0.2.1000 - Intel Corporation)
Intel(R) Network Connections 19.5.303.0 (HKLM\...\PROSetDX) (Version: 19.5.303.0 - Intel)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 13.1.0.1058 - Intel Corporation)
Intel® Chipsatz-Gerätesoftware (x32 Version: 10.0.17 - Intel(R) Corporation) Hidden
Java 8 Update 45 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418045F0}) (Version: 8.0.450 - Oracle Corporation)
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games )
League of Legends (x32 Version: 3.0.1 - Riot Games ) Hidden
LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.2.0.328 - LogMeIn, Inc.)
LogMeIn Hamachi (x32 Version: 2.2.0.328 - LogMeIn, Inc.) Hidden
Magicka (HKLM-x32\...\Steam App 42910) (Version: - Arrowhead Game Studios)
Magicka 2 (HKLM-x32\...\Steam App 238370) (Version: - Pieces Interactive)
Malwarebytes Anti-Malware Version 2.1.6.1022 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 3.1 (HKLM-x32\...\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation)
Minecraft (HKLM-x32\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang)
Mozilla Firefox 38.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 38.0.1 (x86 de)) (Version: 38.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 38.0.1 - Mozilla)
Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.54.10 - Black Tree Gaming)
Nosgoth (HKLM-x32\...\Steam App 200110) (Version: 150516.109666 - Square Enix Ltd)
NVIDIA 3D Vision Controller-Treiber 349.95 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 349.95 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 350.12 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 350.12 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.4.1.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.4.1.21 - NVIDIA Corporation)
NVIDIA Grafiktreiber 350.12 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 350.12 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.33.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.33.0 - NVIDIA Corporation)
NVIDIA Miracast Virtueller Ton 350.12 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Miracast.VirtualAudio) (Version: 350.12 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\...\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation)
Opera Stable 29.0.1795.54600 (HKLM-x32\...\Opera 29.0.1795.54600) (Version: 29.0.1795.54600 - Opera Software ASA)
Origin (HKLM-x32\...\Origin) (Version: 9.5.12.2862 - Electronic Arts, Inc.)
ORION: Prelude (HKLM-x32\...\Steam App 104900) (Version: - Spiral Game Studios)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7443 - Realtek Semiconductor Corp.)
Robocraft (HKLM-x32\...\Steam App 301520) (Version: - Freejam)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.1.6.0 - Rockstar Games)
Rust (HKLM-x32\...\Steam App 252490) (Version: - Facepunch Studios)
Samsung Magician (HKLM-x32\...\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 4.5.1 - Samsung Electronics)
SHIELD Streaming (Version: 4.1.1000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.4.1.21 - NVIDIA Corporation) Hidden
Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version: - 2K Games, Inc.)
Skype™ 7.5 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.5.102 - Skype Technologies S.A.)
Sonic Radar II (HKLM\...\{203BCA8D-BC00-4DD5-85DF-2F84DB803B57}) (Version: 2.1.701 - ASUSTeKcomputer.Inc)
Space Engineers (HKLM-x32\...\Steam App 244850) (Version: - Keen Software House)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Surgeon Simulator (HKLM-x32\...\Steam App 233720) (Version: - Bossa Studios)
TeamSpeak 3 Client (HKU\S-1-5-21-3748175176-1344429532-2253105022-1001\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
The Elder Scrolls Online (HKLM-x32\...\The Elder Scrolls Online) (Version: 1.0.0.0 - Zenimax Online Studios)
The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version: - Bethesda Game Studios)
The Ship (HKLM-x32\...\Steam App 2400) (Version: - Outerlight Ltd.)
Tomb Raider (HKLM-x32\...\Steam App 203160) (Version: - Crystal Dynamics)
Unturned (HKLM-x32\...\Steam App 304930) (Version: - Nelson Sexton)
Uplay (HKLM-x32\...\Uplay) (Version: 2.0 - Ubisoft)
XCOM: Enemy Unknown (HKLM-x32\...\Steam App 200510) (Version: - Firaxis Games)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== Restore Points =========================
02-06-2015 12:21:32 DirectX wurde installiert
03-06-2015 20:20:26 DirectX wurde installiert
07-06-2015 03:38:08 DirectX wurde installiert
10-06-2015 14:34:23 Windows Update
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {046F560B-DF3C-439E-8645-35BD74824157} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-05-14] (Microsoft Corporation)
Task: {0C7F0D09-523E-46D4-B14F-03C618028925} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-05-29] (Google Inc.)
Task: {10A03563-6635-4154-8F14-3CCAC8440A9C} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation)
Task: {14AFF6C5-9F78-4C37-8E2C-C1986118ADF4} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-03-07] (Adobe Systems Incorporated)
Task: {2F320BC9-ED89-4229-8A3F-252E195F7BED} - System32\Tasks\SamsungMagician => C:\Program Files (x86)\Samsung\Samsung Magician\Samsung Magician.exe [2014-09-28] (Samsung Electronics.)
Task: {35FBA7EA-D050-4695-92C4-6AF879989F75} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-05-06] (Microsoft Corporation)
Task: {523EA322-952F-40D4-AD08-F8C333DB5D54} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-05-05] (Avast Software s.r.o.)
Task: {5476852B-DE82-44DA-AD40-F107B25F8332} - System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => C:\Windows\system32\compattel\DiagTrackRunner.exe [2015-03-16] (Microsoft Corporation)
Task: {58642523-32F8-49A1-8D0C-565ECAE5C70B} - System32\Tasks\Opera scheduled Autoupdate 1432482065 => C:\Program Files (x86)\Opera\launcher.exe [2015-05-21] (Opera Software)
Task: {6F3FA118-679E-4E95-A6CC-B790D0A5A89F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-05-29] (Google Inc.)
Task: {7B27AAD3-3C87-40A9-A88B-038EF79A89F5} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation)
Task: {9B98E97E-D2F8-4514-8DAD-91DD650E8E8B} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => schtasks
Task: {D39CBFE6-8821-4BE6-9527-F512A8036607} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-05-21] (Adobe Systems Incorporated)
Task: {D443CF85-9FB6-4E12-8BB2-A7AA1A919F97} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\Logon => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (Whitelisted) ==============
2015-05-05 18:18 - 2015-05-05 18:18 - 00104400 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2015-05-05 18:18 - 2015-05-05 18:18 - 00081728 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2015-06-10 14:38 - 2015-06-10 14:38 - 02953216 _____ () C:\Program Files\AVAST Software\Avast\defs\15061000\algo.dll
2015-05-05 18:18 - 2015-05-05 18:18 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-04-29 16:23 - 2014-04-29 16:23 - 01241560 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\Users\Dennis\OneDrive:ms-properties
==================== Safe Mode (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service"
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3748175176-1344429532-2253105022-1001\Control Panel\Desktop\\Wallpaper -> D:\Dennis\Desktop\bioshock_big_daddy_palm_glass_21783_3840x2160.jpg
DNS Servers: 192.168.2.1
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{3744718E-D799-4763-B95D-85F41D19D657}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{E0AC06FC-65EC-4950-81C9-A640645A9AF0}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{7840B4FD-8B2B-4404-8C34-4F5DE269624E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{31401E8A-39B3-4778-8D57-63A5968CB941}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{C4F5101F-2B47-4A71-9909-B38E1A0501D0}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{E9AABAC4-7294-4EA8-811F-F2FF31E099D4}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{1A5F3D81-51E8-49BE-84CC-368CCD3ED176}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{CB6BCE09-F23D-487E-AC09-F7184ADB7EAA}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [TCP Query User{257802CF-F548-41DB-A809-52FA4676CA93}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{FB01639F-9C04-4E42-AC54-753F704ED50A}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{0690D316-13E9-49FE-8B20-6D450AAA0B33}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{02B68157-9B50-4C56-9510-4DF26CB82D1C}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [TCP Query User{99FB1FAA-3366-4AA6-8F51-9376F0289CA1}C:\users\dennis\appdata\local\temp\i1430919478\windows\resource\jre\bin\javaw.exe] => (Allow) C:\users\dennis\appdata\local\temp\i1430919478\windows\resource\jre\bin\javaw.exe
FirewallRules: [UDP Query User{29DDEE80-737B-4033-A7CB-1AFC3D39D4FB}C:\users\dennis\appdata\local\temp\i1430919478\windows\resource\jre\bin\javaw.exe] => (Allow) C:\users\dennis\appdata\local\temp\i1430919478\windows\resource\jre\bin\javaw.exe
FirewallRules: [TCP Query User{DC3F395A-1BD8-43C4-8F2E-9FDF0C4DB818}D:\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) D:\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{BEE2D7AB-3B7D-4F19-B3D6-9742C10A6839}D:\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) D:\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [TCP Query User{12C55565-8A63-4F84-B862-91EC15705DF2}C:\program files\java\jre1.8.0_45\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_45\bin\javaw.exe
FirewallRules: [UDP Query User{94957F61-6EE5-45D5-A1B0-1CDDF0AC0543}C:\program files\java\jre1.8.0_45\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_45\bin\javaw.exe
FirewallRules: [{75608880-B7E5-4FD5-B5DA-5130B3654236}] => (Allow) D:\SteamLibrary\steamapps\common\Game Dev Tycoon\nw.exe
FirewallRules: [{FC7C1619-DA7A-4AE9-8B60-AADC4811F331}] => (Allow) D:\SteamLibrary\steamapps\common\Game Dev Tycoon\nw.exe
FirewallRules: [{435D3696-7F20-45FF-82AA-34A1297DFE73}] => (Allow) D:\SteamLibrary\steamapps\common\Orion Dino Beatdown\Binaries\Win32\DinoHordeGame.exe
FirewallRules: [{EAC9EF9D-BE3A-4838-8013-C4250B252EA8}] => (Allow) D:\SteamLibrary\steamapps\common\Orion Dino Beatdown\Binaries\Win32\DinoHordeGame.exe
FirewallRules: [{8837AA61-FF47-4DE8-9626-9D9F82585454}] => (Allow) D:\SteamLibrary\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{3BBCD815-FC44-4939-B89F-FF190AEF8B0A}] => (Allow) D:\SteamLibrary\steamapps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{6C4E87DD-ED5D-41A5-9977-330483B415B9}] => (Allow) D:\SteamLibrary\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe
FirewallRules: [{EA97517E-DBD9-4740-9B8A-DFF368A12091}] => (Allow) D:\SteamLibrary\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe
FirewallRules: [TCP Query User{411D758B-40AB-4C5A-9EF9-813D5EF7C33D}D:\steamlibrary\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\steamlibrary\steamapps\common\grand theft auto v\gta5.exe
FirewallRules: [UDP Query User{CE34E450-108C-453A-9CB4-0FCB211B9C18}D:\steamlibrary\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\steamlibrary\steamapps\common\grand theft auto v\gta5.exe
FirewallRules: [{2107C742-B3FE-4224-BE2D-BC05BA11E49C}] => (Allow) D:\SteamLibrary\steamapps\common\Far Cry 3\bin\FC3UpdaterSteam.exe
FirewallRules: [{99F96F72-4777-47C6-BA03-C9FA4BF3B1D3}] => (Allow) D:\SteamLibrary\steamapps\common\Far Cry 3\bin\FC3UpdaterSteam.exe
FirewallRules: [{BA0DCAB8-A288-4C56-BAB4-1B64FB5398C1}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{954741F1-51CD-40FB-B6B5-D521B1D04F05}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{8807A463-12BA-4193-8573-7EBFE2E4FE06}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{31B6ECE8-CE28-4DBE-86F3-8AF1968375A1}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{6EDBDCBA-1D1E-4337-80CD-7DDA9B07E7AE}] => (Allow) D:\SteamLibrary\steamapps\common\Far Cry 3\bin\farcry3.exe
FirewallRules: [{24281EF8-AF5B-4741-8E00-717E6DB77EF8}] => (Allow) D:\SteamLibrary\steamapps\common\Far Cry 3\bin\farcry3.exe
FirewallRules: [{FA2811EA-673C-4897-8A0E-1DD94407A118}] => (Allow) D:\SteamLibrary\steamapps\common\Far Cry 3\bin\farcry3_d3d11.exe
FirewallRules: [{C9782A76-23DE-4617-AC81-72433D924E90}] => (Allow) D:\SteamLibrary\steamapps\common\Far Cry 3\bin\farcry3_d3d11.exe
FirewallRules: [{CE84F77E-55F8-4FEC-9CBF-5F17E824E575}] => (Allow) D:\SteamLibrary\steamapps\common\Tomb Raider\TombRaider.exe
FirewallRules: [{2EEDDF92-887A-41A7-8CAF-4F076F5DB32D}] => (Allow) D:\SteamLibrary\steamapps\common\Tomb Raider\TombRaider.exe
FirewallRules: [{D16A54E4-3011-4C4B-991C-E77E3200CA20}] => (Allow) D:\SteamLibrary\steamapps\common\Magicka\Magicka.exe
FirewallRules: [{103443C4-E79A-449E-9B5E-B265A6787058}] => (Allow) D:\SteamLibrary\steamapps\common\Magicka\Magicka.exe
FirewallRules: [{778EC02B-F231-4CF2-95D8-94CEC0FB94C3}] => (Allow) D:\SteamLibrary\steamapps\common\Unturned\Unturned.exe
FirewallRules: [{197797D6-9449-4AA0-A08A-4FC3C0359366}] => (Allow) D:\SteamLibrary\steamapps\common\Unturned\Unturned.exe
FirewallRules: [{D333B82B-D6BB-461D-84BA-AD6F0A89FD90}] => (Allow) D:\Origin\Spiele\Dragon Age\bin_ship\daorigins.exe
FirewallRules: [{17D04566-55A7-4602-9937-C14155527E38}] => (Allow) D:\Origin\Spiele\Dragon Age\bin_ship\daorigins.exe
FirewallRules: [{FD9BC7DD-5325-4EE6-B874-FE8D7231EFF1}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\dota.exe
FirewallRules: [{A4149809-7277-4FAB-A937-4EC18C3BA4A7}] => (Allow) D:\SteamLibrary\steamapps\common\dota 2 beta\dota.exe
FirewallRules: [TCP Query User{988892C7-1132-496A-B0FB-2B020440D988}C:\users\dennis\appdata\local\vghd\bin\virtuagirl_downloader.exe] => (Allow) C:\users\dennis\appdata\local\vghd\bin\virtuagirl_downloader.exe
FirewallRules: [UDP Query User{06EB1FC0-000A-43D3-8983-B660DBB42214}C:\users\dennis\appdata\local\vghd\bin\virtuagirl_downloader.exe] => (Allow) C:\users\dennis\appdata\local\vghd\bin\virtuagirl_downloader.exe
FirewallRules: [{F0F9BE2D-8C63-4118-A5F0-B44B2AA8440C}] => (Allow) D:\SteamLibrary\steamapps\common\Rust\Rust.exe
FirewallRules: [{095188DA-14F1-4B11-B04C-6CAC003898A8}] => (Allow) D:\SteamLibrary\steamapps\common\Rust\Rust.exe
FirewallRules: [{6A498206-C45E-4498-BF0F-DBC836667343}] => (Allow) D:\SteamLibrary\steamapps\common\The Ship\ship.exe
FirewallRules: [{5D0CDE48-00ED-4BDB-BC3A-F21F29860343}] => (Allow) D:\SteamLibrary\steamapps\common\The Ship\ship.exe
FirewallRules: [{00812D90-BB5F-486E-AE8D-156D4461D397}] => (Allow) C:\Users\Dennis\AppData\Local\BoBrowser\Application\bobrowser.exe
FirewallRules: [{F30406D8-6FF2-4444-9F01-A822CDD5EB5E}] => (Allow) C:\Program Files (x86)\speed browser\Application\browser.exe
FirewallRules: [{F98831EE-00B6-4C18-AB36-6BE6CECDC854}] => (Allow) D:\SteamLibrary\steamapps\common\nosgoth\Binaries\Win32\Nosgoth.exe
FirewallRules: [{9AD92671-269D-441E-B8A4-FE114F740CF1}] => (Allow) D:\SteamLibrary\steamapps\common\nosgoth\Binaries\Win32\Nosgoth.exe
FirewallRules: [{E9BBC50D-7304-43A2-B629-CEF75FF397A1}] => (Allow) D:\SteamLibrary\steamapps\common\Call of Duty Black Ops II\t6zm.exe
FirewallRules: [{74931CE2-C86C-403E-8F2E-8E750337EBCA}] => (Allow) D:\SteamLibrary\steamapps\common\Call of Duty Black Ops II\t6zm.exe
FirewallRules: [{AC903A27-C3D4-4228-AA7B-BE2B596BDC82}] => (Allow) D:\SteamLibrary\steamapps\common\Call of Duty Black Ops II\t6mp.exe
FirewallRules: [{8692278E-8C91-4DF8-983F-34DAFF33B580}] => (Allow) D:\SteamLibrary\steamapps\common\Call of Duty Black Ops II\t6mp.exe
FirewallRules: [{2529F8D8-DE11-4E59-8354-0C3C63C6DD97}] => (Allow) D:\SteamLibrary\steamapps\common\SpaceEngineers\Bin64\SpaceEngineers.exe
FirewallRules: [{631E7BA0-3133-4510-ADE4-975575EC17FD}] => (Allow) D:\SteamLibrary\steamapps\common\SpaceEngineers\Bin64\SpaceEngineers.exe
FirewallRules: [{3549519A-E7D1-4019-92AA-85E39EED65E6}] => (Allow) D:\SteamLibrary\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{B9F6C067-537E-4943-9208-CAE260815498}] => (Allow) D:\SteamLibrary\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{4B6AD024-4473-45BF-B994-456291FF087B}] => (Allow) D:\SteamLibrary\steamapps\common\Surgeon Simulator 2013\ss2013.exe
FirewallRules: [{45C82C11-A6F2-4AAD-AD0E-719F91841BCF}] => (Allow) D:\SteamLibrary\steamapps\common\Surgeon Simulator 2013\ss2013.exe
FirewallRules: [{95847D20-2E20-49D9-8584-A2C3ADCF97C4}] => (Allow) D:\SteamLibrary\steamapps\common\Dying Light\DyingLightGame.exe
FirewallRules: [{9133C841-6D51-4CEF-ABB1-EF35905AC76A}] => (Allow) D:\SteamLibrary\steamapps\common\Dying Light\DyingLightGame.exe
FirewallRules: [{0211F2C4-9A31-4845-9678-7C3D0242DE47}] => (Allow) D:\SteamLibrary\steamapps\common\Dying Light\DevTools\DyingLightPlayer.exe
FirewallRules: [{4352C93D-45AB-4460-A61B-2C94B0F7779C}] => (Allow) D:\SteamLibrary\steamapps\common\Dying Light\DevTools\DyingLightPlayer.exe
FirewallRules: [{F1F3F163-FB55-4096-A52B-F2C1DE0AD7DB}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{FB515FC1-A1E1-4571-9D9B-1E338D6C329A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{1DF39BDA-DFBA-4974-8463-3736C4C9F29C}] => (Allow) D:\SteamLibrary\steamapps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [{ED9DD987-A8A2-4C23-826D-AE7C9BE7E291}] => (Allow) D:\SteamLibrary\steamapps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [{2241FAAE-6454-48D1-8352-6BB99B4655DA}] => (Allow) D:\SteamLibrary\steamapps\common\AdVenture Capitalist\adventure-capitalist.exe
FirewallRules: [{9216C8AA-B000-4C50-AF49-A292A5DBEDDD}] => (Allow) D:\SteamLibrary\steamapps\common\AdVenture Capitalist\adventure-capitalist.exe
FirewallRules: [{1D4CAB6E-D036-42F4-9241-25238BC007D8}] => (Allow) D:\SteamLibrary\steamapps\common\Besiege\Besiege.exe
FirewallRules: [{0E353840-0C05-4C7C-8DEE-815CCB7695AE}] => (Allow) D:\SteamLibrary\steamapps\common\Besiege\Besiege.exe
FirewallRules: [{E142B5F3-2B4F-4597-B545-114ABB66C951}] => (Allow) D:\SteamLibrary\steamapps\common\Duke Nukem Forever\System\DukeForever.exe
FirewallRules: [{E2AF744D-41B5-4B7D-B005-154DBBA838A5}] => (Allow) D:\SteamLibrary\steamapps\common\Duke Nukem Forever\System\DukeForever.exe
FirewallRules: [{FECC43E9-F13C-446C-BB2F-741F5F00AE13}] => (Allow) D:\SteamLibrary\steamapps\common\XCom-Enemy-Unknown\Binaries\Win32\XComGame.exe
FirewallRules: [{C0768A0C-5721-41CA-BDB6-49916224D089}] => (Allow) D:\SteamLibrary\steamapps\common\XCom-Enemy-Unknown\Binaries\Win32\XComGame.exe
FirewallRules: [{A1008A8F-7DFB-45C4-9E98-BA364D10F838}] => (Allow) D:\SteamLibrary\steamapps\common\GarrysMod\hl2.exe
FirewallRules: [{B0C827E2-226E-4AD9-8950-DC5348AEC338}] => (Allow) D:\SteamLibrary\steamapps\common\GarrysMod\hl2.exe
FirewallRules: [{508B21D4-7CFB-4EF6-B07D-DD5D4B586E8A}] => (Allow) D:\SteamLibrary\steamapps\common\Counter-Strike Source\hl2.exe
FirewallRules: [{8573E1E3-D076-46D9-A498-966D4317F47F}] => (Allow) D:\SteamLibrary\steamapps\common\Counter-Strike Source\hl2.exe
FirewallRules: [{8B119107-4517-4CBD-81A6-7FEE3ECB89C8}] => (Allow) D:\SteamLibrary\steamapps\common\Borderlands 2\Binaries\Win32\Launcher.exe
FirewallRules: [{4ADAADDC-A19A-4BD2-AAA4-0F6EFC47B433}] => (Allow) D:\SteamLibrary\steamapps\common\Borderlands 2\Binaries\Win32\Launcher.exe
FirewallRules: [{4922B5B1-15BE-4390-9593-EE98ECB4B84F}] => (Allow) D:\SteamLibrary\steamapps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe
FirewallRules: [{FE43BC3C-472E-477C-8AF9-F111EB1CE079}] => (Allow) D:\SteamLibrary\steamapps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe
FirewallRules: [{97F5525D-BCCE-43D2-B181-8F710179027C}] => (Allow) C:\Program Files (x86)\speed browser\Application\browser.exe
FirewallRules: [{5B893522-383D-4BF9-8440-D4BB7633BF76}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{91C1FCAE-F591-4006-89FD-767D34F834F0}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{C0314C0F-8A08-47FD-80C5-867345A20E1D}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{904C2C66-0437-418A-8D84-6D46EA747DEE}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{A642AAD7-BEB4-429F-A29D-BCB3638230F6}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{1484D31A-82B7-4EF7-B347-DDE482ED783E}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{96F48ADB-1E89-4673-8584-CAFC0AB99DBB}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{615BE743-8D37-4E63-992F-202EC86D6AD8}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{2D0313E3-53BA-460E-B85B-0750CD49428F}] => (Allow) D:\SteamLibrary\steamapps\common\Robocraft\Robocraft.exe
FirewallRules: [{8F20AC26-DFC0-4949-B9D6-928303D176D7}] => (Allow) D:\SteamLibrary\steamapps\common\Robocraft\Robocraft.exe
FirewallRules: [{D28D728E-EB67-4612-AA23-FB2889C160A8}] => (Allow) D:\SteamLibrary\steamapps\common\Don't Starve Together\bin\dontstarve_steam.exe
FirewallRules: [{F86A5164-B7DD-460E-AB9E-D6699166D984}] => (Allow) D:\SteamLibrary\steamapps\common\Don't Starve Together\bin\dontstarve_steam.exe
FirewallRules: [{21FACEED-7993-4E42-B178-4CB30FAD7DEA}] => (Allow) D:\SteamLibrary\steamapps\common\Magicka 2\engine\Magicka2.exe
FirewallRules: [{E18D13E6-C470-49CD-95B0-39A9C2470771}] => (Allow) D:\SteamLibrary\steamapps\common\Magicka 2\engine\Magicka2.exe
FirewallRules: [{7F87DDD9-FFDC-46E5-AEA3-DFADDBE350D7}] => (Allow) D:\SteamLibrary\steamapps\common\nosgoth\Binaries\Win32\Nosgoth.exe
FirewallRules: [{B2F0D6AE-42FA-462E-AF00-E0CE5DE96D43}] => (Allow) D:\SteamLibrary\steamapps\common\nosgoth\Binaries\Win32\Nosgoth.exe
FirewallRules: [{C46520C6-91B7-4560-BDC0-6EB792253258}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Faulty Device Manager Devices =============
Name: avast! SecureLine TAP Adapter v3
Description: avast! SecureLine TAP Adapter v3
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: TAP-Windows Provider V9
Service: aswTap
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (06/10/2015 04:08:51 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcFailed continue stopping. [6]
Error: (06/10/2015 01:40:21 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcFailed continue stopping. [6]
Error: (06/09/2015 02:12:26 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcFailed continue stopping. [6]
Error: (06/08/2015 11:51:49 AM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcFailed continue stopping. [5]
Error: (06/07/2015 08:52:09 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm UNKNOWN, Version 0.0.0.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 10bc
Startzeit: 01d0a136cd60d702
Endzeit: 50
Anwendungspfad: UNKNOWN
Berichts-ID: 49c3a5c5-0d46-11e5-827e-f07959609d4b
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (06/07/2015 02:49:46 PM) (Source: Adobe Reader) (EventID: 16) (User: )
Description:
Error: (06/07/2015 01:26:57 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcFailed continue stopping. [6]
Error: (06/06/2015 10:54:33 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: GWXUX.exe, Version: 6.3.9600.17813, Zeitstempel: 0x554a15f3
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.3.9600.17736, Zeitstempel: 0x550f4336
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000000000003d85e
ID des fehlerhaften Prozesses: 0x1464
Startzeit der fehlerhaften Anwendung: 0xGWXUX.exe0
Pfad der fehlerhaften Anwendung: GWXUX.exe1
Pfad des fehlerhaften Moduls: GWXUX.exe2
Berichtskennung: GWXUX.exe3
Vollständiger Name des fehlerhaften Pakets: GWXUX.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: GWXUX.exe5
Error: (06/06/2015 10:54:32 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcFailed continue stopping. [0]
Error: (06/06/2015 02:31:01 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcFailed continue stopping. [5]
System errors:
=============
Error: (06/10/2015 04:59:33 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Intel(R) Dynamic Application Loader Host Interface Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (06/10/2015 04:59:33 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Intel(R) Rapid Storage Technology" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (06/10/2015 04:59:32 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Steam Client Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (06/10/2015 04:59:32 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "LogMeIn Hamachi Tunneling Engine" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (06/10/2015 04:59:32 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "PnkBstrA" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (06/10/2015 04:59:31 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "NVIDIA Streamer Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (06/10/2015 04:59:31 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "NVIDIA Network Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (06/10/2015 04:59:31 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "MBAMService" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (06/10/2015 04:59:31 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "MBAMScheduler" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (06/10/2015 04:59:31 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Intel(R) PROSet Monitoring Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Microsoft Office:
=========================
Error: (06/10/2015 04:08:51 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcFailed continue stopping. [6]
Error: (06/10/2015 01:40:21 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcFailed continue stopping. [6]
Error: (06/09/2015 02:12:26 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcFailed continue stopping. [6]
Error: (06/08/2015 11:51:49 AM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcFailed continue stopping. [5]
Error: (06/07/2015 08:52:09 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: UNKNOWN0.0.0.010bc01d0a136cd60d70250UNKNOWN49c3a5c5-0d46-11e5-827e-f07959609d4b
Error: (06/07/2015 02:49:46 PM) (Source: Adobe Reader) (EventID: 16) (User: )
Description:
Error: (06/07/2015 01:26:57 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcFailed continue stopping. [6]
Error: (06/06/2015 10:54:33 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: GWXUX.exe6.3.9600.17813554a15f3ntdll.dll6.3.9600.17736550f4336c0000005000000000003d85e146401d0a09afc8fa8c7C:\Windows\System32\GWX\GWXUX.exeC:\Windows\SYSTEM32\ntdll.dll3b748f9c-0c8e-11e5-827e-f07959609d4b
Error: (06/06/2015 10:54:32 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcFailed continue stopping. [0]
Error: (06/06/2015 02:31:01 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcFailed continue stopping. [5]
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i7-4790K CPU @ 4.00GHz
Percentage of memory in use: 22%
Total physical RAM: 8131.7 MB
Available physical RAM: 6271.09 MB
Total Pagefile: 11459.7 MB
Available Pagefile: 9445.77 MB
Total Virtual: 131072 MB
Available Virtual: 131071.83 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:111.27 GB) (Free:71.93 GB) NTFS
Drive d: (Daten) (Fixed) (Total:465.69 GB) (Free:160.27 GB) NTFS
Drive e: (Volume) (Fixed) (Total:465.69 GB) (Free:464.94 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 111.8 GB) (Disk ID: 00000000)
Partition: GPT Partition Type.
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 00000000)
Partition: GPT Partition Type.
==================== End of log ============================ --- --- --- |