Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Pc startet nicht mehr nach versuchtem Neutstart

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 05.02.2015, 23:47   #1
ColdPriest
 
Pc startet nicht mehr nach versuchtem Neutstart - Standard

Pc startet nicht mehr nach versuchtem Neutstart



Hallo zusammen
Ich habe eben gerade versucht meinen Lenovo G710 neuzustarten, da er anscheinend nicht richtig funktioniert hat (ein Programm hat sich nich geöffnet). Als der Laptop wieder hochgefahren ist, erschien eine Nachricht auf dem Bildschirm, dass der Laptop beschädigt wäre oder so ähnlich (ich weiß den Wortlaut nicht mehr auswendig). Da der Laptop erst 2 Tage alt ist, erscheint es mir unwahrscheinlich, dass er wirklich beschädigt ist, ansonsten werde ich mit lenovo Kontakt aufnehmen müssen. Gedownloaded habe ich nichts besonderes mit dem Laptop nur die notwendigen Programme Adobe Flash Player, Teamspeak etc. alles von der jeweiligen Homepage des Anbieters. Da ich einmal Daten per USB Stick von meinem Rechner auf den Laptop gezogen habe könnte ich mir nun vorstellen, dass dadurch vielleicht ein Virus oder Ähnliches darauf gekommen ist. Jetzt möchte ich aber auch nicht auf besagten Rechner Programme downloaden um den Laptop zu überprüfen, dadurch ja nicht geholfen wäre. Die Daten die ich rübergezogen habe sind 100% virenfrei, aber vielleicht hat sich irgendwas im Hintergrund auf den USB Stick kopiert( man weiß ja nie). Auf jeden Fall habe ich auf dem Laptop jetzt einen schwarzen Bildschirm und den lenovo Schriftzug darauf, weiter passiert erstmal nichts (falls sich etwas tut berichte ich). Eine Möglichkeit an einen "sauberen" Rechner zu gelangen habe ich im Moment nicht. Der Laptop läuft mit Windows 8.
Ich hoffe ihr könnt mir helfen und schonmal Danke im Vorraus.
ColdPriest

Alt 05.02.2015, 23:56   #2
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Pc startet nicht mehr nach versuchtem Neutstart - Standard

Pc startet nicht mehr nach versuchtem Neutstart



Hallo und

Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die mal fündig geworden?

Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520

Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs in CODE-Tags posten!
Relevant sind nur Logs der letzten 7 Tage bzw. seitdem das Problem besteht!




Zudem bitte auch ein Log mit Farbars Tool machen:

Scan mit Farbar's Recovery Scan Tool (FRST)

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)



Lesestoff:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit.
Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten.
Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
__________________

__________________

Alt 06.02.2015, 00:15   #3
ColdPriest
 
Pc startet nicht mehr nach versuchtem Neutstart - Standard

Pc startet nicht mehr nach versuchtem Neutstart



Die FRST.txt:


FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-02-2015
Ran by NicoHupe (administrator) on COLDPRIEST on 06-02-2015 00:09:11
Running from C:\Users\NicoHupe\Desktop
Loaded Profiles: NicoHupe (Available profiles: NicoHupe)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(ABBYY) C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
() C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
() C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
(Advanced Micro Devices, Inc.) C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe
(Logitech Inc.) C:\Program Files\Logitech\GamePanel Software\LGDevAgt.exe
(Logitech Inc.) C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
(Logitech Inc.) C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
(Razer Inc) C:\Program Files (x86)\Razer\Razer_Kraken0502_Driver\Drivers\SysAudio\Kraken0502SysAudioLauncher.exe
(Logitech Inc.) C:\Program Files\Logitech\GamePanel Software\Applets\LCDCountdown.exe
(Comodo Security Solutions, Inc.) C:\Program Files\COMODO\GeekBuddy\unit_manager.exe
(Logitech Inc.) C:\Program Files\Logitech\GamePanel Software\Applets\LCDClock.exe
(Logitech Inc.) C:\Program Files\Logitech\GamePanel Software\Applets\LCDPop3.exe
(Logitech Inc.) C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Comodo Security Solutions, Inc.) C:\Program Files\COMODO\GeekBuddy\unit.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\WMPSideShowGadget.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
(Blizzard Entertainment) C:\ProgramData\Battle.net\Agent\Agent.3715\Agent.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [NUSB3MON] => c:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe [97280 2012-04-11] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [Launch LgDeviceAgent] => C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe [415816 2010-06-11] (Logitech Inc.)
HKLM\...\Run: [Launch LCDMon] => C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe [2413128 2010-06-11] (Logitech Inc.)
HKLM\...\Run: [Launch LGDCore] => C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe [4725320 2010-06-11] (Logitech Inc.)
HKLM\...\Run: [COMODO Internet Security] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1297624 2015-02-03] (COMODO)
HKLM-x32\...\Run: [tvncontrol] => C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2014-09-24] (Comodo Security Solutions, Inc.)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3977576 2015-01-20] (LogMeIn Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [585536 2015-01-26] (Razer Inc.)
HKLM-x32\...\Run: [Kraken0502Launcher] => C:\Program Files (x86)\Razer\Razer_Kraken0502_Driver\Drivers\SysAudio\Kraken0502SysAudioLauncher.exe [865088 2015-01-26] (Razer Inc)
HKU\S-1-5-21-2974583261-1939293177-1460826959-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2874560 2015-02-06] (Valve Corporation)
HKU\S-1-5-21-2974583261-1939293177-1460826959-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [30878816 2014-12-11] (Skype Technologies S.A.)
HKU\S-1-5-21-2974583261-1939293177-1460826959-1000\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-2974583261-1939293177-1460826959-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7394584 2015-01-25] (Piriform Ltd)
HKU\S-1-5-21-2974583261-1939293177-1460826959-1000\...\MountPoints2: {0edb3181-26a3-11e4-a679-40167e6366c8} - F:\autorun.exe
HKU\S-1-5-21-2974583261-1939293177-1460826959-1000\...\MountPoints2: {ca0caf7f-bbe6-11e3-b955-806e6f6e6963} - D:\autoplay.exe
HKU\S-1-5-21-2974583261-1939293177-1460826959-1000\...\MountPoints2: {d1d68035-ef3a-11e3-bb69-40167e6366c8} - F:\setup.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
ShortcutTarget: Start GeekBuddy.lnk -> C:\Program Files\COMODO\GeekBuddy\launcher.exe (Comodo Security Solutions, Inc.)
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-2974583261-1939293177-1460826959-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-2974583261-1939293177-1460826959-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://localoem.msn.com
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\..\Interfaces\{3FD63A9C-BFEC-499C-861C-3BAF2630B2EF}: [NameServer] 156.154.70.25,156.154.71.25

FireFox:
========
FF ProfilePath: C:\Users\NicoHupe\AppData\Roaming\Mozilla\Firefox\Profiles\11lc8a2b.default
FF SelectedSearchEngine: Trovi search
FF Homepage: google.de
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll ()
FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2974583261-1939293177-1460826959-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF SearchPlugin: C:\Users\NicoHupe\AppData\Roaming\Mozilla\Firefox\Profiles\11lc8a2b.default\searchplugins\trovi-search.xml

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)
R2 CLPSLauncher; C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe [70864 2014-09-25] (Comodo Security Solutions, Inc.)
R2 CmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [7618952 2015-02-03] (COMODO)
R3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2265304 2015-02-03] (COMODO)
R2 DragonUpdater; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [2135232 2014-01-28] ()
R2 EPSON_EB_RPCV4_04; C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE [166400 2009-09-14] (SEIKO EPSON CORPORATION) [File not signed]
R2 EPSON_PM_RPCV4_04; C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE [128512 2009-09-14] (SEIKO EPSON CORPORATION) [File not signed]
R2 GeekBuddyRSP; C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2014-09-24] (Comodo Security Solutions, Inc.)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2015-01-14] (LogMeIn, Inc.)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1903472 2015-01-22] (Electronic Arts)
R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [186048 2014-12-09] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-11-18] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36096 2013-05-21] (Advanced Micro Devices, Inc.)
R1 CFRMD; C:\Windows\System32\DRIVERS\CFRMD.sys [37976 2014-06-26] (Windows (R) Win 7 DDK provider) [File not signed]
S3 CH375_A64; C:\Windows\System32\Drivers\CH375W64.SYS [29056 2011-03-13] (www.winchiphead.com)
R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [20184 2015-01-30] (COMODO)
R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [792648 2015-01-30] (COMODO)
R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [45880 2015-01-30] (COMODO)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-08-18] (Disc Soft Ltd)
S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [43664 2015-01-10] ()
R1 HMD; C:\Windows\System32\DRIVERS\hmd.sys [14888 2014-06-26] ()
R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [104608 2015-01-30] (COMODO)
R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [37184 2014-12-09] (Razer, Inc.)
R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [129600 2014-12-10] (Razer, Inc.)
S3 DIRECTIO; \??\UNC\srv1c027-b.wds8-b.intern\reminst\Test\BitPro64\DirectIo.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 RTL8192cu; system32\DRIVERS\rtwlanu.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-06 00:09 - 2015-02-06 00:09 - 00014930 _____ () C:\Users\NicoHupe\Desktop\FRST.txt
2015-02-06 00:08 - 2015-02-06 00:08 - 02131968 _____ (Farbar) C:\Users\NicoHupe\Desktop\FRST64.exe
2015-02-06 00:08 - 2015-02-06 00:08 - 00000000 ____D () C:\Users\NicoHupe\AppData\Local\Steam
2015-02-04 18:56 - 2015-02-05 23:20 - 00000417 _____ () C:\Windows\setupact.log
2015-02-04 18:56 - 2015-02-04 18:56 - 00000000 _____ () C:\Windows\setuperr.log
2015-02-03 13:03 - 2015-02-03 13:09 - 00000000 ____D () C:\Users\NicoHupe\Downloads\Eluveitie
2015-01-28 20:48 - 2015-02-06 00:09 - 00000000 ____D () C:\FRST
2015-01-28 20:19 - 2015-01-28 20:19 - 00000168 _____ () C:\Users\NicoHupe\defogger_reenable
2015-01-28 20:01 - 2015-01-28 20:06 - 18570328 _____ () C:\Users\NicoHupe\Downloads\RogueKillerX64.exe
2015-01-27 16:45 - 2015-01-27 16:45 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-26 15:44 - 2015-01-26 15:44 - 00000000 ____D () C:\Users\NicoHupe\AppData\Local\Razer
2015-01-26 15:42 - 2015-01-26 15:42 - 00000000 ____D () C:\Users\NicoHupe\AppData\Local\Razer_Inc
2015-01-26 15:41 - 2014-12-10 21:43 - 00129600 _____ (Razer, Inc.) C:\Windows\system32\Drivers\rzpnk.sys
2015-01-26 15:41 - 2014-12-09 23:21 - 00037184 _____ (Razer, Inc.) C:\Windows\system32\Drivers\rzpmgrk.sys
2015-01-26 15:39 - 2015-01-26 15:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
2015-01-26 15:26 - 2015-01-26 15:41 - 00000000 ____D () C:\ProgramData\Razer
2015-01-26 15:25 - 2015-02-05 23:20 - 00000000 ____D () C:\Program Files (x86)\Razer
2015-01-25 19:58 - 2015-01-25 19:58 - 00000000 ____D () C:\ProgramData\InstallShield
2015-01-25 19:42 - 2015-01-25 19:42 - 00002778 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2015-01-25 19:42 - 2015-01-25 19:42 - 00000829 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2015-01-25 19:42 - 2015-01-25 19:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-01-25 19:42 - 2015-01-25 19:42 - 00000000 ____D () C:\Program Files\CCleaner
2015-01-25 19:30 - 2015-01-25 19:34 - 04188536 _____ (Piriform Ltd) C:\Users\NicoHupe\Downloads\ccsetup501_slim.exe
2015-01-23 17:42 - 2015-01-23 17:42 - 00000000 ____D () C:\Users\NicoHupe\Documents\Diablo III
2015-01-23 15:31 - 2015-01-23 15:31 - 00001167 _____ () C:\Users\NicoHupe\Desktop\Diablo III.lnk
2015-01-23 15:31 - 2015-01-23 15:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo III
2015-01-23 15:29 - 2015-01-23 17:42 - 00000000 ____D () C:\Program Files (x86)\Diablo III
2015-01-23 11:54 - 2015-01-23 11:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2015-01-23 11:54 - 2015-01-23 11:54 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2015-01-22 18:51 - 2015-01-22 18:51 - 00000000 ____D () C:\Users\NicoHupe\AppData\Local\SWTOR
2015-01-22 14:59 - 2015-01-22 14:59 - 00000000 ____D () C:\Users\Public\Documents\BitRaider
2015-01-22 14:59 - 2015-01-22 14:59 - 00000000 ____D () C:\Users\NicoHupe\AppData\Local\SWTORPerf
2015-01-22 14:59 - 2015-01-22 14:59 - 00000000 ____D () C:\ProgramData\BitRaider
2015-01-22 14:54 - 2015-01-22 14:54 - 00016522 _____ () C:\Users\NicoHupe\Documents\Install STAR WARS The Old Republic.log
2015-01-22 14:54 - 2015-01-22 14:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA
2015-01-22 14:54 - 2015-01-22 14:54 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts
2015-01-22 14:54 - 2015-01-22 14:54 - 00000000 _____ () C:\end
2015-01-22 14:53 - 2015-01-22 14:54 - 29720272 _____ () C:\Users\NicoHupe\Downloads\SWTOR_setup.exe
2015-01-19 20:17 - 2015-01-19 20:27 - 00000000 ____D () C:\Users\NicoHupe\AppData\Roaming\RIFT
2015-01-19 20:17 - 2015-01-19 20:17 - 00000000 ____D () C:\Users\NicoHupe\Documents\RIFT
2015-01-19 17:02 - 2015-01-19 17:09 - 00000000 ____D () C:\Users\NicoHupe\AppData\Local\ArmA 2 OA
2015-01-19 17:02 - 2015-01-19 17:06 - 00000000 ____D () C:\Users\NicoHupe\Documents\ArmA 2
2015-01-19 17:02 - 2015-01-19 17:02 - 00000000 ____D () C:\ProgramData\Bohemia Interactive Studio
2015-01-14 14:16 - 2015-01-14 14:16 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-14 14:16 - 2015-01-14 14:16 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-01-14 14:16 - 2015-01-14 14:16 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-01-14 14:16 - 2015-01-14 14:16 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-01-14 14:16 - 2015-01-14 14:16 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-14 14:16 - 2015-01-14 14:16 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-01-14 14:16 - 2015-01-14 14:16 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-14 14:16 - 2015-01-14 14:16 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-01-14 14:16 - 2015-01-14 14:16 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-14 14:16 - 2015-01-14 14:16 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-14 14:16 - 2015-01-14 14:16 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-01-14 14:16 - 2015-01-14 14:16 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-01-14 14:16 - 2015-01-14 14:16 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-01-12 15:50 - 2015-01-26 16:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2015-01-12 15:48 - 2015-01-12 15:48 - 00000000 ____D () C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2015-01-12 15:47 - 2015-01-27 16:59 - 00000000 ____D () C:\Users\NicoHupe\AppData\Local\Microsoft Help
2015-01-12 15:47 - 2015-01-26 16:44 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-01-12 15:47 - 2015-01-12 15:47 - 00000000 __RHD () C:\MSOCache
2015-01-12 15:47 - 2015-01-12 15:47 - 00000000 ____D () C:\Program Files\Microsoft Office
2015-01-12 15:47 - 2015-01-12 15:47 - 00000000 ____D () C:\Program Files (x86)\Microsoft Analysis Services
2015-01-12 13:35 - 2015-01-12 13:35 - 00000000 ____D () C:\Users\NicoHupe\AppData\Roaming\xm1
2015-01-12 13:33 - 2015-01-12 13:33 - 00001006 _____ () C:\Users\NicoHupe\Desktop\Texmaker.lnk
2015-01-12 13:33 - 2015-01-12 13:33 - 00000000 ____D () C:\Users\NicoHupe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Texmaker
2015-01-12 13:33 - 2015-01-12 13:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Texmaker
2015-01-12 13:33 - 2015-01-12 13:33 - 00000000 ____D () C:\Program Files (x86)\Texmaker
2015-01-10 20:06 - 2015-01-10 20:06 - 00043664 _____ () C:\Windows\system32\Drivers\hitmanpro37.sys
2015-01-10 16:33 - 2015-01-10 16:33 - 00000000 ____D () C:\Users\NicoHupe\Desktop\Minecraft Mod
==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-06 00:08 - 2014-12-16 20:14 - 00310396 _____ () C:\Windows\system32\Drivers\fvstore.dat
2015-02-06 00:08 - 2014-12-15 22:27 - 01474832 _____ () C:\Windows\system32\Drivers\sfi.dat
2015-02-06 00:08 - 2014-04-22 19:24 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-02-06 00:07 - 2014-05-20 15:09 - 00000000 ____D () C:\Users\NicoHupe\AppData\Local\Battle.net
2015-02-05 23:45 - 2014-04-06 18:27 - 00000000 ____D () C:\Users\NicoHupe\AppData\Roaming\Skype
2015-02-05 23:36 - 2014-04-04 11:34 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-02-05 23:25 - 2009-07-14 05:45 - 00028720 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-05 23:25 - 2009-07-14 05:45 - 00028720 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-05 23:24 - 2011-04-12 08:43 - 00765482 _____ () C:\Windows\system32\perfh007.dat
2015-02-05 23:24 - 2011-04-12 08:43 - 00204266 _____ () C:\Windows\system32\perfc007.dat
2015-02-05 23:24 - 2009-07-14 06:13 - 01742854 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-02-05 23:20 - 2014-04-04 11:55 - 01214883 _____ () C:\Windows\WindowsUpdate.log
2015-02-05 23:19 - 2015-01-03 12:57 - 00000000 ____D () C:\Users\NicoHupe\AppData\Local\LogMeIn Hamachi
2015-02-05 23:18 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-05 19:36 - 2014-04-04 11:34 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-02-05 19:36 - 2014-04-04 11:34 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-02-05 19:36 - 2014-04-04 11:34 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-02-04 21:40 - 2014-04-04 21:03 - 00000000 ____D () C:\Users\NicoHupe\AppData\Roaming\TS3Client
2015-02-04 16:18 - 2014-04-04 13:58 - 00000000 ____D () C:\Musik
2015-02-04 13:31 - 2014-11-10 18:47 - 00000000 ____D () C:\Users\NicoHupe\Desktop\Uni
2015-02-03 18:41 - 2014-12-15 22:27 - 00001953 _____ () C:\Users\Public\Desktop\COMODO Antivirus.lnk
2015-01-30 21:09 - 2014-05-21 15:43 - 00000000 ____D () C:\Program Files (x86)\Hearthstone
2015-01-30 13:27 - 2014-12-09 00:20 - 00792648 _____ (COMODO) C:\Windows\system32\Drivers\cmdguard.sys
2015-01-30 13:27 - 2014-12-09 00:20 - 00481576 _____ (COMODO) C:\Windows\system32\guard64.dll
2015-01-30 13:27 - 2014-12-09 00:20 - 00386768 _____ (COMODO) C:\Windows\SysWOW64\guard32.dll
2015-01-30 13:27 - 2014-12-09 00:20 - 00354520 _____ (COMODO) C:\Windows\system32\cmdvrt64.dll
2015-01-30 13:27 - 2014-12-09 00:20 - 00286424 _____ (COMODO) C:\Windows\SysWOW64\cmdvrt32.dll
2015-01-30 13:27 - 2014-12-09 00:20 - 00104608 _____ (COMODO) C:\Windows\system32\Drivers\inspect.sys
2015-01-30 13:27 - 2014-12-09 00:20 - 00045880 _____ (COMODO) C:\Windows\system32\Drivers\cmdhlp.sys
2015-01-30 13:27 - 2014-12-09 00:20 - 00045784 _____ (COMODO) C:\Windows\system32\cmdkbd64.dll
2015-01-30 13:27 - 2014-12-09 00:20 - 00040736 _____ (COMODO) C:\Windows\system32\cmdcsr.dll
2015-01-30 13:27 - 2014-12-09 00:20 - 00040664 _____ (COMODO) C:\Windows\SysWOW64\cmdkbd32.dll
2015-01-30 13:27 - 2014-12-09 00:20 - 00020184 _____ (COMODO) C:\Windows\system32\Drivers\cmderd.sys
2015-01-30 02:22 - 2014-08-23 21:31 - 00000000 ____D () C:\Users\NicoHupe\AppData\Roaming\.minecraft
2015-01-29 11:05 - 2014-12-13 20:47 - 00000000 ____D () C:\Users\NicoHupe\Desktop\Feed The Beast
2015-01-29 11:05 - 2014-12-12 23:28 - 00000000 ____D () C:\Users\NicoHupe\AppData\Local\ftblauncher
2015-01-28 20:19 - 2014-04-04 10:55 - 00000000 ____D () C:\Users\NicoHupe
2015-01-28 20:08 - 2014-12-15 13:32 - 00037624 _____ () C:\Windows\system32\Drivers\TrueSight.sys
2015-01-28 19:08 - 2014-04-04 12:15 - 00000000 ____D () C:\Users\NicoHupe\Desktop\Spiele
2015-01-28 16:03 - 2014-04-04 11:02 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-01-26 15:45 - 2014-04-04 11:23 - 00087840 _____ () C:\Users\NicoHupe\AppData\Local\GDIPFONTCACHEV1.DAT
2015-01-26 15:43 - 2009-07-14 05:45 - 00343512 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-01-26 15:40 - 2014-05-23 08:58 - 04713128 _____ (Razer Inc) C:\Windows\system32\Kraken0502lfx.dll
2015-01-26 15:25 - 2014-11-11 05:27 - 00080384 _____ (Razer Inc) C:\Windows\system32\RazerCoinstaller.dll
2015-01-25 20:10 - 2014-04-14 16:47 - 00000000 ____D () C:\Program Files (x86)\epson
2015-01-25 20:03 - 2014-04-22 20:04 - 00000000 ____D () C:\Users\NicoHupe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2015-01-25 19:59 - 2014-04-04 14:43 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-01-25 19:59 - 2014-04-04 12:04 - 00000000 ____D () C:\Users\NicoHupe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2015-01-25 19:59 - 2014-04-04 11:56 - 00000000 ____D () C:\Supreme Commander
2015-01-25 19:58 - 2014-08-24 01:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LucasArts
2015-01-25 19:54 - 2009-07-14 06:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-01-25 19:52 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2015-01-25 19:43 - 2014-04-30 19:03 - 00000000 ____D () C:\Users\NicoHupe\AppData\Roaming\DAEMON Tools Lite
2015-01-25 19:43 - 2014-04-04 11:41 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2015-01-25 19:42 - 2014-12-15 20:34 - 00000000 ____D () C:\Windows\Minidump
2015-01-25 19:42 - 2014-04-07 10:28 - 00000000 ____D () C:\Users\NicoHupe\AppData\Local\CrashDumps
2015-01-25 19:42 - 2013-11-19 10:32 - 00000000 ____D () C:\Windows\Panther
2015-01-25 19:40 - 2014-04-14 16:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
2015-01-25 19:35 - 2014-11-24 16:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Westwood
2015-01-25 19:30 - 2014-06-09 09:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rome - Total War
2015-01-25 19:22 - 2014-04-04 14:43 - 00000000 ____D () C:\Assassin's Creed II
2015-01-25 19:21 - 2014-04-04 14:54 - 00000000 ____D () C:\Program Files (x86)\Ubisoft
2015-01-23 11:54 - 2015-01-03 12:56 - 00000933 _____ () C:\Users\Public\Desktop\LogMeIn Hamachi.lnk
2015-01-22 23:27 - 2014-12-29 11:25 - 00000000 ____D () C:\Users\NicoHupe\AppData\Roaming\Natural Selection 2
2015-01-22 14:56 - 2014-10-08 21:21 - 00000000 ____D () C:\ProgramData\Origin
2015-01-22 14:51 - 2014-10-08 21:21 - 00000000 ____D () C:\Program Files (x86)\Origin
2015-01-20 19:04 - 2014-09-06 09:22 - 00000000 ____D () C:\Program Files (x86)\Glyph
2015-01-14 17:21 - 2014-04-06 10:52 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-14 17:18 - 2014-04-06 10:52 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-14 11:32 - 2014-04-16 12:01 - 00033856 ____H (LogMeIn, Inc.) C:\Windows\system32\hamachi.sys
2015-01-12 15:49 - 2013-11-19 10:39 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2015-01-12 15:49 - 2010-02-20 17:20 - 01207144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FM20.DLL
2015-01-12 15:47 - 2011-04-12 08:54 - 00000000 ____D () C:\Windows\ShellNew
2015-01-10 16:32 - 2015-01-05 13:10 - 00000000 ____D () C:\Users\NicoHupe\Desktop\MC server
2015-01-10 16:32 - 2014-12-15 13:27 - 00000000 ____D () C:\Users\NicoHupe\Desktop\Antivirus
2015-01-10 16:31 - 2014-08-18 09:37 - 00000000 ____D () C:\Users\NicoHupe\Desktop\Filme
2015-01-10 13:52 - 2014-12-15 20:32 - 00000908 _____ () C:\Windows\system32\.crusader
2015-01-09 13:41 - 2010-11-21 04:27 - 00298120 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-01-09 13:39 - 2014-10-04 20:49 - 00000000 ___RD () C:\Program Files (x86)\Skype
2015-01-09 13:39 - 2014-04-06 18:26 - 00000000 ____D () C:\ProgramData\Skype

==================== Files in the root of some directories =======

2014-08-07 11:17 - 2014-08-07 11:17 - 0000057 _____ () C:\ProgramData\Ament.ini
2014-06-11 19:43 - 2014-04-12 19:43 - 0000032 ____R () C:\ProgramData\hash.dat

Files to move or delete:
====================
C:\ProgramData\hash.dat


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-02-05 19:47

==================== End Of Log ============================
         
--- --- ---

--- --- ---


Die Addition.txt :

Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 05-02-2015
Ran by NicoHupe at 2015-02-06 00:09:47
Running from C:\Users\NicoHupe\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: COMODO Antivirus (Enabled - Up to date) {F0BC89B2-8937-0933-021B-B17D981F2A71}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Comodo Defense+ (Enabled - Up to date) {4BDD6856-AF0D-06BD-38AB-8A0FE39860CC}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

99 Levels To Hell (HKLM-x32\...\Steam App 264280) (Version:  - Zaxis Games)
ABBYY FineReader 9.0 Sprint (HKLM-x32\...\ABBYY FineReader 9.0 Sprint) (Version: 9.01.513.58212 - ABBYY)
ABBYY FineReader 9.0 Sprint (x32 Version: 9.01.513.58212 - ABBYY) Hidden
Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (HKLM\...\{60BBC176-C393-6033-837E-B6BF4CDCBFB9}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.)
Apple Application Support (HKLM-x32\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Archeage Beta (HKLM-x32\...\Glyph Archeage Beta) (Version:  - Trion Worlds, Inc.)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
BitRaider Streaming Client (HKLM-x32\...\BitRaider Streaming Client) (Version: 1.3.3.4098 - BitRaider, LLC)
CCleaner (HKLM\...\CCleaner) (Version: 5.01 - Piriform)
COMODO Antivirus (HKLM\...\{18F14F4B-D8A9-4309-817E-3BC0B7664E53}) (Version: 8.0.0.4344 - COMODO Security Solutions Inc.)
Comodo Dragon (HKLM-x32\...\Comodo Dragon) (Version: 31.1.0.0 - COMODO)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
Diablo III (HKLM-x32\...\Diablo III) (Version:  - Blizzard Entertainment)
Dragon Age: Origins (HKLM-x32\...\{AEC81925-9C76-4707-84A9-40696C613ED3}) (Version: 1.05.0.0 - Electronic Arts)
Dungeon Siege (HKLM-x32\...\Steam App 39190) (Version:  - Gas Powered Games)
Dungeon Siege 2 (HKLM-x32\...\Steam App 39200) (Version:  - Gas Powered Games)
Dungeon Siege III (HKLM-x32\...\Steam App 39160) (Version:  - Obsidian Entertainment)
EPSON SX420W Series Printer Uninstall (HKLM\...\EPSON SX420W Series) (Version:  - SEIKO EPSON Corporation)
FORCED (HKLM-x32\...\Steam App 249990) (Version:  - BetaDwarf)
Fotogalerie (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Galería de fotos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Galerie de photos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
GameSpy Arcade (HKLM-x32\...\GameSpy Arcade) (Version:  - )
GeekBuddy (HKLM\...\{E98902C5-09AF-487A-AFAE-D4C386F506C0}) (Version: 4.18.121 - Comodo Security Solutions Inc)
Glyph (HKLM-x32\...\Glyph) (Version:  - Trion Worlds, Inc.)
Hearthstone (HKLM-x32\...\Hearthstone) (Version:  - Blizzard Entertainment)
HitmanPro 3.7 (HKLM\...\HitmanPro37) (Version: 3.7.9.234 - SurfRight B.V.)
iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.)
Java 8 Update 25 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418025F0}) (Version: 8.0.250 - Oracle Corporation)
Junk Mail filter update (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games )
League of Legends (x32 Version: 3.0.1 - Riot Games ) Hidden
Logitech GamePanel Software 3.05.151 (HKLM\...\{BF9FD124-1112-4C8D-8F79-779A11C6287D}) (Version: 3.05.151 - Logitech Inc.)
LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.2.0.303 - LogMeIn, Inc.)
LogMeIn Hamachi (x32 Version: 2.2.0.303 - LogMeIn, Inc.) Hidden
Metro 2033 (HKLM-x32\...\Steam App 43110) (Version:  - 4A Games)
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{42AA4CA8-DCD8-4308-BCAB-0B6D75856A9D}) (Version: 3.5.95.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Outlook Social Connector (KB2289116) ªº§ó·s (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{75F91382-920C-4AE1-B9E6-FFFCEDA797E8}) (Version:  - Microsoft)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
Mount & Blade: Warband (HKLM-x32\...\Steam App 48700) (Version:  - TaleWorlds Entertainment)
Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Mozilla Firefox 35.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 35.0.1 (x86 de)) (Version: 35.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MSXML4 Parser (HKLM-x32\...\{01501EBA-EC35-4F9F-8889-3BE346E5DA13}) (Version: 1.0.0 - Microsoft Game Studios)
Natural Selection 2 (HKLM-x32\...\Steam App 4920) (Version:  - Unknown Worlds Entertainment)
NVIDIA PhysX (HKLM-x32\...\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation)
Origin (HKLM-x32\...\Origin) (Version: 9.4.22.2815 - Electronic Arts, Inc.)
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.2 - pdfforge)
Raccolta foto (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Razer Synapse (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.18.19.23944 - Razer Inc.)
RIFT (HKLM-x32\...\Glyph RIFT) (Version:  - Trion Worlds, Inc.)
Shadowrun Returns (HKLM-x32\...\Steam App 234650) (Version:  - Harebrained Schemes)
Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
Star Wars The Old Republic (HKLM-x32\...\swtor_swtor) (Version: 8.0.0.7 - Bioware/EA)
Star Wars: The Old Republic (HKLM-x32\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.)
StarCraft II (HKLM-x32\...\StarCraft II) (Version:  - Blizzard Entertainment)
Steam (HKLM-x32\...\Steam) (Version:  - Valve Corporation)
TeamSpeak 3 Client (HKU\S-1-5-21-2974583261-1939293177-1460826959-1000\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH)
Terraria (HKLM-x32\...\Steam App 105600) (Version:  - Re-Logic)
Texmaker (HKLM-x32\...\Texmaker) (Version:  - )
The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version:  - Bethesda Game Studios)
Titan Quest (HKLM-x32\...\{412B69AF-C352-4F6F-A318-B92B3CB9ACC6}) (Version: 1.00.0000 - Iron Lore)
Titan Quest Immortal Throne (HKLM-x32\...\{B5C5C17E-FEF6-4062-8151-A427AE8AF9D7}) (Version: 1.00.0000 - Iron Lore)
Total War ROME II (HKLM-x32\...\VG90YWxXYXJST01FSUk=_is1) (Version: 1 - )
Total War: ROME II - Emperor Edition (HKLM-x32\...\Steam App 214950) (Version:  - Creative Assembly)
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
Unturned (HKLM-x32\...\Steam App 304930) (Version:  - Nelson Sexton)
Update für Microsoft Outlook Social Connector (KB2289116) (HKLM-x32\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{10B1662A-566C-43C2-8469-5A470E0C7D7B}) (Version:  - Microsoft)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)
WinRAR 5.01 (32-Bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
WinRAR 5.01 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: 3.3.5.12340 - Blizzard Entertainment)
XCOM: Enemy Unknown (HKLM-x32\...\Steam App 200510) (Version:  - Firaxis Games)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points  =========================

27-01-2015 16:34:04 Windows Update
03-02-2015 12:50:08 Windows Update

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {00D4A4F8-0482-4020-8B51-BB348F62388F} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-24] (Adobe Systems Incorporated)
Task: {11AF3478-A38C-4A07-ABC1-D9A2A9487F66} - System32\Tasks\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2015-02-03] (COMODO)
Task: {12605746-88BC-4668-AFBB-A9B1A0AA4A49} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-01-25] (Piriform Ltd)
Task: {3B2D0FF6-A87D-45A5-8C19-76DD66F32B59} - System32\Tasks\COMODO\COMODO Scan {F140D794-60B6-4F00-9235-D6457AA25B22} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2015-02-03] (COMODO)
Task: {6B9EBDA7-A17C-41CD-874E-F7EE14EBB0EA} - System32\Tasks\{5CBCA87D-F9DF-4746-8C39-75557C2FF0D1} => pcalua.exe -a F:\aoesetup.exe -d F:\ -c /autorun
Task: {964C6635-B7EC-4C00-8127-95F25F0F8EF1} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2015-02-03] (COMODO)
Task: {A2D76EC4-F976-4F15-A9CB-5B347870F002} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {A91DCFCA-898F-46AA-A713-C3FA24B684A6} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {BF3B1B6E-9AAA-4A74-811C-4E43103A18EE} - System32\Tasks\{B44CA52A-DBD6-4900-BC7E-A16CC1BE5629} => pcalua.exe -a "C:\Users\NicoHupe\Desktop\WoW MMowning\InstallWoW.exe" -d "C:\Users\NicoHupe\Desktop\WoW MMowning"
Task: {C4EDFEDA-B8F5-426F-A880-818A0C7B7295} - System32\Tasks\{9C3F305C-B9F3-4951-891C-C53C201D95F6} => pcalua.exe -a "C:\Users\NicoHupe\Desktop\Rome 2\Total War Rome 2 Installer v1.0.exe" -d "C:\Users\NicoHupe\Desktop\Rome 2"
Task: {DA5D01F3-52AC-40F2-AA70-6773CC5BB481} - System32\Tasks\COMODO\COMODO Cache Builder {0FB77674-7905-4F34-A362-C5A9A26F8CF9} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2015-02-03] (COMODO)
Task: {E21D8FD7-BA2B-4032-B208-542BF1A70031} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-05] (Adobe Systems Incorporated)
Task: {E2319A80-EF3D-48B8-A8CA-DF37AD7AE83D} - System32\Tasks\{5F8B612F-5498-4546-9FAB-EDB60426AEE9} => pcalua.exe -a "C:\Program Files (x86)\InstallShield Installation Information\{B2D55EB8-32C5-4B43-9006-9E97DECBA178}\setup.exe" -c -runfromtemp -l0x0007 -removeonly
Task: {F493D574-430C-4DD2-A7F9-88A13170906F} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2015-02-03] (COMODO)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Loaded Modules (whitelisted) ==============

2014-01-28 15:35 - 2014-01-28 15:35 - 02135232 _____ () C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
2014-12-09 23:22 - 2014-12-09 23:22 - 00186048 _____ () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
2014-09-25 05:38 - 2014-09-25 05:38 - 01283792 _____ () C:\Program Files\COMODO\GeekBuddy\QtNetwork4.dll
2014-09-25 05:38 - 2014-09-25 05:38 - 02875600 _____ () C:\Program Files\COMODO\GeekBuddy\QtCore4.dll
2014-09-25 05:38 - 2014-09-25 05:38 - 10451664 _____ () C:\Program Files\COMODO\GeekBuddy\QtGui4.dll
2014-09-25 05:38 - 2014-09-25 05:38 - 00039120 _____ () C:\Program Files\COMODO\GeekBuddy\imageformats\qgif4.dll
2014-09-25 05:38 - 2014-09-25 05:38 - 01529040 _____ () C:\Program Files\COMODO\GeekBuddy\QtScript4.dll
2014-12-12 23:24 - 2014-12-12 23:24 - 00047104 _____ () C:\Program Files\CCleaner\lang\lang-1031.dll
2013-04-15 17:39 - 2013-04-15 17:39 - 00073424 _____ () C:\Program Files\COMODO\COMODO Internet Security\scanners\smart.cav
2014-02-12 19:58 - 2014-02-12 19:58 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-02-12 19:58 - 2014-02-12 19:58 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2014-05-23 08:54 - 2014-05-23 08:54 - 00619328 _____ () C:\Program Files (x86)\Razer\Razer_Kraken0502_Driver\Drivers\SysAudio\Kraken0502DevProps.dll
2015-01-27 16:45 - 2015-01-27 16:45 - 03925104 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Windows\system32\ieUnatt.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Kraken0502lfx.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\MpSigStub.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\mstscax.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\nlasvc.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ntoskrnl.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\profsvc.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\RazerCoinstaller.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\rdpcorets.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\RdpGroupPolicyExtension.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\rstrui.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\srclient.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\srcore.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\TSWbPrxy.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\FlashPlayerApp.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\FM20.DLL:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ieUnatt.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\mstscax.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ncsi.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\nlaapi.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ntkrnlpa.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ntoskrnl.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\srclient.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\hamachi.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\mrxdav.sys:$CmdTcID
AlternateDataStreams: C:\Users\NicoHupe\Desktop\FRST64.exe:$CmdZnID
AlternateDataStreams: C:\Users\NicoHupe\Downloads\ccsetup501_slim.exe:$CmdTcID
AlternateDataStreams: C:\Users\NicoHupe\Downloads\ccsetup501_slim.exe:$CmdZnID
AlternateDataStreams: C:\Users\NicoHupe\Downloads\CrashLandingServer (1).zip:$CmdZnID
AlternateDataStreams: C:\Users\NicoHupe\Downloads\CrashLandingServer (2).zip:$CmdZnID
AlternateDataStreams: C:\Users\NicoHupe\Downloads\CrashLandingServer (3).zip:$CmdZnID
AlternateDataStreams: C:\Users\NicoHupe\Downloads\CrashLandingServer.zip:$CmdZnID
AlternateDataStreams: C:\Users\NicoHupe\Downloads\RogueKillerX64.exe:$CmdTcID
AlternateDataStreams: C:\Users\NicoHupe\Downloads\RogueKillerX64.exe:$CmdZnID
AlternateDataStreams: C:\Users\NicoHupe\Downloads\SWTOR_setup.exe:$CmdTcID
AlternateDataStreams: C:\Users\NicoHupe\Downloads\SWTOR_setup.exe:$CmdZnID

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service"

==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Other Registry Areas =====================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2974583261-1939293177-1460826959-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\NicoHupe\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: iTunesHelper => "C:\iTunesHelper.exe"

==================== Accounts: =============================

Administrator (S-1-5-21-2974583261-1939293177-1460826959-500 - Administrator - Disabled)
Gast (S-1-5-21-2974583261-1939293177-1460826959-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2974583261-1939293177-1460826959-1004 - Limited - Enabled)
NicoHupe (S-1-5-21-2974583261-1939293177-1460826959-1000 - Administrator - Enabled) => C:\Users\NicoHupe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (02/06/2015 00:08:28 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (02/06/2015 00:08:27 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (02/05/2015 11:20:08 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/05/2015 07:51:42 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest2" in Zeile C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.

Error: (02/05/2015 07:30:09 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/05/2015 10:42:40 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/04/2015 06:58:36 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/04/2015 00:21:21 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 05:40:15 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 00:47:10 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (02/06/2015 00:08:49 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Steam Client Service" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1053

Error: (02/06/2015 00:08:49 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Steam Client Service erreicht.

Error: (02/05/2015 07:34:55 PM) (Source: BROWSER) (EventID: 8032) (User: )
Description: Das Einlesen der Sicherungsliste durch den Suchdienst schlug auf Transport "\Device\NetBT_Tcpip_{801EB809-43DC-4674-9077-2C69CA2F3F41}" zu oft fehl.
Der Sicherungssuchdienst wird beendet.

Error: (02/05/2015 07:28:37 PM) (Source: Server) (EventID: 2505) (User: )
Description: Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{3FD63A9C-BFEC-499C-861C-3BAF2630B2EF} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden.

Error: (02/05/2015 07:28:32 PM) (Source: NetBT) (EventID: 4321) (User: )
Description: Der Name "COLDPRIEST     :20" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.0.128
registriert werden. Der Computer mit IP-Adresse 192.168.0.93 hat nicht
zugelassen, dass dieser Computer diesen Namen verwendet.

Error: (02/05/2015 07:28:25 PM) (Source: NetBT) (EventID: 4321) (User: )
Description: Der Name "COLDPRIEST     :0" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.0.128
registriert werden. Der Computer mit IP-Adresse 192.168.0.93 hat nicht
zugelassen, dass dieser Computer diesen Namen verwendet.

Error: (02/04/2015 10:33:30 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden.

Error: (02/04/2015 10:33:29 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden.

Error: (02/04/2015 10:33:29 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden.

Error: (02/04/2015 10:33:28 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden.


Microsoft Office Sessions:
=========================
Error: (02/06/2015 00:08:28 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Program Files\CCleaner\CCleaner64.exe

Error: (02/06/2015 00:08:27 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Program Files\CCleaner\CCleaner64.exe

Error: (02/05/2015 11:20:08 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/05/2015 07:51:42 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestc:\program files\CCleaner\CCleaner.exe

Error: (02/05/2015 07:30:09 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/05/2015 10:42:40 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/04/2015 06:58:36 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/04/2015 00:21:21 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 05:40:15 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (02/03/2015 00:47:10 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


==================== Memory info =========================== 

Processor: AMD A8-6600K APU with Radeon(tm) HD Graphics 
Percentage of memory in use: 31%
Total physical RAM: 7364.8 MB
Available physical RAM: 5051.95 MB
Total Pagefile: 14727.79 MB
Available Pagefile: 12067.89 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:920.13 GB) (Free:464.26 GB) NTFS
Drive d: (TheFrozenThrone) (CDROM) (Total:0.51 GB) (Free:0 GB) CDFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: DFE660DA)
Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=920.1 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=11 GB) - (Type=27)

==================== End Of Log ============================
         
__________________

Alt 06.02.2015, 00:18   #4
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Pc startet nicht mehr nach versuchtem Neutstart - Standard

Pc startet nicht mehr nach versuchtem Neutstart



Was ist mit meiner Frage nach bisherigen Funden?
__________________
Logfiles bitte immer in CODE-Tags posten

Alt 06.02.2015, 00:20   #5
ColdPriest
 
Pc startet nicht mehr nach versuchtem Neutstart - Standard

Pc startet nicht mehr nach versuchtem Neutstart



Oh ja Entschuldigung Ich habe in letzter Zeit keine Funde gehabt, habe aber auch keine weiteren Logs soweit ich weiß :S


Alt 06.02.2015, 00:32   #6
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Pc startet nicht mehr nach versuchtem Neutstart - Standard

Pc startet nicht mehr nach versuchtem Neutstart



Startet das Gerät wieder normal? Wenn nicht wären FRST Logs ja nicht möglich gewesen...
__________________
--> Pc startet nicht mehr nach versuchtem Neutstart

Alt 06.02.2015, 00:36   #7
ColdPriest
 
Pc startet nicht mehr nach versuchtem Neutstart - Standard

Pc startet nicht mehr nach versuchtem Neutstart



Die waren jetzt von meinem Rechner, von dem der Virus, falls es einer ist, wohl gekommen ist. Der Laptop hat noch nicht wieder gestartet.

Alt 06.02.2015, 09:11   #8
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Pc startet nicht mehr nach versuchtem Neutstart - Standard

Pc startet nicht mehr nach versuchtem Neutstart



Sry aber sowas wenig Null Sinn. Das ist so als würdest du in einer Autowerkstatt anrufen um deinen kaputten Wagen anzumelden, herum kommst du zum Termin aber mit einem völlig anderen Auto

Funktioniert der abgesicherte Modus vom betroffenen, hier thematisierten Gerät noch? Bitte jetzt keine Logs mehr von anderen Rechnern hier posten...
__________________
Logfiles bitte immer in CODE-Tags posten

Antwort

Themen zu Pc startet nicht mehr nach versuchtem Neutstart
100%, adobe, adobe flash player, beschädigt, bildschirm, downloaden, flash player, funktioniert, hintergrund, homepage, laptop, neu, nicht mehr, nichts, pc startet nicht mehr, programm, programme, rechner, startet, startet nicht, stick, teamspeak, usb, usb stick, virus, windows



Ähnliche Themen: Pc startet nicht mehr nach versuchtem Neutstart


  1. Pc Startet nicht mehr nach Befall der Samsrv.dll Datei.
    Plagegeister aller Art und deren Bekämpfung - 30.05.2015 (4)
  2. Windows 8.1 startet nach Defragmentierung nicht mehr
    Alles rund um Windows - 13.05.2015 (15)
  3. PC startet nach Windows Updates nicht mehr
    Alles rund um Windows - 17.03.2015 (10)
  4. Nach Omiga startet Telekom Browser nicht mehr
    Alles rund um Windows - 18.07.2014 (18)
  5. DHCP Dienst startet nach Win Update nicht mehr
    Alles rund um Windows - 13.02.2014 (7)
  6. Windows 7 startet nach Update nicht mehr
    Alles rund um Windows - 29.10.2013 (10)
  7. Sorge um Infektion nach versuchtem Identitätsdiebstahl
    Plagegeister aller Art und deren Bekämpfung - 11.09.2013 (9)
  8. Nach Neustart startet Windows nicht mehr
    Alles rund um Windows - 23.04.2012 (10)
  9. nach UKASH Trojaner startet windows nicht mehr, kaspersky rescue disc funktioniert nicht
    Log-Analyse und Auswertung - 26.03.2012 (3)
  10. Desktop startet nicht mehr nach Viruslöschung
    Alles rund um Windows - 12.09.2010 (4)
  11. Windows XP startet nach aut. Updates nicht mehr
    Alles rund um Windows - 05.08.2010 (11)
  12. Pc startet nach einbau neuer grafikkarte nicht mehr.
    Netzwerk und Hardware - 17.01.2009 (11)
  13. nach brastk - windows startet nicht mehr
    Plagegeister aller Art und deren Bekämpfung - 23.10.2008 (4)
  14. nach brastk.exe - windows startet nicht mehr
    Mülltonne - 22.10.2008 (0)
  15. automatischer neutstart unmittelbar nach antivir system-scan start
    Plagegeister aller Art und deren Bekämpfung - 15.08.2008 (1)
  16. Hilfe-Windows startet nach ntos nicht mehr!
    Plagegeister aller Art und deren Bekämpfung - 24.11.2007 (28)
  17. Nach versuch trojaner zu entfernen startet der PC nicht mehr. Help!!!
    Log-Analyse und Auswertung - 03.12.2004 (4)

Zum Thema Pc startet nicht mehr nach versuchtem Neutstart - Hallo zusammen Ich habe eben gerade versucht meinen Lenovo G710 neuzustarten, da er anscheinend nicht richtig funktioniert hat (ein Programm hat sich nich geöffnet). Als der Laptop wieder hochgefahren ist, - Pc startet nicht mehr nach versuchtem Neutstart...
Archiv
Du betrachtest: Pc startet nicht mehr nach versuchtem Neutstart auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.