![]() |
| |||||||
Log-Analyse und Auswertung: Download Protect 2.2.5 lässt sich aus Firefox nicht entfernenWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
| | #8 |
| | Download Protect 2.2.5 lässt sich aus Firefox nicht entfernen Die Fixlog.txt Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 10-08-2014 01
Ran by Atenuvielle at 2014-08-11 19:52:18 Run:4
Running from C:\Users\Atenuvielle\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
start
() C:\Users\Atenuvielle\AppData\Roaming\Hub Timer\hub.exe
HKLM\...\Run: [] => [X]
HKLM-x32\...\Run: [] => [X]
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
FF HKLM-x32\...\Firefox\Extensions: [{0875F592-BC9B-4295-8B08-31DF255C0582}] - C:\Windows\Installer\{3D0DBF78-C478-41C4-BE85-9B6893E8A5E2}\{0875F592-BC9B-4295-8B08-31DF255C0582}.xpi
C:\Windows\Installer\{3D0DBF78-C478-41C4-BE85-9B6893E8A5E2}
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
R2 HubService; C:\Users\Atenuvielle\AppData\Roaming\Hub Timer\hub.exe [536576 2014-07-30] () [File not signed]
C:\Users\Atenuvielle\AppData\Roaming\Hub Timer
C:\Users\Atenuvielle\AppData\Roaming\Security Systems
C:\Windows\System32\Tasks\BasisfiltermodulHintergrundübertragungsdienstBrowsersupporttreiber
Task: {6B4DDF3B-E0CC-481B-A730-B0DE3F1B2CAB} - System32\Tasks\BasisfiltermodulHintergrundübertragungsdienstBrowsersupporttreiber => C:\Windows\IsUnjnst.exe
C:\Windows\IsUnjnst.exe
AlternateDataStreams: C:\ProgramData\Temp:FF9C44FE
EmptyTemp:
Reboot:
end
*****************
C:\Users\Atenuvielle\AppData\Roaming\Hub Timer\hub.exe => No running process found
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => Value not found.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Value not found.
"C:\Windows\system32\GroupPolicy\Machine" => File/Directory not found.
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\{0875F592-BC9B-4295-8B08-31DF255C0582} => Value not found.
"C:\Windows\Installer\{3D0DBF78-C478-41C4-BE85-9B6893E8A5E2}" => File/Directory not found.
"HKLM\SOFTWARE\Policies\Google" => Key not found.
HubService => Service not found.
"C:\Users\Atenuvielle\AppData\Roaming\Hub Timer" => File/Directory not found.
"C:\Users\Atenuvielle\AppData\Roaming\Security Systems" => File/Directory not found.
"C:\Windows\System32\Tasks\BasisfiltermodulHintergrundübertragungsdienstBrowsersupporttreiber" => File/Directory not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6B4DDF3B-E0CC-481B-A730-B0DE3F1B2CAB}" => Key not found.
C:\Windows\System32\Tasks\BasisfiltermodulHintergrundübertragungsdienstBrowsersupporttreiber not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BasisfiltermodulHintergrundübertragungsdienstBrowsersupporttreiber" => Key not found.
"C:\Windows\IsUnjnst.exe" => File/Directory not found.
"C:\ProgramData\Temp" => ":FF9C44FE" ADS not found.
EmptyTemp: => Removed 780 MB temporary data.
The system needed a reboot.
==== End of Fixlog ====
Die Logdatei von Zoek Code:
ATTFilter Zoek.exe v5.0.0.0 Updated 11-August-2014
Tool run by Atenuvielle on 11.08.2014 at 20:05:23,72.
Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Atenuvielle\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
11.08.2014 20:06:50 Zoek.exe System Restore Point Created Succesfully.
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-1616329635-2298572524-3642011023-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} deleted successfully
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== FireFox Fix ======================
ProfilePath: C:\Users\ATENUV~1\AppData\Roaming\Mozilla\Firefox\Profiles\nukrx784.default
user.js not found
---- Lines extensions.50f96ffd8668b removed from prefs.js ----
user_pref("extensions.50f96ffd8668b.epoch", "1361961818");
user_pref("extensions.50f96ffd8668b.url", "hxxp://getjpijs.info/sync/?ext=bit&pid=2049&country=DE®d=130118155333&lsd=130226103402&ind=4199314940&ss
---- FireFox user.js and prefs.js backups ----
prefs__2014_.backup
==== Deleting Files \ Folders ======================
"C:\Windows\Installer\1839723.msi" not found
C:\PROGRA~2\COMMON~1\DVDVideoSoft\bin deleted
C:\Users\Atenuvielle\AppData\Roaming\YoudaGames deleted
C:\PROGRA~3\ICQ deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\Atenuvielle\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847} deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Lunch Design deleted
C:\Users\Atenuvielle\Searches deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
C:\Windows\Syswow64\tmp42CB.tmp deleted
C:\Windows\Syswow64\tmp42FB.tmp deleted
C:\Users\ATENUV~1\AppData\Roaming\Mozilla\Firefox\Profiles\nukrx784.default\foxydeal.sqlite deleted
C:\Users\ATENUV~1\AppData\Roaming\Mozilla\Firefox\Profiles\nukrx784.default\CT3196716 deleted
C:\Users\ATENUV~1\AppData\Roaming\Mozilla\Firefox\Profiles\nukrx784.default\extensions\abs@avira.com deleted
"C:\Users\Atenuvielle\AppData\Roaming\Amazon" deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"{23fcfd51-4958-4f00-80a3-ae97e717ed8b}"="C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5" [06.06.2012 18:02]
==== Firefox Extensions ======================
ProfilePath: C:\Users\ATENUV~1\AppData\Roaming\Mozilla\Firefox\Profiles\nukrx784.default
- A Mystical Land Installer - C:\Users\Atenuvielle\AppData\Roaming\Mozilla\Firefox\Profiles\nukrx784.default\extensions\MysticalLandInstaller@madottergames.com
- Star Stable Online - C:\Users\Atenuvielle\AppData\Roaming\Mozilla\Firefox\Profiles\nukrx784.default\extensions\plugin@starstable.com
- Foxy Secure 7 - C:\Users\Atenuvielle\AppData\Roaming\Mozilla\Firefox\Profiles\nukrx784.default\extensions\connect@foxy-sec.com
- ProxTube - Gesperrte YouTube Videos entsperren - C:\Users\Atenuvielle\AppData\Roaming\Mozilla\Firefox\Profiles\nukrx784.default\extensions\ich@maltegoetz.de
- Foxy Secure 7 - %ProfilePath%\extensions\connect@foxy-sec.com
- ProxTube - Gesperrte YouTube Videos entsperren - %ProfilePath%\extensions\ich@maltegoetz.de
- A Mystical Land Installer - %ProfilePath%\extensions\MysticalLandInstaller@madottergames.com
- Star Stable Online - %ProfilePath%\extensions\plugin@starstable.com
- Stylish - %ProfilePath%\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
==== Firefox Plugins ======================
Profilepath: C:\Users\Atenuvielle\AppData\Roaming\Mozilla\Firefox\Profiles\nukrx784.default
898B418862E387276CD063324744CF5C - C:\Users\Atenuvielle\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player
4390CCD3790F8D9C427C0C29590C62D7 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll - Shockwave Flash
FB5621842FDABF9F8359775573498FBC - C:\Users\Atenuvielle\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll - Google Update
78006383FEDBCDC290B8BD178903D6AB - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll - Shockwave for Director / Shockwave for Director
DE68B6B9EADD500AD9C4E91F8E3B79A3 - C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dll - Happy Cloud Plugin
4902717499A5AE1D3FB4FECAC376D8A7 - C:\Users\Atenuvielle\AppData\Roaming\Kalydo\KalydoPlayer\bin2\npkalydo.dll - Kalydo Player Plugin for Mozilla
DE1121333E9AE62DDDE4EA02F4FEA887 - C:\Users\Atenuvielle\AppData\Roaming\Mozilla\Firefox\Profiles\nukrx784.default\extensions\MysticalLandInstaller@madottergames.com\plugins\NPMysticalLandInstaller.dll - Mystical Land Installer
6B6E59354DB3977E03B67F7FB9A61F70 - C:\Users\Atenuvielle\AppData\Roaming\Mozilla\Firefox\Profiles\nukrx784.default\extensions\plugin@starstable.com\plugins\npstudioruntime.dll - Star Stable Online
==== Chrome Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
flliilndjeohchalpbbcdekjklbdgfkk - No path found[]
nneajnkjbffgblleaoojgaacokifdkhm - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx[12.12.2011 15:13]
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"ICQ Search"="hxxp://www.google.com"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="C:\\ProgramData\\ICQ\\ICQNewTab\\newTab.html"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="C:\\ProgramData\\ICQ\\ICQNewTab\\newTab.html"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="hxxp://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B6EF34C0188ECFA43B48A4BE9C00748E deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\flliilndjeohchalpbbcdekjklbdgfkk deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AmazonMP3DownloaderHelper deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDRegion deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl10 deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RGSC deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sweetpacks Communicator deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XboxStat deleted successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Atenuvielle\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\Users\Atenuvielle\AppData\Local\Mozilla\Firefox\Profiles\nukrx784.default\Cache emptied successfully
==== Empty Chrome Cache ======================
C:\Users\Atenuvielle\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=417 folders=108 43692761 bytes)
==== Empty Temp Folders ======================
C:\Users\Atenuvielle\AppData\Local\Temp will be emptied at reboot
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\ATENUV~1\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on 11.08.2014 at 20:19:11,64 ======================
FRST.txt FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-08-2014 01
Ran by Atenuvielle (administrator) on SASKIA on 11-08-2014 20:22:33
Running from C:\Users\Atenuvielle\Desktop
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Tenda\Common\RaRegistry.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Tenda\Common\RaRegistry64.exe
(Razer, Inc.) C:\Program Files (x86)\Razer\Core\64bit\RzOvlMon.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
() C:\Windows\System32\atwtusb.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
() C:\Windows\System32\atwtusb.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
() D:\Programme\NVIDIA\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
() D:\Programme\NVIDIA\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Akamai Technologies, Inc.) C:\Users\Atenuvielle\AppData\Local\Akamai\netsession_win.exe
(Spotify Ltd) C:\Users\Atenuvielle\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Intenium) C:\Program Files (x86)\OXXOGames\GPlayer\GameCenterNotifier.exe
(Akamai Technologies, Inc.) C:\Users\Atenuvielle\AppData\Local\Akamai\netsession_win.exe
(Tenda Technology, Corp.) C:\Program Files (x86)\Tenda\Common\RaUI.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDRSS.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDWebCam.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDPOP3.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDCountdown.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDPictureViewer.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDMovieViewer.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDYT.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe
(Mozilla Corporation) D:\Programme\FireFox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [8292120 2013-11-14] (Logitech Inc.)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [585560 2014-06-23] (Razer Inc.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [751184 2014-08-05] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [190032 2014-07-24] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-07-09] (Advanced Micro Devices, Inc.)
HKU\.DEFAULT\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2013-03-21] (Microsoft Corporation)
HKU\S-1-5-21-1616329635-2298572524-3642011023-1000\...\Run: [Akamai NetSession Interface] => C:\Users\Atenuvielle\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.)
HKU\S-1-5-21-1616329635-2298572524-3642011023-1000\...\Run: [Google Update] => C:\Users\Atenuvielle\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-07-23] (Google Inc.)
HKU\S-1-5-21-1616329635-2298572524-3642011023-1000\...\Run: [Spotify Web Helper] => C:\Users\Atenuvielle\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171000 2014-05-29] (Spotify Ltd)
HKU\S-1-5-21-1616329635-2298572524-3642011023-1000\...\Run: [DAEMON Tools Lite] => D:\Programme\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-1616329635-2298572524-3642011023-1000\...\Run: [Spiele Post] => C:\Program Files (x86)\OXXOGames\GPlayer\GameCenterNotifier.exe [483400 2013-12-06] (Intenium)
HKU\S-1-5-21-1616329635-2298572524-3642011023-1000\...\MountPoints2: E - E:\ASRSetup.exe
HKU\S-1-5-21-1616329635-2298572524-3642011023-1000\...\MountPoints2: G - G:\.\Autorun.exe AUTORUN=1
HKU\S-1-5-21-1616329635-2298572524-3642011023-1000\...\MountPoints2: H - H:\.\Autorun.exe AUTORUN=1
HKU\S-1-5-21-1616329635-2298572524-3642011023-1000\...\MountPoints2: I - I:\Ridingstar3.exe
HKU\S-1-5-21-1616329635-2298572524-3642011023-1000\...\MountPoints2: {00ae6b7c-c92c-11e1-9c9e-080027008036} - G:\.\Autorun.exe AUTORUN=1
HKU\S-1-5-21-1616329635-2298572524-3642011023-1000\...\MountPoints2: {025cf0fb-2f15-11e2-904a-c4c6daa71751} - J:\.\Autorun.exe AUTORUN=1
HKU\S-1-5-21-1616329635-2298572524-3642011023-1000\...\MountPoints2: {025cf108-2f15-11e2-904a-c4c6daa71751} - J:\.\Autorun.exe AUTORUN=1
HKU\S-1-5-21-1616329635-2298572524-3642011023-1000\...\MountPoints2: {0b85f84f-b010-11e1-be9d-080027008036} - J:\.\Autorun.exe AUTORUN=1
HKU\S-1-5-21-1616329635-2298572524-3642011023-1000\...\MountPoints2: {0b85f85c-b010-11e1-be9d-080027008036} - J:\.\Autorun.exe AUTORUN=1
HKU\S-1-5-21-1616329635-2298572524-3642011023-1000\...\MountPoints2: {0b85f936-b010-11e1-be9d-080027008036} - G:\.\Autorun.exe AUTORUN=1
HKU\S-1-5-21-1616329635-2298572524-3642011023-1000\...\MountPoints2: {0b85f941-b010-11e1-be9d-080027008036} - H:\.\Autorun.exe AUTORUN=1
HKU\S-1-5-21-1616329635-2298572524-3642011023-1000\...\MountPoints2: {0c927f05-e4fe-11e3-8ac4-8e12c3de0601} - G:\Autorun.exe
HKU\S-1-5-21-1616329635-2298572524-3642011023-1000\...\MountPoints2: {12deb2d3-b06a-11e1-a246-080027008036} - G:\.\Autorun.exe AUTORUN=1
HKU\S-1-5-21-1616329635-2298572524-3642011023-1000\...\MountPoints2: {45240372-c867-11e1-b961-080027008036} - G:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1616329635-2298572524-3642011023-1000\...\MountPoints2: {45240395-c867-11e1-b961-080027008036} - G:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1616329635-2298572524-3642011023-1000\...\MountPoints2: {452403dc-c867-11e1-b961-080027008036} - G:\.\Autorun.exe AUTORUN=1
HKU\S-1-5-21-1616329635-2298572524-3642011023-1000\...\MountPoints2: {45240409-c867-11e1-b961-080027008036} - H:\.\Autorun.exe AUTORUN=1
HKU\S-1-5-21-1616329635-2298572524-3642011023-1000\...\MountPoints2: {4524041b-c867-11e1-b961-080027008036} - G:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-1616329635-2298572524-3642011023-1000\...\MountPoints2: {52c11fe3-8aa7-11df-98e5-f176c63de54c} - H:\cdstart.exe
HKU\S-1-5-21-1616329635-2298572524-3642011023-1000\...\MountPoints2: {52fc9a89-28d4-11e2-b5eb-c35c9e290c6c} - G:\.\Autorun.exe AUTORUN=1
HKU\S-1-5-21-1616329635-2298572524-3642011023-1000\...\MountPoints2: {680b2e9f-eb15-11df-8924-88773eb7c741} - G:\setup.exe
HKU\S-1-5-21-1616329635-2298572524-3642011023-1000\...\MountPoints2: {86e587b1-c830-11e1-beeb-080027008036} - G:\.\Autorun.exe AUTORUN=1
HKU\S-1-5-21-1616329635-2298572524-3642011023-1000\...\MountPoints2: {8c0e3874-b5dc-11e1-97d8-080027008036} - G:\.\Autorun.exe AUTORUN=1
HKU\S-1-5-21-1616329635-2298572524-3642011023-1000\...\MountPoints2: {df7190ff-7dcf-11e2-ada9-dfb609612d52} - G:\.\Autorun.exe AUTORUN=1
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Tenda Wireless Utility.lnk
ShortcutTarget: Tenda Wireless Utility.lnk -> C:\Program Files (x86)\Tenda\Common\RaUI.exe (Tenda Technology, Corp.)
ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xB00F5B37461DCB01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll No File
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: DivX Plus Web Player HTML5 <video> -> {326E768D-4182-46FD-9C16-1449A49795F4} -> C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: No Name -> {C32F5BF7-6918-4F78-A97A-53CDF7D07C8C} -> C:\Users\Atenuvielle\AppData\LocalLow\Internet Explorer BHO\bho.dll ()
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {4FF78044-96B4-4312-A5B7-FDA3CB328095}
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Atenuvielle\AppData\Roaming\Mozilla\Firefox\Profiles\nukrx784.default
FF Homepage: www.google.de
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.)
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @exent.com/npExentControl,version=7.1.0.1 -> C:\Program Files (x86)\FreeRide Games\npExentControl.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @eximion.com/KalydoPlayer -> C:\Users\Atenuvielle\AppData\Roaming\Kalydo\KalydoPlayer\bin2\npkalydo.dll (Eximion B.V.)
FF Plugin HKCU: @soe.sony.com/installer,version=1.0.3 -> C:\Users\Atenuvielle\AppData\LocalLow\Sony Online Entertainment\npsoe.dll No File
FF Plugin HKCU: @tools.google.com/Google Update;version=3 -> C:\Users\Atenuvielle\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 -> C:\Users\Atenuvielle\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Atenuvielle\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: thehappycloud.com/HappyCloudPlugin -> C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dll (The Happy Cloud)
FF Extension: Foxy Secure 7 - C:\Users\Atenuvielle\AppData\Roaming\Mozilla\Firefox\Profiles\nukrx784.default\Extensions\connect@foxy-sec.com [2014-08-06]
FF Extension: ProxTube - Unblock YouTube - C:\Users\Atenuvielle\AppData\Roaming\Mozilla\Firefox\Profiles\nukrx784.default\Extensions\ich@maltegoetz.de [2014-08-07]
FF Extension: A Mystical Land Installer - C:\Users\Atenuvielle\AppData\Roaming\Mozilla\Firefox\Profiles\nukrx784.default\Extensions\MysticalLandInstaller@madottergames.com [2013-02-04]
FF Extension: Star Stable Online - C:\Users\Atenuvielle\AppData\Roaming\Mozilla\Firefox\Profiles\nukrx784.default\Extensions\plugin@starstable.com [2012-07-15]
FF Extension: Stylish - C:\Users\Atenuvielle\AppData\Roaming\Mozilla\Firefox\Profiles\nukrx784.default\Extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi [2014-08-11]
FF Extension: Adblock Plus - C:\Users\Atenuvielle\AppData\Roaming\Mozilla\Firefox\Profiles\nukrx784.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-08-11]
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012-06-06]
FF StartMenuInternet: FIREFOX.EXE - D:\Programme\FireFox\firefox.exe
Chrome:
=======
CHR HomePage:
CHR Extension: (Google Wallet) - C:\Users\Atenuvielle\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-26]
CHR Extension: (Mehr Leistung und Videoformate für dein HTML5 <video>) - C:\Users\Atenuvielle\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2012-07-23]
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-12-12]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-07-09] (Advanced Micro Devices, Inc.) [File not signed]
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-08-05] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-08-05] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [141392 2014-07-24] (Avira Operations GmbH & Co. KG)
R2 ForceWare Intelligent Application Manager (IAM); D:\Programme\NVIDIA\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [726016 2008-09-08] () [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [3937512 2012-10-04] (INCA Internet Co., Ltd.) [File not signed]
R2 nSvcIp; D:\Programme\NVIDIA\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [221696 2008-09-08] () [File not signed]
R2 RalinkRegistryWriter; C:\Program Files (x86)\Tenda\Common\RaRegistry.exe [375872 2011-03-31] (Ralink Technology, Corp.)
R2 RalinkRegistryWriter64; C:\Program Files (x86)\Tenda\Common\RaRegistry64.exe [454208 2011-03-31] (Ralink Technology, Corp.)
S3 RaMediaServer; C:\Program Files (x86)\Tenda\Common\RaMediaServer.exe [621632 2011-03-04] ()
R2 RzOvlMon; C:\Program Files (x86)\Razer\Core\64bit\rzovlmon.exe [32960 2014-04-18] (Razer, Inc.)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 WTService; C:\Windows\System32\atwtusb.exe [907496 2010-06-14] () [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S1 acedrv07; C:\Windows\system32\drivers\acedrv07.sys [125440 2012-12-21] () [File not signed]
R2 acedrv10; C:\Windows\system32\drivers\acedrv10.sys [277904 2012-07-04] (Protect Software GmbH)
R2 acehlp10; C:\Windows\system32\drivers\acehlp10.sys [228000 2012-07-04] (Protect Software GmbH)
R2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-07-03] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-06-03] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-25] (Avira Operations GmbH & Co. KG)
R1 BIOS; C:\Windows\system32\drivers\BIOS64.sys [14136 2006-10-31] (BIOSTAR Group)
R1 BIOS; C:\Windows\SysWOW64\drivers\BIOS64.sys [14136 2006-10-31] (BIOSTAR Group)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-05-26] (Disc Soft Ltd)
S3 ew_hwusbdev; C:\Windows\System32\DRIVERS\ew_hwusbdev.sys [117248 2012-11-15] (Huawei Technologies Co., Ltd.) [File not signed]
S3 hwdatacard; C:\Windows\System32\DRIVERS\ewusbmdm.sys [121600 2012-11-15] (Huawei Technologies Co., Ltd.) [File not signed]
R3 LGPBTDD; C:\Windows\System32\Drivers\LGPBTDD.sys [30728 2009-07-01] (Logitech Inc.)
R3 moufiltr; C:\Windows\System32\DRIVERS\moufiltr.sys [7680 2009-03-08] (Windows (R) Codename Longhorn DDK provider)
R3 RzDxgk; C:\Windows\system32\drivers\RzDxgk.sys [129472 2014-04-11] (Razer, Inc.)
R1 RzFilter; C:\Windows\system32\drivers\RzFilter.sys [74432 2014-04-11] (Razer, Inc.)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [386680 2014-05-26] (Duplex Secure Ltd.)
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [52736 2012-07-09] (Apple, Inc.) [File not signed]
R3 vhidmini; C:\Windows\System32\DRIVERS\walvhid.sys [7552 2009-08-26] (Windows (R) Win 7 DDK provider)
R1 vmm; C:\Windows\system32\Treiber\vmm.sys [294232 2014-05-20] (Microsoft Corporation)
S3 AsrCDDrv; \??\C:\Windows\SysWOW64\Drivers\AsrCDDrv.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [X]
S3 IntcAzAudAddService; system32\drivers\RTKVHD64.sys [X]
S3 massfilter; system32\drivers\massfilter.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S2 X5XSEx_Pr148; \??\C:\Program Files (x86)\FreeRide Games\X5XSEx_Pr148.Sys [X]
S3 X6va011; \??\C:\Windows\SysWOW64\Drivers\X6va011 [X]
S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [X]
S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [X]
S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [X]
S2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}; \??\D:\Programme\PowerDVD10\PowerDVD10\NavFilter\000.fcl [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-11 20:17 - 2014-08-11 20:05 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-08-11 20:06 - 2014-08-11 20:19 - 00010290 _____ () C:\zoek-results.log
2014-08-11 20:05 - 2014-08-11 20:14 - 00000000 ____D () C:\zoek_backup
2014-08-11 20:05 - 2014-08-11 20:05 - 04108341 _____ () C:\Users\Atenuvielle\Desktop\zoek.zip
2014-08-11 20:04 - 2014-08-11 20:05 - 01288704 _____ () C:\Users\Atenuvielle\Desktop\zoek.exe
2014-08-11 19:37 - 2014-08-11 19:37 - 23826752 _____ (Portrait Displays, Inc.) C:\Users\Atenuvielle\Desktop\PLP__Philips_SmartControl_Premium_2.10.016_RC3-Setup.exe
2014-08-11 12:33 - 2014-08-11 20:22 - 00024330 _____ () C:\Users\Atenuvielle\Desktop\FRST.txt
2014-08-11 12:32 - 2014-08-11 12:32 - 00001211 _____ () C:\Users\Atenuvielle\Desktop\JRT.txt
2014-08-11 12:26 - 2014-08-11 12:26 - 00000000 ____D () C:\Windows\ERUNT
2014-08-11 12:25 - 2014-08-11 12:25 - 01016261 _____ (Thisisu) C:\Users\Atenuvielle\Desktop\JRT.exe
2014-08-11 12:24 - 2014-08-11 12:24 - 00001162 _____ () C:\Users\Atenuvielle\Desktop\mbam.txt
2014-08-11 12:01 - 2014-08-11 12:01 - 01366203 _____ () C:\Users\Atenuvielle\Desktop\adwcleaner_3.304.exe
2014-08-11 11:47 - 2014-08-11 20:22 - 00000000 ____D () C:\FRST
2014-08-11 11:46 - 2014-08-11 11:46 - 02099712 _____ (Farbar) C:\Users\Atenuvielle\Desktop\FRST64.exe
2014-08-10 17:50 - 2014-08-11 19:55 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2014-08-10 15:52 - 2014-08-10 15:52 - 00000064 _____ () C:\Users\Atenuvielle\Desktop\Pferdedatenbank.ldb
2014-08-10 01:32 - 2014-08-10 01:32 - 00000000 ____D () C:\Users\Atenuvielle\AppData\Roaming\GreenSauceGames
2014-08-09 19:42 - 2014-08-09 19:42 - 00000000 ____D () C:\Users\Atenuvielle\AppData\Roaming\ZOG
2014-08-09 19:42 - 2014-08-09 19:42 - 00000000 ____D () C:\Users\Atenuvielle\AppData\Roaming\Intenium
2014-08-09 13:14 - 2014-08-09 13:14 - 00000000 ____D () C:\ProgramData\ATI
2014-08-09 13:07 - 2014-08-09 13:07 - 00062096 _____ () C:\Windows\SysWOW64\CCCInstall_201408091307171194.log
2014-08-09 13:07 - 2014-08-09 13:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2014-08-09 13:07 - 2014-08-09 13:07 - 00000000 ____D () C:\Program Files (x86)\AMD AVT
2014-08-09 13:07 - 2014-02-16 18:23 - 00060640 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\usbfilter.sys
2014-08-06 19:58 - 2014-08-06 19:58 - 00000000 ____D () C:\Users\Atenuvielle\AppData\Local\Adobe
2014-08-06 19:57 - 2014-08-06 19:57 - 00275776 _____ () C:\Windows\Minidump\080614-83070-01.dmp
2014-08-06 13:33 - 2014-08-11 12:03 - 00000000 ____D () C:\AdwCleaner
2014-08-06 13:33 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-08-06 13:16 - 2014-08-06 13:16 - 00003828 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1407323775
2014-08-06 13:16 - 2014-08-06 13:16 - 00000000 ____D () C:\Users\Atenuvielle\AppData\Roaming\Opera Software
2014-08-06 13:16 - 2014-08-06 13:16 - 00000000 ____D () C:\Users\Atenuvielle\AppData\Local\Opera Software
2014-08-06 13:11 - 2014-08-06 13:11 - 00244408 _____ () C:\Users\Atenuvielle\Downloads\Firefox Setup Stub 31.0.exe
2014-08-06 12:31 - 2014-08-06 12:31 - 00000000 ____D () C:\Users\Atenuvielle\Documents\StarCraft II
2014-08-05 16:15 - 2014-08-05 16:15 - 00008358 _____ () C:\Users\Atenuvielle\AppData\Local\recently-used.xbel
2014-08-05 02:38 - 2014-08-05 02:38 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-08-05 02:38 - 2014-08-05 02:38 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-08-02 14:20 - 2014-08-11 15:37 - 00014815 _____ () C:\Users\Atenuvielle\Desktop\WoW-Mounts.xlsx
2014-08-02 11:02 - 2014-05-14 18:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-08-02 11:02 - 2014-05-14 18:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-08-02 11:02 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-08-02 11:02 - 2014-05-14 18:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-08-02 11:02 - 2014-05-14 18:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-08-02 11:02 - 2014-05-14 18:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-08-02 11:02 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2014-08-02 11:02 - 2014-05-14 18:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-08-02 11:02 - 2014-05-14 18:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-08-02 11:02 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-08-02 11:02 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-08-02 11:02 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-08-02 11:02 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-08-02 11:02 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-07-28 17:33 - 2014-07-28 17:33 - 00275776 _____ () C:\Windows\Minidump\072814-68796-01.dmp
2014-07-24 21:25 - 2014-07-24 21:25 - 00000000 ____D () C:\Users\Atenuvielle\AppData\Roaming\library_dir
2014-07-24 21:24 - 2014-07-24 21:24 - 00061648 _____ () C:\Windows\SysWOW64\CCCInstall_201407242124315385.log
2014-07-24 21:21 - 2014-07-24 21:21 - 00000000 ____D () C:\Program Files\AMD
2014-07-19 17:20 - 2014-07-19 17:21 - 00000000 ____D () C:\Users\Atenuvielle\Desktop\Musik Auto
2014-07-18 17:23 - 2014-08-05 02:38 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-07-18 17:23 - 2014-08-05 02:38 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-07-18 17:23 - 2014-07-18 17:23 - 00004623 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_65-b20.log
2014-07-13 20:56 - 2014-08-11 12:09 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-13 20:55 - 2014-07-13 20:55 - 00000737 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-07-13 20:55 - 2014-07-13 20:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware
2014-07-13 20:55 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-07-13 20:55 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-11 20:22 - 2014-08-11 12:33 - 00024330 _____ () C:\Users\Atenuvielle\Desktop\FRST.txt
2014-08-11 20:22 - 2014-08-11 11:47 - 00000000 ____D () C:\FRST
2014-08-11 20:22 - 2010-07-06 20:19 - 01401836 _____ () C:\Windows\WindowsUpdate.log
2014-08-11 20:19 - 2014-08-11 20:06 - 00010290 _____ () C:\zoek-results.log
2014-08-11 20:18 - 2010-07-06 22:56 - 00356328 _____ () C:\Windows\PFRO.log
2014-08-11 20:18 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-11 20:18 - 2009-07-14 06:51 - 00243856 _____ () C:\Windows\setupact.log
2014-08-11 20:18 - 2009-07-14 04:34 - 00000593 _____ () C:\Windows\win.ini
2014-08-11 20:14 - 2014-08-11 20:05 - 00000000 ____D () C:\zoek_backup
2014-08-11 20:14 - 2010-07-06 20:23 - 00000000 ____D () C:\Users\Atenuvielle
2014-08-11 20:05 - 2014-08-11 20:17 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-08-11 20:05 - 2014-08-11 20:05 - 04108341 _____ () C:\Users\Atenuvielle\Desktop\zoek.zip
2014-08-11 20:05 - 2014-08-11 20:04 - 01288704 _____ () C:\Users\Atenuvielle\Desktop\zoek.exe
2014-08-11 20:02 - 2009-07-14 06:45 - 00014016 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-11 20:02 - 2009-07-14 06:45 - 00014016 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-11 19:57 - 2012-07-23 15:43 - 00001144 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1616329635-2298572524-3642011023-1000UA.job
2014-08-11 19:57 - 2010-08-22 10:42 - 00000000 ____D () C:\Users\Atenuvielle\Desktop\Spiele
2014-08-11 19:55 - 2014-08-10 17:50 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2014-08-11 19:49 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-08-11 19:37 - 2014-08-11 19:37 - 23826752 _____ (Portrait Displays, Inc.) C:\Users\Atenuvielle\Desktop\PLP__Philips_SmartControl_Premium_2.10.016_RC3-Setup.exe
2014-08-11 17:57 - 2012-07-23 15:43 - 00001092 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1616329635-2298572524-3642011023-1000Core.job
2014-08-11 15:37 - 2014-08-02 14:20 - 00014815 _____ () C:\Users\Atenuvielle\Desktop\WoW-Mounts.xlsx
2014-08-11 12:32 - 2014-08-11 12:32 - 00001211 _____ () C:\Users\Atenuvielle\Desktop\JRT.txt
2014-08-11 12:26 - 2014-08-11 12:26 - 00000000 ____D () C:\Windows\ERUNT
2014-08-11 12:25 - 2014-08-11 12:25 - 01016261 _____ (Thisisu) C:\Users\Atenuvielle\Desktop\JRT.exe
2014-08-11 12:24 - 2014-08-11 12:24 - 00001162 _____ () C:\Users\Atenuvielle\Desktop\mbam.txt
2014-08-11 12:09 - 2014-07-13 20:56 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-11 12:03 - 2014-08-06 13:33 - 00000000 ____D () C:\AdwCleaner
2014-08-11 12:01 - 2014-08-11 12:01 - 01366203 _____ () C:\Users\Atenuvielle\Desktop\adwcleaner_3.304.exe
2014-08-11 11:58 - 2010-07-08 16:08 - 00000000 ____D () C:\Users\Atenuvielle\AppData\Roaming\Skype
2014-08-11 11:46 - 2014-08-11 11:46 - 02099712 _____ (Farbar) C:\Users\Atenuvielle\Desktop\FRST64.exe
2014-08-11 02:14 - 2013-09-12 22:35 - 00000000 ____D () C:\Users\Atenuvielle\AppData\Local\Battle.net
2014-08-10 17:54 - 2012-06-08 22:48 - 00000000 ____D () C:\Users\Atenuvielle\Desktop\Sonstiges
2014-08-10 16:34 - 2012-06-08 10:16 - 14360576 _____ () C:\Users\Atenuvielle\Desktop\Pferdedatenbank.mdb
2014-08-10 15:52 - 2014-08-10 15:52 - 00000064 _____ () C:\Users\Atenuvielle\Desktop\Pferdedatenbank.ldb
2014-08-10 14:41 - 2009-07-14 19:58 - 00714114 _____ () C:\Windows\system32\perfh007.dat
2014-08-10 14:41 - 2009-07-14 19:58 - 00156244 _____ () C:\Windows\system32\perfc007.dat
2014-08-10 14:41 - 2009-07-14 07:13 - 01651758 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-10 01:32 - 2014-08-10 01:32 - 00000000 ____D () C:\Users\Atenuvielle\AppData\Roaming\GreenSauceGames
2014-08-10 01:30 - 2012-08-20 10:35 - 00001141 _____ () C:\Users\Public\Desktop\GAME CENTER.lnk
2014-08-10 01:30 - 2010-10-30 20:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DEUTSCHLAND SPIELT
2014-08-09 19:42 - 2014-08-09 19:42 - 00000000 ____D () C:\Users\Atenuvielle\AppData\Roaming\ZOG
2014-08-09 19:42 - 2014-08-09 19:42 - 00000000 ____D () C:\Users\Atenuvielle\AppData\Roaming\Intenium
2014-08-09 13:14 - 2014-08-09 13:14 - 00000000 ____D () C:\ProgramData\ATI
2014-08-09 13:07 - 2014-08-09 13:07 - 00062096 _____ () C:\Windows\SysWOW64\CCCInstall_201408091307171194.log
2014-08-09 13:07 - 2014-08-09 13:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2014-08-09 13:07 - 2014-08-09 13:07 - 00000000 ____D () C:\Program Files (x86)\AMD AVT
2014-08-09 13:07 - 2013-03-21 18:34 - 00000000 ____D () C:\ProgramData\AMD
2014-08-09 13:06 - 2011-01-22 01:13 - 00000000 ____D () C:\Program Files\ATI Technologies
2014-08-09 12:59 - 2011-01-22 01:12 - 00000000 ____D () C:\AMD
2014-08-08 00:48 - 2014-05-29 15:36 - 00016695 _____ () C:\Users\Atenuvielle\Desktop\eD-Pferdeliste.xlsx
2014-08-07 17:55 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Cursors
2014-08-07 15:51 - 2011-05-09 19:13 - 00000000 ____D () C:\Users\Atenuvielle\Desktop\Bilder
2014-08-06 19:58 - 2014-08-06 19:58 - 00000000 ____D () C:\Users\Atenuvielle\AppData\Local\Adobe
2014-08-06 19:57 - 2014-08-06 19:57 - 00275776 _____ () C:\Windows\Minidump\080614-83070-01.dmp
2014-08-06 19:57 - 2011-02-10 19:16 - 00000000 ____D () C:\Windows\Minidump
2014-08-06 19:56 - 2011-02-10 19:16 - 894395837 ____N () C:\Windows\MEMORY.DMP
2014-08-06 13:39 - 2014-06-19 17:52 - 00000000 ____D () C:\Users\Atenuvielle\Desktop\Sweet Manor Stables
2014-08-06 13:39 - 2010-07-08 16:03 - 00000000 ___RD () C:\Users\Atenuvielle\Desktop\Programme
2014-08-06 13:16 - 2014-08-06 13:16 - 00003828 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1407323775
2014-08-06 13:16 - 2014-08-06 13:16 - 00000000 ____D () C:\Users\Atenuvielle\AppData\Roaming\Opera Software
2014-08-06 13:16 - 2014-08-06 13:16 - 00000000 ____D () C:\Users\Atenuvielle\AppData\Local\Opera Software
2014-08-06 13:11 - 2014-08-06 13:11 - 00244408 _____ () C:\Users\Atenuvielle\Downloads\Firefox Setup Stub 31.0.exe
2014-08-06 13:09 - 2012-06-06 17:10 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-08-06 13:09 - 2012-06-06 17:10 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-08-06 12:40 - 2014-06-27 18:14 - 00000000 ____D () C:\Users\Atenuvielle\AppData\Roaming\Ahnenblatt
2014-08-06 12:31 - 2014-08-06 12:31 - 00000000 ____D () C:\Users\Atenuvielle\Documents\StarCraft II
2014-08-06 12:31 - 2010-07-07 11:52 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment
2014-08-06 12:13 - 2014-06-26 00:10 - 00010688 _____ () C:\Users\Atenuvielle\Desktop\Sims Tiere Alterung Juli 2014.xlsx
2014-08-06 11:18 - 2012-10-15 14:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-08-06 11:18 - 2012-10-15 14:09 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-08-05 16:15 - 2014-08-05 16:15 - 00008358 _____ () C:\Users\Atenuvielle\AppData\Local\recently-used.xbel
2014-08-05 16:15 - 2014-06-21 18:18 - 00000000 ____D () C:\Users\Atenuvielle\.gimp-2.8
2014-08-05 10:59 - 2012-10-15 14:09 - 00000000 ____D () C:\ProgramData\Avira
2014-08-05 02:38 - 2014-08-05 02:38 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-08-05 02:38 - 2014-08-05 02:38 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-08-05 02:38 - 2014-07-18 17:23 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-08-05 02:38 - 2014-07-18 17:23 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-08-05 02:38 - 2013-10-18 23:17 - 00000000 ____D () C:\ProgramData\Oracle
2014-08-05 02:38 - 2010-07-09 07:53 - 00000000 ____D () C:\Program Files (x86)\Java
2014-08-03 13:30 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-08-03 12:43 - 2014-06-24 23:35 - 00000000 ____D () C:\Users\Atenuvielle\AppData\Local\gtk-2.0
2014-08-02 18:03 - 2012-06-07 11:53 - 00001960 _____ () C:\Users\Atenuvielle\Desktop\FohlenBeschreibungen.txt
2014-07-29 18:06 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-07-28 17:33 - 2014-07-28 17:33 - 00275776 _____ () C:\Windows\Minidump\072814-68796-01.dmp
2014-07-24 23:27 - 2013-05-07 15:07 - 00042040 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-07-24 21:34 - 2013-06-01 13:31 - 00000000 ____D () C:\Users\Atenuvielle\Documents\Diablo III
2014-07-24 21:34 - 2013-02-28 21:53 - 00000000 ____D () C:\Users\Atenuvielle\Documents\The Lord of the Rings Online
2014-07-24 21:25 - 2014-07-24 21:25 - 00000000 ____D () C:\Users\Atenuvielle\AppData\Roaming\library_dir
2014-07-24 21:24 - 2014-07-24 21:24 - 00061648 _____ () C:\Windows\SysWOW64\CCCInstall_201407242124315385.log
2014-07-24 21:21 - 2014-07-24 21:21 - 00000000 ____D () C:\Program Files\AMD
2014-07-19 17:21 - 2014-07-19 17:20 - 00000000 ____D () C:\Users\Atenuvielle\Desktop\Musik Auto
2014-07-19 14:54 - 2013-07-20 16:11 - 00000000 ____D () C:\Users\Atenuvielle\AppData\Roaming\DVDVideoSoft
2014-07-19 14:54 - 2013-07-20 16:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2014-07-18 17:23 - 2014-07-18 17:23 - 00004623 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_65-b20.log
2014-07-16 23:59 - 2013-09-24 21:31 - 00000000 ____D () C:\Users\Atenuvielle\Desktop\GIMP
2014-07-16 21:37 - 2010-08-28 12:34 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-07-15 18:06 - 2010-07-06 20:27 - 00797264 _____ () C:\Windows\DPINST.LOG
2014-07-13 20:55 - 2014-07-13 20:55 - 00000737 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-07-13 20:55 - 2014-07-13 20:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware
2014-07-13 20:55 - 2011-01-20 11:12 - 00000000 ____D () C:\Users\Atenuvielle\AppData\Roaming\Malwarebytes
2014-07-13 20:55 - 2011-01-20 11:12 - 00000000 ____D () C:\ProgramData\Malwarebytes
Some content of TEMP:
====================
C:\Users\Atenuvielle\AppData\Local\Temp\avgnt.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-08-07 12:54
==================== End Of Log ============================
Addition.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-08-2014 01
Ran by Atenuvielle at 2014-08-11 20:23:23
Running from C:\Users\Atenuvielle\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Acrobat 4.0 (HKLM-x32\...\Adobe Acrobat 4.0) (Version: - )
Adobe Anchor Service CS4 (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe Anchor Service x64 CS4 (Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe Bridge CS4 (x32 Version: 3 - Adobe Systems Incorporated) Hidden
Adobe CMaps CS4 (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe CMaps x64 CS4 (Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe Color - Photoshop Specific CS4 (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe Color EU Recommended Settings CS4 (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe Color JA Extra Settings CS4 (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe Color NA Extra Settings CS4 (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe Color Video Profiles CS CS4 (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.0.0.400 - Adobe Systems Incorporated)
Adobe Community Help (x32 Version: 3.0.0 - Adobe Systems Incorporated) Hidden
Adobe CSI CS4 (x32 Version: 1 - Adobe Systems Incorporated) Hidden
Adobe CSI CS4 x64 (Version: 1 - Adobe Systems Incorporated) Hidden
Adobe Default Language CS4 (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe Device Central CS4 (x32 Version: 2 - Adobe Systems Incorporated) Hidden
Adobe Drive CS4 (x32 Version: 1 - Adobe Systems Incorporated) Hidden
Adobe Drive CS4 x64 (Version: 1 - Adobe Systems Incorporated) Hidden
Adobe ExtendScript Toolkit CS4 (x32 Version: 3.0.0 - Adobe Systems Incorporated) Hidden
Adobe Extension Manager CS4 (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated)
Adobe Fonts All (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe Fonts All x64 (Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe Linguistics CS4 (x32 Version: 4.0.0 - Adobe Systems Incorporated) Hidden
Adobe Linguistics CS4 x64 (Version: 4.0.0 - Adobe Systems Incorporated) Hidden
Adobe Media Player (HKLM-x32\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.8 - Adobe Systems Incorporated)
Adobe Media Player (x32 Version: 1.8 - Adobe Systems Incorporated) Hidden
Adobe Output Module (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe PDF Library Files CS4 (x32 Version: 9.0 - Adobe Systems Incorporated) Hidden
Adobe PDF Library Files x64 CS4 (Version: 9.0 - Adobe Systems Incorporated) Hidden
Adobe Photoshop CS4 (64 Bit) (Version: 11.0 - Adobe Systems Incorporated) Hidden
Adobe Photoshop CS4 (HKLM-x32\...\Adobe_faf656ef605427ee2f42989c3ad31b8) (Version: 11.0 - Adobe Systems Incorporated)
Adobe Photoshop CS4 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
Adobe Photoshop CS4 Support (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
Adobe Photoshop CS5 (HKLM-x32\...\{15FEDA5F-141C-4127-8D7E-B962D1742728}) (Version: 12.0 - Adobe Systems Incorporated)
Adobe Reader XI - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.00 - Adobe Systems Incorporated)
Adobe Search for Help (x32 Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Service Manager Extension (x32 Version: 1.0 - Adobe Systems Incorporated) Hidden
Adobe Setup (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden
Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.2.122 - Adobe Systems, Inc.)
Adobe Type Support CS4 (x32 Version: 9.0 - Adobe Systems Incorporated) Hidden
Adobe Type Support x64 CS4 (Version: 9.0 - Adobe Systems Incorporated) Hidden
Adobe Update Manager CS4 (x32 Version: 6.0.0 - Adobe Systems Incorporated) Hidden
Adobe WinSoft Linguistics Plugin (x32 Version: 1.1 - Adobe Systems Incorporated) Hidden
Adobe WinSoft Linguistics Plugin x64 (Version: 1.1 - Adobe Systems Incorporated) Hidden
Adobe XMP Panels CS4 (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden
AdobeColorCommonSetCMYK (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden
AdobeColorCommonSetRGB (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden
Akamai NetSession Interface (HKCU\...\Akamai) (Version: - Akamai Technologies, Inc)
AMD Accelerated Video Transcoding (Version: 13.30.100.40709 - Advanced Micro Devices, Inc.) Hidden
AMD APP SDK Runtime (Version: 10.0.1084.4 - Advanced Micro Devices Inc.) Hidden
AMD Catalyst Control Center (x32 Version: 2014.0709.1135.19003 - Ihr Firmenname) Hidden
AMD Catalyst Install Manager (HKLM\...\{EE0B4480-194D-C725-EDF8-6CE3FC4DDC89}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
AMD Drag and Drop Transcoding (Version: 2.00.0000 - ATI Technologies Inc.) Hidden
AMD Fuel (Version: 2014.0709.1135.19003 - Ihr Firmenname) Hidden
AMD Media Foundation Decoders (Version: 1.0.80604.1838 - Advanced Micro Devices, Inc.) Hidden
AMD Wireless Display v3.0 (Version: 1.0.0.12 - Advanced Micro Devices, Inc.) Hidden
AMD Wireless Display v3.0 (Version: 1.0.0.15 - Advanced Micro Devices, Inc.) Hidden
Any Media Converter (HKLM-x32\...\Any Media Converter) (Version: 1.14 - Any Media Converter)
ASUS VGA Driver (x32 Version: 3.0.0.1 - Ihr Firmenname) Hidden
ATI AVIVO64 Codecs (Version: 10.12.0.41211 - ATI Technologies Inc.) Hidden
ATI Problem Report Wizard (Version: 3.0.758.0 - ATI Technologies) Hidden
Avira (HKLM-x32\...\{9590977b-7b6f-467e-a11a-efa1fae804da}) (Version: 1.1.18.30000 - Avira Operations GmbH & Co. KG)
Avira (x32 Version: 1.1.18.30000 - Avira Operations GmbH & Co. KG) Hidden
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.6.552 - Avira)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
Big Fish Games: Game Manager (HKLM-x32\...\BFGC) (Version: 2.0.1.43 - )
Blender (HKLM\...\Blender) (Version: 2.70a - Blender Foundation)
Blue Byte Game Channel (HKLM-x32\...\Blue Byte Game Channel) (Version: - UbiSoft)
calibre 64bit (HKLM\...\{618EBBE8-A3B1-465D-B06C-83F9BF7A79A2}) (Version: 0.9.28 - Kovid Goyal)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2014.0709.1135.19003 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2014.0709.1135.19003 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2014.0709.1135.19003 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (x32 Version: 2014.0709.1134.19003 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (x32 Version: 2014.0709.1134.19003 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (x32 Version: 2014.0709.1134.19003 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (x32 Version: 2014.0709.1134.19003 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (x32 Version: 2014.0709.1134.19003 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (x32 Version: 2014.0709.1134.19003 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (x32 Version: 2014.0709.1134.19003 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (x32 Version: 2014.0709.1134.19003 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (x32 Version: 2014.0709.1134.19003 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (x32 Version: 2014.0709.1134.19003 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (x32 Version: 2014.0709.1134.19003 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (x32 Version: 2014.0709.1134.19003 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (x32 Version: 2014.0709.1134.19003 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (x32 Version: 2014.0709.1134.19003 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (x32 Version: 2014.0709.1134.19003 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (x32 Version: 2014.0709.1134.19003 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (x32 Version: 2014.0709.1134.19003 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (x32 Version: 2014.0709.1134.19003 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (x32 Version: 2014.0709.1134.19003 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (x32 Version: 2014.0709.1134.19003 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (x32 Version: 2014.0709.1134.19003 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (x32 Version: 2014.0709.1134.19003 - Advanced Micro Devices, Inc.) Hidden
ccc-utility64 (Version: 2014.0709.1135.19003 - Advanced Micro Devices, Inc.) Hidden
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
Connect (x32 Version: 1.0.0.1 - Adobe Systems Incorporated) Hidden
Converter version 0.1 (HKLM-x32\...\Converter_is1) (Version: 0.1 - )
Corel Shell Extension - 64Bit (Version: 14.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Content (x32 Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Draw (x32 Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Filters (x32 Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - ICA (x32 Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - IPM - No VBA (x32 Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Lang BR (x32 Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Lang DE (x32 Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Lang EN (x32 Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Lang ES (x32 Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Lang FR (x32 Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Lang IT (x32 Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Lang NL (x32 Version: 4.0 - Uw bedrijfsnaam) Hidden
CorelDRAW Essentials 4 - PHOTO-PAINT (x32 Version: 4.0 - Corel Corporation) Hidden
CorelDRAW Essentials 4 - Windows Shell Extension (HKLM-x32\...\_{CF0ADC18-6D8F-4353-8EAA-DF45456B7853}) (Version: - Corel Corporation)
CorelDRAW Essentials 4 - Windows Shell Extension (x32 Version: 1.1 - Corel Corporation) Hidden
CorelDRAW Essentials 4 (HKLM-x32\...\_{C0237AA4-1BFB-46EA-860D-7B0EB365CA13}) (Version: - Corel Corporation)
CorelDRAW Essentials 4 (x32 Version: 4.0 - Corel Corporation) Hidden
Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version: - Valve)
CPUID HWMonitor 1.25 (HKLM\...\CPUID HWMonitor_is1) (Version: - )
CyberLink PowerDVD 10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.1705 - CyberLink Corp.)
CyberLink PowerDVD 10 (x32 Version: 10.0.1705 - CyberLink Corp.) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{5C78021E-3C8E-4EDF-97EA-E9B8D808FD6D}) (Version: - Microsoft)
Der Herr der Ringe Online v03.03.06.8008 (HKLM-x32\...\12bbe590-c890-11d9-9669-0800200c9a66_is1) (Version: 03.03.06.8008 - Turbine, Inc.)
Deutschland Spielt - Spiele Post (HKLM-x32\...\Deutschland Spielt - Spiele Post) (Version: 1.0.4.38 - INTENIUM GmbH)
DEUTSCHLAND SPIELT GAME CENTER (HKLM-x32\...\DSGPlayer) (Version: 2.4.2.13 - INTENIUM GmbH)
DEUTSCHLAND SPIELT Spiele Post (HKLM-x32\...\DEUTSCHLAND SPIELT Spiele Post) (Version: 1.0.3.0 - INTENIUM GmbH)
Diablo III (HKLM-x32\...\Diablo III) (Version: - Blizzard Entertainment)
Die Siedler II - Die nächste Generation (HKLM-x32\...\S2TNG) (Version: - )
Die Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.67.2 - Electronic Arts)
Die Sims™ 3 Einfach tierisch (HKLM-x32\...\{C12631C6-804D-4B32-B0DD-8A496462F106}) (Version: 10.0.96 - Electronic Arts)
DivX-Setup (HKLM-x32\...\DivX Setup.divx.com) (Version: 2.5.0.8 - DivX, LLC)
Download Protect (HKCU\...\{132401a7-2006-4342-b43c-ccf5f02c2b01}) (Version: - Download Protect)
Etron USB3.0 Host Controller (HKLM-x32\...\InstallShield_{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}) (Version: 0.115 - Etron Technology)
Etron USB3.0 Host Controller (x32 Version: 0.115 - Etron Technology) Hidden
FalNET G19 Display Manager (HKLM-x32\...\FalNET G19 Display Manager_is1) (Version: - FalNET)
Fotogalerie (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Foxy Secure (HKLM-x32\...\Foxy Secure) (Version: 6 - )
Free Notes & Office Ink (HKLM-x32\...\{556F2137-B772-43BB-9A45-E0275234DD16}) (Version: - )
Free Video Converter V 2.9 (HKLM-x32\...\Free Video Converter_is1) (Version: 2.9.0.0 - Koyote Soft)
Free YouTube to MP3 Converter version 3.12.42.716 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.42.716 - DVDVideoSoft Ltd.)
FreeRide Games (HKLM-x32\...\{6C26A305-4549-4A8A-9F03-25719C03B0FB}) (Version: 07.05.82.01 - Exent Technologies)
Gameforge Live 2.0.1 "Baby Genius" (HKLM-x32\...\{9C98989A-3A15-42DA-A3B9-D20331437D67}}_is1) (Version: 2.0.1 - Gameforge)
Gamestudio A7 (HKLM-x32\...\Gamestudio A7) (Version: 7.85.4 - oP group)
Geschichten aus dem Orient: Die aufgehende Sonne (HKLM-x32\...\Geschichten aus dem Orient: Die aufgehende Sonne) (Version: 2.0.0.0 - INTENIUM GmbH)
G-Force (HKLM-x32\...\G-Force) (Version: 3.8.5 - SoundSpectrum)
GIMP 2.8.10 (HKLM\...\GIMP-2_is1) (Version: 2.8.10 - The GIMP Team)
Google Chrome (HKCU\...\Google Chrome) (Version: 36.0.1985.125 - Google Inc.)
Happy Cloud Client (HKCU\...\HappyCloud) (Version: 1.342 - Happy Cloud, Inc.)
Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment)
ICQ7.5 (HKLM-x32\...\{7578ADEA-D65F-4C89-A249-B1C88B6FFC20}) (Version: 7.5 - ICQ)
Icy Tower v1.4 (HKLM-x32\...\Icy Tower v1.4_is1) (Version: - Free Lunch Design)
Java 7 Update 67 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217067FF}) (Version: 7.0.670 - Oracle)
Java Auto Updater (x32 Version: 2.1.67.1 - Oracle, Inc.) Hidden
Java(TM) 6 Update 24 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216024FF}) (Version: 6.0.240 - Oracle)
JavaFX 2.1.1 (HKLM-x32\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation)
JDownloader 0.9 (HKLM-x32\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH)
Kalydo Player 4.10.01 (HKCU\...\KalydoPlayer) (Version: 4.10.01 - Eximion B.V.)
kuler (x32 Version: 2.0 - Adobe Systems Incorporated) Hidden
Logitech Gaming Software (Version: 8.45.88 - Logitech Inc.) Hidden
Logitech Gaming Software 8.51 (HKLM\...\Logitech Gaming Software) (Version: 8.51.5 - Logitech Inc.)
MacroKey Manager (HKLM-x32\...\InstallShield_{66A4349A-AA55-43E5-A781-62867A701A90}) (Version: - )
MacroKey Manager (Version: 1.00.0000 - Ihr Firmenname) Hidden
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Marvell Miniport Driver (HKLM\...\{5254156F-AA77-499A-B7C1-D5581D44E788}) (Version: 9.12.4.3 - Marvell)
Mein Gestüt – Ein Leben für die Pferde (HKLM-x32\...\MyRidingStables) (Version: 1.0 - Sproing Interactive GmbH)
Microsoft .NET Framework 1.1 (HKLM-x32\...\Microsoft .NET Framework 1.1 (1033)) (Version: - )
Microsoft .NET Framework 1.1 (x32 Version: 1.1.4322 - Microsoft) Hidden
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Games for Windows - LIVE (HKLM-x32\...\{2C9EE786-1DDB-4C98-8FA4-B1B9B5A66B77}) (Version: 3.1.186.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{00C5F4F4-62F9-40D7-8000-AD8A9CD0C669}) (Version: 3.1.99.0 - Microsoft Corporation)
Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Virtual PC 2007 (HKLM\...\{8A7CAA24-7B23-410B-A7C3-F994B0944160}) (Version: 6.0.156.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{14297226-E0A0-3781-8911-E9D529552663}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{09298F26-A95C-31E2-9D95-2C60F586F075}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Microsoft_VC80_ATL_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053 - Adobe) Hidden
Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000 - Adobe) Hidden
MorphVOX Pro (HKLM-x32\...\{86E0CAC0-6DF8-416D-A195-31FEAD651191}) (Version: 4.3.9 - Screaming Bee)
Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Mozilla Firefox 13.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 13.0.1 (x86 de)) (Version: 13.0.1 - Mozilla)
Mozilla Firefox 31.0 (x86 de) (HKCU\...\Mozilla Firefox 31.0 (x86 de)) (Version: 31.0 - Mozilla)
Mozilla Firefox 31.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 31.0 (x86 de)) (Version: 31.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 13.0.1 - Mozilla)
Mp3tag v2.56 (HKLM-x32\...\Mp3tag) (Version: v2.56 - Florian Heidenreich)
MSM2MSI_gstudio (HKLM-x32\...\{C53F001E-5912-4E76-AC49-9AC20B36B1A2}) (Version: 2.0 - Pantaray)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden
MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: - )
NVIDIA ForceWare Network Access Manager (HKLM-x32\...\InstallShield_{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}) (Version: - )
NVIDIA ForceWare Network Access Manager (Version: 1.00.6793 - NVIDIA Corporation) Hidden
NVIDIA PhysX (HKLM-x32\...\{5DB65884-C963-4454-AABA-4CA3089281FA}) (Version: 9.09.0720 - NVIDIA Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
Opera 12.17 (HKLM-x32\...\Opera 12.17.1863) (Version: 12.17.1863 - Opera Software ASA)
Opera Stable 23.0.1522.72 (HKLM-x32\...\Opera 23.0.1522.72) (Version: 23.0.1522.72 - Opera Software ASA)
Oracle VM VirtualBox 4.0.4 (HKLM\...\{82E3FBCE-9BA2-44E3-9FF9-EFE9E8B70131}) (Version: 4.0.4 - Oracle Corporation)
Origin (HKLM-x32\...\Origin) (Version: 8.6.0.357 - Electronic Arts, Inc.)
PDF Settings CS4 (x32 Version: 9.0 - Adobe Systems Incorporated) Hidden
PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden
Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Photo Gallery (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Photoshop Camera Raw (x32 Version: 5.0 - Adobe Systems Incorporated) Hidden
Photoshop Camera Raw_x64 (Version: 5.0 - Adobe Systems Incorporated) Hidden
ProtectDisc Helper Driver 10 (HKLM-x32\...\ProtectDisc Driver 10) (Version: 10.0.0.3 - )
QuickTime (HKLM-x32\...\{57752979-A1C9-4C02-856B-FBB27AC4E02C}) (Version: 7.69.80.9 - Apple Inc.)
Razer Core (HKLM-x32\...\Razer Core) (Version: 1.0.1.66 - Razer Inc)
Razer Synapse 2.0 (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.18.15.20888 - Razer Inc.)
REALTEK GbE & FE Ethernet PCI NIC Driver (HKLM-x32\...\{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}) (Version: 1.13.0000 - Realtek)
Rtl8180 (HKLM-x32\...\{01558B00-3F19-4E26-8B56-11CA9F97E81C}) (Version: - )
Sacred 2 (HKLM-x32\...\{1023383E-D9F6-478C-A965-23A4657B3C9A}) (Version: 2.0.2.0 - Ascaron Entertainment)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version: - Microsoft) Hidden
Skype™ 6.16 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.16.105 - Skype Technologies S.A.)
SOE Web Installer (HKCU\...\SOE Web Installer) (Version: 1.0.3.133 - Sony Online Entertainment)
Spotify (HKCU\...\Spotify) (Version: 0.9.8.296.g91f68827 - Spotify AB)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
Suite Shared Configuration CS4 (x32 Version: 1.0 - Adobe Systems Incorporated) Hidden
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.10 - TeamSpeak Systems GmbH)
Tenda Wireless LAN Card (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 1.5.12.0 - Tenda)
Titan Quest (HKLM-x32\...\{412B69AF-C352-4F6F-A318-B92B3CB9ACC6}) (Version: 1.00.0000 - Iron Lore)
Unity Web Player (HKCU\...\UnityWebPlayer) (Version: - Unity Technologies ApS)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version: - Microsoft)
Update for Microsoft Excel 2010 (KB2837600) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{4ACD847E-547D-493F-9A86-F73EAE1B5174}) (Version: - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version: - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version: - Microsoft)
Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version: - Microsoft)
Update for Microsoft InfoPath 2010 (KB2817396) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{39767ECA-1731-45DB-AB5B-6BF40E151D66}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2825635) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{F1A20C69-9FE5-40FD-9CD5-84EABC2EF64A}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2825640) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{BA610006-2C39-4419-9834-CF61AB24810A}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2837581) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{334FB202-28D7-4BA4-8BC9-4FE4AB233EA0}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2837606) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{B0D672F7-883E-4279-8E75-D97A5445AB46}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2878252) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{B0DB9F71-E0F7-4FE6-8925-35B860CAC0C4}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.PROPLUS_{EAD7BEF9-B28C-425F-B2C5-538CB27EF013}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUS_{C0BDC1DE-C35E-422B-8CBD-C1D555468720}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUS_{089DBFD7-8211-43B2-AAAE-5BDD8C23E3A8}) (Version: - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version: - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.PROPLUS_{A0657506-69DC-44AE-8DC1-58E7C6F5B1C9}) (Version: - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{2BA40F82-F3A4-441C-BF1A-ED4C42FF4872}) (Version: - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0407-0000-0000000FF1CE}_Office14.PROPLUS_{40EC8FB1-5202-469D-9232-C28FB1C6FC64}) (Version: - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version: - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version: - Microsoft)
Update for Microsoft Visio 2010 (KB2880526) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{7B29D8B8-6A87-496C-A65E-B935E740448A}) (Version: - Microsoft)
Update for Microsoft Visio Viewer 2010 (KB2837587) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{38CF30E4-3348-4BD1-A859-B630C355A56F}) (Version: - Microsoft)
Update for Microsoft Word 2010 (KB2880529) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{B9B89E01-5B6B-4F73-BC34-B2C0D8ACB4CD}) (Version: - Microsoft)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
VLC media player 1.1.5 (HKLM-x32\...\VLC media player) (Version: 1.1.5 - VideoLAN)
Windows Live Communications Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Media Lite 2.3.0 (HKLM-x32\...\wmlite2_is1) (Version: 2.3.0 - )
WinRAR (HKLM\...\WinRAR archiver) (Version: - )
World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment)
XP Codec Pack (HKLM-x32\...\XP Codec Pack) (Version: 2.5.3 - XP Codec Pack team)
Zip Motion Block Video codec (Remove Only) (HKLM-x32\...\ZMBV) (Version: - DOSBox Team)
Zoo Tycoon 2 - Ausgestorbene Tierarten (HKLM-x32\...\InstallShield_{15292416-A464-4FBA-BB96-7298EAACFC07}) (Version: 1.00.0000 - Microsoft Game Studios)
Zoo Tycoon 2 - Ausgestorbene Tierarten (x32 Version: 1.00.0000 - Microsoft Game Studios) Hidden
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-1616329635-2298572524-3642011023-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Atenuvielle\AppData\Roaming\Dropbox\bin\Dropbox.exe /autoplay No File
CustomCLSID: HKU\S-1-5-21-1616329635-2298572524-3642011023-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Atenuvielle\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-1616329635-2298572524-3642011023-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Atenuvielle\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1616329635-2298572524-3642011023-1000_Classes\CLSID\{D45F043D-F17F-4e8a-8435-70971D9FA46D}\InprocServer32 -> D:\Programme\Blender\BlendThumb64.dll ()
CustomCLSID: HKU\S-1-5-21-1616329635-2298572524-3642011023-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Atenuvielle\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1616329635-2298572524-3642011023-1000_Classes\CLSID\{F7D4B6AD-AB5F-4fe8-9469-3A4697E41129}\InprocServer32 -> C:\Users\Atenuvielle\AppData\Roaming\Kalydo\KalydoPlayer\bin2\kalydoplayer64.dll (Eximion B.V.)
CustomCLSID: HKU\S-1-5-21-1616329635-2298572524-3642011023-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Atenuvielle\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll No File
==================== Restore Points =========================
11-08-2014 14:50:59 Geplanter Prüfpunkt
11-08-2014 18:06:34 zoek.exe restore point
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {190C9BCC-634F-470E-A133-FD2D2228DE62} - System32\Tasks\Microsoft\Windows\TabletPC\InputPersonalization => C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe [2009-07-14] (Microsoft Corporation)
Task: {4A053DCE-C4DC-41A0-ABE4-0B7F2001A95A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1616329635-2298572524-3642011023-1000Core => C:\Users\Atenuvielle\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-23] (Google Inc.)
Task: {85725B47-D53C-4E60-B848-0A012170A178} - System32\Tasks\SidebarExecute => C:\Program Files (x86)\Windows Sidebar\sidebar.exe [2010-11-20] (Microsoft Corporation)
Task: {88EF4E50-7211-4014-A1E4-6F1F508F8A5C} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1616329635-2298572524-3642011023-1000UA => C:\Users\Atenuvielle\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-23] (Google Inc.)
Task: {A30CA0FD-6526-4558-A713-B82CA90A5318} - System32\Tasks\{39B299EC-197C-4921-BF40-02DB6D330631} => Firefox.exe hxxp://ui.skype.com/ui/0/5.1.0.112.259/en/abandoninstall?page=tsMain&installinfo=google-toolbar:notoffered;ienotdefaultbrowser2,google-chrome:offered-installed;madedefault
Task: {F8647819-1999-43FE-9FC5-0B85B5E25DD6} - System32\Tasks\Opera scheduled Autoupdate 1407323775 => D:\Programme\Opera\launcher.exe [2014-08-05] (Opera Software)
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1616329635-2298572524-3642011023-1000Core.job => C:\Users\Atenuvielle\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1616329635-2298572524-3642011023-1000UA.job => C:\Users\Atenuvielle\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2014-07-09 11:36 - 2014-07-09 11:36 - 00214528 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.PerformanceTuning.dll
2014-02-11 07:08 - 2014-02-11 07:08 - 00817152 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll
2014-02-11 07:08 - 2014-02-11 07:08 - 03650560 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Platform.dll
2014-07-09 11:35 - 2014-07-09 11:35 - 00127488 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
2010-06-14 14:27 - 2010-06-14 14:27 - 00907496 _____ () C:\Windows\System32\atwtusb.exe
2010-06-14 14:27 - 2010-06-14 14:27 - 00907496 _____ () C:\Windows\system32\atwtusb.exe
2014-07-22 18:49 - 2008-09-08 11:11 - 00726016 _____ () D:\Programme\NVIDIA\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
2014-07-22 18:49 - 2008-09-08 10:57 - 00115712 _____ () D:\Programme\NVIDIA\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\nv_common.dll
2014-07-22 18:49 - 2008-09-08 11:09 - 00221696 _____ () D:\Programme\NVIDIA\NetworkAccessManager\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2010-07-14 17:06 - 2010-03-15 11:28 - 00166400 _____ () C:\Program Files\WinRAR\rarext.dll
2014-07-09 11:35 - 2014-07-09 11:35 - 00102400 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2014-07-24 11:50 - 2014-07-24 11:50 - 00137296 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.NativeCore.dll
2014-07-24 11:49 - 2014-07-24 11:49 - 00065104 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.AvConnectorNative.dll
2014-03-04 13:57 - 2011-05-04 20:53 - 01058664 _____ () C:\Program Files (x86)\Tenda\Common\RaWLAPI.dll
2014-08-11 20:19 - 2014-07-24 11:50 - 00049744 _____ () C:\Users\Atenuvielle\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
2014-08-06 13:12 - 2014-07-17 07:42 - 03800688 _____ () D:\Programme\FireFox\mozjs.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^108Mbps Wireless LAN Adapter Configuration Utility.lnk => C:\Windows\pss\108Mbps Wireless LAN Adapter Configuration Utility.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Air Mouse.lnk => C:\Windows\pss\Air Mouse.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^GomezPEER.lnk => C:\Windows\pss\GomezPEER.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Reg.lnk => C:\Windows\pss\Reg.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Atenuvielle^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Atenuvielle^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Facebook Messenger.lnk => C:\Windows\pss\Facebook Messenger.lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: AdobeCS4ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
MSCONFIG\startupreg: AdobeCS5ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
MSCONFIG\startupreg: DAEMON Tools Lite => "D:\Programme\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: DivXUpdate => "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
MSCONFIG\startupreg: Google Update => "C:\Users\Atenuvielle\AppData\Local\Google\Update\GoogleUpdate.exe" /c
MSCONFIG\startupreg: MacroKeyManager => WTMKM.exe
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
MSCONFIG\startupreg: Spiele Post => C:\Program Files (x86)\OXXOGames\GPlayer\GameCenterNotifier.exe
MSCONFIG\startupreg: Spotify => "C:\Users\Atenuvielle\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart
MSCONFIG\startupreg: Spotify Web Helper => "C:\Users\Atenuvielle\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
MSCONFIG\startupreg: Steam => "D:\Programme\Steam\Steam.exe" -silent
==================== Faulty Device Manager Devices =============
Name: X5XSEx_Pr148
Description: X5XSEx_Pr148
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: X5XSEx_Pr148
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
Name: Power Control [2010/07/31 12:00:17]
Description: Power Control [2010/07/31 12:00:17]
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
Name: Realtek PCIe GBE Family Controller
Description: Realtek PCIe GBE Family Controller
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Realtek
Service: RTL8167
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
Name: Microsoft Virtual WiFi Miniport Adapter #5
Description: Microsoft-Adapter für Miniports virtueller WiFis
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: vwifimp
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (08/11/2014 07:51:37 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm FRST64.exe, Version 10.8.2014.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 43fc
Startzeit: 01cfb58cd9e35347
Endzeit: 6
Anwendungspfad: C:\Users\Atenuvielle\Desktop\FRST64.exe
Berichts-ID: 2298f33e-2180-11e4-9efb-9a72df0d481e
Error: (08/11/2014 07:50:48 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm FRST64.exe, Version 10.8.2014.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: d4d8
Startzeit: 01cfb58c986317e0
Endzeit: 4
Anwendungspfad: C:\Users\Atenuvielle\Desktop\FRST64.exe
Berichts-ID: 01079fcb-2180-11e4-9efb-9a72df0d481e
Error: (08/11/2014 07:49:33 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 31.0.0.5310, Zeitstempel: 0x53c75e91
Name des fehlerhaften Moduls: mozalloc.dll, Version: 31.0.0.5310, Zeitstempel: 0x53c72e91
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000141b
ID des fehlerhaften Prozesses: 0x4084
Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0
Pfad der fehlerhaften Anwendung: plugin-container.exe1
Pfad des fehlerhaften Moduls: plugin-container.exe2
Berichtskennung: plugin-container.exe3
System errors:
=============
Error: (08/11/2014 08:18:59 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
acedrv07
Error: (08/11/2014 08:18:52 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Power Control [2010/07/31 12:00:17]" wurde aufgrund folgenden Fehlers nicht gestartet:
%%3
Error: (08/11/2014 08:18:52 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "X5XSEx_Pr148" wurde aufgrund folgenden Fehlers nicht gestartet:
%%3
Error: (08/11/2014 08:14:43 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (08/11/2014 08:14:43 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (08/11/2014 08:14:43 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (08/11/2014 08:14:42 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (08/11/2014 08:14:42 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (08/11/2014 07:55:27 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
acedrv07
Error: (08/11/2014 07:55:14 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Power Control [2010/07/31 12:00:17]" wurde aufgrund folgenden Fehlers nicht gestartet:
%%3
Microsoft Office Sessions:
=========================
Error: (08/11/2014 07:51:37 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: FRST64.exe10.8.2014.043fc01cfb58cd9e353476C:\Users\Atenuvielle\Desktop\FRST64.exe2298f33e-2180-11e4-9efb-9a72df0d481e
Error: (08/11/2014 07:50:48 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: FRST64.exe10.8.2014.0d4d801cfb58c986317e04C:\Users\Atenuvielle\Desktop\FRST64.exe01079fcb-2180-11e4-9efb-9a72df0d481e
Error: (08/11/2014 07:49:33 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe31.0.0.531053c75e91mozalloc.dll31.0.0.531053c72e91800000030000141b408401cfb58b82f67d97D:\Programme\FireFox\plugin-container.exeD:\Programme\FireFox\mozalloc.dlld96e2c4a-217f-11e4-9efb-9a72df0d481e
CodeIntegrity Errors:
===================================
Date: 2014-08-11 20:18:32.739
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\acedrv07.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-08-11 20:18:32.583
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\acedrv07.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-08-11 19:54:55.864
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\acedrv07.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-08-11 19:54:55.724
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\acedrv07.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-08-11 12:05:10.287
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\acedrv07.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-08-11 12:05:10.146
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\acedrv07.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-08-11 10:48:35.736
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\acedrv07.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-08-11 10:48:35.596
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\acedrv07.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-08-10 17:48:44.362
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\acedrv07.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2014-08-10 17:48:44.221
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\acedrv07.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
==================== Memory info ===========================
Percentage of memory in use: 33%
Total physical RAM: 8148.75 MB
Available physical RAM: 5413.09 MB
Total Pagefile: 16295.68 MB
Available Pagefile: 13382.31 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB
==================== Drives ================================
Drive c: (System) (Fixed) (Total:99.9 GB) (Free:32.4 GB) NTFS
Drive d: (Spiele) (Fixed) (Total:365.76 GB) (Free:240.45 GB) NTFS
Drive g: (Sims3EP05) (CDROM) (Total:5.31 GB) (Free:0 GB) CDFS
Drive k: (Hitachi) (Fixed) (Total:931.51 GB) (Free:549.13 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 2D56708D)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=100 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=366 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 932 GB) (Disk ID: 06E79B81)
Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS)
==================== End Of Log ============================
Logdatei von Systemlog Code:
ATTFilter SystemLook 30.07.11 by jpshortstuff
Log created at 20:24 on 11/08/2014 by Atenuvielle
Administrator - Elevation successful
========== regfind ==========
Searching for "Security Systems"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Foxy Secure]
"UninstallString"="C:\Users\Atenuvielle\AppData\Roaming\Security Systems\uninstall.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Foxy Secure]
"DisplayIcon"="C:\Users\Atenuvielle\AppData\Roaming\Security Systems\uninstall.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Foxy Secure]
"InstallLocation"="C:\Users\Atenuvielle\AppData\Roaming\Security Systems\"
Searching for "Hub Timer"
No data found.
Searching for "IsUnjnst.exe"
No data found.
-= EOF =-
Die Quarantine.zip habe ich hochgeladen, habe auch meinen Usernamen und den Link zum Thema angegeben, ich hoffe das war richtig so |
| Themen zu Download Protect 2.2.5 lässt sich aus Firefox nicht entfernen |
| erweiterung, georg, hallo zusammen, komplett, malwarebytes, msil/webcake.a, problem, protect, verschwunden, win32/bundled.toolbar.ask, win32/bundled.toolbar.ask.d, win32/bundled.toolbar.ask.g, win32/bundled.toolbar.google.d, win32/hiddenstart.a, win32/sweetim.l, win32/toolbar.conduit.b, zusammen |