Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: PC hängt alle paar Sek & Programme laufen langsamer

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

 
Alt 22.07.2015, 08:40   #1
Kirito[GER]
 
PC hängt alle paar Sek & Programme laufen langsamer - Standard

PC hängt alle paar Sek & Programme laufen langsamer



Seit ca. vorgestern hängt mein PC alle paar Sekunden und alle Programme laufen im allgemeinen langsamer. Ich hab mir in letzter Zeit über Google ein 3 Bilder gedownloadet und über Steam ein Spiel (Trove)

Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-07-2015
Ran by peer (administrator) on PEER-PC on 22-07-2015 09:18:50
Running from C:\Users\peer\Desktop
Loaded Profiles: peer (Available Profiles: peer)
Platform: Microsoft Windows 7 Ultimate  Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser path: "C:\Users\peer\AppData\Local\BoBrowser\Application\bobrowser.exe" -- "%1")
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVM Berlin) C:\Program Files\avmwlanstick\WLanNetService.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.2\avp.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(ClaraLabs) C:\Program Files\Common Files\ClaraUpdater\ClaraUpdater.exe
(ClanServers Hosting LLC) C:\Program Files\GameTracker\GSInGameService.exe
() C:\Program Files\WajIntEnhance\WajIntEnhance Internet Enhancer\InternetEnhancerService.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(AVM Berlin) C:\Program Files\avmwlanstick\WLanGUI.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Dropbox, Inc.) C:\Program Files\Dropbox\Client\Dropbox.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(ClanServers Hosting LLC) C:\Program Files\GameTracker\GTLite.exe
(AAA Internet Publishing, Inc.) C:\Program Files\WTFast Beta\WTFast.exe
(WinZip Computing, S.L.) C:\Program Files\WinZip\WzPreloader.exe
(Nico Mak Computing) C:\Program Files\WinZip\FAH\FAHWindow32.exe
(AMD) C:\Program Files\ATI Technologies\HydraVision\HydraDM.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.2\avpui.exe
(Valve Corporation) C:\Program Files\Steam\Steam.exe
(Valve Corporation) C:\Program Files\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files\Common Files\Steam\SteamService.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.2\plugin-nm-server.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe [747264 2013-12-06] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [AVMWlanClient] => C:\Program Files\avmwlanstick\wlangui.exe [2105344 2010-10-22] (AVM Berlin)
HKLM\...\Run: [Dropbox] => C:\Program Files\Dropbox\Client\Dropbox.exe [43871968 2015-06-26] (Dropbox, Inc.)
HKLM\...\Run: [BlueStacks Agent] => C:\Program Files\BlueStacks\HD-Agent.exe
HKU\S-1-5-21-1044166359-3000482697-3890932768-1000\...\Run: [HydraVisionDesktopManager] => C:\Program Files\ATI Technologies\HydraVision\HydraDM.exe [389120 2013-12-06] (AMD)
HKU\S-1-5-21-1044166359-3000482697-3890932768-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [53282944 2015-06-29] (Skype Technologies S.A.)
HKU\S-1-5-21-1044166359-3000482697-3890932768-1000\...\Run: [Steam] => C:\Program Files\Steam\steam.exe [2895552 2015-07-21] (Valve Corporation)
HKU\S-1-5-21-1044166359-3000482697-3890932768-1000\...\Run: [GameTracker] => C:\Program Files\GameTracker\GTLite.exe [4019992 2013-12-19] (ClanServers Hosting LLC)
HKU\S-1-5-21-1044166359-3000482697-3890932768-1000\...\Run: [WTFast Tray] => C:\Program Files\WTFast Beta\WTFast.exe [4702296 2015-05-08] (AAA Internet Publishing, Inc.)
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2015-01-07] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FAH.lnk [2015-07-04]
ShortcutTarget: FAH.lnk -> C:\Program Files\WinZip\FAH\FAHConsole.exe (Nico Mak Computing)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Preloader.lnk [2015-07-04]
ShortcutTarget: WinZip Preloader.lnk -> C:\Program Files\WinZip\WzPreloader.exe (WinZip Computing, S.L.)
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files\Dropbox\Client\DropboxExt.26.dll [2015-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files\Dropbox\Client\DropboxExt.26.dll [2015-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files\Dropbox\Client\DropboxExt.26.dll [2015-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files\Dropbox\Client\DropboxExt.26.dll [2015-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files\Dropbox\Client\DropboxExt.26.dll [2015-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files\Dropbox\Client\DropboxExt.26.dll [2015-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files\Dropbox\Client\DropboxExt.26.dll [2015-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files\Dropbox\Client\DropboxExt.26.dll [2015-06-26] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-1044166359-3000482697-3890932768-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://myhome.vi-view.com/web/?type=ds&ts=1420561021&from=cor&uid=WDCXWD2500AAJS-07M0A0_WD-WMAV2963090030900&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://myhome.vi-view.com/web/?type=ds&ts=1420561021&from=cor&uid=WDCXWD2500AAJS-07M0A0_WD-WMAV2963090030900&q={searchTerms}
HKU\S-1-5-21-1044166359-3000482697-3890932768-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9hoxUv82Ac0l78Z5H3z-5F1l27HhyU0OoTryrvFbsX6jim90UcD6M_QUitVg3K2_BuecGVRvARmle7zzwC2g3Oi7Xy5NLX51tajl8LnBtg4gxy40mkFFgKSpHz5VPteXqjtvxNZtQYj-Otd6MicaE1FNa9HG_7iSbTdgbw_&q={searchTerms}
HKU\S-1-5-21-1044166359-3000482697-3890932768-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-1044166359-3000482697-3890932768-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp
HKU\S-1-5-21-1044166359-3000482697-3890932768-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9hoxUv82Ac0l78Z5H3z-5F1l27HhyU0OoTryrvFbsX6jim90UcD6M_QUitVg3K2_BuecGVRvARmle7zzwC2g3Oi7Xy5NLX51tajl8LnBtg4gxy40mkFFgKSpHz5VPteXqjtvxNZtQYj-Otd6MicaE1FNa9HG_7iSbTdgbw_&q={searchTerms}
HKU\S-1-5-21-1044166359-3000482697-3890932768-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.giga.de/androidnews/
SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = 
SearchScopes: HKU\S-1-5-21-1044166359-3000482697-3890932768-1000 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = 
BHO: Virtual Keyboard Plugin -> {4A66AD60-A03D-4D01-86F0-5F0F7C0EF1AD} -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2015-01-08] (Oracle Corporation)
BHO: Content Blocker Plugin -> {93BC2EA7-2F17-4729-948A-D2E03FFB2412} -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO: Safe Money Plugin -> {AB379017-4C03-4E00-8EDF-E6D6AF7CCF82} -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
BHO: No Name -> {b608cc98-54de-4775-96c9-097de398500c} ->  No File
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2015-01-08] (Oracle Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
Winsock: Catalog9 01 C:\Windows\system32\abengine.dll [324592 2015-01-06] (Abengine)
Winsock: Catalog9 02 C:\Windows\system32\abengine.dll [324592 2015-01-06] (Abengine)
Winsock: Catalog9 03 C:\Windows\system32\abengine.dll [324592 2015-01-06] (Abengine)
Winsock: Catalog9 04 C:\Windows\system32\abengine.dll [324592 2015-01-06] (Abengine)
Winsock: Catalog9 15 C:\Windows\system32\abengine.dll [324592 2015-01-06] (Abengine)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{AD9157E6-1FCD-4207-A619-32915DF88733}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{CD409118-7BF1-4F7B-92F7-0D2B9D1CC9B8}: [DhcpNameServer] 192.168.1.1
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FireFox:
========
FF ProfilePath: C:\Users\peer\AppData\Roaming\Mozilla\Firefox\Profiles\5hp5imh4.default
FF NetworkProxy: "                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     type", 5
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-15] ()
FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2015-01-08] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2015-01-08] (Oracle Corporation)
FF Plugin: @kaspersky.com/content_blocker_663BE84DBCC949E88C7600F63CA7F098 -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\content_blocker@kaspersky.com [2015-02-21] ()
FF Plugin: @kaspersky.com/online_banking_08806E753BE44495B44E90AA2513BDC5 -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\online_banking@kaspersky.com [2015-02-21] ()
FF Plugin: @kaspersky.com/virtual_keyboard_07402848C2F6470194F131B0F3DE025E -> C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\virtual_keyboard@kaspersky.com [2015-02-21] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll [2011-03-09] ( Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF user.js: detected! => C:\Users\peer\AppData\Roaming\Mozilla\Firefox\Profiles\5hp5imh4.default\user.js [2015-07-21]
FF HKLM\...\Firefox\Extensions: [content_blocker_663BE84DBCC949E88C7600F63CA7F098@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\content_blocker@kaspersky.com
FF Extension: Dangerous Websites Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\content_blocker@kaspersky.com [2015-02-21]
FF HKLM\...\Firefox\Extensions: [virtual_keyboard_07402848C2F6470194F131B0F3DE025E@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\virtual_keyboard@kaspersky.com [2015-02-21]
FF HKLM\...\Firefox\Extensions: [online_banking_08806E753BE44495B44E90AA2513BDC5@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\online_banking@kaspersky.com [2015-02-21]
FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [not found]

Chrome: 
=======
CHR Profile: C:\Users\peer\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\peer\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-01-06]
CHR Extension: (Google Docs) - C:\Users\peer\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-01-06]
CHR Extension: (Google Drive) - C:\Users\peer\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-01-06]
CHR Extension: (YouTube) - C:\Users\peer\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-01-06]
CHR Extension: (Agar.io Mods) - C:\Users\peer\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmofencpfjfladdmoiflekmblmhflbkp [2015-06-06]
CHR Extension: (Adblock Plus) - C:\Users\peer\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-07-09]
CHR Extension: (Google Search) - C:\Users\peer\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-01-06]
CHR Extension: (Kaspersky Protection) - C:\Users\peer\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbhjdbfgekjfcfkkfjjmlmojhbllhbho [2015-02-21]
CHR Extension: (Google Sheets) - C:\Users\peer\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-01-06]
CHR Extension: (Floating YouTube™) - C:\Users\peer\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjphmlaoffndcnecccgemfdaaoighkel [2015-07-21]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\peer\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-11]
CHR Extension: (Google Wallet) - C:\Users\peer\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-06]
CHR Extension: (Gmail) - C:\Users\peer\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-01-06]
CHR HKLM\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-05-01]
CHR HKLM\...\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - https://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1044166359-3000482697-3890932768-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - https://clients2.google.com/service/update2/crx

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AVM WLAN Connection Service; C:\Program Files\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin) [File not signed]
R2 AVP15.0.2; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.2\avp.exe [194000 2015-06-23] (Kaspersky Lab ZAO)
S3 BEService; C:\Program Files\Common Files\BattlEye\BEService.exe [348032 2015-05-09] ()
R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
R2 ClaraUpdater; C:\Program Files\Common Files\ClaraUpdater\ClaraUpdater.exe [926832 2015-07-17] (ClaraLabs)
S2 dbupdate; C:\Program Files\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-09] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-09] (Dropbox, Inc.)
R2 GS In-Game Service; C:\Program Files\GameTracker\GSInGameService.exe [1677080 2013-12-19] (ClanServers Hosting LLC)
R2 Internet Enhancer Service; C:\Program Files\WajIntEnhance\WajIntEnhance Internet Enhancer\InternetEnhancerService.exe [477696 2015-02-03] () [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [4352 2010-10-22] (AVM Berlin) [File not signed]
R0 cm_km_w; C:\Windows\System32\DRIVERS\cm_km_w.sys [197864 2015-06-23] (Kaspersky Lab UK Ltd)
R3 fwlanusbn; C:\Windows\System32\DRIVERS\fwlanusbn.sys [586752 2010-10-22] (AVM GmbH)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [153784 2015-06-23] (Kaspersky Lab ZAO)
R2 kldisk; C:\Windows\System32\DRIVERS\kldisk.sys [54640 2015-06-23] (Kaspersky Lab ZAO)
R3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [128728 2015-06-23] (Kaspersky Lab ZAO)
R1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [44208 2015-07-01] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [705208 2015-06-23] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [34160 2015-06-23] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [36208 2015-06-23] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [35696 2015-06-23] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [23920 2015-06-23] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [54328 2015-06-23] (Kaspersky Lab ZAO)
R1 Klwtp; C:\Windows\System32\DRIVERS\klwtp.sys [72560 2015-06-23] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [157240 2015-06-23] (Kaspersky Lab ZAO)
R2 WtfEngineDrv; C:\Windows\System32\DRIVERS\WtfEngineDrv.sys [22784 2015-04-02] (AAA Internet Publishing, Inc.)
S1 cherimoya; system32\drivers\cherimoya.sys [X]
S3 cpuz134; \??\C:\Users\peer\AppData\Local\Temp\cpuz134\cpuz134_x32.sys [X]
U4 klkbdflt2; system32\DRIVERS\klkbdflt2.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-22 09:18 - 2015-07-22 09:19 - 00026035 _____ C:\Users\peer\Desktop\FRST.txt
2015-07-22 09:18 - 2015-07-22 09:18 - 00000610 _____ C:\Users\peer\Downloads\FRST.txt
2015-07-22 09:18 - 2015-07-22 09:16 - 01638912 _____ (Farbar) C:\Users\peer\Desktop\FRST.exe
2015-07-22 09:17 - 2015-07-22 09:18 - 00000000 ____D C:\FRST
2015-07-22 09:16 - 2015-07-22 09:16 - 01638912 _____ (Farbar) C:\Users\peer\Downloads\FRST.exe
2015-07-22 08:32 - 2015-07-22 08:32 - 00000000 ____D C:\Users\peer\AppData\Local\CEF
2015-07-21 22:11 - 2015-07-22 09:07 - 00000000 ____D C:\Users\peer\AppData\Roaming\Trove
2015-07-21 16:34 - 2015-07-21 16:34 - 00000216 _____ C:\Users\peer\Desktop\Trove.url
2015-07-21 14:07 - 2015-07-15 04:55 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-07-21 14:07 - 2015-07-15 04:55 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-07-21 14:07 - 2015-07-15 04:55 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-07-21 14:07 - 2015-07-15 04:55 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-07-21 14:07 - 2015-07-15 03:52 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-07-21 01:13 - 2015-07-21 01:13 - 00000000 ____D C:\Users\peer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-07-20 16:46 - 2015-07-20 16:47 - 14246072 _____ (BlueStack Systems Inc.) C:\Users\peer\Downloads\BlueStacks-ThinInstaller.exe
2015-07-18 17:43 - 2015-07-18 17:43 - 00482031 _____ C:\Users\peer\Downloads\TerraMap-1.3.4.zip
2015-07-15 13:57 - 2015-07-15 13:57 - 00000000 ___HD C:\Users\peer\Desktop\.updtmp
2015-07-15 11:21 - 2015-07-01 22:46 - 00137664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-07-15 11:21 - 2015-07-01 22:46 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-07-15 11:21 - 2015-07-01 22:30 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-07-15 11:21 - 2015-07-01 22:30 - 00655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-07-15 11:21 - 2015-07-01 22:30 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-07-15 11:21 - 2015-07-01 22:30 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-07-15 11:21 - 2015-07-01 22:30 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-07-15 11:21 - 2015-07-01 22:30 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-07-15 11:21 - 2015-07-01 22:30 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-07-15 11:21 - 2015-07-01 22:30 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-07-15 11:21 - 2015-07-01 22:30 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-07-15 11:21 - 2015-07-01 22:30 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2015-07-15 11:21 - 2015-07-01 22:30 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-07-15 11:21 - 2015-07-01 22:30 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-07-15 11:21 - 2015-07-01 22:30 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-07-15 11:21 - 2015-07-01 22:29 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-07-15 11:21 - 2015-07-01 22:29 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-07-15 11:21 - 2015-07-01 22:27 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-07-15 11:21 - 2015-07-01 22:26 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-07-15 11:21 - 2015-07-01 22:24 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-07-15 11:21 - 2015-07-01 21:18 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-07-15 11:21 - 2015-07-01 21:18 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-07-15 11:21 - 2015-07-01 21:18 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-07-15 11:21 - 2015-06-25 10:46 - 02383872 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-07-15 11:21 - 2015-06-15 23:47 - 00101824 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2015-07-15 11:21 - 2015-06-15 23:43 - 02364416 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2015-07-15 11:21 - 2015-06-15 23:43 - 01805824 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-07-15 11:21 - 2015-06-15 23:43 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2015-07-15 11:21 - 2015-06-15 23:43 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2015-07-15 11:21 - 2015-06-15 23:42 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2015-07-15 11:21 - 2015-06-15 23:37 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll
2015-07-15 11:20 - 2015-07-09 19:44 - 00015808 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2015-07-15 11:20 - 2015-07-09 19:43 - 00587264 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-07-15 11:20 - 2015-07-09 19:42 - 00924160 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-07-15 11:20 - 2015-07-09 19:42 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-07-15 11:20 - 2015-07-09 19:42 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-07-15 11:20 - 2015-07-09 19:42 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-07-15 11:20 - 2015-07-09 19:42 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-07-15 11:20 - 2015-07-09 19:34 - 00932864 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-07-15 11:20 - 2015-07-04 19:48 - 01414656 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2015-07-15 11:20 - 2015-06-17 19:39 - 00305664 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-07-15 11:20 - 2015-06-11 19:57 - 00919552 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2015-07-15 11:20 - 2015-06-11 19:15 - 00134656 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2015-07-15 11:20 - 2015-06-11 19:15 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2015-07-15 11:20 - 2015-04-27 21:05 - 00179200 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2015-07-15 11:20 - 2015-04-27 21:04 - 01174528 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2015-07-15 11:20 - 2015-04-27 21:04 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2015-07-15 11:20 - 2015-04-27 21:04 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2015-07-15 11:19 - 2015-07-09 19:43 - 02943488 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-07-15 11:19 - 2015-07-09 19:43 - 02057216 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-07-15 11:19 - 2015-07-09 19:43 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-07-15 11:19 - 2015-07-09 19:43 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-07-15 11:19 - 2015-07-09 19:43 - 00093184 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-07-15 11:19 - 2015-07-09 19:43 - 00073728 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-07-15 11:19 - 2015-07-09 19:43 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-07-15 11:19 - 2015-07-09 19:43 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-07-15 11:19 - 2015-07-09 19:42 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-07-15 11:19 - 2015-07-09 19:42 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-07-15 11:19 - 2015-07-09 19:42 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-07-15 11:19 - 2015-07-02 23:21 - 19877376 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-07-15 11:19 - 2015-07-02 23:08 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-07-15 11:19 - 2015-07-02 22:50 - 02279424 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-07-15 11:19 - 2015-07-02 22:46 - 00479232 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-07-15 11:19 - 2015-07-02 22:19 - 12855296 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-07-15 11:19 - 2015-07-02 21:55 - 01310720 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-07-15 11:19 - 2015-06-27 03:58 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-07-15 11:19 - 2015-06-27 03:39 - 04520448 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-07-15 11:19 - 2015-06-25 19:43 - 00342736 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-07-15 11:19 - 2015-06-19 20:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-07-15 11:19 - 2015-06-19 20:25 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-07-15 11:19 - 2015-06-19 20:25 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-07-15 11:19 - 2015-06-19 20:24 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-07-15 11:19 - 2015-06-19 20:24 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-07-15 11:19 - 2015-06-19 20:23 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-07-15 11:19 - 2015-06-19 20:17 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-07-15 11:19 - 2015-06-19 20:16 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-07-15 11:19 - 2015-06-19 20:13 - 00664064 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-07-15 11:19 - 2015-06-19 20:13 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-07-15 11:19 - 2015-06-19 20:13 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-07-15 11:19 - 2015-06-19 20:06 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-07-15 11:19 - 2015-06-19 20:03 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-07-15 11:19 - 2015-06-19 19:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-07-15 11:19 - 2015-06-19 19:53 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-07-15 11:19 - 2015-06-19 19:52 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-07-15 11:19 - 2015-06-19 19:51 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-07-15 11:19 - 2015-06-19 19:40 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-07-15 11:19 - 2015-06-19 19:40 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-07-15 11:19 - 2015-06-19 19:40 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-07-15 11:19 - 2015-06-19 19:39 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-07-15 11:19 - 2015-06-19 19:15 - 01951232 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-07-15 11:19 - 2015-06-19 19:11 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-07-15 11:19 - 2015-06-02 01:47 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\cewmdm.dll
2015-07-13 18:33 - 2015-07-13 18:33 - 01143808 _____ C:\Users\peer\Downloads\TerrariViewer.exe
2015-07-13 15:31 - 2015-07-13 15:32 - 09080832 _____ (ChbShoot.me) C:\Users\peer\Downloads\TerrariaInvEdit.61.exe
2015-07-13 14:10 - 2015-07-13 14:10 - 00000316 _____ C:\Windows\PFRO.log
2015-07-12 14:25 - 2015-07-12 13:54 - 00327680 _____ C:\Users\peer\Desktop\Spassteas.exe
2015-07-12 13:54 - 2015-07-12 13:54 - 00327680 _____ C:\Users\peer\Downloads\Spassteas.exe
2015-07-12 12:27 - 2015-07-12 12:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-07-08 20:52 - 2015-07-08 20:52 - 00000216 _____ C:\Users\peer\Desktop\Scribblenauts Unlimited.url
2015-07-07 22:03 - 2015-07-07 22:03 - 00632468 _____ C:\Users\peer\Downloads\PaySafeCard Code Generator Downloader (2).zip
2015-07-07 22:03 - 2015-07-07 22:03 - 00632468 _____ C:\Users\peer\Downloads\PaySafeCard Code Generator Downloader (1).zip
2015-07-07 22:02 - 2015-07-07 22:02 - 00632469 _____ C:\Users\peer\Downloads\PaySafeCard Code Generator Downloader.zip
2015-07-06 21:42 - 2015-07-06 21:42 - 00000000 ____D C:\SinusBot
2015-07-06 21:39 - 2015-07-06 21:41 - 10001388 _____ (Michael Friese) C:\Users\peer\Downloads\sinusbot-win-0.9.8.6.exe
2015-07-06 21:39 - 2015-07-06 21:41 - 10001388 _____ (Michael Friese) C:\Users\peer\Downloads\sinusbot-win-0.9.8.6 (1).exe
2015-07-05 19:49 - 2015-07-05 19:49 - 00000216 _____ C:\Users\peer\Desktop\Terraria.url
2015-07-05 01:20 - 2015-07-05 01:20 - 00000213 _____ C:\Users\peer\Desktop\Left 4 Dead.url
2015-07-04 14:52 - 2015-07-04 14:52 - 00000000 ___HD C:\Users\peer\AppData\Roaming\.kbd
2015-07-04 14:48 - 2015-07-04 14:49 - 08319897 _____ C:\Users\peer\Downloads\Kronos_3.7_1.8.zip
2015-07-04 14:24 - 2015-07-21 23:45 - 00000000 ____D C:\Users\peer\AppData\Local\WinZip
2015-07-04 14:24 - 2015-07-04 14:26 - 19653086 _____ C:\Users\peer\Downloads\Kronus1.8 (1).zip
2015-07-04 14:23 - 2015-07-04 14:24 - 00000000 ____D C:\ProgramData\WinZip
2015-07-04 14:23 - 2015-07-04 14:23 - 00002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\WinZip.lnk
2015-07-04 14:23 - 2015-07-04 14:23 - 00002189 _____ C:\Users\peer\AppData\Roaming\WinZip.lnk
2015-07-04 14:23 - 2015-07-04 14:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
2015-07-04 14:23 - 2015-07-04 14:23 - 00000000 ____D C:\Program Files\WinZip
2015-07-04 14:20 - 2015-07-04 14:21 - 68722688 _____ C:\Users\peer\Downloads\wz195gev-32.msi
2015-07-04 14:16 - 2015-07-04 14:17 - 19653086 _____ C:\Users\peer\Downloads\Kronus1.8.zip
2015-07-04 14:09 - 2015-07-04 14:10 - 03215267 _____ C:\Users\peer\Downloads\Minecraft_client_Downloader.zip
2015-07-04 14:06 - 2015-07-04 13:06 - 00917504 _____ C:\Users\peer\AppData\Roaming\srt.exe.exe
2015-07-04 14:04 - 2015-07-04 14:05 - 04774848 _____ C:\Users\peer\Downloads\Huzuni 1.7 & 1.8 Hacked Client.zip
2015-07-04 13:53 - 2015-07-04 13:54 - 05934977 _____ C:\Users\peer\Downloads\Huzuni ColettYT.zip
2015-07-04 00:58 - 2015-07-04 01:12 - 209715200 _____ C:\Users\peer\Downloads\NekoParaVol1Adult.part01.rar
2015-07-03 23:55 - 2015-07-03 23:56 - 00517384 _____ ( ) C:\Users\peer\Downloads\jetzt_installieren.exe
2015-07-03 21:17 - 2015-07-03 21:17 - 00000216 _____ C:\Users\peer\Desktop\The Binding of Isaac Rebirth.url
2015-07-02 17:43 - 2015-07-02 17:43 - 01294088 _____ (Mojang) C:\Users\peer\Desktop\Minecraft.exe
2015-07-02 17:42 - 2015-07-02 17:43 - 01294088 _____ (Mojang) C:\Users\peer\Downloads\Minecraft.exe
2015-07-02 17:36 - 2015-07-02 17:36 - 00000000 ____D C:\Users\peer\Desktop\runtime
2015-07-02 17:35 - 2015-07-02 17:44 - 00000000 ____D C:\Users\peer\Desktop\game
2015-06-27 23:20 - 2015-06-27 23:20 - 00058982 _____ C:\Users\peer\Downloads\deagle-1.wav
2015-06-27 22:44 - 2015-06-27 22:44 - 19517177 _____ C:\Users\peer\Downloads\garysmodweaponpackspassteas.7z
2015-06-27 20:42 - 2013-09-24 11:14 - 00179200 _____ (fabi.me) C:\Users\peer\Desktop\SpeedAutoClicker.exe
2015-06-27 16:23 - 2015-06-27 16:23 - 00000000 ____D C:\Users\peer\AppData\Roaming\com.playsaurus.heroclicker
2015-06-27 16:13 - 2015-06-28 13:10 - 00000000 ____D C:\Users\peer\AppData\Local\fabi.me
2015-06-27 16:11 - 2015-06-27 16:12 - 00094899 _____ C:\Users\peer\Downloads\SpeedAutoClicker.zip
2015-06-27 16:08 - 2015-06-27 16:08 - 00000216 _____ C:\Users\peer\Desktop\Clicker Heroes.url
2015-06-25 20:30 - 2015-06-25 19:50 - 534821939 _____ C:\Users\peer\Desktop\YanSimJune19th.rar
2015-06-25 19:50 - 2015-06-25 19:50 - 534821939 _____ C:\Users\peer\Downloads\YanSimJune19th.rar
2015-06-24 06:57 - 2015-06-24 06:57 - 00285198 _____ C:\Windows\msxml4-KB954430-enu.LOG
2015-06-24 06:56 - 2015-06-24 06:57 - 00291746 _____ C:\Windows\msxml4-KB973688-enu.LOG
2015-06-24 06:56 - 2015-06-24 06:56 - 00000000 ____D C:\Program Files\MSXML 4.0
2015-06-22 22:24 - 2015-06-22 22:24 - 00000000 ____D C:\Users\peer\Documents\MAGIX
2015-06-22 22:23 - 2015-06-22 22:24 - 00000000 ____D C:\ProgramData\MAGIX
2015-06-22 22:23 - 2015-06-22 22:23 - 00000000 ____D C:\Users\peer\AppData\Roaming\MAGIX
2015-06-22 22:23 - 2015-06-22 22:23 - 00000000 ____D C:\Users\peer\AppData\Local\MAGIX
2015-06-22 22:23 - 2015-06-22 22:23 - 00000000 ____D C:\Program Files\Common Files\MAGIX Services
2015-06-22 22:00 - 2015-06-22 22:01 - 24003400 _____ (MAGIX AG) C:\Users\peer\Downloads\foto_designer_7011_23mb_d.exe
2015-06-22 17:11 - 2015-06-22 17:11 - 00242810 _____ C:\Users\peer\Desktop\3000x1687xKillua-Zoldyck.jpg.pagespeed.ic.IaGsWwpE_B.webp

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-22 09:19 - 2015-01-06 16:43 - 00001332 _____ C:\Windows\Tasks\AEIJZ.job
2015-07-22 09:16 - 2015-01-10 16:35 - 00000000 ____D C:\Users\peer\AppData\Roaming\Skype
2015-07-22 09:08 - 2015-01-11 15:33 - 00000000 ____D C:\Program Files\Steam
2015-07-22 09:07 - 2015-01-06 17:42 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-22 09:00 - 2009-07-14 06:34 - 00016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-22 09:00 - 2009-07-14 06:34 - 00016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-22 08:44 - 2015-02-21 16:08 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2015-07-22 08:35 - 2015-01-07 15:52 - 01145877 _____ C:\Windows\WindowsUpdate.log
2015-07-22 08:33 - 2015-01-06 16:29 - 00001332 _____ C:\Windows\Tasks\GACRJ.job
2015-07-22 08:32 - 2015-01-11 15:33 - 00000000 ____D C:\Program Files\Common Files\Steam
2015-07-22 08:31 - 2015-06-09 18:29 - 00000000 ___RD C:\Users\peer\Dropbox
2015-07-22 08:31 - 2015-06-09 17:12 - 00000000 ____D C:\Users\peer\AppData\Local\Dropbox
2015-07-22 08:30 - 2015-02-16 17:22 - 00000000 ____D C:\Users\peer\AppData\Roaming\GameTracker
2015-07-22 08:29 - 2015-06-09 17:12 - 00001194 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
2015-07-22 08:29 - 2015-01-06 17:42 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-22 08:28 - 2015-06-21 19:47 - 00002240 _____ C:\Windows\setupact.log
2015-07-22 08:28 - 2015-01-06 16:04 - 00001334 _____ C:\Windows\Tasks\DUITSQ.job
2015-07-22 08:28 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-22 00:17 - 2015-02-05 20:58 - 00000000 ____D C:\Users\peer\AppData\Roaming\TS3Client
2015-07-21 23:24 - 2015-06-09 17:12 - 00001198 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job
2015-07-21 23:24 - 2015-02-19 19:27 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-07-21 19:03 - 2009-07-14 06:33 - 00267160 _____ C:\Windows\system32\FNTCACHE.DAT
2015-07-21 18:33 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET
2015-07-21 16:34 - 2015-01-11 15:50 - 00000000 ____D C:\Users\peer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2015-07-21 16:25 - 2015-01-06 16:04 - 00000000 ____D C:\Program Files\Google
2015-07-21 16:13 - 2009-07-14 04:37 - 00000000 __RHD C:\Users\Public\Libraries
2015-07-18 13:26 - 2015-01-06 16:43 - 00000000 ____D C:\Program Files\Common Files\ClaraUpdater
2015-07-16 09:10 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache
2015-07-16 08:30 - 2015-04-17 06:38 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-07-16 08:30 - 2015-04-17 06:38 - 00000000 ____D C:\Windows\system32\appraiser
2015-07-16 08:30 - 2015-04-05 12:03 - 00000000 ___SD C:\Windows\system32\GWX
2015-07-16 08:30 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE
2015-07-16 08:14 - 2015-01-06 17:14 - 00000000 ____D C:\Windows\system32\MRT
2015-07-15 14:24 - 2015-02-19 19:27 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-07-15 14:24 - 2015-02-19 19:27 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-07-13 14:10 - 2009-07-14 06:53 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-07-12 12:27 - 2015-06-09 17:12 - 00000000 ____D C:\Program Files\Dropbox
2015-07-09 14:42 - 2015-01-10 16:35 - 00000000 ___RD C:\Program Files\Skype
2015-07-09 14:42 - 2015-01-10 16:35 - 00000000 ____D C:\ProgramData\Skype
2015-07-05 20:35 - 2015-01-11 17:31 - 00000000 ____D C:\Users\peer\Documents\My Games
2015-07-05 03:19 - 2015-01-09 15:53 - 00000000 ____D C:\Users\peer\AppData\Roaming\Mirai Nikki Bilder von Yuno
2015-07-04 18:06 - 2015-01-08 19:55 - 00000000 ____D C:\Users\peer\AppData\Roaming\.minecraft
2015-07-04 14:24 - 2015-01-06 15:31 - 00000000 ____D C:\Users\peer
2015-07-03 08:49 - 2015-01-06 17:14 - 127070192 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-07-01 15:01 - 2014-10-22 22:13 - 00044208 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klhk.sys
2015-06-28 14:39 - 2015-02-19 19:27 - 00000000 __SHD C:\Users\peer\AppData\Local\EmieUserList
2015-06-28 14:39 - 2015-02-19 19:27 - 00000000 __SHD C:\Users\peer\AppData\Local\EmieSiteList
2015-06-28 14:39 - 2015-02-19 19:27 - 00000000 __SHD C:\Users\peer\AppData\Local\EmieBrowserModeList
2015-06-23 21:57 - 2014-11-22 15:12 - 00072560 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klwtp.sys
2015-06-23 21:57 - 2014-11-10 18:48 - 00157240 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kneps.sys
2015-06-23 21:57 - 2014-10-10 18:02 - 00034160 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klim6.sys
2015-06-23 21:57 - 2014-10-09 13:31 - 00054328 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kltdi.sys
2015-06-23 21:57 - 2014-08-19 13:31 - 00054640 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kldisk.sys
2015-06-23 21:57 - 2014-03-31 11:47 - 00153784 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kl1.sys
2015-06-23 21:57 - 2013-04-12 15:34 - 00023920 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klpd.sys
2015-06-23 21:56 - 2014-12-13 19:21 - 00705208 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys
2015-06-23 21:56 - 2014-11-28 19:19 - 00128728 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys
2015-06-23 21:56 - 2014-10-30 05:22 - 00036208 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klkbdflt.sys
2015-06-23 21:56 - 2013-08-08 17:10 - 00035696 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klmouflt.sys
2015-06-23 21:56 - 2013-01-14 21:10 - 00197864 _____ (Kaspersky Lab UK Ltd) C:\Windows\system32\Drivers\cm_km_w.sys
2015-06-23 13:27 - 2015-01-06 16:06 - 00246952 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe

==================== Files in the root of some directories =======

2014-09-01 10:18 - 2014-09-01 10:18 - 0001248 _____ () C:\Users\peer\AppData\Roaming\AEIJZ
2015-05-09 19:28 - 2015-05-09 19:28 - 0001047 _____ () C:\Users\peer\AppData\Roaming\Cheat Engine.lnk
2014-09-01 10:18 - 2014-09-01 10:18 - 0001248 _____ () C:\Users\peer\AppData\Roaming\DUITSQ
2015-02-06 18:35 - 2015-02-06 18:35 - 0000572 _____ () C:\Users\peer\AppData\Roaming\Fraps.lnk
2014-09-01 10:18 - 2014-09-01 10:18 - 0001248 _____ () C:\Users\peer\AppData\Roaming\GACRJ
2015-04-17 07:21 - 2015-04-17 08:51 - 0000255 _____ () C:\Users\peer\AppData\Roaming\mb3settings.xml
2015-03-21 12:50 - 2015-03-21 12:47 - 10708434 _____ () C:\Users\peer\AppData\Roaming\Savior Mod 1.2.rar
2015-07-04 14:06 - 2015-07-04 13:06 - 0917504 _____ () C:\Users\peer\AppData\Roaming\srt.exe.exe
2015-05-05 20:58 - 2015-05-05 20:57 - 13791079 _____ () C:\Users\peer\AppData\Roaming\thebindingofisaacgodmode_1.9.5 (1).zip
2015-01-09 15:53 - 2015-01-09 15:55 - 0018944 ___SH () C:\Users\peer\AppData\Roaming\Thumbs.db
2015-01-30 15:17 - 2015-01-30 15:17 - 0000046 _____ () C:\Users\peer\AppData\Roaming\WB.CFG
2015-07-04 14:23 - 2015-07-04 14:23 - 0002189 _____ () C:\Users\peer\AppData\Roaming\WinZip.lnk

Some files in TEMP:
====================
C:\Users\peer\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpkifp1c.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-07-14 17:07

==================== End of log ============================
         
Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 20-07-2015
Ran by peer at 2015-07-22 09:22:13
Running from C:\Users\peer\Desktop
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1044166359-3000482697-3890932768-500 - Administrator - Disabled)
Gast (S-1-5-21-1044166359-3000482697-3890932768-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1044166359-3000482697-3890932768-1002 - Limited - Enabled)
peer (S-1-5-21-1044166359-3000482697-3890932768-1000 - Administrator - Enabled) => C:\Users\peer

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Kaspersky Internet Security (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}
AS: Kaspersky Internet Security (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Enabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 18 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 18.0.0.209 - Adobe Systems Incorporated)
AdVenture Capitalist (HKLM\...\Steam App 346900) (Version:  - Hyper Hippo Games)
AMD Catalyst Install Manager (HKLM\...\{0CF4D060-11E5-D612-1F01-D5F67A5C7E78}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.)
AVM FRITZ!WLAN (HKLM\...\AVMWLANCLI) (Version:  - AVM Berlin)
BattleBlock Theater (HKLM\...\Steam App 238460) (Version:  - The Behemoth)
Castle Crashers (HKLM\...\Steam App 204360) (Version:  - The Behemoth)
Clicker Heroes (HKLM\...\Steam App 363970) (Version:  - )
Dropbox (HKLM\...\Dropbox) (Version: 3.6.8 - Dropbox, Inc.)
Dropbox Update Helper (Version: 1.3.27.33 - Dropbox, Inc.) Hidden
Echoes+ (HKLM\...\Steam App 338000) (Version:  - Binary Zoo)
GameTracker Lite (HKLM\...\GameTracker Lite) (Version:  - ClanServers Hosting LLC.)
Garry's Mod (HKLM\...\Steam App 4000) (Version:  - Facepunch Studios)
Goat Simulator (HKLM\...\Steam App 265930) (Version:  - Coffee Stain Studios)
Google Chrome (HKLM\...\Google Chrome) (Version: 43.0.2357.134 - Google Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.28.1 - Google Inc.) Hidden
HydraVision (Version: 4.2.252.0 - Advanced Micro Devices, Inc.) Hidden
Java 7 Update 71 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
Kaspersky Internet Security (HKLM\...\InstallWIX_{02FECEE0-16B2-43DB-BC3B-C844477FC142}) (Version: 15.0.2.361 - Kaspersky Lab)
Kaspersky Internet Security (Version: 15.0.2.361 - Kaspersky Lab) Hidden
Left 4 Dead (HKLM\...\Steam App 500) (Version:  - Valve)
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.60310.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Scribblenauts Unlimited (HKLM\...\Steam App 218680) (Version:  - 5th Cell Media)
Skype Click to Call (HKLM\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.4.0.9058 - Microsoft Corporation)
Skype™ 7.6 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.6.105 - Skype Technologies S.A.)
Steam (HKLM\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Super Amazing Wagon Adventure (HKLM\...\Steam App 250500) (Version:  - sparsevector)
TeamSpeak 3 Client (HKU\S-1-5-21-1044166359-3000482697-3890932768-1000\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
Terraria (HKLM\...\Steam App 105600) (Version:  - Re-Logic)
The Binding of Isaac: Rebirth (HKLM\...\Steam App 250900) (Version:  - Nicalis, Inc.)
Trove (HKLM\...\Steam App 304050) (Version:  - Trion Worlds)
Wajam (HKLM\...\WajIntEnhance) (Version: 2.23.2.12 (i2.6) - WajIntEnhance) <==== ATTENTION
WinRAR 5.20 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 5.20.0 - win.rar GmbH)
WinZip 19.5 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240EC}) (Version: 19.5.11532 - WinZip Computing, S.L. )
WTFast Beta 4.0 (HKLM\...\{162DC956-6167-407C-8265-4CC3B8E61B96}_is1) (Version: 4.0.1.459 - Initex & AAA Internet Publishing)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1044166359-3000482697-3890932768-1000_Classes\CLSID\{19041B6B-8F97-4669-BA21-C17572737ED2}\localserver32 -> C:\Users\peer\AppData\Local\BoBrowser\Application\36.0.1985.136\delegate_execute.exe (The Chromium Authors)

==================== Restore Points =========================

10-07-2015 13:59:16 Windows Update
14-07-2015 11:59:13 Windows Update
16-07-2015 07:45:47 Windows Update
21-07-2015 16:01:02 Removed BlueStacks Notification Center
21-07-2015 16:06:38 Removed BlueStacks Notification Center
21-07-2015 16:22:24 Removed Google Earth
21-07-2015 18:55:32 Windows Update

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0847D1A9-C505-43E5-9B1F-6C63B0BDA1AA} - System32\Tasks\DUITSQ => C:\Users\peer\AppData\Roaming\DUITSQ.exe <==== ATTENTION
Task: {0849AB36-C572-4631-9C9C-552EBB299882} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files\Dropbox\Update\DropboxUpdate.exe [2015-06-09] (Dropbox, Inc.)
Task: {352584E1-0C91-4CC6-9B2A-EEA9766A827D} - System32\Tasks\AEIJZ => C:\Users\peer\AppData\Roaming\AEIJZ.exe <==== ATTENTION
Task: {4C8D46B9-B2B5-409C-85FA-63653C8104BB} - System32\Tasks\GACRJ => C:\Users\peer\AppData\Roaming\GACRJ.exe <==== ATTENTION
Task: {4ED14997-48E5-4891-B86F-0594B3D9773A} - \Run_Bobby_Browser No Task File <==== ATTENTION
Task: {6247D802-DFD5-4BE1-929C-8BE14CA40863} - System32\Tasks\avastBCLRestartS-1-5-21-1044166359-3000482697-3890932768-1000 => Chrome.exe 
Task: {653F1E69-2415-49F7-8EC5-34A73C94B15B} - System32\Tasks\{B8421162-75E0-44C2-926D-49386904A405} => pcalua.exe -a C:\Users\peer\Downloads\forge-1.8-11.14.0.1299-installer-win.exe -d C:\Users\peer\Downloads
Task: {69BF0F00-43EC-4B67-9545-F9A395992F7E} - System32\Tasks\PostPoneInstall => C:\Users\peer\AppData\Local\Temp\ce98ac2e-20c0-4a93-86f6-bdb3e61caf55.exe <==== ATTENTION
Task: {8F547A99-BFEC-42AA-8121-D8CDF358AAF7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-01-06] (Google Inc.)
Task: {A85A22B0-2DDB-4CAB-99B7-074C8514BF09} - \upfs7235 No Task File <==== ATTENTION
Task: {B06CD2AB-5A2B-4F71-BD09-E959BA1B59A3} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files\Dropbox\Update\DropboxUpdate.exe [2015-06-09] (Dropbox, Inc.)
Task: {BE1DAD1D-FA59-4BE3-9560-5FF4D529EB83} - System32\Tasks\{0B2E862F-28C7-460D-BC85-94CDE498ED1A} => C:\Users\peer\AppData\Local\TeamSpeak 3 Client\ts3client_win32.exe [2014-08-04] (TeamSpeak Systems GmbH)
Task: {C15253F5-5F87-4E39-89FC-349966428646} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-01-06] (Google Inc.)
Task: {D27471AB-DA63-4796-9DC8-AF2B4F2DDC4E} - System32\Tasks\{DB01E593-6648-45E2-854D-B8E8299813D3} => pcalua.exe -a C:\Users\peer\AppData\Roaming\mystartsearch\UninstallManager.exe -c  -ptid=tugs
Task: {F52B544F-A543-4DE7-BCE9-C8746E51A211} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-15] (Adobe Systems Incorporated)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\AEIJZ.job => C:\Users\peer\AppData\Roaming\AEIJZ.exe <==== ATTENTION
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DUITSQ.job => C:\Users\peer\AppData\Roaming\DUITSQ.exe <==== ATTENTION
Task: C:\Windows\Tasks\GACRJ.job => C:\Users\peer\AppData\Roaming\GACRJ.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2014-12-23 17:54 - 2014-12-23 17:54 - 01272616 _____ () C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.2\kpcengine.2.3.dll
2015-02-03 21:03 - 2015-02-03 21:03 - 00477696 _____ () C:\Program Files\WajIntEnhance\WajIntEnhance Internet Enhancer\InternetEnhancerService.exe
2015-07-22 08:30 - 2015-07-22 08:30 - 00043008 _____ () c:\users\peer\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpkifp1c.dll
2015-06-09 17:14 - 2015-03-19 09:15 - 00750080 _____ () C:\Program Files\Dropbox\Client\libGLESv2.dll
2015-06-09 17:14 - 2015-03-19 09:15 - 00047616 _____ () C:\Program Files\Dropbox\Client\libEGL.dll
2015-06-09 17:14 - 2015-03-19 09:15 - 00865280 _____ () C:\Program Files\Dropbox\Client\plugins\platforms\qwindows.dll
2015-06-09 17:14 - 2015-03-19 09:15 - 00200704 _____ () C:\Program Files\Dropbox\Client\plugins\imageformats\qjpeg.dll
2015-06-09 17:15 - 2015-03-19 09:15 - 00010240 _____ () C:\Program Files\Dropbox\Client\QtQuick.2\qtquick2plugin.dll
2015-06-09 17:14 - 2015-03-19 09:15 - 00726016 _____ () C:\Program Files\Dropbox\Client\QtQuick\Controls\qtquickcontrolsplugin.dll
2015-06-09 17:15 - 2015-03-19 09:15 - 00010240 _____ () C:\Program Files\Dropbox\Client\QtQuick\Window.2\windowplugin.dll
2015-01-11 15:42 - 2015-07-03 18:12 - 00778240 _____ () C:\Program Files\Steam\SDL2.dll
2015-01-20 16:34 - 2015-07-03 18:12 - 04962816 _____ () C:\Program Files\Steam\v8.dll
2015-01-20 16:34 - 2015-07-03 18:12 - 01556992 _____ () C:\Program Files\Steam\icui18n.dll
2015-01-20 16:34 - 2015-07-03 18:12 - 01187840 _____ () C:\Program Files\Steam\icuuc.dll
2015-01-11 15:42 - 2015-07-21 21:32 - 02410176 _____ () C:\Program Files\Steam\video.dll
2015-01-11 15:42 - 2014-12-01 23:31 - 02396672 _____ () C:\Program Files\Steam\libavcodec-56.dll
2015-01-11 15:42 - 2014-12-01 23:31 - 00442880 _____ () C:\Program Files\Steam\libavutil-54.dll
2015-01-11 15:42 - 2014-12-01 23:31 - 00479744 _____ () C:\Program Files\Steam\libavformat-56.dll
2015-01-11 15:42 - 2014-12-01 23:31 - 00332800 _____ () C:\Program Files\Steam\libavresample-2.dll
2015-01-11 15:42 - 2014-12-01 23:31 - 00485888 _____ () C:\Program Files\Steam\libswscale-3.dll
2015-01-11 15:42 - 2015-07-21 21:32 - 00703168 _____ () C:\Program Files\Steam\bin\chromehtml.DLL
2015-07-22 08:31 - 2015-07-07 22:41 - 00169984 _____ () C:\Program Files\Steam\bin\openvr_api.dll
2015-01-11 15:42 - 2015-07-03 18:12 - 39553928 _____ () C:\Program Files\Steam\bin\libcef.dll
2015-07-14 18:40 - 2015-07-13 23:55 - 01281864 _____ () C:\Program Files\Google\Chrome\Application\43.0.2357.134\libglesv2.dll
2015-07-14 18:40 - 2015-07-13 23:55 - 00080712 _____ () C:\Program Files\Google\Chrome\Application\43.0.2357.134\libegl.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\abengine => ""="service"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1044166359-3000482697-3890932768-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\peer\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{AF50EA8D-2907-4A89-BFFE-68420A7BF43C}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [{D79D08CC-A4DD-419D-85B8-5B1EABDB2820}] => (Allow) C:\Users\peer\AppData\Local\CrossBrowser\Application\crossbrowser.exe
FirewallRules: [{5E922166-8A48-4312-B7CE-25D36B1B2CFA}] => (Allow) C:\Users\peer\AppData\Local\BoBrowser\Application\bobrowser.exe
FirewallRules: [TCP Query User{E05C71DC-BC36-4B52-A528-2832F3B522B7}C:\program files\java\jre1.8.0_25\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{A249048E-9160-4662-AABB-D5CEE8FE9C9B}C:\program files\java\jre1.8.0_25\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_25\bin\javaw.exe
FirewallRules: [TCP Query User{52FC3A64-0C28-4EBF-823B-F471B44EE057}C:\users\peer\desktop\runtime\jre-x32\1.8.0_25\bin\javaw.exe] => (Allow) C:\users\peer\desktop\runtime\jre-x32\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{AC7E6F61-15FA-4575-9078-21F231CF68DF}C:\users\peer\desktop\runtime\jre-x32\1.8.0_25\bin\javaw.exe] => (Allow) C:\users\peer\desktop\runtime\jre-x32\1.8.0_25\bin\javaw.exe
FirewallRules: [{20E8AE1A-F0AD-41D2-A3C8-90AC55222BF0}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe
FirewallRules: [{AAA6C38C-066F-4DCD-8020-59B3D46DFF2C}] => (Allow) C:\Program Files\Steam\Steam.exe
FirewallRules: [{A589396B-A5EF-48B1-A3FC-D05BF860E802}] => (Allow) C:\Program Files\Steam\Steam.exe
FirewallRules: [{D309AE60-4535-489A-AB67-A7941BAD1EB9}] => (Allow) C:\Program Files\Steam\bin\steamwebhelper.exe
FirewallRules: [{D0674F56-00E7-4393-8743-1C86A3ED16A3}] => (Allow) C:\Program Files\Steam\bin\steamwebhelper.exe
FirewallRules: [TCP Query User{7D62B1EE-A08F-4E8F-A285-6D094DD2F1DD}C:\program files\java\jre1.8.0_25\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{499C9F5D-3079-4566-860D-D912686508AC}C:\program files\java\jre1.8.0_25\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_25\bin\javaw.exe
FirewallRules: [TCP Query User{6AC2A4C4-B95D-4120-AA70-EAC511002E84}C:\users\peer\desktop\runtime\jre-x32\1.8.0_25\bin\javaw.exe] => (Allow) C:\users\peer\desktop\runtime\jre-x32\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{4183B6F5-8295-48DF-ACFD-9C2D3B487C99}C:\users\peer\desktop\runtime\jre-x32\1.8.0_25\bin\javaw.exe] => (Allow) C:\users\peer\desktop\runtime\jre-x32\1.8.0_25\bin\javaw.exe
FirewallRules: [TCP Query User{FA4F12C1-EC15-418F-BE82-DD9FB54F87DC}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{189EA21C-0C64-4256-81E1-94F3C481C6AF}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
FirewallRules: [{BC6DC2DD-2D4E-4F58-9C2F-46811B9DE109}] => (Allow) C:\Program Files\Steam\steamapps\common\Super Amazing Wagon Adventure\WagonAdventure.exe
FirewallRules: [{5D982A09-9C4E-4895-9C21-5E648CF8AAF1}] => (Allow) C:\Program Files\Steam\steamapps\common\Super Amazing Wagon Adventure\WagonAdventure.exe
FirewallRules: [{08F7A903-163D-4E86-B5C1-50D05E20D5C4}] => (Allow) C:\Program Files\Steam\steamapps\common\Echoes+\echoes+.exe
FirewallRules: [{43F1C9F1-1D51-4CC3-B3BC-BE5338706FF9}] => (Allow) C:\Program Files\Steam\steamapps\common\Echoes+\echoes+.exe
FirewallRules: [{4C658117-DD5F-4AC9-811A-B89E09BC4AAA}] => (Allow) C:\Program Files\Steam\steamapps\common\GarrysMod\hl2.exe
FirewallRules: [{94BAD1AB-4AC8-4014-8352-0E3BBB901DEA}] => (Allow) C:\Program Files\Steam\steamapps\common\GarrysMod\hl2.exe
FirewallRules: [{F0EC67D5-ADAE-4BE0-87CD-A97546481D36}] => (Allow) C:\Program Files\Steam\steamapps\common\AdVenture Capitalist\adventure-capitalist.exe
FirewallRules: [{364DD5FD-8662-4E03-8B2C-FF2F631C1686}] => (Allow) C:\Program Files\Steam\steamapps\common\AdVenture Capitalist\adventure-capitalist.exe
FirewallRules: [{A872B8C6-F4AD-4137-BA79-93E18C3E13F7}] => (Allow) C:\Program Files\Steam\steamapps\common\GoatSimulator\Binaries\Win32\GoatGame-Win32-Shipping.exe
FirewallRules: [{8C3BC03B-CA8D-4A3B-BB35-C2B81D7301D2}] => (Allow) C:\Program Files\Steam\steamapps\common\GoatSimulator\Binaries\Win32\GoatGame-Win32-Shipping.exe
FirewallRules: [TCP Query User{A579D655-6C56-4DB9-96C9-37D6367A7993}C:\program files\wtfast beta\wtfast.exe] => (Allow) C:\program files\wtfast beta\wtfast.exe
FirewallRules: [UDP Query User{D1723E1A-4818-4C95-BBE2-082B90BE126C}C:\program files\wtfast beta\wtfast.exe] => (Allow) C:\program files\wtfast beta\wtfast.exe
FirewallRules: [{147CA2F5-D7AD-4CC3-B517-6DBC53B552AC}] => (Allow) C:\Program Files\Steam\steamapps\common\CastleCrashers\castle.exe
FirewallRules: [{46C54343-8578-48D2-AA83-C51BC5D100CC}] => (Allow) C:\Program Files\Steam\steamapps\common\CastleCrashers\castle.exe
FirewallRules: [{7210288D-EDCC-4C09-B66F-708D54D85E37}] => (Allow) C:\Program Files\Steam\steamapps\common\BattleBlock Theater\BattleBlockTheater.exe
FirewallRules: [{B7D3FA46-047F-4257-B2FB-6100FB4DFD20}] => (Allow) C:\Program Files\Steam\steamapps\common\BattleBlock Theater\BattleBlockTheater.exe
FirewallRules: [TCP Query User{1501C086-D6F9-42A2-816F-22D008B9FAA0}C:\program files\wtfast beta\wtfast.exe] => (Allow) C:\program files\wtfast beta\wtfast.exe
FirewallRules: [UDP Query User{E36B206C-ACA8-4E09-A79F-4BF9DBF1626E}C:\program files\wtfast beta\wtfast.exe] => (Allow) C:\program files\wtfast beta\wtfast.exe
FirewallRules: [{145D2736-556B-459D-B7C9-B0CF304A28D3}] => (Allow) C:\Program Files\Steam\steamapps\common\Clicker Heroes\Clicker Heroes.exe
FirewallRules: [{6A16AA74-5671-4E2F-9281-0C1FFE7C188B}] => (Allow) C:\Program Files\Steam\steamapps\common\Clicker Heroes\Clicker Heroes.exe
FirewallRules: [{7900A3BB-3C14-4987-9DA9-FC77ACBE55AA}] => (Allow) C:\Program Files\Steam\steamapps\common\The Binding of Isaac Rebirth\isaac-ng.exe
FirewallRules: [{01ED2CB7-46F3-43F0-9476-769DD4930D7B}] => (Allow) C:\Program Files\Steam\steamapps\common\The Binding of Isaac Rebirth\isaac-ng.exe
FirewallRules: [{CE925788-1B59-42D2-920A-7236429A0ED0}] => (Allow) C:\Program Files\Steam\steamapps\common\left 4 dead\left4dead.exe
FirewallRules: [{C9F23A68-C52B-40AF-9F3C-07B429AACA38}] => (Allow) C:\Program Files\Steam\steamapps\common\left 4 dead\left4dead.exe
FirewallRules: [{455E51E3-97CC-43B6-B381-5F41F8821603}] => (Allow) C:\Program Files\Steam\steamapps\common\Terraria\Terraria.exe
FirewallRules: [{C7A4F47D-739F-41B2-9566-974016F14C04}] => (Allow) C:\Program Files\Steam\steamapps\common\Terraria\Terraria.exe
FirewallRules: [{1398FFBB-9616-40A9-8C1A-34B0BE27D5AE}] => (Allow) C:\Program Files\Steam\steamapps\common\Scribblenauts\Scribble.exe
FirewallRules: [{2DF777F0-E860-4D60-9D1D-0FB44552FEDA}] => (Allow) C:\Program Files\Steam\steamapps\common\Scribblenauts\Scribble.exe
FirewallRules: [{05065864-5DFF-4D99-B015-FFBDB8A14BBC}] => (Allow) C:\Program Files\Dropbox\Client\Dropbox.exe
FirewallRules: [{C4CEB63D-6F51-4642-B718-468F6DF94B7B}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
FirewallRules: [{3959B8F3-BC1F-4FA8-829E-964376719D44}] => (Allow) C:\Program Files\Steam\steamapps\common\Trove\GlyphClient.exe
FirewallRules: [{ACE472A0-E228-4253-96D6-540EAED0D658}] => (Allow) C:\Program Files\Steam\steamapps\common\Trove\GlyphClient.exe

==================== Faulty Device Manager Devices =============

Name: cherimoya
Description: cherimoya
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer: 
Service: cherimoya
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (07/21/2015 09:06:11 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm hl2.exe, Version 0.0.0.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 195c

Startzeit: 01d0c3e7b23bb567

Endzeit: 75

Anwendungspfad: C:\Program Files\Steam\steamapps\common\GarrysMod\hl2.exe

Berichts-ID: 508ee919-2fdb-11e5-9fe4-00199962f02b

Error: (07/21/2015 04:03:46 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d6727a7
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18869, Zeitstempel: 0x55636303
Ausnahmecode: 0xc0000374
Fehleroffset: 0x000c3c23
ID des fehlerhaften Prozesses: 0x7ac
Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0
Pfad der fehlerhaften Anwendung: Explorer.EXE1
Pfad des fehlerhaften Moduls: Explorer.EXE2
Berichtskennung: Explorer.EXE3

Error: (07/21/2015 02:32:38 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Terraria.exe, Version: 1.3.0.6, Zeitstempel: 0x55ac1237
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18847, Zeitstempel: 0x554d7b00
Ausnahmecode: 0xe0434352
Fehleroffset: 0x0000812f
ID des fehlerhaften Prozesses: 0x1dec
Startzeit der fehlerhaften Anwendung: 0xTerraria.exe0
Pfad der fehlerhaften Anwendung: Terraria.exe1
Pfad des fehlerhaften Moduls: Terraria.exe2
Berichtskennung: Terraria.exe3

Error: (07/21/2015 02:32:23 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: Terraria.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.IO.IOException
Stapel:
   bei System.IO.__Error.WinIOError(Int32, System.String)
   bei System.IO.FileStream.Init(System.String, System.IO.FileMode, System.IO.FileAccess, Int32, Boolean, System.IO.FileShare, Int32, System.IO.FileOptions, SECURITY_ATTRIBUTES, System.String, Boolean, Boolean, Boolean)
   bei System.IO.FileStream..ctor(System.String, System.IO.FileMode, System.IO.FileAccess, System.IO.FileShare)
   bei Terraria.Utilities.FileUtilities.Write(System.String, Byte[], Int32, Boolean)
   bei Terraria.IO.WorldFile.saveWorld(Boolean, Boolean)
   bei Terraria.WorldGen.saveAndPlayCallBack(System.Object)
   bei System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object)
   bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   bei System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
   bei System.Threading.ThreadPoolWorkQueue.Dispatch()
   bei System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()

Error: (07/21/2015 01:56:54 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\Windows\system32\svchost.exe -k netsvcs; Beschreibung = Windows Update; Fehler = 0x81000101).

Error: (07/21/2015 02:11:44 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: GoogleUpdate.exe, Version: 1.3.25.11, Zeitstempel: 0x545bb4ac
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x007a2af1
ID des fehlerhaften Prozesses: 0x248c
Startzeit der fehlerhaften Anwendung: 0xGoogleUpdate.exe0
Pfad der fehlerhaften Anwendung: GoogleUpdate.exe1
Pfad des fehlerhaften Moduls: GoogleUpdate.exe2
Berichtskennung: GoogleUpdate.exe3

Error: (07/20/2015 06:27:41 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - Failed to compile C:\Program Files\BlueStacks\HD-CreateSymlink.exe because this image is not a valid Win32 application.

Error: (07/18/2015 05:49:14 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: TerraMapCmd.exe, Version: 1.3.4.16437, Zeitstempel: 0x55aa5dba
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18847, Zeitstempel: 0x554d7b00
Ausnahmecode: 0xe0434352
Fehleroffset: 0x0000812f
ID des fehlerhaften Prozesses: 0x14cc
Startzeit der fehlerhaften Anwendung: 0xTerraMapCmd.exe0
Pfad der fehlerhaften Anwendung: TerraMapCmd.exe1
Pfad des fehlerhaften Moduls: TerraMapCmd.exe2
Berichtskennung: TerraMapCmd.exe3

Error: (07/18/2015 05:49:11 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: TerraMapCmd.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.IO.FileNotFoundException
Stapel:
   bei TerraMap.Program.Main(System.String[])

Error: (07/18/2015 05:39:05 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Skype.exe, Version: 7.6.0.105, Zeitstempel: 0x559165ab
Name des fehlerhaften Moduls: mshtml.dll, Version: 11.0.9600.17924, Zeitstempel: 0x5595ab25
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0015433d
ID des fehlerhaften Prozesses: 0xc64
Startzeit der fehlerhaften Anwendung: 0xSkype.exe0
Pfad der fehlerhaften Anwendung: Skype.exe1
Pfad des fehlerhaften Moduls: Skype.exe2
Berichtskennung: Skype.exe3


System errors:
=============
Error: (07/22/2015 09:23:37 AM) (Source: Disk) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0.

Error: (07/22/2015 09:23:35 AM) (Source: Disk) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0.

Error: (07/22/2015 09:23:33 AM) (Source: Disk) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0.

Error: (07/22/2015 09:23:30 AM) (Source: Disk) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0.

Error: (07/22/2015 09:23:22 AM) (Source: Disk) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0.

Error: (07/22/2015 09:23:20 AM) (Source: Disk) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0.

Error: (07/22/2015 09:23:18 AM) (Source: Disk) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0.

Error: (07/22/2015 09:23:16 AM) (Source: Disk) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0.

Error: (07/22/2015 09:23:09 AM) (Source: Disk) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0.

Error: (07/22/2015 09:23:07 AM) (Source: Disk) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk0\DR0.


Microsoft Office:
=========================
Error: (07/21/2015 09:06:11 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: hl2.exe0.0.0.0195c01d0c3e7b23bb56775C:\Program Files\Steam\steamapps\common\GarrysMod\hl2.exe508ee919-2fdb-11e5-9fe4-00199962f02b

Error: (07/21/2015 04:03:46 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Explorer.EXE6.1.7601.175674d6727a7ntdll.dll6.1.7601.1886955636303c0000374000c3c237ac01d0c3a8b5f390c0C:\Windows\Explorer.EXEC:\Windows\SYSTEM32\ntdll.dll4cf9bf5a-2fb1-11e5-b8b6-00199962f02b

Error: (07/21/2015 02:32:38 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Terraria.exe1.3.0.655ac1237KERNELBASE.dll6.1.7601.18847554d7b00e04343520000812f1dec01d0c3ab437647d7C:\Program Files\Steam\steamapps\common\Terraria\Terraria.exeC:\Windows\system32\KERNELBASE.dll91fa811f-2fa4-11e5-b8b6-00199962f02b

Error: (07/21/2015 02:32:23 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: Terraria.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.IO.IOException
Stapel:
   bei System.IO.__Error.WinIOError(Int32, System.String)
   bei System.IO.FileStream.Init(System.String, System.IO.FileMode, System.IO.FileAccess, Int32, Boolean, System.IO.FileShare, Int32, System.IO.FileOptions, SECURITY_ATTRIBUTES, System.String, Boolean, Boolean, Boolean)
   bei System.IO.FileStream..ctor(System.String, System.IO.FileMode, System.IO.FileAccess, System.IO.FileShare)
   bei Terraria.Utilities.FileUtilities.Write(System.String, Byte[], Int32, Boolean)
   bei Terraria.IO.WorldFile.saveWorld(Boolean, Boolean)
   bei Terraria.WorldGen.saveAndPlayCallBack(System.Object)
   bei System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object)
   bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   bei System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
   bei System.Threading.ThreadPoolWorkQueue.Dispatch()
   bei System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()

Error: (07/21/2015 01:56:54 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: C:\Windows\system32\svchost.exe -k netsvcsWindows Update0x81000101

Error: (07/21/2015 02:11:44 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: GoogleUpdate.exe1.3.25.11545bb4acunknown0.0.0.000000000c0000005007a2af1248c01d0c3491c2587c7C:\Program Files\Google\Update\GoogleUpdate.exeunknown115bda8c-2f3d-11e5-8730-00199962f02b

Error: (07/20/2015 06:27:41 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - Failed to compile C:\Program Files\BlueStacks\HD-CreateSymlink.exe because this image is not a valid Win32 application.
C:\Program Files\BlueStacks\HD-CreateSymlink.exe

Error: (07/18/2015 05:49:14 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: TerraMapCmd.exe1.3.4.1643755aa5dbaKERNELBASE.dll6.1.7601.18847554d7b00e04343520000812f14cc01d0c171490f8f50C:\Users\peer\AppData\Local\Temp\wz44d1\TerraMap-1.3.4\TerraMapCmd.exeC:\Windows\system32\KERNELBASE.dll89738bd8-2d64-11e5-8730-00199962f02b

Error: (07/18/2015 05:49:11 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: TerraMapCmd.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.IO.FileNotFoundException
Stapel:
   bei TerraMap.Program.Main(System.String[])

Error: (07/18/2015 05:39:05 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Skype.exe7.6.0.105559165abmshtml.dll11.0.9600.179245595ab25c00000050015433dc6401d0c14cbbb22124C:\Program Files\Skype\Phone\Skype.exeC:\Windows\System32\mshtml.dll1ef8ab05-2d63-11e5-8730-00199962f02b


CodeIntegrity Errors:
===================================
  Date: 2015-03-11 07:37:21.956
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-03-11 07:37:21.954
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-03-11 07:37:21.952
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-03-11 07:37:21.945
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-03-11 07:37:21.943
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-03-11 07:37:21.941
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-03-11 07:37:21.937
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.2\KLELAMX86\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-03-11 07:37:21.935
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.2\KLELAMX86\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-03-11 07:37:21.933
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.2\KLELAMX86\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-03-11 07:37:21.926
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Internet Security 15.0.2\KLELAMX86\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info =========================== 

Processor: Intel(R) Core(TM)2 Duo CPU E7400 @ 2.80GHz
Percentage of memory in use: 66%
Total physical RAM: 3070.42 MB
Available physical RAM: 1033.08 MB
Total Virtual: 6439.16 MB
Available Virtual: 3746.28 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:232.79 GB) (Free:144.5 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: E49C41A0)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=232.8 GB) - (Type=07 NTFS)

==================== End of log ============================
         

 

Themen zu PC hängt alle paar Sek & Programme laufen langsamer
adware, bluestacks, bobrowser, browser, cherimoya.sys, chromium, crossbrowser, defender, downloader, error, failed, flash player, google, hacked, hängt, iexplore.exe, installmanager.exe, kaspersky, mozilla, registry, scan, security, sekunden, services.exe, software, stick, svchost.exe, system, teredo, udp, usb, windows




Ähnliche Themen: PC hängt alle paar Sek & Programme laufen langsamer


  1. Windows 8.1: Programme laufen sehr langsam,
    Log-Analyse und Auswertung - 08.08.2015 (1)
  2. Win8 seid paar Tagen langsamer und erhöhte CPU
    Plagegeister aller Art und deren Bekämpfung - 14.01.2015 (11)
  3. Win 8.1 hängt beim booten - 800 Hintergrundprozesse laufen - Virus ?
    Plagegeister aller Art und deren Bekämpfung - 11.08.2014 (7)
  4. Programme ruckeln stark und laufen instabil.
    Plagegeister aller Art und deren Bekämpfung - 18.07.2014 (11)
  5. Spiele und Internet laufen plötzlich langsamer
    Plagegeister aller Art und deren Bekämpfung - 10.11.2013 (9)
  6. CPU alle paar sekunden auf 100%
    Alles rund um Windows - 03.09.2013 (1)
  7. Pc ist langsamer geworden ... hier ein paar Logs
    Log-Analyse und Auswertung - 15.06.2013 (7)
  8. PC wird immer langsamer und es laufen mehrere svchost-Prozesse gleichzeitig
    Plagegeister aller Art und deren Bekämpfung - 08.11.2012 (18)
  9. Notebook (MD96630) hängt für paar sekunden (CPU 100%)
    Log-Analyse und Auswertung - 31.10.2012 (19)
  10. Internet Explorer und alle Programme und Downloads die über ihn laufen funktionieren nicht
    Log-Analyse und Auswertung - 25.09.2012 (6)
  11. Rechner hakt alle paar sekunden, Programme öffnen erst nach mehreren Minuten, JAVA/Stutter.I.1
    Log-Analyse und Auswertung - 01.08.2011 (1)
  12. Pc hängt alle paar sekunden
    Log-Analyse und Auswertung - 17.10.2008 (0)
  13. Pc langsamer, Programme sterben, inet langsamer
    Log-Analyse und Auswertung - 11.10.2008 (1)
  14. PC hängt alle paar Sekunden - AntiVir erfolglos !
    Log-Analyse und Auswertung - 24.06.2008 (0)
  15. Laufen hier irgendwelche Spionage Programme?
    Mülltonne - 24.02.2007 (1)
  16. Alle verbindungen laufen über 127.0.0.1
    Antiviren-, Firewall- und andere Schutzprogramme - 13.02.2006 (2)
  17. Welche Programme sollten immer laufen?
    Antiviren-, Firewall- und andere Schutzprogramme - 28.02.2005 (17)

Zum Thema PC hängt alle paar Sek & Programme laufen langsamer - Seit ca. vorgestern hängt mein PC alle paar Sekunden und alle Programme laufen im allgemeinen langsamer. Ich hab mir in letzter Zeit über Google ein 3 Bilder gedownloadet und über - PC hängt alle paar Sek & Programme laufen langsamer...
Archiv
Du betrachtest: PC hängt alle paar Sek & Programme laufen langsamer auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.