Alt 24.07.2015, 12:38   #1
Google Chrome  öffnet laufend neue  Fenster - Standard

Google Chrome öffnet laufend neue Fenster


Ich habe seit gestern Abend ein Problem ! Muss dazu sagen das ich bisher immer von Viren verschont wurde.

Also allein ebend als ich diesen Text eingeben wollte und das Feld anklickt habe ging eine neue HP auf mit Werbung und Malware warnt das er eine viren verseuchte HP geblockt hat.

also Malwarebytes findet nischt

ADW findet das kann es aber nicht löschen schon 20 mal versucht

***** [ Dienste ] *****

***** [ Dateien / Ordner ] *****

***** [ Geplante Tasks ] *****

***** [ Verknüpfungen ] *****

***** [ Registrierungsdatenbank ] *****

***** [ Internetbrowser ] *****

-\\ Internet Explorer v11.0.9600.17840

-\\ Mozilla Firefox v

-\\ Google Chrome v43.0.2357.134

[C:\Users\Björn\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Gelöscht [Homepage] : management","searchProvider","startupPages"],"explicit_host":["hxxp://*.bing.com/*","hxxp://g.ceipmsn.com/*"],"manifest_permissions":[]},"commands":{},"content_settings":[],"creation_flags":9,"events":[],"from_bookmark":false,"from_webstore":true,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_parameter":"UP97","install_time":"13067299916778314","lastpingday":"13067251194271 406","location":6,"manifest":{"background":{"persistent":false,"scripts":["background.js"]},"chrome_settings_overrides":{"homepage":"hxxp://www.msn.com/de-de/?pc=__PARAM__&ocid=__PARAM__DHP","search_provider":{"encoding":"UTF-8","favicon_url":"hxxp://www.bing.com/favicon.ico","is_default":true,"keyword":"bing.com","name":"Bing","search_url":"hxxp://www.bing.com/search?FORM=__PARAM__DF&PC=__PARAM__&q={searchTerms}"},"startup_pages":["hxxp://www.msn.com/de-de/?pc=__PARAM__&ocid=__PARAM__DHP"]},"current_locale":"de","default_locale":"en","description":"MSN Homepage & Bing Search Engine","icons":{"128":"Logo_128.ico","16":"Logo.png","48":"Logo_48.ico"},"key":"MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0JA3sXSSGLZfdufL1gcnN5sgZ 7Upqkq0FF8aaRTf8v/banM0MIX3o6XqEV+ireOgQZIz1GcNKMEJ1BpeaheabEGRn3ZqQrO+gwpbeJDhuNcT8MD3npRoColMqG6rPG/b+GxM60gS0bBrELyNB6EeNj1j5hVvZA/VG92sW4Ld/Yqea6iKrs/Vfh99utT6V7CmTPMXLAvY40yufxWHEqpgsqU2gNn1FY94BB0UbWE40t5DHmC6y67F26uBRodQu//TZTd2BxcuGEUohU8jDTAs+dl8wCHGP19xBzWkEnI+RRTtUyZ1IeRY3x7W+Xbe60wz/UeoYQMmCdzdq1WDo8kgtwIDAQAB","manifest_version":2,"name":"MSN Homepage & Bing Search Engine","permissions":["hxxp://g.ceipmsn.com/*","hxxp://*.bing.com/*","cookies","management"],"short_name":"MSN Homepage & Bing Search Engine","update_url":"hxxps://clients2.google.com/service/update2/crx","version":""},"path":"fcfenmboojpjinhpgggodefccipikbpd\\","preferences":{},"regular_only_preferences":{},"state":2,"was_installed _by_default":false,"was_installed_by_oem":false},"fdhbkaahephniejapepaiggngjnedpci":{"ack_external":true,"ack_ntp_bubble":true,"ack_settings_bubble":t rue,"active_permissions":{"api":["alarms","searchProvider","storage","tabs","unlimitedStorage","webRequest","webRequestBlocking"],"explicit_host":["*://*.mystart.com/*


AdwCleaner[R0].txt - [8328 Bytes] - [23/07/2015 23:16:06]
AdwCleaner[R1].txt - [4104 Bytes] - [24/07/2015 12:39:02]
AdwCleaner[R2].txt - [3353 Bytes] - [24/07/2015 12:42:51]
AdwCleaner[R3].txt - [3471 Bytes] - [24/07/2015 12:45:21]
AdwCleaner[R4].txt - [3589 Bytes] - [24/07/2015 12:47:50]
AdwCleaner[R5].txt - [3707 Bytes] - [24/07/2015 12:50:58]
AdwCleaner[S0].txt - [8008 Bytes] - [23/07/2015 23:16:49]
AdwCleaner[S1].txt - [4163 Bytes] - [24/07/2015 12:40:40]
AdwCleaner[S2].txt - [3412 Bytes] - [24/07/2015 12:44:08]
AdwCleaner[S3].txt - [3530 Bytes] - [24/07/2015 12:46:26]
AdwCleaner[S4].txt - [3648 Bytes] - [24/07/2015 12:49:38]
AdwCleaner[S5].txt - [3627 Bytes] - [24/07/2015 12:52:58]

########## EOF - C:\AdwCleaner\AdwCleaner[S5].txt - [3686 Bytes] ##########

Kaspersky hatte auch nichts gefunden.

Könnt Ihr mir helfen sonst geh ich bald mit Format dran ^^

Alt 24.07.2015, 12:48   #2
/// the machine
/// TB-Ausbilder

Google Chrome  öffnet laufend neue  Fenster - Standard

Google Chrome öffnet laufend neue Fenster


Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)



Alt 25.07.2015, 10:27   #3
Google Chrome  öffnet laufend neue  Fenster - Standard

Google Chrome öffnet laufend neue Fenster

FRST Logfile:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:20-07-2015
Ran by Björn (administrator) on GAMINGMEILE on 25-07-2015 11:18:46
Running from E:\BETHESDA
Loaded Profiles: Björn (Available Profiles: Björn & Ich)
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVerMedia TECHNOLOGIES, Inc.) C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRECentral.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\avp.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Razer Inc.) C:\Program Files (x86)\Razer\RzWizard\RzWizardService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\avpui.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
() C:\Program Files (x86)\GIGABYTE\ET6\GUI.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Beepa P/L) C:\Fraps\fraps.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Beepa P/L) C:\Fraps\fraps64.dat
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\avp.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Users\Björn\Desktop\adwcleaner_4.208 (1).exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2754704 2015-06-03] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [11877656 2014-09-16] (Logitech Inc.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13651672 2013-09-03] (Realtek Semiconductor)
HKLM-x32\...\Run: [APSDaemon] => c:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => c:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM-x32\...\Run: [Speedup_umh] => C:\Program Files (x86)\Avira\AviraSpeedup\Speedup_umh.exe [191640 2015-04-14] ()
HKLM-x32\...\Run: [RzWizard] => C:\Program Files (x86)\Razer\RzWizard\RzWizard.exe [254976 2015-04-16] (Razer Inc.)
HKLM-x32\...\RunOnce: [EasyTuneVI] => C:\Program Files (x86)\GIGABYTE\ET6\ETCall.exe [40960 2012-07-09] ()
HKLM\...\Winlogon: [Userinit] C:\WINDOWS\SysWOW64\userinit.exe,
HKU\S-1-5-21-1148309869-985715220-1964481749-1001\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3632112 2015-06-30] (Electronic Arts)
HKU\S-1-5-21-1148309869-985715220-1964481749-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53288576 2015-06-30] (Skype Technologies S.A.)
HKU\S-1-5-21-1148309869-985715220-1964481749-1001\...\Run: [AudialsNotifier] => C:\Program Files (x86)\Audials\Audials 12\AudialsNotifier.exe
HKU\S-1-5-21-1148309869-985715220-1964481749-1001\...\Run: [GalaxyClient] => C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe [7247416 2015-07-21] (GOG.com)
HKU\S-1-5-21-1148309869-985715220-1964481749-1001\...\Run: [Prime95] => E:\BETHESDA\p95v286.win64\prime95.exe [36369920 2015-04-04] ()
Startup: C:\Users\Björn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip [2014-08-06] ()
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-1148309869-985715220-1964481749-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKU\S-1-5-21-1148309869-985715220-1964481749-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-1148309869-985715220-1964481749-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = 
SearchScopes: HKU\S-1-5-21-1148309869-985715220-1964481749-1001 -> {465ED461-AA32-4D6D-A609-D080E9D43667} URL = 
BHO: Virtual Keyboard Plugin -> {4A66AD60-A03D-4D01-86F0-5F0F7C0EF1AD} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\x64\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO: Content Blocker Plugin -> {93BC2EA7-2F17-4729-948A-D2E03FFB2412} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\x64\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO: Safe Money Plugin -> {AB379017-4C03-4E00-8EDF-E6D6AF7CCF82} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\x64\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: Virtual Keyboard Plugin -> {4A66AD60-A03D-4D01-86F0-5F0F7C0EF1AD} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-10-03] (Oracle Corporation)
BHO-x32: Content Blocker Plugin -> {93BC2EA7-2F17-4729-948A-D2E03FFB2412} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO-x32: Safe Money Plugin -> {AB379017-4C03-4E00-8EDF-E6D6AF7CCF82} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-10-03] (Oracle Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer]
Tcpip\..\Interfaces\{6E5966A4-68DD-4163-AD41-6FD3C2223282}: [DhcpNameServer]
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FF ProfilePath: C:\Users\Björn\AppData\Roaming\Mozilla\Firefox\Profiles\BgRnuSqd.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-14] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-14] ()
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-10-03] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-10-03] (Oracle Corporation)
FF Plugin-x32: @kaspersky.com/content_blocker_663BE84DBCC949E88C7600F63CA7F098 -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\content_blocker@kaspersky.com [2015-07-23] ()
FF Plugin-x32: @kaspersky.com/online_banking_08806E753BE44495B44E90AA2513BDC5 -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\online_banking@kaspersky.com [2015-07-23] ()
FF Plugin-x32: @kaspersky.com/virtual_keyboard_07402848C2F6470194F131B0F3DE025E -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\virtual_keyboard@kaspersky.com [2015-07-23] ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-04-08] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-04-08] (NVIDIA Corporation)
FF Plugin-x32: @protectdisc.com/NPPDLicenseHelper -> C:\Program Files (x86)\ProtectDisc\License Helper\NPPDLicenseHelper.dll [2008-02-22] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Extension: Avira Browser Safety - C:\Users\Björn\AppData\Roaming\Mozilla\Firefox\Profiles\BgRnuSqd.default\Extensions\abs@avira.com [2015-02-19]
FF Extension: Amazon-Icon - C:\Users\Björn\AppData\Roaming\Mozilla\Firefox\Profiles\BgRnuSqd.default\Extensions\amazon-icon@giga.de [2015-02-21]
FF HKLM-x32\...\Firefox\Extensions: [content_blocker_663BE84DBCC949E88C7600F63CA7F098@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\content_blocker@kaspersky.com
FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\content_blocker@kaspersky.com [2015-07-23]
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard_07402848C2F6470194F131B0F3DE025E@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\virtual_keyboard@kaspersky.com [2015-07-23]
FF HKLM-x32\...\Firefox\Extensions: [online_banking_08806E753BE44495B44E90AA2513BDC5@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\FFExt\online_banking@kaspersky.com [2015-07-23]

CHR Profile: C:\Users\Björn\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\Björn\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-15]
CHR Extension: (YouTube) - C:\Users\Björn\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-15]
CHR Extension: (Google Search) - C:\Users\Björn\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-15]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Björn\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-12]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Björn\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-15]
CHR Extension: (Gmail) - C:\Users\Björn\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-15]
CHR HKLM\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
CHR HKLM-x32\...\Chrome\Extension: [fdhbkaahephniejapepaiggngjnedpci] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-05-01]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AVerRECentral; C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRECentral.exe [373248 2013-11-07] (AVerMedia TECHNOLOGIES, Inc.) [File not signed]
R2 AVP15.0.2; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\avp.exe [194000 2015-07-09] (Kaspersky Lab ZAO)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1141248 2015-06-19] ()
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1858048 2012-01-23] (MAGIX AG) [File not signed]
S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed]
S3 GalaxyClientService; C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe [1718840 2015-07-21] (GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6871608 2015-07-21] (GOG.com)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152656 2015-06-03] (NVIDIA Corporation)
S3 ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [160256 2011-08-30] (Intel Corporation) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1893008 2015-06-03] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [23007376 2015-06-03] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2004488 2015-06-30] (Electronic Arts)
R2 RzWizardService; C:\Program Files (x86)\Razer\RzWizard\RzWizardService.exe [368128 2015-04-16] (Razer Inc.) [File not signed]
S3 Survarium Update Service; C:\Program Files (x86)\Survarium\game\binaries\x86\survarium_service.exe [76408 2015-01-10] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AVMU3HC64; C:\Windows\system32\drivers\avmu364.sys [520192 2014-03-27] (AVerMedia TECHNOLOGIES, Inc.)
R0 cm_km_w; C:\Windows\System32\DRIVERS\cm_km_w.sys [247016 2015-07-09] (Kaspersky Lab UK Ltd)
S3 ElgatoGC658Y; C:\Windows\System32\Drivers\ElgatoGC658.sys [50288 2012-11-12] (UB658)
R3 GVTDrv64; C:\WINDOWS\GVTDrv64.sys [30528 2015-07-25] ()
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [478392 2015-07-09] (Kaspersky Lab ZAO)
R2 kldisk; C:\Windows\system32\DRIVERS\kldisk.sys [64368 2015-07-09] (Kaspersky Lab ZAO)
S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [29616 2012-07-27] (Kaspersky Lab)
R3 klflt; C:\Windows\system32\DRIVERS\klflt.sys [159960 2015-07-09] (Kaspersky Lab ZAO)
R1 klhk; C:\Windows\system32\DRIVERS\klhk.sys [226480 2015-07-09] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [831664 2015-07-09] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [39792 2015-07-09] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [40304 2015-07-09] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [39792 2015-07-09] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [24944 2015-07-09] (Kaspersky Lab ZAO)
R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [77680 2015-07-09] (Kaspersky Lab ZAO)
R1 Klwtp; C:\Windows\system32\DRIVERS\klwtp.sys [85360 2015-07-09] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [190648 2015-07-09] (Kaspersky Lab ZAO)
R3 LGSHidFilt; C:\Windows\system32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)
S3 mbamchameleon; C:\WINDOWS\system32\drivers\mbamchameleon.sys [107736 2015-07-24] (Malwarebytes Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [113880 2015-07-25] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-06-03] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [46768 2015-05-19] (NVIDIA Corporation)
S1 RrNetCapFilterDriver; C:\Windows\system32\DRIVERS\RrNetCapFilterDriver.sys [24744 2015-01-09] (Audials AG)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
U4 klkbdflt2; \SystemRoot\system32\DRIVERS\klkbdflt2.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-25 11:16 - 2015-07-25 11:18 - 00000000 ____D C:\FRST
2015-07-24 13:49 - 2015-07-24 15:57 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-07-24 13:46 - 2015-07-24 13:46 - 00000000 ____D C:\Users\Björn\Desktop\mbar
2015-07-24 12:57 - 2015-07-24 12:57 - 00000000 ____D C:\Program Files (x86)\ESET
2015-07-24 12:42 - 2015-07-24 12:38 - 02248704 _____ C:\Users\Björn\Desktop\adwcleaner_4.208 (1).exe
2015-07-23 23:16 - 2015-07-25 11:13 - 00000000 ____D C:\AdwCleaner
2015-07-23 22:50 - 2015-07-25 09:51 - 00000004 _____ C:\WINDOWS\SysWOW64\GVTunner.ref
2015-07-23 22:02 - 2015-07-23 22:02 - 00000000 ____D C:\Users\Björn\AppData\Local\CEF
2015-07-23 21:54 - 2015-07-25 10:12 - 00113880 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-07-23 21:53 - 2015-07-24 13:46 - 00107736 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-07-23 21:53 - 2015-07-23 21:53 - 00001114 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2015-07-23 21:53 - 2015-07-23 21:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-07-23 21:53 - 2015-07-23 21:53 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-07-23 21:53 - 2015-07-23 21:53 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2015-07-23 21:53 - 2015-06-18 08:42 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-07-23 21:53 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-07-23 18:19 - 2015-07-23 18:19 - 00002346 _____ C:\Users\Björn\Desktop\Sicherer Zahlungsverkehr.lnk
2015-07-23 18:14 - 2015-07-23 18:14 - 00002156 _____ C:\Users\Public\Desktop\Kaspersky Internet Security.lnk
2015-07-23 18:14 - 2015-07-23 18:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security
2015-07-23 18:14 - 2013-05-06 08:13 - 00110176 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\klfphc.dll
2015-07-23 18:13 - 2015-07-25 10:06 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2015-07-23 18:13 - 2015-07-23 18:13 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab
2015-07-23 18:13 - 2015-07-09 19:11 - 00831664 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klif.sys
2015-07-23 18:13 - 2015-07-09 19:11 - 00226480 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klhk.sys
2015-07-23 18:13 - 2015-07-09 19:11 - 00159960 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klflt.sys
2015-07-22 14:44 - 2015-07-22 14:44 - 00003084 _____ C:\WINDOWS\System32\Tasks\Browser Ball
2015-07-22 14:44 - 2015-07-22 14:44 - 00000000 ____D C:\Users\Björn\AppData\Local\Browser Ball
2015-07-21 10:23 - 2015-07-14 16:14 - 00358912 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-07-21 10:23 - 2015-07-14 16:14 - 00301056 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-07-21 10:23 - 2015-07-14 16:14 - 00035840 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-07-21 10:23 - 2015-07-14 16:13 - 00044032 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-07-16 14:16 - 2015-07-16 14:47 - 00000000 ____D C:\Users\Björn\Documents\DayZ
2015-07-16 14:16 - 2015-07-16 14:17 - 00000000 ____D C:\Users\Björn\AppData\Local\DayZ
2015-07-15 01:30 - 2015-07-09 21:51 - 00136904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2015-07-15 01:30 - 2015-07-09 20:40 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSetupUI.dll
2015-07-15 01:30 - 2015-07-09 18:03 - 03701760 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-07-15 01:30 - 2015-07-09 17:54 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2015-07-15 01:30 - 2015-07-09 17:53 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2015-07-15 01:30 - 2015-07-09 17:50 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2015-07-15 01:30 - 2015-07-09 17:50 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2015-07-15 01:30 - 2015-07-09 17:48 - 00891904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2015-07-15 01:30 - 2015-07-09 17:46 - 02229248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2015-07-15 01:30 - 2015-07-09 17:38 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
2015-07-15 01:30 - 2015-07-09 17:37 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
2015-07-15 01:30 - 2015-07-09 17:35 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2015-07-15 01:30 - 2015-07-09 17:34 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2015-07-15 01:30 - 2015-06-27 05:08 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2015-07-15 01:30 - 2015-06-27 05:08 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2015-07-15 01:30 - 2015-06-27 04:14 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2015-07-15 01:29 - 2015-07-02 22:49 - 25193984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-07-15 01:29 - 2015-07-02 00:08 - 05923840 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-07-15 01:29 - 2015-07-01 23:14 - 04520448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-07-15 01:29 - 2015-06-30 00:43 - 00026288 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2015-07-15 01:29 - 2015-06-29 17:07 - 01145856 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2015-07-15 01:29 - 2015-06-29 17:07 - 01084928 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2015-07-15 01:29 - 2015-06-29 17:07 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2015-07-15 01:29 - 2015-06-29 17:07 - 00433152 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2015-07-15 01:29 - 2015-06-29 17:07 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-07-15 01:29 - 2015-06-28 07:07 - 00442712 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2015-07-15 01:29 - 2015-06-28 07:07 - 00178008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2015-07-15 01:29 - 2015-06-28 07:06 - 01311960 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2015-07-15 01:29 - 2015-06-28 07:06 - 00332120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2015-07-15 01:29 - 2015-06-27 18:42 - 00747520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2015-07-15 01:29 - 2015-06-27 05:13 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2015-07-15 01:29 - 2015-06-27 05:12 - 00401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2015-07-15 01:29 - 2015-06-27 05:12 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2015-07-15 01:29 - 2015-06-27 04:40 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2015-07-15 01:29 - 2015-06-27 04:05 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2015-07-15 01:29 - 2015-06-27 04:00 - 00989184 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2015-07-15 01:29 - 2015-06-27 03:53 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2015-07-15 01:29 - 2015-06-27 03:26 - 00802816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2015-07-15 01:29 - 2015-06-27 01:21 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2015-07-15 01:29 - 2015-06-27 01:21 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
2015-07-15 01:29 - 2015-06-25 04:31 - 04177920 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-07-15 01:29 - 2015-06-16 00:41 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe
2015-07-15 01:29 - 2015-06-16 00:24 - 03320320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2015-07-15 01:29 - 2015-06-15 23:16 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msiexec.exe
2015-07-15 01:29 - 2015-06-15 23:09 - 03607552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2015-07-15 01:29 - 2015-06-15 22:50 - 02774528 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2015-07-15 01:29 - 2015-06-15 21:57 - 02460160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2015-07-15 01:29 - 2015-05-30 23:18 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2015-07-15 01:29 - 2015-05-30 21:36 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-07-15 01:29 - 2015-05-30 21:35 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-07-15 01:29 - 2015-05-07 19:50 - 22292672 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-07-15 01:29 - 2015-05-07 19:00 - 03109376 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2015-07-15 01:29 - 2015-05-07 18:53 - 19734960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-07-15 01:29 - 2015-05-07 18:12 - 02706432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2015-07-15 01:29 - 2015-05-07 17:21 - 00522240 _____ (Microsoft Corporation) C:\WINDOWS\system32\GeofenceMonitorService.dll
2015-07-15 01:29 - 2015-05-07 17:05 - 00367104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GeofenceMonitorService.dll
2015-07-15 01:29 - 2015-05-03 17:09 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-15 01:29 - 2015-05-03 16:58 - 00210944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-15 01:29 - 2015-05-03 16:55 - 00971776 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2015-07-15 01:29 - 2015-05-03 16:49 - 00811008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2015-07-15 01:29 - 2015-05-03 02:39 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2015-07-15 01:29 - 2015-04-30 01:22 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll
2015-07-15 01:29 - 2015-04-25 04:25 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usb8023.sys
2015-07-15 01:29 - 2014-11-04 21:25 - 00059712 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdclass.sys
2015-07-15 01:29 - 2014-11-04 21:25 - 00051008 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mouclass.sys
2015-07-15 01:29 - 2014-11-04 08:55 - 00026112 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sermouse.sys
2015-07-15 01:29 - 2014-11-04 08:54 - 00108544 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\i8042prt.sys
2015-07-15 01:29 - 2014-11-04 08:54 - 00032256 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdhid.sys
2015-07-15 01:29 - 2014-11-04 08:54 - 00030208 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mouhid.sys
2015-07-15 01:28 - 2015-07-02 23:21 - 19877376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-07-15 01:28 - 2015-07-02 22:50 - 02279424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-07-15 01:28 - 2015-07-02 22:23 - 02885632 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-07-15 01:28 - 2015-07-02 22:19 - 12855296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-07-15 01:28 - 2015-07-02 21:55 - 01310720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-07-15 01:28 - 2015-07-02 21:20 - 14453248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-07-15 01:28 - 2015-07-02 20:59 - 01545728 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-07-15 01:26 - 2015-06-16 07:36 - 01661576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2015-07-15 01:26 - 2015-06-16 07:36 - 01212248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2015-07-15 01:26 - 2015-06-16 00:39 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-07-15 01:26 - 2015-06-16 00:38 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2015-07-15 01:26 - 2015-06-16 00:26 - 00633856 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
2015-07-15 01:26 - 2015-06-16 00:24 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-07-15 01:26 - 2015-06-16 00:02 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx
2015-07-15 01:26 - 2015-06-15 23:58 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll
2015-07-15 01:26 - 2015-06-15 23:57 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2015-07-15 01:26 - 2015-06-15 23:56 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2015-07-15 01:26 - 2015-06-15 23:55 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2015-07-15 01:26 - 2015-06-15 23:49 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-07-15 01:26 - 2015-06-15 23:41 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2015-07-15 01:26 - 2015-06-15 23:38 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-07-15 01:26 - 2015-06-15 23:36 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-07-15 01:26 - 2015-06-15 23:17 - 02880000 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2015-07-15 01:26 - 2015-06-15 23:16 - 02427392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-07-15 01:26 - 2015-06-15 23:15 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-07-15 01:26 - 2015-06-15 23:13 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2015-07-15 01:26 - 2015-06-15 23:04 - 00478208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieui.dll
2015-07-15 01:26 - 2015-06-15 23:03 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-07-15 01:26 - 2015-06-15 22:52 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-07-15 01:26 - 2015-06-15 22:47 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx
2015-07-15 01:26 - 2015-06-15 22:44 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll
2015-07-15 01:26 - 2015-06-15 22:43 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2015-07-15 01:26 - 2015-06-15 22:42 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2015-07-15 01:26 - 2015-06-15 22:41 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2015-07-15 01:26 - 2015-06-15 22:37 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-07-15 01:26 - 2015-06-15 22:32 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2015-07-15 01:26 - 2015-06-15 22:31 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-07-15 01:26 - 2015-06-15 22:30 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2015-07-15 01:26 - 2015-06-15 22:30 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2015-07-15 01:26 - 2015-06-15 22:17 - 01048576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2015-07-15 01:26 - 2015-06-15 22:07 - 01951232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-07-15 01:26 - 2015-06-15 22:02 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-07-15 01:26 - 2015-06-11 05:49 - 01380600 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2015-07-15 01:26 - 2015-06-10 18:13 - 01097216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2015-07-15 01:26 - 2015-05-12 15:19 - 00294912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2015-07-15 01:26 - 2015-05-11 18:34 - 00332800 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcpl.dll
2015-07-15 01:26 - 2015-05-03 17:07 - 07784448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2015-07-15 01:26 - 2015-05-02 01:33 - 00410739 _____ C:\WINDOWS\system32\ApnDatabase.xml
2015-07-15 01:26 - 2015-04-28 15:13 - 00513480 _____ C:\WINDOWS\SysWOW64\locale.nls
2015-07-15 01:26 - 2015-04-28 15:13 - 00513480 _____ C:\WINDOWS\system32\locale.nls
2015-07-15 01:26 - 2015-04-23 17:47 - 03084288 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2015-07-15 01:26 - 2015-04-23 17:16 - 02471424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2015-07-15 01:25 - 2015-05-07 18:47 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\apphelp.dll
2015-07-15 01:25 - 2015-05-03 16:57 - 05264384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2015-07-10 16:36 - 2015-07-10 16:36 - 00000000 ____D C:\Users\Björn\AppData\Local\Razer_Inc
2015-07-10 16:13 - 2015-07-10 16:13 - 00000000 ____D C:\ProgramData\Razer
2015-07-10 16:13 - 2015-07-10 16:13 - 00000000 ____D C:\Program Files (x86)\Razer
2015-07-09 19:11 - 2015-07-09 19:11 - 00478392 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\kl1.sys
2015-07-09 19:11 - 2015-07-09 19:11 - 00247016 _____ (Kaspersky Lab UK Ltd) C:\WINDOWS\system32\Drivers\cm_km_w.sys
2015-07-09 19:11 - 2015-07-09 19:11 - 00190648 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\kneps.sys
2015-07-09 19:11 - 2015-07-09 19:11 - 00085360 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klwtp.sys
2015-07-09 19:11 - 2015-07-09 19:11 - 00077680 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klwfp.sys
2015-07-09 19:11 - 2015-07-09 19:11 - 00064368 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\kldisk.sys
2015-07-09 19:11 - 2015-07-09 19:11 - 00040304 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klkbdflt.sys
2015-07-09 19:11 - 2015-07-09 19:11 - 00039792 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klmouflt.sys
2015-07-09 19:11 - 2015-07-09 19:11 - 00039792 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klim6.sys
2015-07-09 19:11 - 2015-07-09 19:11 - 00024944 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\Drivers\klpd.sys
2015-06-30 12:50 - 2015-07-25 09:51 - 00003144 _____ C:\WINDOWS\System32\Tasks\FRAPS
2015-06-29 18:37 - 2015-06-29 18:37 - 00000222 _____ C:\Users\Björn\Desktop\Heroes & Generals.url

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-25 11:13 - 2015-04-16 21:12 - 02072894 _____ C:\WINDOWS\WindowsUpdate.log
2015-07-25 11:12 - 2014-08-08 00:29 - 00000000 ____D C:\Users\Björn\AppData\Roaming\Skype
2015-07-25 11:02 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\sru
2015-07-25 10:58 - 2015-05-16 11:47 - 00001142 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-25 09:58 - 2014-03-18 12:03 - 00005430 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-07-25 09:58 - 2014-03-18 11:25 - 02624012 _____ C:\WINDOWS\system32\perfh007.dat
2015-07-25 09:58 - 2014-03-18 11:25 - 00735760 _____ C:\WINDOWS\system32\perfc007.dat
2015-07-25 09:54 - 2015-04-04 12:58 - 00000000 ___SD C:\WINDOWS\system32\GWX
2015-07-25 09:51 - 2015-05-16 11:47 - 00001138 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-25 09:51 - 2015-05-01 16:02 - 00030528 _____ C:\WINDOWS\GVTDrv64.sys
2015-07-25 09:51 - 2015-05-01 16:02 - 00025640 _____ (Windows (R) Server 2003 DDK provider) C:\WINDOWS\gdrv.sys
2015-07-25 09:51 - 2015-04-16 21:12 - 00000000 ____D C:\ProgramData\NVIDIA
2015-07-25 09:51 - 2014-06-21 23:26 - 00000000 ____D C:\Fraps
2015-07-25 09:51 - 2013-08-22 16:46 - 00374034 _____ C:\WINDOWS\setupact.log
2015-07-25 09:51 - 2013-08-22 16:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-07-25 02:44 - 2014-05-15 19:15 - 00000000 ____D C:\Program Files (x86)\Steam
2015-07-24 19:05 - 2014-03-18 03:50 - 00177456 _____ C:\WINDOWS\PFRO.log
2015-07-24 16:02 - 2014-06-17 18:16 - 00000000 ____D C:\Users\Björn\AppData\Local\CrashDumps
2015-07-24 15:50 - 2015-05-15 01:36 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1148309869-985715220-1964481749-1001
2015-07-24 12:44 - 2013-08-22 15:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-07-24 12:43 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-07-24 12:34 - 2014-05-15 19:33 - 00000000 ____D C:\Users\Björn\AppData\Local\Google
2015-07-24 11:43 - 2014-05-20 22:03 - 00000000 ____D C:\Users\Björn\AppData\Roaming\TS3Client
2015-07-23 23:18 - 2014-06-09 20:15 - 00000000 ____D C:\ProgramData\Origin
2015-07-23 22:49 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\vpnplugins
2015-07-23 22:11 - 2015-04-16 22:11 - 00000000 ___DC C:\WINDOWS\Panther
2015-07-23 22:10 - 2014-05-15 19:34 - 00002195 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-07-23 21:25 - 2015-05-15 01:19 - 00000000 ____D C:\ProgramData\Panda Security URL Filtering
2015-07-23 20:25 - 2014-08-25 13:20 - 00001743 _____ C:\Users\Björn\Desktop\WorldofTanks.lnk
2015-07-23 18:26 - 2014-05-17 23:25 - 00000000 ____D C:\ProgramData\Package Cache
2015-07-23 18:25 - 2015-02-19 12:36 - 00000000 ____D C:\Program Files (x86)\Avira
2015-07-23 18:19 - 2015-02-19 11:34 - 00000000 ____D C:\ProgramData\Kaspersky Lab Setup Files
2015-07-23 18:14 - 2013-08-22 15:25 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM
2015-07-23 18:13 - 2013-08-22 17:36 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2015-07-23 18:13 - 2013-08-22 15:36 - 00000000 ____D C:\Users\Default.migrated
2015-07-23 18:12 - 2015-05-15 01:19 - 00000000 ____D C:\ProgramData\panda_url_filtering
2015-07-23 18:12 - 2013-08-22 16:44 - 00508560 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-07-23 18:09 - 2015-05-15 01:18 - 00000000 ____D C:\Program Files (x86)\Panda Security
2015-07-23 18:09 - 2015-05-15 01:16 - 00000000 ____D C:\ProgramData\Panda Security
2015-07-23 18:08 - 2015-05-15 01:18 - 00000000 ____D C:\Users\Björn\AppData\Roaming\Panda Security
2015-07-21 10:44 - 2013-08-22 17:20 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-07-18 15:16 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\rescache
2015-07-18 11:18 - 2014-08-08 00:29 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-07-18 11:18 - 2014-08-08 00:29 - 00000000 ____D C:\ProgramData\Skype
2015-07-18 01:36 - 2015-04-04 12:58 - 00000000 ___SD C:\WINDOWS\SysWOW64\GWX
2015-07-18 01:36 - 2013-08-22 17:36 - 00000000 ___RD C:\WINDOWS\ToastData
2015-07-18 01:36 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\WinStore
2015-07-17 14:58 - 2014-07-22 15:06 - 00000000 ____D C:\Users\Björn\Documents\ProfileCache
2015-07-16 04:53 - 2015-05-16 11:47 - 00004114 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-07-16 04:53 - 2015-05-16 11:47 - 00003878 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-07-15 13:26 - 2014-12-09 22:02 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-07-15 13:26 - 2014-07-11 01:37 - 00000000 ___SD C:\WINDOWS\system32\CompatTel
2015-07-15 13:26 - 2014-05-17 20:08 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-07-13 23:10 - 2013-08-22 17:38 - 00792568 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-07-13 23:10 - 2013-08-22 17:38 - 00178168 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-07-12 15:23 - 2014-06-01 16:15 - 00000000 ____D C:\Users\Björn\AppData\Roaming\Audacity
2015-07-07 14:08 - 2015-05-14 17:05 - 00000000 ____D C:\Users\Björn\.thumbnails
2015-07-05 12:08 - 2014-07-11 14:29 - 00300704 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2015-07-03 08:43 - 2014-05-17 20:08 - 130333168 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-07-01 23:33 - 2014-05-15 19:21 - 00000000 ____D C:\Users\Björn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2015-07-01 00:04 - 2015-04-16 21:14 - 00000000 ____D C:\Users\Björn
2015-06-30 12:54 - 2014-06-09 20:15 - 00000000 ____D C:\Program Files (x86)\Origin

==================== Files in the root of some directories =======

2014-08-25 14:20 - 2014-11-08 10:20 - 0000119 _____ () C:\Users\Björn\AppData\Roaming\WB.CFG
2015-04-15 17:12 - 2015-04-15 17:12 - 0000017 _____ () C:\Users\Björn\AppData\Local\resmon.resmoncfg
2015-04-14 17:59 - 2015-04-14 17:59 - 0271934 _____ () C:\ProgramData\1429027094.bdinstall.bin
2015-05-25 02:04 - 2015-05-25 02:04 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Files to move or delete:
C:\Users\Bjoern\ntuser (2).dat

Some files in TEMP:

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2015-07-17 05:29

==================== End of log ============================
--- --- ---

FRST Logfile:
scan result of Farbar Recovery Scan Tool (x64) Version:20-07-2015
Ran by Björn at 2015-07-25 11:19:20
Running from E:\BETHESDA
Boot Mode: Normal

==================== Accounts: =============================

Administrator (S-1-5-21-1148309869-985715220-1964481749-500 - Administrator - Disabled)
Björn (S-1-5-21-1148309869-985715220-1964481749-1001 - Administrator - Enabled) => C:\Users\Björn
Gast (S-1-5-21-1148309869-985715220-1964481749-501 - Limited - Enabled)
HomeGroupUser$ (S-1-5-21-1148309869-985715220-1964481749-1003 - Limited - Enabled)
Ich (S-1-5-21-1148309869-985715220-1964481749-1009 - Administrator - Enabled) => C:\Users\Ich

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Kaspersky Internet Security (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Kaspersky Internet Security (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Enabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: - Adobe Systems Incorporated)
Apple Application Support (HKLM-x32\...\{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}) (Version: 2.3.4 - Apple Inc.)
Assassin's Creed IV Black Flag (HKLM-x32\...\Steam App 242050) (Version:  - Ubisoft Montreal)
Audacity 2.0.5 (HKLM-x32\...\Audacity_is1) (Version: 2.0.5 - Audacity Team)
AVerMedia CV710 USB3 HD Capture (HKLM-x32\...\AVerMedia CV710 USB3 HD Capture) (Version: - AVerMedia TECHNOLOGIES, Inc.)
AVerMedia RECentral (HKLM-x32\...\InstallShield_{30D6B6ED-E039-4D62-8E07-E058D17A9372}) (Version: - AVerMedia Technologies, Inc.)
AVerMedia RECentral (x32 Version: - AVerMedia Technologies, Inc.) Hidden
Avira System Speedup (HKLM-x32\...\Avira System Speedup_is1) (Version: - Avira Operations GmbH & Co. KG)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Blender (HKLM-x32\...\Steam App 365670) (Version:  - Blender Foundation)
Browser Ball (HKU\S-1-5-21-1148309869-985715220-1964481749-1001\...\{9563BC59-9556-4805-8CD4-886781779D8D}) (Version: 1.9.9 - Mart Plugin corp)
Cities: Skylines (HKLM-x32\...\Steam App 255710) (Version:  - Colossal Order Ltd.)
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version:  - Valve)
CPUID CPU-Z 1.72 (HKLM\...\CPUID CPU-Z_is1) (Version:  - )
Curse Client (HKU\S-1-5-21-1148309869-985715220-1964481749-1001\...\101a9f93b8f0bb6f) (Version: - Curse)
DayZ (HKLM-x32\...\Steam App 221100) (Version:  - Bohemia Interactive)
Dota 2 (HKLM-x32\...\Steam App 570) (Version:  - Valve)
Easy Tune 6 B12.1121.1 (HKLM-x32\...\InstallShield_{457D7505-D665-4F95-91C3-ECB8C56E9ACA}) (Version: 1.00.0000 - GIGABYTE)
Easy Tune 6 B12.1121.1 (x32 Version: 1.00.0000 - GIGABYTE) Hidden
Elgato Game Capture HD (HKLM-x32\...\{4DB7DE87-F483-4FEF-8633-C48957AB0567}) (Version: - Elgato Systems GmbH)
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version:  - )
Firebird SQL Server - MAGIX Edition (HKLM-x32\...\{39AB2E37-1A55-4292-A5D3-971E9F70D0F8}) (Version: - MAGIX AG)
Fotosizer 2.09 (HKLM-x32\...\Fotosizer) (Version: - Fotosizer.com)
Fraps (remove only) (HKLM-x32\...\Fraps) (Version:  - )
Game Capture HD60 v2.1.1.3 (HKLM-x32\...\Software_Elgato_Game Capture HD60) (Version: - Elgato Systems)
Game Dev Tycoon (HKLM-x32\...\Steam App 239820) (Version:  - Greenheart Games)
GOG Galaxy (HKLM-x32\...\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version:  - GOG.com)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.134 - Google Inc.)
Google Update Helper (x32 Version: - Google Inc.) Hidden
Google Update Helper (x32 Version: - Google Inc.) Hidden
Grand Theft Auto V (HKLM-x32\...\{E01FA564-2094-4833-8F2F-1FFEC6AFCC46}) (Version: "1.00.0000" - Rockstar Games)
GRID Autosport (HKLM-x32\...\Steam App 255220) (Version:  - Codemasters Racing)
H1Z1 (HKLM-x32\...\Steam App 295110) (Version:  - Daybreak Games)
Hearthstone (HKLM-x32\...\Hearthstone) (Version:  - Blizzard Entertainment)
Heroes & Generals (HKLM-x32\...\Steam App 227940) (Version:  - Reto-Moto)
IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.38 - Irfan Skiljan)
Java 7 Update 67 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217067FF}) (Version: 7.0.670 - Oracle)
Kaspersky Internet Security (HKLM-x32\...\InstallWIX_{02FECEE0-16B2-43DB-BC3B-C844477FC142}) (Version: - Kaspersky Lab)
Kaspersky Internet Security (x32 Version: - Kaspersky Lab) Hidden
Logitech Gaming Software 8.56 (HKLM\...\Logitech Gaming Software) (Version: 8.56.109 - Logitech Inc.)
MAGIX Screenshare (HKLM-x32\...\MAGIX_{4F57E848-AC32-4178-BCF0-7D05A58B8F49}) (Version: - MAGIX AG)
MAGIX Screenshare (x32 Version: - MAGIX AG) Hidden
MAGIX Speed burnR (MSI) (HKLM-x32\...\MAGIX_{E0E6D1E1-32D6-427D-9696-4090DA2C5743}) (Version: - MAGIX AG)
MAGIX Speed burnR (MSI) (Version: - MAGIX AG) Hidden
MAGIX Video deluxe 2013 Premium (HKLM-x32\...\MAGIX_{47E960B1-A285-4D31-87BA-4D2936FC8FF1}) (Version: - MAGIX AG)
MAGIX Video deluxe 2013 Premium (Version: - MAGIX AG) Hidden
MAGIX Web Designer MX Premium (HKLM-x32\...\MAGIX_{739FE2DC-0C7E-4A1C-AC6E-46348169E27E}) (Version: - MAGIX AG)
MAGIX Web Designer MX Premium (Version: - MAGIX AG) Hidden
Malwarebytes Anti-Malware Version (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: - Malwarebytes Corporation)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Middle-earth: Shadow of Mordor (HKLM-x32\...\Steam App 241930) (Version:  - Monolith Productions, Inc.)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.7.5 - Notepad++ Team)
NVIDIA 3D Vision Controller-Treiber 349.95 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 349.95 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 350.12 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 350.12 - NVIDIA Corporation)
NVIDIA GeForce Experience (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: - NVIDIA Corporation)
NVIDIA Grafiktreiber 350.12 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 350.12 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: - NVIDIA Corporation)
NVIDIA Miracast Virtueller Ton 350.12 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Miracast.VirtualAudio) (Version: 350.12 - NVIDIA Corporation)
NVIDIA PhysX (Legacy) (HKLM-x32\...\{FAAC26AD-73BA-40CE-86AA-C9213F9E064A}) (Version: 9.13.0604 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.15.0324 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0324 - NVIDIA Corporation)
Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version:  - )
OpenOffice 4.1.0 (HKLM-x32\...\{E19483E2-6C18-494D-A307-D4498BCFD2C7}) (Version: 4.10.9764 - Apache Software Foundation)
Origin (HKLM-x32\...\Origin) (Version: - Electronic Arts, Inc.)
Project CARS (HKLM-x32\...\Steam App 234630) (Version:  - Slightly Mad Studios)
Protect Disc License Helper 1.0.118 (HKLM-x32\...\Protect Disc License Helper) (Version: 1.0.118 - Protect Disc)
ProtectDisc Driver, Version 11 (HKLM-x32\...\ProtectDisc Driver 11) (Version: - ProtectDisc Software GmbH)
QuickTime (HKLM-x32\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: - Realtek Semiconductor Corp.)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: - Rockstar Games)
Sherlock Holmes: Crimes and Punishments (HKLM-x32\...\Steam App 241260) (Version:  - Frogwares)
SHIELD Streaming (Version: 4.1.2000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: - NVIDIA Corporation) Hidden
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: - Microsoft Corporation)
Skype™ 7.6 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.6.105 - Skype Technologies S.A.)
Steam (HKLM-x32\...\Steam) (Version:  - Valve Corporation)
Stranded Deep (HKLM-x32\...\Steam App 313120) (Version:  - Beam Team Games)
Survarium (HKLM-x32\...\{FEA2E954-A6D0-42FA-8FF1-DFA325758FAC}_is1) (Version: 0.26i - )
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH)
TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH)
The Crew (Worldwide) (HKLM-x32\...\Uplay Install 413) (Version:  - Ubisoft)
The Evil Within (HKLM-x32\...\Steam App 268050) (Version:  - Tango Gameworks)
The Testament of Sherlock Holmes (HKLM-x32\...\Steam App 205650) (Version:  - Frogwares)
The Witcher 3 - Wild Hunt (HKLM-x32\...\1207664643_is1) (Version: - GOG.com)
TransOcean - The Shipping Company (HKLM-x32\...\Steam App 289930) (Version:  - Deck 13 Hamburg)
Tropico 5 (HKU\S-1-5-21-1148309869-985715220-1964481749-1001\...\Tropico5) (Version: 1.03 - Kalypso Media)
Uplay (HKLM-x32\...\Uplay) (Version: 4.9 - Ubisoft)
Watch_Dogs (HKLM-x32\...\Uplay Install 274) (Version:  - Ubisoft)
Web Designer Premium MX Update (Version: - MAGIX AG) Hidden
World of Warcraft (HKLM-x32\...\World of Warcraft) (Version:  - Blizzard Entertainment)
Xfire (HKLM-x32\...\Xfire) (Version:  - )

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== Restore Points =========================

25-07-2015 10:18:25 Geplanter Prüfpunkt

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____N C:\WINDOWS\system32\Drivers\etc\hosts

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {1C91D5A2-3226-49D2-ACD0-F05106ED4930} - System32\Tasks\Browser Ball => Rundll32.exe "C:\Users\Björn\AppData\Local\Browser Ball\Bin\BrowserBall.dll",#3
Task: {4FE724A6-28E5-4593-9753-4928A3AB17F5} - \CreateChoiceProcessTask No Task File <==== ATTENTION
Task: {537B93DC-88E4-4270-8B8D-9E3B73248A90} - \Optimize Start Menu Cache Files-S-1-5-21-1148309869-985715220-1964481749-1009 No Task File <==== ATTENTION
Task: {91955724-2764-47EF-9600-6CD2EA7468C5} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-15] (Google Inc.)
Task: {B74EF10D-6C27-42F7-9463-C6D737601B0F} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-07-03] (Microsoft Corporation)
Task: {C0F3219A-AF0F-4F76-A6E0-8D3405D9394B} - \AviraSpeedup No Task File <==== ATTENTION
Task: {CD0B25DA-18DB-4E3D-B989-0064ED4141FB} - System32\Tasks\FRAPS => C:\Fraps\fraps.exe [2013-02-26] (Beepa P/L)
Task: {D8B72F6C-8605-426C-847F-B61DD5DDE143} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-05-15] (Google Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2015-04-16 21:12 - 2015-04-08 23:30 - 00116552 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2012-01-13 14:04 - 2012-01-13 14:04 - 00219760 _____ () C:\Program Files (x86)\GIGABYTE\ET6\GUI.exe
2014-05-15 19:16 - 2015-06-03 23:06 - 00721552 _____ () C:\Program Files\NVIDIA Corporation\ShadowPlay\gamecaster64.dll
2014-05-15 19:16 - 2015-06-03 23:06 - 00854160 _____ () C:\Program Files\NVIDIA Corporation\ShadowPlay\twitchsdk64.dll
2015-07-24 12:42 - 2015-07-24 12:38 - 02248704 _____ () C:\Users\Björn\Desktop\adwcleaner_4.208 (1).exe
2014-12-23 16:54 - 2014-12-23 16:54 - 01272616 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.2\kpcengine.2.3.dll
2012-11-14 14:44 - 2012-11-14 14:44 - 02875463 _____ () C:\Program Files (x86)\GIGABYTE\ET6\Normal.dll
2012-11-14 10:42 - 2012-11-14 10:42 - 00651331 _____ () C:\Program Files (x86)\GIGABYTE\ET6\work.dll
2012-09-18 14:45 - 2012-09-18 14:45 - 01335362 _____ () C:\Program Files (x86)\GIGABYTE\ET6\HM.dll
2012-11-09 16:51 - 2012-11-09 16:51 - 01429582 _____ () C:\Program Files (x86)\GIGABYTE\ET6\GVTunner.dll
2003-02-14 14:11 - 2003-02-14 14:11 - 00102400 _____ () C:\Program Files (x86)\GIGABYTE\ET6\Sound.dll
2010-06-10 15:52 - 2010-06-10 15:52 - 00110592 _____ () C:\Program Files (x86)\GIGABYTE\ET6\AMD8.dll
2012-09-17 16:25 - 2012-09-17 16:25 - 00106496 _____ () C:\Program Files (x86)\GIGABYTE\ET6\SF.dll
2008-05-07 15:22 - 2008-05-07 15:22 - 00102400 _____ () C:\Program Files (x86)\GIGABYTE\ET6\CIAMIB.dll
2012-05-08 15:01 - 2012-05-08 15:01 - 00069632 _____ () C:\Program Files (x86)\GIGABYTE\ET6\GPTT.dll
2011-10-18 09:26 - 2011-10-18 09:26 - 00024576 _____ () C:\Program Files (x86)\GIGABYTE\ET6\STT.dll
2012-11-14 14:00 - 2012-11-14 14:00 - 01499204 _____ () C:\Program Files (x86)\GIGABYTE\ET6\OCK.dll
2011-09-14 17:12 - 2011-09-14 17:12 - 00102400 _____ () C:\Program Files (x86)\GIGABYTE\ET6\ycc.dll
2010-03-12 05:40 - 2010-03-12 05:40 - 04449632 _____ () C:\Program Files (x86)\GIGABYTE\ET6\Platform.dll
2010-06-24 15:50 - 2010-06-24 15:50 - 00094208 _____ () C:\Program Files (x86)\GIGABYTE\ET6\IccLibDll.dll
2011-03-01 19:00 - 2011-03-01 19:00 - 00126976 _____ () C:\Program Files (x86)\GIGABYTE\ET6\StabilityLib.dll
2010-03-12 05:40 - 2010-03-12 05:40 - 00423256 _____ () C:\Program Files (x86)\GIGABYTE\ET6\Device.dll
2012-11-20 17:38 - 2012-11-20 17:38 - 00311296 _____ () C:\Program Files (x86)\GIGABYTE\ET6\MFCCPU.DLL
2015-07-22 14:44 - 2015-07-22 14:44 - 00044032 _____ () C:\Users\Björn\AppData\Local\Browser Ball\Bin\BrowserBall.dll
2015-07-22 14:44 - 2015-07-22 14:44 - 00011776 _____ () C:\Users\Björn\AppData\Local\Browser Ball\Bin\aqzx.dll
2015-04-14 00:02 - 2015-06-03 23:06 - 00011920 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2015-07-14 17:53 - 2015-07-13 23:55 - 01281864 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.134\libglesv2.dll
2015-07-14 17:53 - 2015-07-13 23:55 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.134\libegl.dll
2015-07-14 17:53 - 2015-07-13 23:55 - 16308040 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.134\PepperFlash\pepflashplayer.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

==================== Safe Mode (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-1148309869-985715220-1964481749-1001\...\clonewarsadventures.com -> clonewarsadventures.com
IE trusted site: HKU\S-1-5-21-1148309869-985715220-1964481749-1001\...\freerealms.com -> freerealms.com
IE trusted site: HKU\S-1-5-21-1148309869-985715220-1964481749-1001\...\soe.com -> soe.com
IE trusted site: HKU\S-1-5-21-1148309869-985715220-1964481749-1001\...\sony.com -> sony.com

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1148309869-985715220-1964481749-1001\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg
DNS Servers:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is disabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

HKLM\...\StartupApproved\Run: => "Launch LCore"
HKLM\...\StartupApproved\Run32: => "QuickTime Task"
HKLM\...\StartupApproved\Run32: => "RzWizard"
HKU\S-1-5-21-1148309869-985715220-1964481749-1001\...\StartupApproved\StartupFolder: => "CurseClientStartup.ccip"
HKU\S-1-5-21-1148309869-985715220-1964481749-1001\...\StartupApproved\Run: => "GalaxyClient"
HKU\S-1-5-21-1148309869-985715220-1964481749-1001\...\StartupApproved\Run: => "Prime95"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{C634FA98-415E-4394-8F5B-C313E5902FDE}] => (Allow) E:\SteamLibrary\SteamApps\common\Cities_Skylines\Cities.exe
FirewallRules: [{DC05A221-8002-45F9-AD0A-C56BFA7D5E72}] => (Allow) E:\SteamLibrary\SteamApps\common\Cities_Skylines\Cities.exe
FirewallRules: [UDP Query User{51DBF8F0-5460-46B7-A246-2A1AC2232A9B}E:\star citizen\starcitizen\citizenclient\bin64\starcitizen.exe] => (Allow) E:\star citizen\starcitizen\citizenclient\bin64\starcitizen.exe
FirewallRules: [TCP Query User{AF9537C3-B81B-49F9-AC11-2046DE9CBAF0}E:\star citizen\starcitizen\citizenclient\bin64\starcitizen.exe] => (Allow) E:\star citizen\starcitizen\citizenclient\bin64\starcitizen.exe
FirewallRules: [UDP Query User{3565B75D-F8FB-4039-87CA-24236BA76D87}E:\ubisoft\covers\kts15.0.1.415de_6973.exe] => (Allow) E:\ubisoft\covers\kts15.0.1.415de_6973.exe
FirewallRules: [TCP Query User{4836BC9C-A5F1-485C-B36A-3BB8BE22B853}E:\ubisoft\covers\kts15.0.1.415de_6973.exe] => (Allow) E:\ubisoft\covers\kts15.0.1.415de_6973.exe
FirewallRules: [{75E97C6D-A6D5-43F2-80C2-1CC6D3611E9C}] => (Allow) E:\SteamLibrary\SteamApps\common\Stranded Deep\Stranded_Deep_x64.exe
FirewallRules: [{8900F624-7B85-445D-B88A-92EA89C2A161}] => (Allow) E:\SteamLibrary\SteamApps\common\Stranded Deep\Stranded_Deep_x64.exe
FirewallRules: [UDP Query User{5B95471E-2BDB-4AD3-96EB-A48B5A8CFBB4}E:\steamlibrary\steamapps\common\h1z1\h1z1.exe] => (Allow) E:\steamlibrary\steamapps\common\h1z1\h1z1.exe
FirewallRules: [TCP Query User{1362C93D-A754-46EF-9CEE-B97E1E179F82}E:\steamlibrary\steamapps\common\h1z1\h1z1.exe] => (Allow) E:\steamlibrary\steamapps\common\h1z1\h1z1.exe
FirewallRules: [{59D8BEFD-35FE-4264-85E1-4AE7C5A36F19}] => (Allow) E:\SteamLibrary\SteamApps\common\H1Z1\LaunchPad.exe
FirewallRules: [{AABF8620-E6EA-4C93-919A-3706180E9FDB}] => (Allow) E:\SteamLibrary\SteamApps\common\H1Z1\LaunchPad.exe
FirewallRules: [{0F3A0E2B-786D-4A95-BB5C-BC2AFBA5B61F}] => (Allow) C:\Program Files (x86)\Survarium\game\binaries\x86\survarium.exe
FirewallRules: [{7A4A45DB-A141-4EC2-9335-DDE04F5ED260}] => (Allow) C:\Program Files (x86)\Survarium\game\binaries\x86\survarium.exe
FirewallRules: [{E9B6FE65-A109-42EC-B8E0-4BF0F33E0651}] => (Allow) C:\Program Files (x86)\Survarium\temp\survarium_updater.exe
FirewallRules: [{6A89A3F9-5B9A-4AFF-8E18-405C5AC304FC}] => (Allow) C:\Program Files (x86)\Survarium\temp\survarium_updater.exe
FirewallRules: [{A3570C8A-DBAE-403E-A3B3-2238421E9CBB}] => (Allow) C:\Program Files (x86)\Survarium\temp\survarium_updater.exe
FirewallRules: [{5046B1B3-355D-4498-BA74-260C05583038}] => (Allow) C:\Program Files (x86)\Survarium\temp\survarium_updater.exe
FirewallRules: [{FD8965DC-0504-4675-8274-13FA4D5CD72E}] => (Allow) C:\Program Files (x86)\Survarium\temp\survarium_launcher.exe
FirewallRules: [UDP Query User{0531F996-E2D6-4DB0-9AB2-E9C12F000810}E:\neuer ordner (2)\the crew (worldwide)\thecrew.exe] => (Allow) E:\neuer ordner (2)\the crew (worldwide)\thecrew.exe
FirewallRules: [TCP Query User{C970D811-E8A8-4267-BA2F-19716E2E21B0}E:\neuer ordner (2)\the crew (worldwide)\thecrew.exe] => (Allow) E:\neuer ordner (2)\the crew (worldwide)\thecrew.exe
FirewallRules: [{62023226-7A4D-43E0-ADB5-F964E2CC276A}] => (Allow) E:\SteamLibrary\SteamApps\common\DayZ\DayZ_BE.exe
FirewallRules: [{F391950B-1C59-4A6C-A366-ACE98AC39EB0}] => (Allow) E:\SteamLibrary\SteamApps\common\DayZ\DayZ_BE.exe
FirewallRules: [{85409A1C-4180-4EB7-AEC6-443E764E85C8}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{9C26B8FF-3A22-402B-A7B9-DF95D7296522}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{3B63A81A-5459-442C-BBE6-CF8C126E4E94}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{3C023A12-E88B-414F-B999-0ABE0D171A18}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{8A013D74-0C9F-4E23-A746-073F217F25BE}] => (Allow) E:\Neuer Ordner (2)\The Crew (Worldwide)\TheCrew.exe
FirewallRules: [{6FF5AC74-4050-4D09-BF64-5A6069C89C91}] => (Allow) E:\Neuer Ordner (2)\The Crew (Worldwide)\TheCrew.exe
FirewallRules: [{5ADA4C03-D671-4B15-93D3-B2583E1FED71}] => (Allow) E:\SteamLibrary\SteamApps\common\GRID Autosport\GRIDAutosport.exe
FirewallRules: [{1D07CA7D-701D-4C59-A089-EA25BF9F602C}] => (Allow) E:\SteamLibrary\SteamApps\common\GRID Autosport\GRIDAutosport.exe
FirewallRules: [{1371CF66-9F29-4035-A2FB-5ADC02F1B61C}] => (Allow) E:\SteamLibrary\SteamApps\common\Assassin's Creed IV Black Flag\AC4BFSP.exe
FirewallRules: [{601474DB-6ECC-47AC-A54C-2EE7F8D17260}] => (Allow) E:\SteamLibrary\SteamApps\common\Assassin's Creed IV Black Flag\AC4BFSP.exe
FirewallRules: [{443A9BD8-55E9-448A-A05C-70FFB5596952}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\ShadowOfMordor\x64\ShadowOfMordor.exe
FirewallRules: [{F5ECD17F-B9AB-420F-A94A-3D7AF937FF26}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\ShadowOfMordor\x64\ShadowOfMordor.exe
FirewallRules: [{43F35C7A-9E3A-4E05-A69E-E93ED2AA5A9E}] => (Allow) E:\SteamLibrary\SteamApps\common\TheEvilWithin\EvilWithin.exe
FirewallRules: [{9264ECCD-EFB3-4154-80B1-245013D1D3A3}] => (Allow) E:\SteamLibrary\SteamApps\common\TheEvilWithin\EvilWithin.exe
FirewallRules: [{3DD64E31-7FE5-430D-985F-97398828B1DC}] => (Allow) C:\Program Files\Logitech Gaming Software\LCore.exe
FirewallRules: [{56B13B13-4498-41A4-B292-6D5254D47A8D}] => (Allow) C:\Program Files\Logitech Gaming Software\LCore.exe
FirewallRules: [{8200E340-0DAF-4151-B70E-209C64A33010}] => (Allow) E:\SteamLibrary\SteamApps\common\Sherlock Holmes - Crimes and Punishments\Binaries\Win32\Sherlock.exe
FirewallRules: [{495236BD-7C60-41B3-A05F-8EA60185ECB3}] => (Allow) E:\SteamLibrary\SteamApps\common\Sherlock Holmes - Crimes and Punishments\Binaries\Win32\Sherlock.exe
FirewallRules: [{D30FDB9B-E423-4F5E-A9B9-32BDC314FBD2}] => (Allow) E:\SteamLibrary\SteamApps\common\The Testament of Sherlock Holmes\game.exe
FirewallRules: [{16CF442A-948E-4BB8-9C1F-6C44A0C3AC39}] => (Allow) E:\SteamLibrary\SteamApps\common\The Testament of Sherlock Holmes\game.exe
FirewallRules: [{1F1FAB56-EDE5-4B05-AE38-621B30C6B513}] => (Allow) E:\SteamLibrary\SteamApps\common\TransOcean - The Shipping Company\TransOcean.exe
FirewallRules: [{3A9A5BCE-EEF9-461F-AA14-A00BAE35DE69}] => (Allow) E:\SteamLibrary\SteamApps\common\TransOcean - The Shipping Company\TransOcean.exe
FirewallRules: [{C7B264F6-44D7-4B8B-A7FC-B0A3E2664C54}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Game Dev Tycoon\nw.exe
FirewallRules: [{675A432E-94A3-4052-A768-15DDAC051FEF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Game Dev Tycoon\nw.exe
FirewallRules: [UDP Query User{A19AAF9F-94D2-4BE8-AFAE-61ADDE08DDAD}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [TCP Query User{352D1493-67C4-46C7-A784-71DC8739D82E}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{B7F7442C-396C-4FDB-A1CF-10C65156F14D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Game Dev Tycoon\GameDevTycoon.exe
FirewallRules: [{82BE26F3-6664-4F64-8D0C-8B09E9F6A238}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Game Dev Tycoon\GameDevTycoon.exe
FirewallRules: [{4638EF31-94A6-448D-9044-87E1DF7A0477}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{838C51FC-A1F0-4455-A70A-1640DABF6668}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [UDP Query User{14DA0747-EF25-4B9F-9CD4-7A6A31CE293B}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [TCP Query User{0A11A351-7C64-4518-AD64-E18CC7D374C8}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{8EC30B74-BB8F-4F87-AA2B-C09F1B6AC43C}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [TCP Query User{3FA55BAC-37D0-472B-8CCB-E7F04A74930B}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [{ACC584B6-BFD6-4542-BC7E-4623F5871434}] => (Allow) c:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
FirewallRules: [{55A29B8E-AE1D-4C40-ABFE-C116BF6289F3}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{A0F6DF68-4537-4A92-B53A-5E9E36C6D34C}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{20AF583E-EAC6-4D4A-A15D-877A01D9FBCD}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{C723C60A-9FA8-4B3D-B188-78663362D8D1}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{91FCE117-76D1-4C7A-838B-DC4B4EF90614}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{1436DEBD-3C74-46D5-A450-C538928442A0}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{C6E56012-B369-4A34-AC96-CA542ECFC9BE}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{0969452A-B026-4A17-85FB-B343BE8AE9BE}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{36C4185A-5072-45B2-ADCF-2707551B8F9E}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{EF5D73E1-F577-4D70-BA71-94D8C00B8C17}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{A829363B-451E-465A-A9DC-82FB2F0D5CD1}] => (Allow) D:\install\data\Disk1\setup.exe
FirewallRules: [{DA8B225C-E427-4236-BEDD-C08B3117C199}] => (Allow) D:\install\data\Disk1\setup.exe
FirewallRules: [{15FEE9CA-9BD9-4F2E-A186-4E1AD0DE9E8F}] => (Allow) E:\SteamLibrary\SteamApps\common\pCars\pCARS64.exe
FirewallRules: [{F4EB3D86-12BA-4E9D-AAFD-F911A1BC5ED8}] => (Allow) E:\SteamLibrary\SteamApps\common\pCars\pCARS64.exe
FirewallRules: [{C397D038-1EFC-4815-8EA1-A3BB324DC5DD}] => (Allow) E:\SteamLibrary\SteamApps\common\Blender\blender.exe
FirewallRules: [{13AD3265-D979-4156-8A83-27A75ABC9080}] => (Allow) E:\SteamLibrary\SteamApps\common\Blender\blender.exe
FirewallRules: [{70726F25-BE06-4C01-BAA1-ECC62CFDD63E}] => (Allow) C:\Program Files (x86)\pandasecuritytb\ToolbarCleaner.exe
FirewallRules: [{2AF8F1A0-8A7C-4E88-B128-9D1E766CCC6E}] => (Allow) C:\Program Files (x86)\pandasecuritytb\ToolbarCleaner.exe
FirewallRules: [{50870703-9C28-4683-8E90-9C8B9F2EAF5B}] => (Allow) E:\SteamLibrary\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{592F79BD-D034-45A0-92FD-02C6B23AB2B8}] => (Allow) E:\SteamLibrary\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{671FB83C-362A-45AD-B662-29F0372F0424}] => (Allow) E:\SteamLibrary\SteamApps\COMMON\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{E57CF021-8DE3-4FCC-AC10-2B4DF1F93CA9}] => (Allow) E:\SteamLibrary\SteamApps\COMMON\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{BB612141-28AA-47D8-97DE-A7E5BAD22C2F}] => (Allow) E:\SteamLibrary\SteamApps\COMMON\Heroes & Generals\hngsteamlauncher.exe
FirewallRules: [{0640D47F-B539-4541-B48F-4F23B2FDBD51}] => (Allow) E:\SteamLibrary\SteamApps\COMMON\Heroes & Generals\hngsteamlauncher.exe
FirewallRules: [{BE4FA766-0456-4C46-AA57-DD8D5DB9C284}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\ShadowOfMordor\x64\ShadowOfMordor.exe
FirewallRules: [{56584DB2-21AF-4D2D-9C49-5FC49394262E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\ShadowOfMordor\x64\ShadowOfMordor.exe
FirewallRules: [{45900130-5AE7-4B3E-8D12-3B1FED894740}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Faulty Device Manager Devices =============

==================== Event log errors: =========================

Application errors:
Error: (07/25/2015 11:11:32 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm IEXPLORE.EXE, Version 11.0.9600.17840 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: dc8

Startzeit: 01d0c6b7c631001a

Endzeit: 46

Anwendungspfad: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Berichts-ID: 21f11d15-32ad-11e5-8357-1c6f65d547e1

Vollständiger Name des fehlerhaften Pakets: 

Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (07/25/2015 10:02:35 AM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: )
Description: Das Volume "System-reserviert" wurde aufgrund eines Fehlers nicht optimiert: Falscher Parameter. (0x80070057)

Error: (07/25/2015 09:57:57 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT-AUTORITÄT)
Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich.

Error: (07/25/2015 09:57:57 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT)
Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich.

Error: (07/25/2015 09:57:57 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT)
Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich.

Error: (07/25/2015 09:53:11 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm IEXPLORE.EXE, Version 11.0.9600.17840 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1508

Startzeit: 01d0c6aedd834c18

Endzeit: 31

Anwendungspfad: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Berichts-ID: 2fd5d911-32a2-11e5-8357-1c6f65d547e1

Vollständiger Name des fehlerhaften Pakets: 

Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (07/25/2015 09:52:26 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm iexplore.exe, Version 11.0.9600.17840 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 161c

Startzeit: 01d0c6aeb60a7f72

Endzeit: 0

Anwendungspfad: C:\Program Files\Internet Explorer\iexplore.exe

Berichts-ID: 151ae3cc-32a2-11e5-8357-1c6f65d547e1

Vollständiger Name des fehlerhaften Pakets: 

Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (07/24/2015 07:12:11 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT-AUTORITÄT)
Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich.

Error: (07/24/2015 07:12:11 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT)
Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich.

Error: (07/24/2015 07:12:11 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT)
Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich.

System errors:
Error: (07/25/2015 10:57:03 AM) (Source: Schannel) (EventID: 4119) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung vom Remoteendpunkt empfangen. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 40.

Error: (07/25/2015 10:57:03 AM) (Source: Schannel) (EventID: 4119) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung vom Remoteendpunkt empfangen. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 40.

Error: (07/25/2015 10:03:33 AM) (Source: DCOM) (EventID: 10010) (User: Gamingmeile)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}

Error: (07/25/2015 10:03:03 AM) (Source: DCOM) (EventID: 10010) (User: Gamingmeile)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}

Error: (07/25/2015 02:45:03 AM) (Source: Service Control Manager) (EventID: 7043) (User: )
Description: Der Dienst AVerRECentral konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden.

Error: (07/24/2015 09:49:24 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Steam Client Service" wurde aufgrund folgenden Fehlers nicht gestartet: 

Error: (07/24/2015 09:49:24 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Steam Client Service erreicht.

Error: (07/24/2015 09:37:39 PM) (Source: Schannel) (EventID: 4119) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung vom Remoteendpunkt empfangen. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 20.

Error: (07/24/2015 07:04:30 PM) (Source: Service Control Manager) (EventID: 7043) (User: )
Description: Der Dienst AVerRECentral konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden.

Error: (07/24/2015 07:04:08 PM) (Source: DCOM) (EventID: 10010) (User: Gamingmeile)
Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39}

Microsoft Office:
Error: (07/25/2015 11:11:32 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IEXPLORE.EXE11.0.9600.17840dc801d0c6b7c631001a46C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE21f11d15-32ad-11e5-8357-1c6f65d547e1

Error: (07/25/2015 10:02:35 AM) (Source: Microsoft-Windows-Defrag) (EventID: 257) (User: )
Description: System-reserviertFalscher Parameter. (0x80070057)

Error: (07/25/2015 09:57:57 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT-AUTORITÄT)
Description: WmiApRplWmiApRpl8F2030000E5050000

Error: (07/25/2015 09:57:57 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT)
Description: Performance163707000000000000000000008F020000

Error: (07/25/2015 09:57:57 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT)
Description: Performance163707000000000000000000008F020000

Error: (07/25/2015 09:53:11 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IEXPLORE.EXE11.0.9600.17840150801d0c6aedd834c1831C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE2fd5d911-32a2-11e5-8357-1c6f65d547e1

Error: (07/25/2015 09:52:26 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: iexplore.exe11.0.9600.17840161c01d0c6aeb60a7f720C:\Program Files\Internet Explorer\iexplore.exe151ae3cc-32a2-11e5-8357-1c6f65d547e1

Error: (07/24/2015 07:12:11 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT-AUTORITÄT)
Description: WmiApRplWmiApRpl8F2030000E5050000

Error: (07/24/2015 07:12:11 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT)
Description: Performance163707000000000000000000008F020000

Error: (07/24/2015 07:12:11 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT)
Description: Performance163707000000000000000000008F020000

CodeIntegrity Errors:
  Date: 2015-05-07 00:15:35.867
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-05-07 00:15:35.694
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-05-07 00:15:35.524
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-05-07 00:15:32.463
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-05-07 00:15:23.728
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-05-07 00:14:46.252
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-05-07 00:14:46.132
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-05-07 00:14:46.020
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-05-07 00:14:38.864
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-05-07 00:14:38.729
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

==================== Memory info =========================== 

Processor: Intel(R) Core(TM) i5-2500K CPU @ 3.30GHz
Percentage of memory in use: 15%
Total physical RAM: 16367.43 MB
Available physical RAM: 13807.97 MB
Total Virtual: 18799.43 MB
Available Virtual: 15335.58 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:111.45 GB) (Free:3.66 GB) NTFS
Drive d: (the_witcher3_wild_hunt_disc4) (CDROM) (Total:5.43 GB) (Free:0 GB) UDF
Drive e: (INTENSO) (Fixed) (Total:2794.25 GB) (Free:2100.33 GB) FAT32

==================== MBR & Partition Table ==================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 111.8 GB) (Disk ID: 68F7D3F8)
Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=111.4 GB) - (Type=07 NTFS)
Attempted reading MBR returned 0 bytes.
 Could not read MBR for disk 1.

==================== End of log ============================
--- --- ---

ich seh es schon das neu mache alles ^^

Auch viele Error Dateien frag mich echt wo mein Kumpel rumgesuft ist habe sowas noch nie gehabt ^^

Alt 25.07.2015, 17:16   #4
/// the machine
/// TB-Ausbilder

Google Chrome  öffnet laufend neue  Fenster - Standard

Google Chrome öffnet laufend neue Fenster

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Task: {4FE724A6-28E5-4593-9753-4928A3AB17F5} - \CreateChoiceProcessTask No Task File <==== ATTENTION

Task: {537B93DC-88E4-4270-8B8D-9E3B73248A90} - \Optimize Start Menu Cache Files-S-1-5-21-1148309869-985715220-1964481749-1009 No Task File <==== ATTENTION

Task: {C0F3219A-AF0F-4F76-A6E0-8D3405D9394B} - \AviraSpeedup No Task File <==== ATTENTION
CHR HKLM\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
CHR HKLM-x32\...\Chrome\Extension: [fdhbkaahephniejapepaiggngjnedpci] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.

Revo Uninstaller - Download - Filepony
damit Chrome deinstallieren, keine Daten behalten, Reste entfernen lassen, neu installieren.


Proud Member of UNITE and ASAP since 2009

Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!


