![]() |
|
Plagegeister aller Art und deren Bekämpfung: Ich verschicke SpamWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 |
![]() ![]() | ![]() Ich verschicke Spam Hi zusammen, Wie der Titel schon sagt, werden Spam Mails mit meinem Namen im Absender verschickt. Ca. einmal pro Woche kriege ich etwa 50 Meldungen, dass E-Mails nicht zugestellt werden konnten so wie persönliche Rückmeldungen, dass Spam Mails angekommen sind. Diese sehen dann so aus: Fw: new message Hey! Open message hxxp://flooring-tile.co.uk/took.php benjay@freakmail.de Ich nutze drei Mailaccounts. Bzw. nutzte. Der erste, bei dem es aufgetreten ist, ist mittlerweile deaktiviert (freenet/freakmail). Seit gestern ist aber anscheinend auch mein gmail Account kompromittiert. Kann mir da bitte jemand helfen? Grüße Addition Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version:31-12-2015 Ran by benjay (2015-12-31 13:20:12) Running from C:\Users\benjay\Desktop Windows 7 Professional Service Pack 1 (X64) (2011-11-02 23:20:18) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-1780921663-2346165912-1911888604-500 - Administrator - Disabled) benjay (S-1-5-21-1780921663-2346165912-1911888604-1000 - Administrator - Enabled) => C:\Users\benjay Guest (S-1-5-21-1780921663-2346165912-1911888604-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1780921663-2346165912-1911888604-1003 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Antivirus (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A} AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7} AS: Avira Antivirus (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - ) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated) Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.4.980 - Adobe Systems Incorporated.) Adobe Download Assistant (HKLM-x32\...\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.0.6 - Adobe Systems Incorporated) Adobe Flash Player 20 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 20.0.0.267 - Adobe Systems Incorporated) Adobe Flash Player 20 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 20.0.0.267 - Adobe Systems Incorporated) Adobe Photoshop CS2 (HKLM-x32\...\Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}) (Version: 9.0 - Adobe Systems, Inc.) Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.9.149 - Adobe Systems, Inc.) Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.15.129 - Avira Operations GmbH & Co. KG) Avira Launcher (HKLM-x32\...\{d0e166af-1634-4c0b-ae96-2180e61f9d38}) (Version: 1.1.52.15531 - Avira Operations GmbH & Co. KG) Avira Launcher (x32 Version: 1.1.52.15531 - Avira Operations GmbH & Co. KG) Hidden Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) BioShock (HKLM-x32\...\{E280923D-C5D9-4728-8C79-AC9A0DC75875}) (Version: 2.5.0000 - 2K Games) BioShock 2 (x32 Version: 1.0.0005.131 - Take-Two Interactive Software) Hidden DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.45.1.0236 - DT Soft Ltd) Diablo III (HKLM-x32\...\Diablo III) (Version: - Blizzard Entertainment) DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.44 - DivX, LLC) Dolphin (HKLM-x32\...\Dolphin) (Version: 4.0.2 - Dolphin Development Team) Dropbox (HKU\S-1-5-21-1780921663-2346165912-1911888604-1000\...\Dropbox) (Version: 2.0.22 - Dropbox, Inc.) Dropbox (HKU\S-1-5-21-1780921663-2346165912-1911888604-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Dropbox) (Version: 2.0.22 - Dropbox, Inc.) Fallout 4 (HKLM-x32\...\Steam App 377160) (Version: - Bethesda Game Studios) Foxit Cloud (HKLM-x32\...\{41914D8B-9D6E-4764-A1F9-BC43FB6782C1}_is1) (Version: 3.7.143.923 - Foxit Software Inc.) Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 7.1.5.425 - Foxit Software Inc.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 47.0.2526.106 - Google Inc.) Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden Guitar Pro 5.2 (HKLM-x32\...\Guitar Pro 5_is1) (Version: - Arobas Music) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.1.50.1172 - Intel Corporation) Java 7 Update 65 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.650 - Oracle) Live Update 5 (HKLM-x32\...\{36F6E986-D2D1-403C-8BD3-D95EF7BC705D}}_is1) (Version: 5.0.109 - MSI) Logitech Webcam Software Driver Package (HKLM\...\lvdrivers_12.10) (Version: 12.10.1110 - Logitech Inc.) Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes) Media Player Classic - Home Cinema v1.5.2.3456 x64 (HKLM\...\{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1) (Version: 1.5.2.3456 - MPC-HC Team) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{F2508213-9989-4E85-A078-72BE483917EF}) (Version: 3.5.88.0 - Microsoft Corporation) Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Report Viewer Redistributable 2005 (HKLM-x32\...\Microsoft Report Viewer Redistributable 2005) (Version: - Microsoft Corporation) Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.8.204.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41105.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Mozilla Firefox 42.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 42.0 (x86 de)) (Version: 42.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 24.0 - Mozilla) Mozilla Thunderbird 38.5.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 38.5.0 (x86 de)) (Version: 38.5.0 - Mozilla) NVIDIA 3D Vision Controller Driver 347.09 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 347.09 - NVIDIA Corporation) NVIDIA 3D Vision Driver 347.88 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 347.88 - NVIDIA Corporation) NVIDIA GeForce Experience 2.4.5.28 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.4.5.28 - NVIDIA Corporation) NVIDIA Graphics Driver 347.88 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 347.88 - NVIDIA Corporation) NVIDIA HD Audio Driver 1.3.33.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.33.0 - NVIDIA Corporation) NVIDIA PhysX System Software 9.14.0702 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation) Oblivion - Knights of the Nine (HKLM-x32\...\{14C87AA7-08E6-419F-A165-998EBE5023D7}) (Version: 1.00.0000 - Bethesda Softworks) Oblivion - Mehrunes Razor (HKLM-x32\...\{EF295F5C-7B57-47AA-8889-6B3E8E214E89}) (Version: 1.00.0000 - Bethesda Softworks) Oblivion - Vile Lair (HKLM-x32\...\{520F4B09-3A51-47A2-82B0-9FF1DC2D20FA}) (Version: 1.00.0000 - Bethesda Softworks) Oblivion - Wizard's Tower (HKLM-x32\...\{2F2E3D62-8B8C-448F-8900-451325E50948}) (Version: 1.00.0000 - Bethesda Softworks) OpenAL (HKLM-x32\...\OpenAL) (Version: - ) PDF24 Creator 7.4.1 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.37.1229.2010 - Realtek) Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.34.0 - Renesas Electronics Corporation) Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.34.0 - Renesas Electronics Corporation) Hidden ScummVM 1.7.0 (HKLM-x32\...\ScummVM_is1) (Version: - The ScummVM Team) SHIELD Streaming (Version: 4.1.2000 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 2.4.5.28 - NVIDIA Corporation) Hidden Skype™ 6.21 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.21.104 - Skype Technologies S.A.) Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden TeamSpeak 3 Client (HKU\S-1-5-21-1780921663-2346165912-1911888604-1000\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH) TeamSpeak 3 Client (HKU\S-1-5-21-1780921663-2346165912-1911888604-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH) TL-WN822N/TL-WN821N Driver (HKLM-x32\...\{62FE0726-9652-4CD2-9F09-C769D8699C21}) (Version: 1.0.0 - TP-LINK) Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT) UNi Xonar Audio Driver (HKLM\...\C-Media Oxygen HD Audio Driver) (Version: - ) Unity Web Player (HKU\S-1-5-21-1780921663-2346165912-1911888604-1000\...\UnityWebPlayer) (Version: - Unity Technologies ApS) Unity Web Player (HKU\S-1-5-21-1780921663-2346165912-1911888604-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\UnityWebPlayer) (Version: - Unity Technologies ApS) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden VLC media player 1.1.11 (HKLM-x32\...\VLC media player) (Version: 1.1.11 - VideoLAN) Winamp (HKLM-x32\...\Winamp) (Version: 5.62 - Nullsoft, Inc) Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-1780921663-2346165912-1911888604-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\benjay\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1780921663-2346165912-1911888604-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\benjay\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1780921663-2346165912-1911888604-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\benjay\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1780921663-2346165912-1911888604-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\benjay\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-1780921663-2346165912-1911888604-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\benjay\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll (Dropbox, Inc.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {12A21D38-E243-472B-AAAA-3D54F9FBBDB2} - System32\Tasks\{4DC7E083-C052-4F68-BE68-C0013673421C} => K:\INSTALL.EXE Task: {12CF6B43-1715-4AD4-8844-D99D053BDA4D} - System32\Tasks\AdobeAAMUpdater-1.0-benjay-PC-benjay => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2011-03-15] (Adobe Systems Incorporated) Task: {2061113B-6101-49F1-ABE2-1CEA0E410B3E} - System32\Tasks\{BC482785-3E2F-40AC-AE4F-E1E7E50637BE} => J:\install.exe Task: {2A569622-B446-4CD3-BA2D-62278738BB0B} - System32\Tasks\{5A684C7D-9519-4705-9E1B-FB11053117DA} => C:\Program Files (x86)\Atari\Desperados 2\Desperados2.exe Task: {352485ED-ED40-4E44-AAF0-DBE87CE6C833} - System32\Tasks\{FFA36975-C895-4B07-A20F-D60C14C1A3BE} => K:\INSTALL.EXE Task: {39BA6308-1331-4544-8C6B-A8544F2BA9CE} - System32\Tasks\{23BC10D8-8D1F-424E-97BC-F07142F25C5D} => J:\install.exe Task: {3AEDCEF3-24CF-466C-B436-163BB6C95447} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-06-21] (Google Inc.) Task: {3B7DEA0C-ABF1-4508-A9BF-0023A8E8D300} - System32\Tasks\{AA4FE6BD-B397-4668-93EB-D03E71BEFBE7} => J:\install.exe Task: {4080960D-B993-4F5F-807C-3EEDB0105985} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-12-29] (Adobe Systems Incorporated) Task: {5A40E926-9E86-4B89-9CFD-B12311724371} - System32\Tasks\Microsoft\Windows\UPnP\UPnPHostConfig => config upnphost start= auto Task: {62AD0709-1C33-4F4C-AB53-0E6938FC4BF9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-06-21] (Google Inc.) Task: {AD9FA85A-80BE-446A-9F5B-9B0CD2319E91} - System32\Tasks\{A8C03F36-13A2-4E4D-A512-9049A27573F6} => K:\INSTALL.EXE Task: {BA7B668C-54F5-4D08-ADC1-828418329C1B} - System32\Tasks\{E99F55D7-FAE6-4D3D-A89C-0303810AEFB9} => K:\INSTALL.EXE Task: {C434A2B8-A478-4876-9FCA-A7E2894D5CD2} - System32\Tasks\{FDCAB79B-0C3E-4704-A7A1-B6993F219C05} => J:\install.exe Task: {CC562DC9-AE0C-4B9F-8B34-7756FC87EF84} - System32\Tasks\{1590464B-1892-4A4D-9F97-B5EF5826FE1A} => pcalua.exe -a K:\German\setup.exe -d K:\German Task: {DD9F510C-95F4-499A-90C8-BAC5BC372FF4} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask => start sppsvc Task: {DDBAD45E-4BAB-43D8-80E5-F41B86E6AD12} - System32\Tasks\{4105F22C-5814-41DE-9DA1-A44D7F7FAE34} => K:\INSTALL.EXE Task: {FD6CCED3-2124-480C-B09F-78613D428D81} - System32\Tasks\{3A9ED561-51AE-4442-85B8-84CD49F4E3C0} => J:\install.exe (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2015-01-26 22:30 - 2015-03-13 17:16 - 00118472 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2015-06-08 22:29 - 2008-07-11 14:04 - 00200704 ____N () C:\Windows\SysWOW64\HsMgr.exe 2015-06-08 22:29 - 2008-07-11 14:03 - 00282112 ____N () C:\Windows\system\HsMgr64.exe 2015-12-16 23:05 - 2015-12-11 13:34 - 01971528 _____ () C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.106\libglesv2.dll 2015-12-16 23:05 - 2015-12-11 13:34 - 00093512 _____ () C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.106\libegl.dll 2015-11-10 11:12 - 2015-11-10 11:41 - 00348160 _____ () C:\Program Files (x86)\Steam\steamapps\common\Fallout 4\GFSDK_GodraysLib.x64.dll 2015-05-27 23:26 - 2015-05-23 02:48 - 00011920 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2015-06-08 22:29 - 2012-06-06 08:56 - 00143360 ____N () C:\Program Files\UNi Xonar Audio\Customapp\VmixP8.dll 2015-12-08 11:35 - 2015-11-18 13:04 - 00074272 _____ () C:\Program Files (x86)\PDF24\zlib.dll 2015-12-08 11:35 - 2015-11-18 13:04 - 00052256 _____ () C:\Program Files (x86)\PDF24\OperationUI.dll 2015-03-09 21:37 - 2015-11-10 20:55 - 00778752 _____ () C:\Program Files (x86)\Steam\SDL2.dll 2014-12-01 15:29 - 2015-07-03 17:12 - 04962816 _____ () C:\Program Files (x86)\Steam\v8.dll 2014-12-01 15:29 - 2015-07-03 17:12 - 01556992 _____ () C:\Program Files (x86)\Steam\icui18n.dll 2014-12-01 15:29 - 2015-07-03 17:12 - 01187840 _____ () C:\Program Files (x86)\Steam\icuuc.dll 2015-03-23 19:22 - 2015-12-14 21:01 - 02547280 _____ () C:\Program Files (x86)\Steam\video.dll 2014-12-01 12:31 - 2015-09-24 01:33 - 02549248 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll 2014-12-01 12:31 - 2015-09-24 01:33 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll 2014-12-01 12:31 - 2015-09-24 01:33 - 00491008 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll 2014-12-01 12:31 - 2015-09-24 01:33 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll 2014-12-01 12:31 - 2015-09-24 01:33 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll 2015-03-23 19:22 - 2015-12-14 21:01 - 00804432 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL 2015-11-13 19:36 - 2015-11-03 23:00 - 00201728 _____ () C:\Program Files (x86)\Steam\bin\openvr_api.dll 2015-02-24 16:58 - 2015-11-17 01:31 - 47846176 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll 2015-12-31 13:05 - 2015-12-31 13:05 - 00153768 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll 2015-12-31 13:05 - 2015-12-31 13:05 - 00023208 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\ProgramData\TEMP:8CE646EE ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2013-10-20 17:45 - 00000027 ___RA C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1780921663-2346165912-1911888604-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\benjay\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg HKU\S-1-5-21-1780921663-2346165912-1911888604-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\benjay\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.178.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^Users^benjay^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Gamma.lnk => C:\Windows\pss\Adobe Gamma.lnk.Startup MSCONFIG\startupfolder: C:^Users^benjay^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun MSCONFIG\startupreg: DivXUpdate => "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW MSCONFIG\startupreg: EvolveClient => "C:\Program Files\Echobit\Evolve\EvolveClient.exe" -autorun MSCONFIG\startupreg: Live Update 5 => C:\Program Files (x86)\MSI\Live Update 5\BootStartLiveupdate.exe /reminder MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\Steam.exe" -silent ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [TCP Query User{0F6DFCC7-4D47-4924-B569-5C5755C48973}C:\program files (x86)\internet explorer\iexplore.exe] => (Block) C:\program files (x86)\internet explorer\iexplore.exe FirewallRules: [UDP Query User{C295E058-2FA5-4B68-B678-B16B8BB29D1F}C:\program files (x86)\internet explorer\iexplore.exe] => (Block) C:\program files (x86)\internet explorer\iexplore.exe FirewallRules: [TCP Query User{1A5CD637-824E-4DAA-8FF9-FFC9AD8826BA}C:\program files (x86)\orbitdownloader\orbitnet.exe] => (Allow) C:\program files (x86)\orbitdownloader\orbitnet.exe FirewallRules: [UDP Query User{809A0247-19A7-4B5A-BE62-900769916E8D}C:\program files (x86)\orbitdownloader\orbitnet.exe] => (Allow) C:\program files (x86)\orbitdownloader\orbitnet.exe FirewallRules: [{39F87BDE-E5BB-47EA-A5C3-2CB3E387721F}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{BB5F0DD7-35EF-441F-982C-56FD6A010B83}] => (Allow) C:\Users\benjay\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [{1238E446-DAD4-45FF-A2E0-9D676E7788CE}] => (Allow) C:\Users\benjay\AppData\Roaming\Dropbox\bin\Dropbox.exe FirewallRules: [TCP Query User{1FBE5297-64A6-4534-AA37-EB5B0C54038C}C:\program files (x86)\winamp\winamp.exe] => (Allow) C:\program files (x86)\winamp\winamp.exe FirewallRules: [UDP Query User{9B9C20B5-40F5-4A1C-997B-2035E72156A5}C:\program files (x86)\winamp\winamp.exe] => (Allow) C:\program files (x86)\winamp\winamp.exe FirewallRules: [{01A0A08D-C688-406A-A0C3-59D069B7172F}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe FirewallRules: [{D0B543E3-5689-4079-B35C-05DB03942B43}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe FirewallRules: [{6C182283-B207-4B36-A722-58F64512C243}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.515\Agent.exe FirewallRules: [{3B9D77E6-DC50-4777-8829-3B978F3AABAA}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.515\Agent.exe FirewallRules: [{C0608C4A-07E6-4384-9553-78C9A244D0A6}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.649\Agent.exe FirewallRules: [{8456CCC6-30AF-4E97-88EA-7D8E57F0C563}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.649\Agent.exe FirewallRules: [{66B8F3C1-E30B-4B64-9AB9-EDB29BFF6078}] => (Allow) C:\Program Files (x86)\Diablo III Beta\Diablo III.exe FirewallRules: [{E9DF8FEF-C65E-42AA-BE51-39786C617FB6}] => (Allow) C:\Program Files (x86)\Diablo III Beta\Diablo III.exe FirewallRules: [TCP Query User{6AF58584-35A9-4C58-B40A-DABC2154EEF6}C:\programdata\battle.net\agent\agent.749\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.749\agent.exe FirewallRules: [UDP Query User{CD55E8A7-8561-4AB2-A3BA-7FFFDC2854C6}C:\programdata\battle.net\agent\agent.749\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.749\agent.exe FirewallRules: [TCP Query User{E71EDC47-AE54-47AA-8311-204B3F25EF4E}C:\programdata\battle.net\agent\agent.954\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.954\agent.exe FirewallRules: [UDP Query User{F9996362-C16A-4FD9-A405-BCF88D3BF7CD}C:\programdata\battle.net\agent\agent.954\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.954\agent.exe FirewallRules: [TCP Query User{80B1205D-75D4-4EBF-B7E2-59707ACB7B0F}C:\program files (x86)\diablo iii\diablo iii.exe] => (Allow) C:\program files (x86)\diablo iii\diablo iii.exe FirewallRules: [UDP Query User{AFE46DA5-5B41-4CB8-9A47-9AAE330D54E7}C:\program files (x86)\diablo iii\diablo iii.exe] => (Allow) C:\program files (x86)\diablo iii\diablo iii.exe FirewallRules: [TCP Query User{D0FC0044-A78A-4293-8AB4-EA58B6EB8F94}C:\programdata\battle.net\agent\agent.976\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.976\agent.exe FirewallRules: [UDP Query User{5ACE821D-1517-4FFF-92D8-AF1377A98D81}C:\programdata\battle.net\agent\agent.976\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.976\agent.exe FirewallRules: [TCP Query User{90E609CA-1A7D-4AF3-92DD-C89A8E464238}C:\programdata\battle.net\agent\agent.998\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.998\agent.exe FirewallRules: [UDP Query User{95AFA473-F5E1-4FE7-8CC4-265843ADBDB5}C:\programdata\battle.net\agent\agent.998\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.998\agent.exe FirewallRules: [TCP Query User{83766DDC-ACAD-429D-B16C-315454178B3A}C:\programdata\battle.net\agent\agent.1040\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.1040\agent.exe FirewallRules: [UDP Query User{EF9D19CD-EABF-4582-9426-5C45B8434839}C:\programdata\battle.net\agent\agent.1040\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.1040\agent.exe FirewallRules: [{3BEC5EC9-9E50-40EC-940C-342EC5A29B4B}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1199\Agent.exe FirewallRules: [{FB57C8AE-661F-46B0-B20C-5850B5A1A027}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1199\Agent.exe FirewallRules: [{9B135F9A-03BB-44C3-A51B-53530255836E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1225\Agent.exe FirewallRules: [{4036EAF4-0CB2-49E3-9ACE-1460C956D632}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1225\Agent.exe FirewallRules: [{F1A66AE7-9472-41FF-A70A-DCB8333463BE}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1267\Agent.exe FirewallRules: [{35C95002-4008-4D01-A4B4-662A70DB443C}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1267\Agent.exe FirewallRules: [{5C65D816-2D0B-4BDD-BAD3-EDA0A5A6E325}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1363\Agent.exe FirewallRules: [{A07F7F2F-7189-4680-9E3C-B6F8A8610233}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1363\Agent.exe FirewallRules: [{9FAF5BF7-6579-46CC-AD87-7A2AB1EA98C3}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1544\Agent.exe FirewallRules: [{DC49891D-A36F-4179-A1EF-A18444CE7FDF}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1544\Agent.exe FirewallRules: [TCP Query User{D1C8E81E-DC8A-4B5C-84F3-5FC7019D889A}C:\program files (x86)\2k games\gearbox software\borderlands\binaries\borderlands.exe] => (Allow) C:\program files (x86)\2k games\gearbox software\borderlands\binaries\borderlands.exe FirewallRules: [UDP Query User{6067107C-A2FE-4D23-9B6E-89D19884809F}C:\program files (x86)\2k games\gearbox software\borderlands\binaries\borderlands.exe] => (Allow) C:\program files (x86)\2k games\gearbox software\borderlands\binaries\borderlands.exe FirewallRules: [{0B9B4838-1C2E-4E12-B2FC-6AD1A2761A98}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1544\Agent.exe FirewallRules: [{9448DCCF-D1A1-434C-95D2-D1C4A7DA101F}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1544\Agent.exe FirewallRules: [TCP Query User{A61D4624-AA40-4850-B410-6726ED199DFB}C:\program files (x86)\diablo iii\diablo iii.exe] => (Allow) C:\program files (x86)\diablo iii\diablo iii.exe FirewallRules: [UDP Query User{28FBB594-EF61-4A1E-A8A7-39BEB7AE8528}C:\program files (x86)\diablo iii\diablo iii.exe] => (Allow) C:\program files (x86)\diablo iii\diablo iii.exe FirewallRules: [TCP Query User{8E277956-A6AC-4602-96FE-6E59A1BF8F6A}C:\program files (x86)\2k games\gearbox software\borderlands\binaries\borderlands.exe] => (Block) C:\program files (x86)\2k games\gearbox software\borderlands\binaries\borderlands.exe FirewallRules: [UDP Query User{657707A6-368C-4A83-A8F7-31009B949C6C}C:\program files (x86)\2k games\gearbox software\borderlands\binaries\borderlands.exe] => (Block) C:\program files (x86)\2k games\gearbox software\borderlands\binaries\borderlands.exe FirewallRules: [TCP Query User{301A99A4-2A0C-42C4-B85C-929FA3DC578A}C:\program files (x86)\sid meier's civilization v\civilizationv_dx11.exe] => (Allow) C:\program files (x86)\sid meier's civilization v\civilizationv_dx11.exe FirewallRules: [UDP Query User{21E65557-DFDD-4924-85E2-392A8D5AF82C}C:\program files (x86)\sid meier's civilization v\civilizationv_dx11.exe] => (Allow) C:\program files (x86)\sid meier's civilization v\civilizationv_dx11.exe FirewallRules: [TCP Query User{59727D75-5F3B-4B99-8AB6-EFB80CE6E454}C:\program files (x86)\sid meier's civilization v\civilizationv_dx11.exe] => (Allow) C:\program files (x86)\sid meier's civilization v\civilizationv_dx11.exe FirewallRules: [UDP Query User{B7AA76D9-3D59-4799-A7E2-354D4375DB70}C:\program files (x86)\sid meier's civilization v\civilizationv_dx11.exe] => (Allow) C:\program files (x86)\sid meier's civilization v\civilizationv_dx11.exe FirewallRules: [{C6BAC3BA-0D22-4049-A7FE-BB103C34A86E}] => (Allow) C:\Program Files\Echobit\Evolve\EvoSvc.exe FirewallRules: [{85D1E51E-B08E-4069-AF44-3FCE52AD05CC}] => (Allow) C:\Program Files\Echobit\Evolve\EvolveClient.exe FirewallRules: [TCP Query User{E9EA77EC-002A-4C4E-8E58-249E9A51DC1D}C:\program files (x86)\sid meier's civilization v\civilizationv.exe] => (Allow) C:\program files (x86)\sid meier's civilization v\civilizationv.exe FirewallRules: [UDP Query User{3584F9BD-8B3F-4146-8DF2-2D2D42189E64}C:\program files (x86)\sid meier's civilization v\civilizationv.exe] => (Allow) C:\program files (x86)\sid meier's civilization v\civilizationv.exe FirewallRules: [{0FE34B5D-2679-4043-9C2E-351E36961F0B}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1637\Agent.exe FirewallRules: [{4D832D93-9917-4763-834D-916AD6E8A2CC}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1637\Agent.exe FirewallRules: [{16F224C7-0D96-4C95-AE8F-3851E1D403A1}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1675\Agent.exe FirewallRules: [{87D35EAE-E971-4486-A17F-621552028416}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1675\Agent.exe FirewallRules: [{1360E61F-2488-4D29-8AB8-E2D746ADCF02}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1737\Agent.exe FirewallRules: [{17A605CE-48BE-42D0-9DFA-78A8C86E90C9}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1737\Agent.exe FirewallRules: [TCP Query User{A5993935-A1A8-4C9A-B58D-F62858C74B7D}C:\program files (x86)\ea sports\fifa 11\game\fifa.exe] => (Block) C:\program files (x86)\ea sports\fifa 11\game\fifa.exe FirewallRules: [UDP Query User{B1280C40-46B6-43E0-9207-1D7B761D4681}C:\program files (x86)\ea sports\fifa 11\game\fifa.exe] => (Block) C:\program files (x86)\ea sports\fifa 11\game\fifa.exe FirewallRules: [{8FA81560-293C-4A58-9B62-D196921D8673}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2045\Agent.exe FirewallRules: [{E767DB21-500B-4EF0-8E09-C8BD8D1FD97A}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2045\Agent.exe FirewallRules: [TCP Query User{B5215464-8812-4390-9713-B0095039EC2E}C:\program files (x86)\winamp\winamp.exe] => (Block) C:\program files (x86)\winamp\winamp.exe FirewallRules: [UDP Query User{B9E11CB2-7A3D-480A-A687-A8CC622B7544}C:\program files (x86)\winamp\winamp.exe] => (Block) C:\program files (x86)\winamp\winamp.exe FirewallRules: [TCP Query User{055BA207-12A0-485B-8716-DE81F204FFE1}C:\program files (x86)\orbitdownloader\orbitnet.exe] => (Allow) C:\program files (x86)\orbitdownloader\orbitnet.exe FirewallRules: [UDP Query User{2E7329A4-9B19-4505-BD94-FC97BB794378}C:\program files (x86)\orbitdownloader\orbitnet.exe] => (Allow) C:\program files (x86)\orbitdownloader\orbitnet.exe FirewallRules: [TCP Query User{709E6C82-5293-46EB-A680-79439667ECD3}C:\program files (x86)\internet explorer\iexplore.exe] => (Block) C:\program files (x86)\internet explorer\iexplore.exe FirewallRules: [UDP Query User{7FC58348-EA2D-4B93-97F5-1FCC28A13098}C:\program files (x86)\internet explorer\iexplore.exe] => (Block) C:\program files (x86)\internet explorer\iexplore.exe FirewallRules: [TCP Query User{3EA5B687-CB70-4B38-8EDB-DA92D5DEA03E}H:\images\warcraft iii\war3.exe] => (Block) H:\images\warcraft iii\war3.exe FirewallRules: [UDP Query User{E4CE38B1-67C6-48BE-AEB0-43741A5DB61A}H:\images\warcraft iii\war3.exe] => (Block) H:\images\warcraft iii\war3.exe FirewallRules: [{3CEA719B-59CA-47A3-A128-EA38F6203767}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe FirewallRules: [{ED046DE6-8593-4ACB-88AB-12FE9DADCE5E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe FirewallRules: [{50F22C28-A275-49F5-8FFB-4FC705790566}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{1CF30EEA-5266-4843-842E-A5848F3B3A8C}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [TCP Query User{2071ED9D-CDA3-4AE0-AB99-589D0063C1A3}H:\images\warcraft iii\war3.exe] => (Block) H:\images\warcraft iii\war3.exe FirewallRules: [UDP Query User{4AD09943-4E0B-4B4C-BE6F-8BEC47558360}H:\images\warcraft iii\war3.exe] => (Block) H:\images\warcraft iii\war3.exe FirewallRules: [{E0C67E8B-538C-4C58-9B8D-E9A136C6561A}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2689\Agent.exe FirewallRules: [{089ABDF0-6301-454A-9E00-D13741DD5F78}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2689\Agent.exe FirewallRules: [{A62C35D7-1438-4E07-A376-9045403121FB}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe FirewallRules: [{CF93EF37-7C0C-4FBE-9E76-1DB4ECD36BE4}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe FirewallRules: [{258D4E68-9F48-4A3D-99FF-4B8A893327FC}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe FirewallRules: [{3CA64B4F-3945-45D9-B296-59A57D7668DE}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.beta.2737\Agent.exe FirewallRules: [{CA7BFC79-27B7-4FD4-8D55-A3D36F815288}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2717\Agent.exe FirewallRules: [{2E631837-A925-4599-898C-62EDE02384B7}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2717\Agent.exe FirewallRules: [TCP Query User{3D05B55B-499A-43EA-AC1B-DC84C070E646}C:\programdata\battle.net\agent\agent.beta.2753\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.beta.2753\agent.exe FirewallRules: [UDP Query User{BEBCDCC8-3A54-4488-888A-CC1124C73A24}C:\programdata\battle.net\agent\agent.beta.2753\agent.exe] => (Allow) C:\programdata\battle.net\agent\agent.beta.2753\agent.exe FirewallRules: [{2525FEB5-4C76-4820-9E01-EEEE099226AF}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2787\Agent.exe FirewallRules: [{738646F5-B9CD-48CC-8481-E5F32FE03D8F}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2787\Agent.exe FirewallRules: [{6BF1BE8E-9965-4F07-8A7F-098D1FA07692}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2816\Agent.exe FirewallRules: [{C000DB22-758D-4972-8ACE-D6846D0EBEBC}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2816\Agent.exe FirewallRules: [{E08FA131-8EE3-4BC3-B230-A993E75926BB}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2880\Agent.exe FirewallRules: [{7F43164F-A3E3-4828-A84D-3860D76E119D}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2880\Agent.exe FirewallRules: [{E80D329B-C554-44EC-9AF2-6642CCEFFFF3}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3147\Agent.exe FirewallRules: [{DC37F596-A736-4BC2-9EDD-7A571139BEB2}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3147\Agent.exe FirewallRules: [{6315E9FB-005B-451B-9465-45F90B02F124}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{CE581422-A7C9-4DD0-AEC7-A132E5ACA086}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{839CDCCA-5215-4C87-8F03-77F1DB5FC8CE}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3526\Agent.exe FirewallRules: [{BF82BF46-B9F3-4496-AF19-515B13C00AF3}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3526\Agent.exe FirewallRules: [{CE821BED-65FA-40E8-8B5C-9F0090F25DC4}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3632\Agent.exe FirewallRules: [{0BA6424E-E16B-4462-BBC8-ABDDEF8AC93A}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3632\Agent.exe FirewallRules: [{3855BB20-4D88-4158-9639-EEF44C206138}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe FirewallRules: [{D9063798-C745-454E-8603-0A6D57671F75}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3634\Agent.exe FirewallRules: [{88712BB0-D5F5-4DE7-AE51-04E1A168B205}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3668\Agent.exe FirewallRules: [{1ED02756-ED68-4E0C-A669-008DD26E65D1}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3668\Agent.exe FirewallRules: [{281651BA-1176-4C05-A603-035167472F7F}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3669\Agent.exe FirewallRules: [{42FF3278-2FD6-44B7-B0BD-B92F2B56992C}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3669\Agent.exe FirewallRules: [{53F137EF-F8F1-45EA-AA2B-4E646B5E6691}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3688\Agent.exe FirewallRules: [{D0FEAEA8-BF35-409E-838E-13FF2748490C}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3688\Agent.exe FirewallRules: [{D58C92BB-93AB-4929-9097-D46A5915577E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3689\Agent.exe FirewallRules: [{33CA1E79-5DDC-4344-BE83-402446E0E1A5}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3689\Agent.exe FirewallRules: [{55230E58-E582-4278-B295-9881D7A259EC}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{AD73000A-66E6-476A-B801-93276BB049C2}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe FirewallRules: [{ED4B1177-E3C3-46F4-8D53-D0E5280FAE47}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{8C48C058-1ED7-491B-B109-1A2763612EF7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe FirewallRules: [{34C1140C-BC6D-4169-A56A-197A4E6DF4B3}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{7C41BEBA-7DCE-4F11-AAFB-191E2BD9696A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{4F2971CB-2AF3-4BA1-BF92-397547B2BC36}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3715\Agent.exe FirewallRules: [{DB683BEC-4583-40F1-ADB1-1639A8E4C0F8}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.3715\Agent.exe FirewallRules: [TCP Query User{50A20A17-A0F4-4551-9288-7C0FC6774E58}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [UDP Query User{77ACD185-CEBC-4E21-B547-B9D1952775A6}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [TCP Query User{2A7955DA-B167-4725-914E-871EE27C98FB}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [UDP Query User{7CEEB1ED-31CC-47CC-A481-7F3A0B46A7DE}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe FirewallRules: [{9D2A75DE-90DE-4B23-A49F-A024821864BE}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{F44820B3-9FB0-466D-8D5D-C6C1AD7EEEBB}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [TCP Query User{31F0C286-4B92-4A29-AC2A-1F34C2F53DE8}H:\unrealtournament\system\unrealtournament.exe] => (Block) H:\unrealtournament\system\unrealtournament.exe FirewallRules: [UDP Query User{9E8CF545-129E-471D-B4B4-1E2F56C06C1D}H:\unrealtournament\system\unrealtournament.exe] => (Block) H:\unrealtournament\system\unrealtournament.exe FirewallRules: [{4A64229C-E342-4F29-A41D-563CEBC24A7D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Fallout 4\Fallout4Launcher.exe FirewallRules: [{DC1AF2C8-DEC4-4329-AAC2-02E64FEFF89C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Fallout 4\Fallout4Launcher.exe FirewallRules: [TCP Query User{EC78C749-D555-4833-9C3F-FE2B3BC1039B}C:\program files (x86)\steam\steamapps\common\fallout 4\fallout4.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\fallout 4\fallout4.exe FirewallRules: [UDP Query User{3C686866-55BA-45BD-A161-9E4934ECCAFE}C:\program files (x86)\steam\steamapps\common\fallout 4\fallout4.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\fallout 4\fallout4.exe FirewallRules: [{767C01C4-A9A7-43A4-8B4F-4819E2F57C62}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Restore Points ========================= 29-12-2015 20:52:19 Windows Update 29-12-2015 21:00:17 Windows Backup ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (11/22/2015 04:54:58 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: Avira.ServiceHost.exe, version: 1.1.49.18939, time stamp: 0x561e029a Faulting module name: KERNELBASE.dll, version: 6.1.7601.19045, time stamp: 0x56258f05 Exception code: 0xe0434352 Fault offset: 0x0000c42d Faulting process id: 0xd00 Faulting application start time: 0xAvira.ServiceHost.exe0 Faulting application path: Avira.ServiceHost.exe1 Faulting module path: Avira.ServiceHost.exe2 Report Id: Avira.ServiceHost.exe3 Error: (11/22/2015 04:54:57 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Application: Avira.ServiceHost.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: System.InvalidOperationException Stack: at System.ThrowHelper.ThrowInvalidOperationException(System.ExceptionResource) at System.Collections.Generic.Dictionary`2+ValueCollection+Enumerator[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089],[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]].MoveNext() at Avira.OE.ServiceHost.ServiceStatusProviderContainer.GetDeviceStatus() at Avira.OE.ServiceHost.ComputerAndServicesInfoFactory.CreateComputerAndServicesInfo() at Avira.OE.ServiceHost.AnonymousUserDeviceStatusConnector.UpdateCurrentComputerAndServiceInfo() at Avira.OE.ServiceHost.AnonymousUserDeviceStatusConnector.SendAnonymousSyncStatus() at Avira.OE.ServiceHost.AnonymousUserDeviceStatusConnector.AnonymousSyncStatusNeeded(System.Object, System.EventArgs) at Avira.OE.WinCore.EventHandlerExtensions.SafeInvoke[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.EventHandler`1<System.__Canon>, System.Object, System.__Canon) at Avira.OE.Communicator.Communicator.CheckAndRequestAnonymousSyncStatus() at Avira.OE.Communicator.Communicator.CreateAndSendDeviceUpdateDataMessage(System.String) at Avira.OE.Communicator.Communicator.SessionChanged(Avira.OE.WinCore.Interface.Session, Avira.OE.WinCore.Interface.Session) at Avira.OE.Communicator.Communicator.OnActiveSessionChanged(System.Object, Avira.OE.WinCore.Interface.ActiveSessionChangedEventArgs) at Avira.OE.WinCore.EventHandlerExtensions.SafeInvoke[[System.__Canon, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]](System.EventHandler`1<System.__Canon>, System.Object, System.__Canon) at Avira.OE.ServiceHost.SessionManager.FireActiveSessionChangeAndSetActiveSession(Avira.OE.WinCore.Interface.Session) at Avira.OE.ServiceHost.SessionManager.Initialize() at Avira.OE.ServiceHost.ServiceHost.Initialize() at Avira.OE.ServiceHost.Program+<>c__DisplayClass1.<OnServiceStart>b__0(System.Object) at System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object) at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) at System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem() at System.Threading.ThreadPoolWorkQueue.Dispatch() at System.Threading._ThreadPoolWaitCallback.PerformWaitCallback() Error: (11/17/2015 05:58:00 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: Fallout4.exe, version: 1.1.30.0, time stamp: 0x563b8ba7 Faulting module name: Fallout4.exe, version: 1.1.30.0, time stamp: 0x563b8ba7 Exception code: 0xc000041d Fault offset: 0x00000000016c723e Faulting process id: 0x147c Faulting application start time: 0xFallout4.exe0 Faulting application path: Fallout4.exe1 Faulting module path: Fallout4.exe2 Report Id: Fallout4.exe3 Error: (11/14/2015 04:44:09 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program Fallout4.exe version 1.1.30.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 1540 Start Time: 01d11ed224656f7e Termination Time: 634 Application Path: C:\Program Files (x86)\Steam\steamapps\common\Fallout 4\Fallout4.exe Report Id: Error: (11/10/2015 10:28:35 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program Fallout4.exe version 1.1.29.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 4c0 Start Time: 01d11ba9172af642 Termination Time: 898 Application Path: C:\Program Files (x86)\Steam\steamapps\common\Fallout 4\Fallout4.exe Report Id: Error: (11/08/2015 08:52:04 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: Bioshock.exe, version: 1.0.0.0, time stamp: 0x474f5a3a Faulting module name: kernel32.dll, version: 6.1.7601.19018, time stamp: 0x5609fed3 Exception code: 0xc0000005 Fault offset: 0x00011390 Faulting process id: 0x158 Faulting application start time: 0xBioshock.exe0 Faulting application path: Bioshock.exe1 Faulting module path: Bioshock.exe2 Report Id: Bioshock.exe3 Error: (09/07/2015 01:48:52 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: Gothic3.exe, version: 1.74.25931.14, time stamp: 0x4c030371 Faulting module name: Engine.dll, version: 1.74.25931.14, time stamp: 0x4c02ffc9 Exception code: 0xc0000005 Fault offset: 0x000dfcc1 Faulting process id: 0xbec Faulting application start time: 0xGothic3.exe0 Faulting application path: Gothic3.exe1 Faulting module path: Gothic3.exe2 Report Id: Gothic3.exe3 Error: (09/06/2015 06:39:33 PM) (Source: Application Error) (EventID: 1005) (User: ) Description: Windows cannot access the file for one of the following reasons: there is a problem with the network connection, the disk that the file is stored on, or the storage drivers installed on this computer; or the disk is missing. Windows closed the program Genome Gaming System because of this error. Program: Genome Gaming System File: The error value is listed in the Additional Data section. User Action 1. Open the file again. This situation might be a temporary problem that corrects itself when the program runs again. 2. If the file still cannot be accessed and - It is on the network, your network administrator should verify that there is not a problem with the network and that the server can be contacted. - It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer. 3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER. 4. If the problem persists, restore the file from a backup copy. 5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for further assistance. Additional Data Error value: 00000000 Disk type: 0 Error: (09/06/2015 06:39:33 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: Gothic3.exe, version: 1.74.25931.14, time stamp: 0x4c030371 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000096 Fault offset: 0x3e931996 Faulting process id: 0x3f4 Faulting application start time: 0xGothic3.exe0 Faulting application path: Gothic3.exe1 Faulting module path: Gothic3.exe2 Report Id: Gothic3.exe3 Error: (07/21/2015 09:27:03 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: audacity.exe, version: 0.0.0.0, time stamp: 0x43791554 Faulting module name: ntdll.dll, version: 6.1.7601.18798, time stamp: 0x5507b3e0 Exception code: 0xc0000005 Fault offset: 0x00039e03 Faulting process id: 0x834 Faulting application start time: 0xaudacity.exe0 Faulting application path: audacity.exe1 Faulting module path: audacity.exe2 Report Id: audacity.exe3 System errors: ============= Error: (12/31/2015 12:02:09 PM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: The Avira Email-Schutz service terminated with service-specific error %%1. Error: (12/31/2015 12:02:09 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: The Avira Email-Schutz service hung on starting. Error: (12/31/2015 12:02:09 PM) (Source: WMPNetworkSvc) (EventID: 14332) (User: ) Description: Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80070420'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly. Error: (12/30/2015 03:24:25 PM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: The Avira Email-Schutz service terminated with service-specific error %%1. Error: (12/30/2015 03:24:25 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: The Avira Email-Schutz service hung on starting. Error: (12/30/2015 01:20:33 PM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: The Avira Email-Schutz service terminated with service-specific error %%1. Error: (12/30/2015 01:20:32 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: The Avira Email-Schutz service hung on starting. Error: (12/30/2015 01:20:33 PM) (Source: WMPNetworkSvc) (EventID: 14332) (User: ) Description: Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80070420'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly. Error: (12/29/2015 08:51:37 PM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: The Avira Email-Schutz service terminated with service-specific error %%1. Error: (12/29/2015 08:51:37 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: The Avira Email-Schutz service hung on starting. CodeIntegrity: =================================== Date: 2013-10-20 18:45:44.901 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2013-10-20 18:45:44.848 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-2500K CPU @ 3.30GHz Percentage of memory in use: 74% Total physical RAM: 8173.57 MB Available physical RAM: 2103.8 MB Total Virtual: 16345.36 MB Available Virtual: 6925.63 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:119.14 GB) (Free:3.9 GB) NTFS Drive e: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[system with boot components (obtained from drive)] Drive f: (Elements) (Fixed) (Total:465.75 GB) (Free:49.9 GB) NTFS Drive g: () (Fixed) (Total:99.51 GB) (Free:71.44 GB) NTFS Drive h: (Games) (Fixed) (Total:244.14 GB) (Free:92.53 GB) NTFS Drive i: (Musik und Filme) (Fixed) (Total:587.76 GB) (Free:107.92 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 119.2 GB) (Disk ID: 786EE9E8) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=119.1 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 61BCEE7D) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=99.5 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=244.1 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=587.8 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (Size: 465.8 GB) (Disk ID: 946FF2BA) Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================ |
Themen zu Ich verschicke Spam |
.dll, adware, antivirus, avira, canon, combofix, cpu, downloader, explorer, firefox, firewall, flash player, help, helper, iexplore.exe, internet, internet explorer, musik, photoshop, problem, scan, security, software, spam, temp, tower, udp |