robblubb | 28.01.2014 13:27 | Danke für die schnelle Antwort!
Achso: Die Funde von Malewarebytes habe ich noch nicht gelöscht oder in Quarantäne verschoben, ne.
Hier die Logs:
FRST:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-01-2014 02
Ran by Robert (administrator) on ROBERT-LAPTOP on 28-01-2014 13:21:40
Running from D:\Robert\Downloads
Windows 8.1 Pro (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(ANSYS, Inc.) C:\Program Files\ANSYS Inc\Shared Files\Licensing\winx64\ansysli_server.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(MKS Software Inc.) C:\Windows\System32\nutsrv4.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(ANSYS, Inc.) C:\Program Files\ANSYS Inc\Shared Files\Licensing\winx64\ansysli_monitor.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20315_x64__8wekyb3d8bbwe\livecomm.exe
(Flexera Software, Inc.) C:\Program Files\ANSYS Inc\Shared Files\Licensing\winx64\lmgrd.exe
(ANSYS, Inc.) C:\Program Files\ANSYS Inc\Shared Files\Licensing\winx64\ansyslmd.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OFFICE15\CSISYNCCLIENT.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Google Inc.) C:\Users\Robert\AppData\Local\Programs\Google\MusicManager\MusicManager.exe
(Google) C:\Program Files (x86)\Google\Google Calendar Sync\GoogleCalendarSync.exe
(CANON INC.) C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Outcold Solutions) C:\Program Files\WindowsApps\47286outcoldman.gMusic_2.2.14.89_x64__z1q2m7teapq4y\gMusic.exe
(Rogue Amoeba) C:\Program Files (x86)\Airfoil\Airfoil.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Source Engine\OSE.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1842472 2009-09-17] (Synaptics Incorporated)
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13513288 2013-03-29] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1278024 2013-03-08] (Realtek Semiconductor)
HKLM\...\Run: [CanonMyPrinter] - C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2726728 2010-03-24] (CANON INC.)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2009-12-23] (Intel Corporation)
HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-03-20] (Geek Software GmbH)
HKLM-x32\...\Run: [IJNetworkScanUtility] - C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe [140640 2010-03-02] (CANON INC.)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-08-30] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [NuTCSetupEnviron] - C:\Program Files\PTC\MKS Toolkit\bin\ncoeenv.exe [37160 2009-11-23] (MKS Software Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3764024 2013-12-22] (AVAST Software)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] - C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [707472 2013-12-12] (Cisco Systems, Inc.)
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware] - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation)
HKCU\...\Run: [OfficeSyncProcess] - C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [911040 2013-04-22] (Microsoft Corporation)
HKCU\...\Run: [SkyDrive] - C:\Users\Robert\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [257136 2013-08-14] (Microsoft Corporation)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
HKCU\...\Run: [Google Update] - C:\Users\Robert\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2014-01-10] (Google Inc.)
HKCU\...\Run: [MusicManager] - C:\Users\Robert\AppData\Local\Programs\Google\MusicManager\MusicManager.exe [7380992 2013-11-12] (Google Inc.)
HKCU\...\Run: [Spotify Web Helper] - C:\Users\Robert\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1168896 2013-12-05] (Spotify Ltd)
AppInit_DLLs-x32: AirfoilInject3.dll => File Not Found
Startup: C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Airfoil.lnk
ShortcutTarget: Airfoil.lnk -> C:\Program Files (x86)\Airfoil\Airfoil.exe (Rogue Amoeba)
Startup: C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Robert\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://play.google.com/music/listen#/now
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x4944E57A0D0ECF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE,de;q=0.5
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Chrome:
=======
CHR HomePage:
CHR Extension: (Google Docs) - C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-28]
CHR Extension: (Google Drive) - C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-28]
CHR Extension: (YouTube) - C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-28]
CHR Extension: (Adblock Plus) - C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-01-28]
CHR Extension: (Google-Suche) - C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-28]
CHR Extension: (avast! Online Security) - C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-01-28]
CHR Extension: (Google Play Music) - C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\icppfcnhkcmnfdhfhphakoifcfokfdhg [2014-01-28]
CHR Extension: (Google Wallet) - C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-28]
CHR Extension: (Google Mail) - C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-28]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2013-12-22]
==================== Services (Whitelisted) =================
R2 ANSYS, Inc. License Manager; C:\Program Files\ANSYS Inc\Shared Files\Licensing\winx64\ansysli_server.exe [4954112 2011-10-17] (ANSYS, Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-12-22] (AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [113704 2013-12-23] (AVAST Software)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 NuTCRACKERService; C:\Windows\system32\nutsrv4.exe [563424 2009-11-10] (MKS Software Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
R0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [21160 2012-09-23] (Advanced Micro Devices, Inc.)
R1 aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [28184 2013-12-23] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [78648 2013-12-22] (AVAST Software)
R1 aswNdisFlt; C:\Windows\system32\DRIVERS\aswNdisFlt.sys [439648 2014-01-09] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [92544 2013-12-22] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-12-22] ()
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [1034464 2013-12-22] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [422216 2013-12-22] (AVAST Software)
R3 aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [79672 2013-12-22] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2013-12-22] ()
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [129536 2013-07-05] (Advanced Micro Devices)
R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [8536752 2013-07-01] (Broadcom Corporation)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider)
R3 BthA2DP; C:\Windows\system32\drivers\BthA2DP.sys [131584 2013-08-22] (Microsoft Corporation)
R3 bthav; C:\Windows\system32\drivers\bthav.sys [40448 2008-07-10] (CSR, plc)
S3 BtHidBus; C:\Windows\System32\Drivers\BtHidBus.sys [23904 2013-05-20] (IVT Corporation.)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [224768 2013-08-22] (Microsoft Corporation)
S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation)
S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation)
S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation)
R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-11] (Microsoft Corporation)
S3 IvtAudioBusSrv; C:\Windows\System32\Drivers\IvtBtBus.sys [27256 2012-12-24] (IVT Corporation.)
S3 IvtPanBusSrv; C:\Windows\System32\Drivers\btnetBus.sys [31480 2012-12-24] (IVT Corporation.)
S3 kbldfltr; C:\Windows\System32\drivers\kbldfltr.sys [22272 2013-09-30] (Microsoft Corporation)
S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation)
R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [47320 2013-07-29] (Realtek Microelectronics)
S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-10-26] (Microsoft Corporation)
S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-10-05] (Microsoft Corporation)
S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
R3 VBAudioVACMME; C:\Windows\system32\DRIVERS\vbaudio_cable64_win7.sys [38272 2013-08-17] (Windows (R) Win 7 DDK provider)
S3 vpnva; C:\Windows\system32\DRIVERS\vpnva64-6.sys [52080 2013-10-10] (Cisco Systems, Inc.)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation)
S3 xusb22; C:\Windows\System32\drivers\xusb22.sys [87040 2013-08-22] (Microsoft Corporation)
S3 BlueletAudio; \SystemRoot\system32\DRIVERS\blueletaudio.sys [x]
S3 BT; \SystemRoot\system32\DRIVERS\btnetdrv.sys [x]
S3 BTCOM; \SystemRoot\system32\DRIVERS\btcomport.sys [x]
S3 Btcsrusb; \SystemRoot\System32\Drivers\btcusb.sys [x]
S3 IvtComBusSrv; \SystemRoot\System32\Drivers\btcombus.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-28 13:21 - 2014-01-28 13:21 - 00000000 ____D C:\FRST
2014-01-28 11:38 - 2014-01-28 11:38 - 00000000 ____D C:\Users\Robert\AppData\Roaming\Malwarebytes
2014-01-28 11:37 - 2014-01-28 11:37 - 00001125 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-28 11:37 - 2014-01-28 11:37 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-28 11:37 - 2014-01-28 11:37 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-28 11:37 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-01-28 11:34 - 2014-01-28 11:34 - 00000078 _____ C:\WINDOWS\setupact.log
2014-01-28 11:34 - 2014-01-28 11:34 - 00000000 _____ C:\WINDOWS\setuperr.log
2014-01-28 11:22 - 2014-01-28 12:55 - 00027160 _____ C:\WINDOWS\WindowsUpdate.log
2014-01-28 11:22 - 2014-01-28 11:31 - 00002195 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2014-01-28 11:21 - 2014-01-28 12:31 - 00001138 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-28 11:21 - 2014-01-28 11:31 - 00001134 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-28 11:21 - 2014-01-28 11:26 - 00004110 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2014-01-28 11:21 - 2014-01-28 11:26 - 00003874 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2014-01-28 11:21 - 2014-01-28 11:21 - 00000000 ____D C:\Users\Robert\AppData\Local\Deployment
2014-01-18 17:33 - 2014-01-18 17:33 - 00005327 _____ C:\WINDOWS\SysWOW64\jupdate-1.7.0_51-b13.log
2014-01-15 12:52 - 2013-12-09 01:15 - 00787968 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2014-01-15 12:52 - 2013-11-27 16:36 - 03395920 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll
2014-01-15 12:52 - 2013-11-27 12:41 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSCollect.exe
2014-01-15 12:52 - 2013-11-27 11:34 - 00138240 _____ C:\WINDOWS\system32\OEMLicense.dll
2014-01-15 12:52 - 2013-11-27 10:54 - 00103936 _____ C:\WINDOWS\SysWOW64\OEMLicense.dll
2014-01-15 12:52 - 2013-11-27 09:48 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-01-15 12:52 - 2013-11-27 09:45 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSClient.dll
2014-01-15 12:52 - 2013-11-27 09:40 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-01-15 12:52 - 2013-11-27 09:38 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSClient.dll
2014-01-15 12:52 - 2013-11-27 09:17 - 00695808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2014-01-15 12:52 - 2013-11-27 09:12 - 00848384 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2014-01-12 13:10 - 2014-01-12 13:31 - 00000000 ____D C:\ProgramData\BlueStacksSetup
2014-01-11 15:26 - 2014-01-11 15:26 - 00000000 ____D C:\Users\Public\Foxit Software
2014-01-10 13:16 - 2014-01-10 13:29 - 00000000 ____D C:\Users\Robert\AppData\Local\Rogue Amoeba
2014-01-10 13:16 - 2014-01-10 13:16 - 00000000 ____D C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Airfoil
2014-01-10 13:16 - 2014-01-10 13:16 - 00000000 ____D C:\Program Files (x86)\Airfoil
2014-01-10 13:10 - 2014-01-28 13:20 - 00001152 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1966479420-4144997280-1241761937-1001UA.job
2014-01-10 13:10 - 2014-01-28 13:20 - 00001100 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1966479420-4144997280-1241761937-1001Core.job
2014-01-10 13:10 - 2014-01-10 13:15 - 00004100 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1966479420-4144997280-1241761937-1001UA
2014-01-10 13:10 - 2014-01-10 13:15 - 00003720 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1966479420-4144997280-1241761937-1001Core
2014-01-10 13:10 - 2014-01-10 13:10 - 00000000 ____D C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Music Manager
2014-01-09 17:43 - 2014-01-09 17:43 - 00000000 ____D C:\Program Files (x86)\RootClockworkMod
2014-01-09 17:40 - 2014-01-09 17:40 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_WinUSB_01009.Wdf
2014-01-09 17:05 - 2014-01-09 17:06 - 00000000 ____D C:\Program Files (x86)\PdaNet for Android
2014-01-09 16:32 - 2014-01-09 16:32 - 00000000 ____D C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wugs Nexus Root Tookit
2014-01-09 16:32 - 2014-01-09 16:32 - 00000000 ____D C:\Users\Robert\.android
2014-01-09 16:32 - 2014-01-09 16:32 - 00000000 ____D C:\Program Files (x86)\WugFresh Development
2014-01-09 14:23 - 2014-01-09 14:31 - 00000000 ____D C:\Users\Robert\AppData\Roaming\Apple Computer
2014-01-09 14:23 - 2014-01-09 14:23 - 00000000 ____D C:\Users\Robert\AppData\Local\Apple Computer
2014-01-09 14:22 - 2014-01-11 12:47 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-01-09 14:22 - 2014-01-09 14:22 - 00000000 ____D C:\Users\Robert\AppData\Local\Apple
2014-01-09 14:22 - 2014-01-09 14:22 - 00000000 ____D C:\ProgramData\Apple Computer
2014-01-09 14:21 - 2014-01-09 14:22 - 00000000 ____D C:\ProgramData\Apple
2014-01-09 14:21 - 2014-01-09 14:21 - 00000000 ____D C:\Program Files\Bonjour
2014-01-09 14:21 - 2014-01-09 14:21 - 00000000 ____D C:\Program Files (x86)\Bonjour
2014-01-07 15:57 - 2014-01-09 17:26 - 00000000 ____D C:\Program Files\Recuva
2014-01-05 18:19 - 2014-01-28 13:20 - 00000000 ____D C:\Users\Robert\AppData\Roaming\Skype
2014-01-05 18:19 - 2014-01-05 18:19 - 00000000 ___RD C:\Program Files (x86)\Skype
2014-01-05 18:19 - 2014-01-05 18:19 - 00000000 ____D C:\ProgramData\Skype
2014-01-02 22:04 - 2014-01-19 20:42 - 00000000 ____D C:\Users\Robert\AppData\Local\Battle.net
2014-01-02 22:04 - 2014-01-03 17:50 - 00000000 ____D C:\Users\Robert\AppData\Roaming\Battle.net
2014-01-02 22:04 - 2014-01-02 22:04 - 00000000 ____D C:\Users\Robert\AppData\Local\Blizzard Entertainment
2014-01-02 22:04 - 2014-01-02 22:04 - 00000000 ____D C:\ProgramData\Blizzard Entertainment
2014-01-02 22:03 - 2014-01-03 17:01 - 00000000 ____D C:\ProgramData\Battle.net
==================== One Month Modified Files and Folders =======
2014-01-28 13:21 - 2014-01-28 13:21 - 00000000 ____D C:\FRST
2014-01-28 13:20 - 2014-01-10 13:10 - 00001152 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1966479420-4144997280-1241761937-1001UA.job
2014-01-28 13:20 - 2014-01-10 13:10 - 00001100 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1966479420-4144997280-1241761937-1001Core.job
2014-01-28 13:20 - 2014-01-05 18:19 - 00000000 ____D C:\Users\Robert\AppData\Roaming\Skype
2014-01-28 13:00 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\sru
2014-01-28 12:55 - 2014-01-28 11:22 - 00027160 _____ C:\WINDOWS\WindowsUpdate.log
2014-01-28 12:31 - 2014-01-28 11:21 - 00001138 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-28 11:43 - 2013-04-10 17:31 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1966479420-4144997280-1241761937-1001
2014-01-28 11:38 - 2014-01-28 11:38 - 00000000 ____D C:\Users\Robert\AppData\Roaming\Malwarebytes
2014-01-28 11:37 - 2014-01-28 11:37 - 00001125 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-28 11:37 - 2014-01-28 11:37 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-28 11:37 - 2014-01-28 11:37 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-28 11:34 - 2014-01-28 11:34 - 00000078 _____ C:\WINDOWS\setupact.log
2014-01-28 11:34 - 2014-01-28 11:34 - 00000000 _____ C:\WINDOWS\setuperr.log
2014-01-28 11:31 - 2014-01-28 11:22 - 00002195 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2014-01-28 11:31 - 2014-01-28 11:21 - 00001134 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-28 11:29 - 2013-05-20 15:01 - 00005144 _____ C:\WINDOWS\System32\Tasks\Microsoft Office 15 Sync Maintenance for ROBERT-LAPTOP-Robert Robert-Laptop
2014-01-28 11:26 - 2014-01-28 11:21 - 00004110 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2014-01-28 11:26 - 2014-01-28 11:21 - 00003874 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2014-01-28 11:24 - 2013-09-30 05:14 - 01785518 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2014-01-28 11:24 - 2013-09-30 04:56 - 00769092 _____ C:\WINDOWS\system32\perfh007.dat
2014-01-28 11:24 - 2013-09-30 04:56 - 00160376 _____ C:\WINDOWS\system32\perfc007.dat
2014-01-28 11:22 - 2013-04-10 18:44 - 00000000 ____D C:\Users\Robert\AppData\Local\Google
2014-01-28 11:22 - 2013-04-10 18:44 - 00000000 ____D C:\Program Files (x86)\Google
2014-01-28 11:21 - 2014-01-28 11:21 - 00000000 ____D C:\Users\Robert\AppData\Local\Deployment
2014-01-28 11:21 - 2013-04-25 16:37 - 00000000 ____D C:\Users\Robert\AppData\Local\Apps\2.0
2014-01-28 11:19 - 2013-08-22 15:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2014-01-28 11:19 - 2013-08-22 14:25 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2014-01-26 20:27 - 2013-08-22 15:44 - 00482920 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2014-01-26 20:08 - 2013-04-10 20:08 - 00000000 ____D C:\ProgramData\Cisco
2014-01-26 20:08 - 2013-04-10 20:08 - 00000000 ____D C:\Program Files (x86)\Cisco
2014-01-25 12:58 - 2013-10-18 16:45 - 00000000 ____D C:\Users\Robert
2014-01-23 13:57 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2014-01-22 12:28 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\FxsTmp
2014-01-21 14:15 - 2013-04-19 22:11 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2014-01-20 15:41 - 2013-04-10 22:09 - 00000000 ____D C:\Users\Robert\AppData\Roaming\Dropbox
2014-01-19 20:42 - 2014-01-02 22:04 - 00000000 ____D C:\Users\Robert\AppData\Local\Battle.net
2014-01-19 18:37 - 2013-04-10 17:22 - 00000000 ___RD C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-19 17:48 - 2013-04-10 22:10 - 00000000 ____D C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-01-19 17:12 - 2013-12-22 20:05 - 00004182 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2014-01-19 17:08 - 2013-04-11 13:27 - 00000000 ____D C:\Program Files (x86)\JDownloader
2014-01-19 17:07 - 2013-06-04 15:40 - 00000000 ____D C:\Users\Robert\AppData\Roaming\MediaMonkey
2014-01-19 16:29 - 2013-08-22 16:36 - 00000000 __RHD C:\Users\Public\Libraries
2014-01-18 17:34 - 2013-10-18 17:08 - 00000000 ____D C:\ProgramData\Oracle
2014-01-18 17:33 - 2014-01-18 17:33 - 00005327 _____ C:\WINDOWS\SysWOW64\jupdate-1.7.0_51-b13.log
2014-01-18 17:33 - 2013-06-22 19:55 - 00000000 ____D C:\Program Files (x86)\Java
2014-01-17 14:41 - 2013-07-16 11:08 - 00000000 ____D C:\WINDOWS\system32\MRT
2014-01-17 14:40 - 2013-04-10 18:01 - 86054176 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-01-15 13:52 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\WinStore
2014-01-12 15:12 - 2013-04-10 21:49 - 00000000 ____D C:\Users\Robert\AppData\Roaming\Spotify
2014-01-12 13:31 - 2014-01-12 13:10 - 00000000 ____D C:\ProgramData\BlueStacksSetup
2014-01-11 22:35 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\NDF
2014-01-11 22:31 - 2013-10-21 17:47 - 00000000 ____D C:\Users\Robert\AppData\Roaming\vlc
2014-01-11 20:28 - 2013-04-12 19:48 - 00000000 ____D C:\Users\Robert\AppData\Roaming\XBMC
2014-01-11 15:26 - 2014-01-11 15:26 - 00000000 ____D C:\Users\Public\Foxit Software
2014-01-11 15:25 - 2013-04-19 16:31 - 00000000 ____D C:\Users\Robert\AppData\Roaming\Foxit Software
2014-01-11 13:36 - 2013-04-10 19:02 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2014-01-11 13:31 - 2013-08-18 11:51 - 00000000 ____D C:\Program Files (x86)\Origin
2014-01-11 12:47 - 2014-01-09 14:22 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-01-10 14:02 - 2013-04-11 12:53 - 00000000 ____D C:\Users\Robert\AppData\Local\Spotify
2014-01-10 13:29 - 2014-01-10 13:16 - 00000000 ____D C:\Users\Robert\AppData\Local\Rogue Amoeba
2014-01-10 13:16 - 2014-01-10 13:16 - 00000000 ____D C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Airfoil
2014-01-10 13:16 - 2014-01-10 13:16 - 00000000 ____D C:\Program Files (x86)\Airfoil
2014-01-10 13:15 - 2014-01-10 13:10 - 00004100 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1966479420-4144997280-1241761937-1001UA
2014-01-10 13:15 - 2014-01-10 13:10 - 00003720 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1966479420-4144997280-1241761937-1001Core
2014-01-10 13:10 - 2014-01-10 13:10 - 00000000 ____D C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Music Manager
2014-01-10 12:53 - 2013-04-10 17:21 - 00000000 ____D C:\Users\Robert\AppData\Local\Packages
2014-01-09 17:43 - 2014-01-09 17:43 - 00000000 ____D C:\Program Files (x86)\RootClockworkMod
2014-01-09 17:40 - 2014-01-09 17:40 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_WinUSB_01009.Wdf
2014-01-09 17:26 - 2014-01-07 15:57 - 00000000 ____D C:\Program Files\Recuva
2014-01-09 17:06 - 2014-01-09 17:05 - 00000000 ____D C:\Program Files (x86)\PdaNet for Android
2014-01-09 16:32 - 2014-01-09 16:32 - 00000000 ____D C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wugs Nexus Root Tookit
2014-01-09 16:32 - 2014-01-09 16:32 - 00000000 ____D C:\Users\Robert\.android
2014-01-09 16:32 - 2014-01-09 16:32 - 00000000 ____D C:\Program Files (x86)\WugFresh Development
2014-01-09 14:31 - 2014-01-09 14:23 - 00000000 ____D C:\Users\Robert\AppData\Roaming\Apple Computer
2014-01-09 14:23 - 2014-01-09 14:23 - 00000000 ____D C:\Users\Robert\AppData\Local\Apple Computer
2014-01-09 14:22 - 2014-01-09 14:22 - 00000000 ____D C:\Users\Robert\AppData\Local\Apple
2014-01-09 14:22 - 2014-01-09 14:22 - 00000000 ____D C:\ProgramData\Apple Computer
2014-01-09 14:22 - 2014-01-09 14:21 - 00000000 ____D C:\ProgramData\Apple
2014-01-09 14:21 - 2014-01-09 14:21 - 00000000 ____D C:\Program Files\Bonjour
2014-01-09 14:21 - 2014-01-09 14:21 - 00000000 ____D C:\Program Files (x86)\Bonjour
2014-01-09 11:46 - 2013-12-23 19:10 - 00439648 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswndisflt.sys
2014-01-06 23:31 - 2013-08-22 16:38 - 00693240 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-01-06 23:31 - 2013-08-22 16:38 - 00105464 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-01-05 18:19 - 2014-01-05 18:19 - 00000000 ___RD C:\Program Files (x86)\Skype
2014-01-05 18:19 - 2014-01-05 18:19 - 00000000 ____D C:\ProgramData\Skype
2014-01-03 17:50 - 2014-01-02 22:04 - 00000000 ____D C:\Users\Robert\AppData\Roaming\Battle.net
2014-01-03 17:01 - 2014-01-02 22:03 - 00000000 ____D C:\ProgramData\Battle.net
2014-01-02 22:04 - 2014-01-02 22:04 - 00000000 ____D C:\Users\Robert\AppData\Local\Blizzard Entertainment
2014-01-02 22:04 - 2014-01-02 22:04 - 00000000 ____D C:\ProgramData\Blizzard Entertainment
2013-12-30 16:56 - 2013-10-30 11:38 - 00000000 ___HD C:\jexepackres
Some content of TEMP:
====================
C:\Users\Robert\AppData\Local\Temp\Foxit Reader Updater.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-27 13:14
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
Addition: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-01-2014 02
Ran by Robert at 2014-01-28 13:22:14
Running from D:\Robert\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Internet Security (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Internet Security (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Internet Security (Enabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
==================== Installed Programs ======================
7-Zip 9.20 (x64 edition) (Version: 9.20.00.0 - Igor Pavlov)
Airfoil (x32 Version: 3.5.3 - Rogue Amoeba)
AMD Accelerated Video Transcoding (Version: 13.15.100.30830 - Advanced Micro Devices, Inc.) Hidden
AMD APP SDK Runtime (Version: 10.0.1084.4 - Advanced Micro Devices Inc.) Hidden
AMD Catalyst Control Center (x32 Version: 2013.0830.1944.33589 - Ihr Firmenname) Hidden
avast! Internet Security (x32 Version: 9.0.2011 - Avast Software)
Battle.net (x32 Version: - Blizzard Entertainment)
Battlefield 3™ (x32 Version: 1.6.0.0 - Electronic Arts)
Bonjour (Version: 3.0.0.10 - Apple Inc.)
Broadcom 802.11 Network Adapter (Version: 5.60.48.35 - Broadcom Corporation)
calibre (x32 Version: 1.3.0 - Kovid Goyal)
Canon IJ Network Scan Utility (x32 Version: - )
Canon IJ Network Tool (x32 Version: - )
Canon MG5200 series Benutzerregistrierung (x32 Version: - )
Canon MG5200 series MP Drivers (Version: - )
Canon MP Navigator EX 4.0 (x32 Version: - )
Canon My Printer (x32 Version: - )
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2013.0830.1944.33589 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2013.0830.1944.33589 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2013.0830.1944.33589 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (x32 Version: 2013.0830.1943.33589 - Advanced Micro Devices, Inc.) Hidden
ccc-utility64 (Version: 2013.0830.1944.33589 - Advanced Micro Devices, Inc.) Hidden
CCleaner (Version: 4.08 - Piriform)
Cisco AnyConnect Secure Mobility Client (x32 Version: 3.1.05152 - Cisco Systems, Inc.)
Cisco AnyConnect Secure Mobility Client (x32 Version: 3.1.05152 - Cisco Systems, Inc.) Hidden
CloudReading (x32 Version: 1.1.47.1220 - Foxit Corporation)
Creo Direct Version 2.0 Datecode [F001] (x32 Version: - PTC)
Creo Help Version 2.0 Datecode [M040] (x32 Version: 2.0 - PTC)
Creo Parametric Version 2.0 Datecode [F001] (x32 Version: - PTC)
Creo Platform 2.6 (x32 Version: 2.6.0 - PTC)
Creo Simulate Version 2.0 Datecode [F001] (x32 Version: - PTC)
Creo Thumbnail Viewer 2.0 (Version: 30.12.060 - PTC)
Cube World version 0.0.1 (x32 Version: 0.0.1 - Picroma)
Dead Space™ 3 (x32 Version: 1.0.0.0 - Electronic Arts, Inc.)
Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition (Version: - Microsoft)
Definition Update for Microsoft Office 2013 (KB2760587) 64-Bit Edition (Version: - Microsoft)
Diablo III (x32 Version: - Blizzard Entertainment)
Dropbox (HKCU Version: 2.4.11 - Dropbox, Inc.)
ESN Sonar (x32 Version: 0.70.4 - ESN Social Software AB)
Far Cry 3 (x32 Version: 1.05 - Ubisoft)
FIFA 14 (x32 Version: 1.0.0.4 - Electronic Arts)
Flatcast Viewer Plugin 5.3.0.784 (x32 Version: - 1 mal 1 Software GmbH)
foobar2000 v1.2.4 (x32 Version: 1.2.4 - Peter Pawlowski)
Foxit Reader (x32 Version: 6.1.2.1224 - Foxit Corporation)
Fraps (x32 Version: - )
FreeMind (x32 Version: 0.9.0 - )
Google Calendar Sync (x32 Version: - )
Google Chrome (x32 Version: 32.0.1700.102 - Google Inc.)
Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) Hidden
ImgBurn (x32 Version: 2.5.8.0 - LIGHTNING UK!)
Intel(R) Rapid Storage Technology (x32 Version: 9.5.6.1001 - Intel Corporation)
IrfanView (remove only) (x32 Version: 4.36 - Irfan Skiljan)
Java 7 Update 51 (x32 Version: 7.0.510 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
JDownloader 0.9 (x32 Version: 0.9 - AppWork GmbH)
LAV Filters 0.56.2 (x32 Version: 0.56.2 - Hendrik Leppkes)
Logitech Harmony Remote Software 7 (x32 Version: 7.7.0.0 - Logitech)
Logitech Harmony Remote Software 7 (x32 Version: 7.7.0.0 - Logitech) Hidden
LS-DYNA (x32 Version: - )
LS-PrePost-4.0-X64 (x32 Version: 4.0 - Livermore Software Technology Corporation)
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300 - Malwarebytes Corporation)
MediaMonkey 4.0 (x32 Version: 4.0 - Ventis Media Inc.)
MediaPortal (x32 Version: 1.3.0 - Team MediaPortal)
Microsoft Office 32-bit Components 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Korrekturhilfen 2013 - Deutsch (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office Office 32-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OSM MUI (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2010 (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2013 - English (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2013 - Italiano (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 32-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 32-bit MUI (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft SkyDrive (HKCU Version: 17.0.2015.0811 - Microsoft Corporation)
Microsoft Visio MUI (German) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Visio Professional 2013 (Version: 15.0.4420.1017 - Microsoft Corporation)
Microsoft Visio Professional 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (x32 Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
Mirror's Edge (x32 Version: - DICE)
MKS Platform Components 9.x (Version: 9.3.0000 - Mortice Kern Systems)
MKVToolNix 6.1.0 (x32 Version: 6.1.0 - Moritz Bunkus)
Mp3tag v2.55a (x32 Version: v2.55a - Florian Heidenreich)
Music Manager (HKCU Version: - Google, Inc.)
MusicBrainz Picard (x32 Version: 1.2 - MusicBrainz)
Nexus Mod Manager (Version: 0.44.10 - Black Tree Gaming)
Notepad++ (x32 Version: 6.3.3 - Notepad++ Team)
NVIDIA PhysX v8.10.17 (x32 Version: 8.10.17 - NVIDIA Corporation)
Origin (x32 Version: 9.3.1.4482 - Electronic Arts, Inc.)
Outils de vérification linguistique 2013 de Microsoft Office*- Français (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Paint.NET v3.5.11 (Version: 3.61.0 - dotPDN LLC)
PDF24 Creator 5.4.0 (x32 Version: - PDF24.org)
PFPortChecker 1.0.39 (x32 Version: 1.0.39 - Portforward.com)
PTC Portmapper Version 2.0 Datecode [F001] (x32 Version: - PTC)
PTC Quality Agent (x32 Version: 2.0.0.0 - PTC)
PunkBuster Services (x32 Version: 0.991 - Even Balance, Inc.)
Realtek HDMI Audio Driver for ATI (x32 Version: 6.0.1.6650 - Realtek Semiconductor Corp.)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6873 - Realtek Semiconductor Corp.)
Remote Control USB Driver (x32 Version: 2.3.2.317 - )
Room EQ Wizard V5 (x32 Version: - John Mulcahy)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version: - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version: - Microsoft) Hidden
Skype™ 6.11 (x32 Version: 6.11.102 - Skype Technologies S.A.)
Spotify (HKCU Version: 0.9.6.81.gd359a796 - Spotify AB)
Steam (x32 Version: 1.0.0.0 - Valve Corporation)
Synaptics Pointing Device Driver (Version: 14.0.6.0 - Synaptics Incorporated)
TeamViewer 9 (x32 Version: 9.0.24951 - TeamViewer)
The Elder Scrolls V: Skyrim (x32 Version: - Bethesda Game Studios)
The Lord of the Rings: War in the North (x32 Version: - Snowblind Studios)
Universal Adb Driver (x32 Version: 1.0.0 - ClockworkMod)
Update for Microsoft Access 2010 (KB2553446) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2810071) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2553092) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2825640) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2826026) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2013 (KB2726954) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2013 (KB2726996) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2013 (KB2738038) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2013 (KB2760224) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2013 (KB2760242) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2013 (KB2760267) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2013 (KB2760610) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2013 (KB2767845) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2013 (KB2768016) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2013 (KB2817490) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2013 (KB2817626) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2013 (KB2826004) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2013 (KB2827225) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2013 (KB2827227) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2013 (KB2827230) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2013 (KB2827239) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2013 (KB2837626) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2013 (KB2837637) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2013 (KB2837638) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2013 (KB2837655) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2013 (KB2850066) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft OneNote 2010 (KB2810072) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft OneNote 2013 (KB2850063) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Outlook 2013 (KB2850061) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2553145) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Project 2013 (KB2727085) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft SkyDrive Pro (KB2817495) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft SkyDrive Pro (KB2837652) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Visio 2013 (KB2817306) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Visio Viewer 2010 (KB2810066) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Visio Viewer 2013 (KB2768338) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Word 2010 (KB2837593) 64-Bit Edition (Version: - Microsoft)
Uplay (x32 Version: 2.1 - Ubisoft)
VLC media player 2.1.0 (Version: 2.1.0 - VideoLAN)
War Thunder (x32 Version: - Gaijin Entertainment)
XBMC (HKCU Version: - Team XBMC)
==================== Restore Points =========================
18-01-2014 16:32:48 Installed Java 7 Update 51
26-01-2014 15:20:23 Geplanter Prüfpunkt
28-01-2014 10:16:36 Entfernt Harmony Browser Plug-in
==================== Hosts content: ==========================
2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask
Task: {058B441A-59B6-4191-ACFC-068B6CC1376D} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2012-10-01] (Microsoft Corporation)
Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation)
Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation)
Task: {44B692B9-1727-40B9-A70E-63224F7694A5} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2014-01-17] (Microsoft Corporation)
Task: {4600BC8E-7545-42F6-85FD-07044CE191BB} - System32\Tasks\Microsoft SkyDrive Auto Update Task-S-1-5-21-1966479420-4144997280-1241761937-1001 => %localappdata%\Microsoft\SkyDrive\SkyDrive.exe
Task: {473243AD-5AFD-449D-9FC7-0D1B6E62857D} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1966479420-4144997280-1241761937-1001Core => C:\Users\Robert\AppData\Local\Google\Update\GoogleUpdate.exe [2014-01-10] (Google Inc.)
Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance
Task: {550256CC-10F6-4761-8AA7-AD9150732FF5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-01-28] (Google Inc.)
Task: {58E9384C-CD98-40DB-ACF2-4CE370BDFFED} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup
Task: {6AAC91E5-E578-4E47-B7D7-92B04925E46A} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-12-22] (AVAST Software)
Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task
Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {83094D2C-5776-492E-80DA-9B7389C61E5F} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1966479420-4144997280-1241761937-1001UA => C:\Users\Robert\AppData\Local\Google\Update\GoogleUpdate.exe [2014-01-10] (Google Inc.)
Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task
Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work
Task: {A43A3B6F-5752-45B3-A544-4973B4735E29} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
Task: {AFD85AEC-EBEF-408E-A8E1-0F72F875CF1D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-11-22] (Piriform Ltd)
Task: {B8C3537C-3A2E-4B90-A8EA-A1631FCC9464} - System32\Tasks\Microsoft Office 15 Sync Maintenance for ROBERT-LAPTOP-Robert Robert-Laptop => C:\Program Files\Microsoft Office\Office15\MsoSync.exe [2013-09-10] (Microsoft Corporation)
Task: {C96C7F11-6DE1-4349-AD17-5177F18061FE} - System32\Tasks\APM_off => D:\Robert\FestplWD\hdparm.exe [2007-02-24] ()
Task: {CB0BBA49-A498-4B66-A3F5-59BED0688CD6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-01-28] (Google Inc.)
Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask
Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization
Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1966479420-4144997280-1241761937-1001Core.job => C:\Users\Robert\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1966479420-4144997280-1241761937-1001UA.job => C:\Users\Robert\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2012-06-18 16:24 - 2012-06-18 16:24 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_05.dll
2013-11-20 13:27 - 2013-11-20 13:27 - 00183808 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20315_x64__8wekyb3d8bbwe\ErrorReporting.dll
2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\office14\Cultures\office.odf
2010-10-20 14:19 - 2010-10-20 14:19 - 00166240 _____ () C:\Program Files\Microsoft Office\Office14\OUTLCTL.DLL
2014-01-10 16:00 - 2014-01-10 16:00 - 05179392 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.UI.Xaml\1a4edd280e2cfb782141cf02237ae00c\Windows.UI.Xaml.ni.dll
2013-10-20 17:39 - 2013-10-20 17:39 - 01782272 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.App640a3541#\600862031eb4d4cfdc6f4d2025a7990e\Windows.ApplicationModel.ni.dll
2013-10-20 17:39 - 2013-10-20 17:39 - 01278464 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Storage\4c323000d6c8d1d462abb0968333c937\Windows.Storage.ni.dll
2013-10-20 17:39 - 2013-10-20 17:39 - 00363520 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Foundation\432868bf54b081b16eaf68729020b30a\Windows.Foundation.ni.dll
2014-01-10 16:00 - 2014-01-10 16:00 - 00632320 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Security\4f00f54318cefa03d2a77a61e842ffca\Windows.Security.ni.dll
2014-01-10 16:00 - 2014-01-10 16:00 - 00467456 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Graphics\e06f4482547bc7feaa453c9e02585f52\Windows.Graphics.ni.dll
2013-10-20 17:39 - 2013-10-20 17:39 - 00207872 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.System\e8f8737bea4f0df4b88bbc4bf24fa2a8\Windows.System.ni.dll
2013-10-20 17:39 - 2013-10-20 17:39 - 02019840 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Devices\aaa76dfc70840ddd1028b4e1783ec5aa\Windows.Devices.ni.dll
2013-10-20 17:39 - 2013-10-20 17:39 - 01459712 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.UI\0ff25bd7c20be35c2e915bb82db13b72\Windows.UI.ni.dll
2013-10-20 17:39 - 2013-10-20 17:39 - 00521216 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Data\4e1b0dc15d072d992e08612cd74a34db\Windows.Data.ni.dll
2014-01-10 16:00 - 2014-01-10 16:00 - 00347136 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Gloaae92e31#\e0e7493cf161f0e0899caa7eb5e0e259\Windows.Globalization.ni.dll
2013-10-20 17:39 - 2013-10-20 17:39 - 01259520 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Networking\45eee6d0ec199bb4a183edf3d8f2370f\Windows.Networking.ni.dll
2014-01-12 13:19 - 2014-01-12 13:19 - 01187328 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Media\298707df029c6c37394d58686b459e67\Windows.Media.ni.dll
2013-12-12 23:36 - 2013-12-12 23:36 - 00063376 _____ () C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\zlib1.dll
2014-01-26 16:30 - 2014-01-26 11:54 - 02166272 _____ () C:\Program Files\AVAST Software\Avast\defs\14012600\algo.dll
2014-01-28 11:20 - 2014-01-28 10:06 - 02166272 _____ () C:\Program Files\AVAST Software\Avast\defs\14012800\algo.dll
2013-04-11 16:58 - 2009-12-23 16:32 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2013-02-27 20:33 - 2013-02-27 20:33 - 10683392 _____ () C:\Users\Robert\AppData\Local\Programs\Google\MusicManager\QtWebKit4.dll
2013-02-27 20:32 - 2013-02-27 20:32 - 07741952 _____ () C:\Users\Robert\AppData\Local\Programs\Google\MusicManager\QtGui4.dll
2013-02-27 20:33 - 2013-02-27 20:33 - 01681408 _____ () C:\Users\Robert\AppData\Local\Programs\Google\MusicManager\QtNetwork4.dll
2013-02-27 20:32 - 2013-02-27 20:32 - 02248192 _____ () C:\Users\Robert\AppData\Local\Programs\Google\MusicManager\QtCore4.dll
2013-11-12 02:03 - 2013-11-12 02:03 - 00117248 _____ () C:\Users\Robert\AppData\Local\Programs\Google\MusicManager\libaacdec.dll
2013-11-12 02:04 - 2013-11-12 02:04 - 00231936 _____ () C:\Users\Robert\AppData\Local\Programs\Google\MusicManager\libmpgdec.dll
2013-11-12 02:03 - 2013-11-12 02:03 - 00253440 _____ () C:\Users\Robert\AppData\Local\Programs\Google\MusicManager\libid3tag.dll
2013-11-12 02:05 - 2013-11-12 02:05 - 00344064 _____ () C:\Users\Robert\AppData\Local\Programs\Google\MusicManager\libaudioenc.dll
2013-02-27 20:33 - 2013-02-27 20:33 - 00026624 _____ () C:\Users\Robert\AppData\Local\Programs\Google\MusicManager\imageformats\qgif4.dll
2013-12-22 20:05 - 2013-12-22 20:05 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2013-11-09 08:55 - 2013-11-09 08:55 - 00175176 _____ () C:\Program Files (x86)\Airfoil\AirfoilInject3.dll
2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: vpnva
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Could not start eventlog service, could not read events.
==================== Memory info ===========================
Percentage of memory in use: 79%
Total physical RAM: 4028.49 MB
Available physical RAM: 811.38 MB
Total Pagefile: 6972.49 MB
Available Pagefile: 3113.95 MB
Total Virtual: 131072 MB
Available Virtual: 131071.79 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:119.14 GB) (Free:51.45 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: () (Fixed) (Total:596.17 GB) (Free:218.12 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 119 GB) (Disk ID: 53F07522)
Partition 1: (Active) - (Size=119 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 596 GB) (Disk ID: 8F7EF934)
Partition 1: (Active) - (Size=596 GB) - (Type=07 NTFS)
==================== End Of Log ============================ |