th3falc0n | 01.12.2014 14:05 | Hallo Lieber schrauber,
hab soweit alles durch. Problem besteht weiterhin.
Die beiden Toolbars wurden bereits durch AdwCleaner beseitigt, und ich habe noch ein wenig weiter aufgeräumt um die Programmliste ein wenig kleiner zu bekommen ;)
Hier das Combofix-Log und FRST einmal neu:
Combofix: Code:
ComboFix 14-12-01.01 - Fabian 01.12.2014 13:49:34.1.8 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.16332.12961 [GMT 1:00]
ausgeführt von:: c:\users\Fabian\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859}
SP: Avira Desktop *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Fabian\AppData\Local\TempDIR
c:\users\Fabian\AppData\Roaming\Love
c:\users\Fabian\AppData\Roaming\Love\mari0\options.txt
c:\users\Fabian\AppData\Roaming\Love\ortho_robot\save.txt
c:\users\Fabian\AppData\Roaming\mIRC\logs\status.log
c:\users\Fabian\AppData\Roaming\poclbm
c:\users\Fabian\AppData\Roaming\poclbm\poclbm.ini
c:\users\Fabian\AppData\Roaming\poclbm\poclbm_scrypt.ini
c:\users\Fabian\AppData\Roaming\technic-launcher.jar
c:\windows\Downloaded Program Files\IDropPTB.dll
c:\windows\SysWow64\ccrpTmr6.dll
c:\windows\SysWow64\DEBUG.log
f:\temp\_MEI50842\_ctypes.pyd
f:\temp\_MEI50842\_elementtree.pyd
f:\temp\_MEI50842\_hashlib.pyd
f:\temp\_MEI50842\_multiprocessing.pyd
f:\temp\_MEI50842\_socket.pyd
f:\temp\_MEI50842\_ssl.pyd
f:\temp\_MEI50842\hashobjs_ext.pyd
f:\temp\_MEI50842\pyexpat.pyd
f:\temp\_MEI50842\pysqlite2._sqlite.pyd
f:\temp\_MEI50842\python27.dll
f:\temp\_MEI50842\pythoncom27.dll
f:\temp\_MEI50842\PyWinTypes27.dll
f:\temp\_MEI50842\select.pyd
f:\temp\_MEI50842\unicodedata.pyd
f:\temp\_MEI50842\win32api.pyd
f:\temp\_MEI50842\win32com.shell.shell.pyd
f:\temp\_MEI50842\win32crypt.pyd
f:\temp\_MEI50842\win32event.pyd
f:\temp\_MEI50842\win32file.pyd
f:\temp\_MEI50842\win32gui.pyd
f:\temp\_MEI50842\win32inet.pyd
f:\temp\_MEI50842\win32pdh.pyd
f:\temp\_MEI50842\win32pipe.pyd
f:\temp\_MEI50842\win32process.pyd
f:\temp\_MEI50842\win32profile.pyd
f:\temp\_MEI50842\win32security.pyd
f:\temp\_MEI50842\win32ts.pyd
f:\temp\_MEI50842\windows._lib_cacheinvalidation.pyd
f:\temp\_MEI50842\wx._animate.pyd
f:\temp\_MEI50842\wx._controls_.pyd
f:\temp\_MEI50842\wx._core_.pyd
f:\temp\_MEI50842\wx._gdi_.pyd
f:\temp\_MEI50842\wx._html2.pyd
f:\temp\_MEI50842\wx._misc_.pyd
f:\temp\_MEI50842\wx._windows_.pyd
f:\temp\_MEI50842\wx._wizard.pyd
f:\temp\_MEI50842\wxbase294u_net_vc90.dll
f:\temp\_MEI50842\wxbase294u_vc90.dll
f:\temp\_MEI50842\wxmsw294u_adv_vc90.dll
f:\temp\_MEI50842\wxmsw294u_core_vc90.dll
f:\temp\_MEI50842\wxmsw294u_html_vc90.dll
f:\temp\_MEI50842\wxmsw294u_webview_vc90.dll
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-11-01 bis 2014-12-01 ))))))))))))))))))))))))))))))
.
.
2074-05-07 16:38 . 2006-11-21 18:48 203576 ------w- c:\program files (x86)\Microsoft Games\Age of Empires III\autopatcher2.exe
2014-12-01 12:21 . 2014-12-01 12:21 -------- d-----w- c:\program files (x86)\VS Revo Group
2014-11-30 15:19 . 2014-11-30 15:45 -------- d-----w- C:\AdwCleaner
2014-11-30 14:35 . 2014-11-30 14:42 -------- d-----w- C:\FRST
2014-11-30 14:18 . 2014-12-01 12:47 129752 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-11-30 14:18 . 2014-11-30 14:18 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware
2014-11-30 14:18 . 2014-11-30 14:18 -------- d-----w- c:\programdata\Malwarebytes
2014-11-30 14:18 . 2014-10-01 10:11 63704 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-11-30 14:18 . 2014-10-01 10:11 93400 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-11-30 14:18 . 2014-10-01 10:11 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-11-30 12:58 . 2013-11-25 08:28 41392 ----a-w- c:\windows\system32\drivers\nbdrv.sys
2014-11-30 11:42 . 2013-01-28 12:21 393728 ----a-w- c:\program files (x86)\Windows Media Player\Plugins\wmp_scrobbler.dll
2014-11-30 11:42 . 2014-11-30 11:42 -------- d-----w- c:\programdata\Last.fm
2014-11-30 11:40 . 2014-12-01 12:43 -------- d-----w- c:\users\Fabian\AppData\Local\Last.fm
2014-11-30 11:40 . 2014-11-30 11:40 -------- d-----w- c:\program files (x86)\Last.fm
2014-11-30 03:07 . 2014-11-30 03:07 -------- d-----w- C:\SymCache
2014-11-30 03:04 . 2014-11-30 03:04 -------- d-----w- c:\program files\Microsoft Windows Performance Toolkit
2014-11-30 02:57 . 2014-11-30 02:57 -------- d-----w- c:\program files\Debugging Tools for Windows (x64)
2014-11-30 02:29 . 2013-10-21 11:26 25504 ----a-w- c:\windows\system32\drivers\rspLLL64.sys
2014-11-29 20:15 . 2014-11-30 13:01 -------- d-----w- c:\program files\Wippien
2014-11-29 20:15 . 2014-11-30 13:01 -------- d-----w- c:\users\Fabian\AppData\Roaming\Wippien
2014-11-29 20:15 . 2011-04-23 19:30 33160 ----a-w- c:\windows\system32\drivers\wod0205.sys
2014-11-29 19:22 . 2014-11-29 19:22 -------- d-----w- C:\SUPERDelete
2014-11-29 19:21 . 2014-12-01 12:46 -------- d-----w- c:\program files\SUPERAntiSpyware
2014-11-29 13:14 . 2014-11-30 13:55 215416 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2014-11-29 13:14 . 2014-11-29 13:14 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2014-11-28 23:29 . 2014-11-28 23:29 -------- d-----w- c:\users\Fabian\AppData\Local\PAYDAY 2
2014-11-28 23:28 . 2014-11-28 23:28 -------- d-----w- c:\program files (x86)\AGEIA Technologies
2014-11-28 11:09 . 2014-11-28 11:09 -------- d-----w- c:\users\Fabian\AppData\Local\PopCap Games
2014-11-28 11:09 . 2014-11-28 11:09 -------- d-----w- c:\programdata\EA Core
2014-11-28 10:36 . 2014-11-28 11:09 -------- d-----w- c:\programdata\EA Logs
2014-11-27 21:17 . 2014-11-30 16:45 76152 ----a-w- c:\windows\system32\PnkBstrA.exe
2014-11-27 21:02 . 2014-11-27 21:02 -------- d-----w- c:\users\Fabian\AppData\Local\ESN
2014-11-27 20:32 . 2014-11-28 10:39 -------- d-----w- c:\program files (x86)\Battlelog Web Plugins
2014-11-22 21:44 . 2014-11-23 14:42 -------- d-----w- c:\users\Fabian\Zomboid
2014-11-22 00:56 . 2014-11-22 00:56 -------- d-----w- c:\windows\SysWow64\Wat
2014-11-22 00:56 . 2014-11-22 00:56 -------- d-----w- c:\windows\system32\Wat
2014-11-19 08:39 . 2014-11-11 03:08 241152 ----a-w- c:\windows\system32\pku2u.dll
2014-11-19 08:39 . 2014-11-11 03:08 728064 ----a-w- c:\windows\system32\kerberos.dll
2014-11-19 08:39 . 2014-11-11 02:44 186880 ----a-w- c:\windows\SysWow64\pku2u.dll
2014-11-19 08:39 . 2014-11-11 02:44 550912 ----a-w- c:\windows\SysWow64\kerberos.dll
2014-11-17 19:11 . 2014-11-17 19:11 -------- d-----w- c:\users\Fabian\AppData\Roaming\java
2014-11-17 19:11 . 2014-11-29 21:19 -------- d-----w- c:\users\Fabian\AppData\Roaming\.minecraft
2014-11-12 08:37 . 2014-11-05 17:56 304640 ----a-w- c:\windows\system32\generaltel.dll
2014-11-12 08:37 . 2014-11-05 17:56 228864 ----a-w- c:\windows\system32\aepdu.dll
2014-11-12 08:37 . 2014-11-05 17:52 424448 ----a-w- c:\windows\system32\aeinv.dll
2014-11-12 08:37 . 2014-10-14 02:16 155064 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2014-11-12 08:37 . 2014-10-14 02:13 683520 ----a-w- c:\windows\system32\termsrv.dll
2014-11-12 08:37 . 2014-10-14 02:07 681984 ----a-w- c:\windows\system32\adtschema.dll
2014-11-12 08:37 . 2014-10-14 01:46 681984 ----a-w- c:\windows\SysWow64\adtschema.dll
2014-11-12 08:37 . 2014-10-14 02:12 1460736 ----a-w- c:\windows\system32\lsasrv.dll
2014-11-12 08:37 . 2014-10-14 02:09 146432 ----a-w- c:\windows\system32\msaudite.dll
2014-11-12 08:37 . 2014-10-14 01:50 22016 ----a-w- c:\windows\SysWow64\secur32.dll
2014-11-12 08:37 . 2014-10-14 01:49 96768 ----a-w- c:\windows\SysWow64\sspicli.dll
2014-11-12 08:37 . 2014-10-14 01:47 146432 ----a-w- c:\windows\SysWow64\msaudite.dll
2014-11-07 08:44 . 2014-11-07 08:44 -------- d-----w- c:\windows\SysWow64\tmp7xzots
2014-11-04 23:45 . 2014-11-04 23:45 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi
2014-11-01 21:53 . 2014-11-01 21:53 -------- d-----w- c:\users\Fabian\AppData\Roaming\HeroesAndGeneralsDesktop
2014-11-01 18:18 . 2014-11-01 18:18 -------- d-----w- c:\program files\x264vfw64
2014-11-01 18:15 . 2014-11-01 18:15 -------- d-----w- C:\Autodesk
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-12-01 08:23 . 2014-10-14 12:15 163504 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10145.bin
2014-11-30 13:58 . 2013-05-02 13:24 43064 ----a-w- c:\windows\system32\drivers\avnetflt.sys
2014-11-30 13:58 . 2013-03-21 15:49 131608 ----a-w- c:\windows\system32\drivers\avipbb.sys
2014-11-30 13:58 . 2013-03-21 15:49 119272 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2014-11-30 13:51 . 2012-03-27 15:00 215416 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2014-11-29 19:13 . 2014-04-15 13:09 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2014-11-26 16:24 . 2012-04-21 08:06 701104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-11-26 16:24 . 2011-12-29 13:02 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-11-12 21:44 . 2012-01-13 18:50 2354848 ----a-w- c:\programdata\Microsoft\VisualStudio\10.0\1033\ResourceCache.dll
2014-11-12 21:44 . 2011-12-30 10:36 2393664 ----a-w- c:\programdata\Microsoft\VisualStudio\10.0\1031\ResourceCache.dll
2014-11-12 21:39 . 2011-12-29 10:39 103374192 ----a-w- c:\windows\system32\MRT.exe
2014-10-02 12:23 . 2014-10-02 12:23 94208 ----a-w- c:\windows\SysWow64\QuickTimeVR.qtx
2014-10-02 12:23 . 2014-10-02 12:23 69632 ----a-w- c:\windows\SysWow64\QuickTime.qts
2014-09-25 02:08 . 2014-10-01 08:17 371712 ----a-w- c:\windows\system32\qdvd.dll
2014-09-25 01:40 . 2014-10-01 08:17 519680 ----a-w- c:\windows\SysWow64\qdvd.dll
2014-09-11 08:50 . 2014-09-11 08:50 27552 ----a-w- c:\windows\system32\drivers\HWiNFO64A.SYS
2014-09-09 22:11 . 2014-09-24 11:27 2048 ----a-w- c:\windows\system32\tzres.dll
2014-09-09 21:47 . 2014-09-24 11:27 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2014-09-04 05:23 . 2014-10-15 10:19 424448 ----a-w- c:\windows\system32\rastls.dll
2014-09-04 05:04 . 2014-10-15 10:19 372736 ----a-w- c:\windows\SysWow64\rastls.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 64792 ----a-w- c:\program files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="j:\steam\steam.exe" [2014-11-18 1940160]
"DisplayFusion"="c:\program files (x86)\DisplayFusion\DisplayFusion.exe" [2014-09-09 8854880]
"GoogleDriveSync"="c:\program files (x86)\Google\Drive\googledrivesync.exe" [2014-10-21 22869088]
"Speech Recognition"="c:\windows\Speech\Common\sapisvr.exe" [2009-07-14 44544]
"puush"="c:\program files (x86)\puush\puush.exe" [2014-09-06 567880]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2014-10-01 22065760]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2014-11-30 703736]
"USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2013-02-22 292088]
"ControlCenterCount"="c:\program files (x86)\MSI\ControlCenter\ControlCenterCount.exe" [2012-03-26 872448]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2014-04-17 767200]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2014-09-12 959176]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2014-10-15 157480]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2014-10-02 421888]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2014-11-03 3835728]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Autodesk Sync"="c:\program files\Autodesk\Autodesk Sync\AdSync.exe" [2014-05-14 1208712]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
"DisableCAD"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\userinit.exe,c:\users\Fabian\AppData\Roaming\appconf32.exe,"
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli c:\program files\Protector Suite\psqlpwd.dll
.
R1 ArcSec;ArcSec;c:\windows\system32\drivers\ArcSec.sys;c:\windows\SYSNATIVE\drivers\ArcSec.sys [x]
R1 hwinterfacex64;hwinterfacex64;c:\windows\system32\Drivers\hwinterfacex64.sys;c:\windows\SYSNATIVE\Drivers\hwinterfacex64.sys [x]
R2 AntiVirMailService;Avira Email-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\avmailc7.exe;c:\program files (x86)\Avira\AntiVir Desktop\avmailc7.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 1394hub;1394 Enabled Hub;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
R3 ActionReplayDS;ActionReplayDS;c:\windows\system32\Drivers\ActionReplayDS_x64.sys;c:\windows\SYSNATIVE\Drivers\ActionReplayDS_x64.sys [x]
R3 andnetadb;ADB Interface DriverNet;c:\windows\system32\Drivers\lgandnetadb.sys;c:\windows\SYSNATIVE\Drivers\lgandnetadb.sys [x]
R3 AndNetDiag;LGE AndroidNet USB Serial Port;c:\windows\system32\DRIVERS\lgandnetdiag64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandnetdiag64.sys [x]
R3 ANDNetModem;LGE AndroidNet USB Modem;c:\windows\system32\DRIVERS\lgandnetmodem64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandnetmodem64.sys [x]
R3 andnetndis;LGE AndroidNet NDIS Ethernet Adapter;c:\windows\system32\DRIVERS\lgandnetndis64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandnetndis64.sys [x]
R3 atillk64;atillk64;c:\users\Fabian\Desktop\gBIOS\atillk64.sys;c:\users\Fabian\Desktop\gBIOS\atillk64.sys [x]
R3 BRDriver64;BRDriver64;c:\programdata\BitRaider\BRDriver64.sys;c:\programdata\BitRaider\BRDriver64.sys [x]
R3 cpuz135;cpuz135;c:\users\Fabian\AppData\Local\Temp\cpuz135\cpuz135_x64.sys;c:\users\Fabian\AppData\Local\Temp\cpuz135\cpuz135_x64.sys [x]
R3 cpuz136;cpuz136;c:\windows\TEMP\cpuz136\cpuz136_x64.sys;c:\windows\TEMP\cpuz136\cpuz136_x64.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 DrvAgent64;DrvAgent64;c:\windows\SysWOW64\Drivers\DrvAgent64.SYS;c:\windows\SysWOW64\Drivers\DrvAgent64.SYS [x]
R3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys;c:\windows\SYSNATIVE\Drivers\EtronHub3.sys [x]
R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys;c:\windows\SYSNATIVE\Drivers\EtronXHCI.sys [x]
R3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);c:\windows\system32\DRIVERS\vrtaucbl.sys;c:\windows\SYSNATIVE\DRIVERS\vrtaucbl.sys [x]
R3 GPUZ;GPUZ;c:\windows\TEMP\GPUZ.sys;c:\windows\TEMP\GPUZ.sys [x]
R3 hhdspmc64;HHD Software Serial Port Monitoring Control Filter Driver;c:\windows\system32\DRIVERS\hhdspmc64.sys;c:\windows\SYSNATIVE\DRIVERS\hhdspmc64.sys [x]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [x]
R3 INETMON;INETMON;c:\windows\System32\Drivers\INETMON.sys;c:\windows\SYSNATIVE\Drivers\INETMON.sys [x]
R3 ISCT;Intel(R) Smart Connect Technology Device Driver;c:\windows\system32\DRIVERS\ISCTD64.sys;c:\windows\SYSNATIVE\DRIVERS\ISCTD64.sys [x]
R3 iumsvc;Intel(R) Update Manager;c:\program files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe;c:\program files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [x]
R3 LADF_CaptureOnly;LADF Capture Filter Driver;c:\windows\system32\DRIVERS\ladfGSCamd64.sys;c:\windows\SYSNATIVE\DRIVERS\ladfGSCamd64.sys [x]
R3 LADF_RenderOnly;LADF Render Filter Driver;c:\windows\system32\DRIVERS\ladfGSRamd64.sys;c:\windows\SYSNATIVE\DRIVERS\ladfGSRamd64.sys [x]
R3 libusb0;LibUsb-Win32 - Kernel Driver 03/20/2007, 0.1.12.1;c:\windows\system32\DRIVERS\libusb0.sys;c:\windows\SYSNATIVE\DRIVERS\libusb0.sys [x]
R3 mc2avs;Maschine MK2 MIDI;c:\windows\system32\Drivers\mc2avs.sys;c:\windows\SYSNATIVE\Drivers\mc2avs.sys [x]
R3 mc2usb_svc;Maschine Controller MK2;c:\windows\system32\Drivers\mc2usb.sys;c:\windows\SYSNATIVE\Drivers\mc2usb.sys [x]
R3 NDMSHLP;Device Monitor Helper Driver;c:\program files (x86)\Common Files\HHD Software\Device Monitor\ndmshlp.sys;c:\program files (x86)\Common Files\HHD Software\Device Monitor\ndmshlp.sys [x]
R3 NIWinCDEmu;ISO Mounter driver;c:\windows\system32\DRIVERS\NIWinCDEmu.sys;c:\windows\SYSNATIVE\DRIVERS\NIWinCDEmu.sys [x]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des;c:\windows\SYSNATIVE\GameMon.des [x]
R3 NTIOLib_MSISMB_CC;NTIOLib_MSISMB_CC;c:\program files (x86)\MSI\ControlCenter\Sleep\NTIOLib_X64.sys;c:\program files (x86)\MSI\ControlCenter\Sleep\NTIOLib_X64.sys [x]
R3 okdmx31;OksiD DMX 3/1 interface;c:\windows\system32\Drivers\okdmx31.sys;c:\windows\SYSNATIVE\Drivers\okdmx31.sys [x]
R3 Origin Client Service;Origin Client Service;c:\program files (x86)\Origin\OriginClientService.exe;c:\program files (x86)\Origin\OriginClientService.exe [x]
R3 PCAMp50a64;PCAMp50a64 NDIS Protocol Driver;c:\windows\system32\Drivers\PCAMp50a64.sys;c:\windows\SYSNATIVE\Drivers\PCAMp50a64.sys [x]
R3 PCASp50a64;PCASp50a64 NDIS Protocol Driver;c:\windows\system32\Drivers\PCASp50a64.sys;c:\windows\SYSNATIVE\Drivers\PCASp50a64.sys [x]
R3 rspLLL;rspLLL;c:\windows\system32\DRIVERS\rspLLL64.sys;c:\windows\SYSNATIVE\DRIVERS\rspLLL64.sys [x]
R3 SaiK0CCB;SaiK0CCB;c:\windows\system32\DRIVERS\SaiK0CCB.sys;c:\windows\SYSNATIVE\DRIVERS\SaiK0CCB.sys [x]
R3 SaiU0CCB;SaiU0CCB;c:\windows\system32\DRIVERS\SaiU0CCB.sys;c:\windows\SYSNATIVE\DRIVERS\SaiU0CCB.sys [x]
R3 SCL01164;SCL011 Contactless Reader;c:\windows\system32\DRIVERS\SCL01164.sys;c:\windows\SYSNATIVE\DRIVERS\SCL01164.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 USBTINSP;TI-Nspire(TM) Handheld or TI Network Bridge Device Driver;c:\windows\system32\DRIVERS\tinspusb.sys;c:\windows\SYSNATIVE\DRIVERS\tinspusb.sys [x]
R3 VASDeviceDrm;Virtual Audio Streaming with Drm (WDM);c:\windows\system32\drivers\vasdDev.sys;c:\windows\SYSNATIVE\drivers\vasdDev.sys [x]
R3 VBoxUSB;VirtualBox USB;c:\windows\system32\Drivers\VBoxUSB.sys;c:\windows\SYSNATIVE\Drivers\VBoxUSB.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;c:\windows\system32\DRIVERS\WPN111vx.sys;c:\windows\SYSNATIVE\DRIVERS\WPN111vx.sys [x]
R3 X6va008;X6va008;c:\windows\SysWOW64\Drivers\X6va008;c:\windows\SysWOW64\Drivers\X6va008 [x]
R3 zlportio;zlportio;c:\program files (x86)\PHOENIXstudios\PC_DIMMER\zlportio.sys;c:\program files (x86)\PHOENIXstudios\PC_DIMMER\zlportio.sys [x]
R4 AdAppMgrSvc;Autodesk Application Manager Service;c:\program files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe ;c:\program files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [x]
R4 ADExchange;ArcSoft Exchange Service;c:\program files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe;c:\program files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe [x]
R4 Apache2.4;Apache2.4;f:\xampp\apache\bin\httpd.exe;f:\xampp\apache\bin\httpd.exe [x]
R4 ArcService;Arc Service;f:\arc\Arc\ArcService.exe;f:\arc\Arc\ArcService.exe [x]
R4 BRSptSvc;BitRaider Mini-Support Service;c:\programdata\BitRaider\BRSptSvc.exe;c:\programdata\BitRaider\BRSptSvc.exe [x]
R4 Desura Install Service;Desura Install Service;c:\program files (x86)\Common Files\Desura\desura_service.exe;c:\program files (x86)\Common Files\Desura\desura_service.exe [x]
R4 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x]
R4 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe [x]
R4 Icecast-trunk;Icecast-trunk Streaming Media Server;c:\program files (x86)\Icecast2 Win32\icecastService.exe;c:\program files (x86)\Icecast2 Win32\icecastService.exe [x]
R4 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;c:\program files\Intel\iCLS Client\SocketHeciServer.exe;c:\program files\Intel\iCLS Client\SocketHeciServer.exe [x]
R4 ISCTAgent;Intel(R) Smart Connect Technology Agent;c:\program files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe ;c:\program files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [x]
R4 mi-raysat_3dsmax2015_64;mental ray Satellite for Autodesk 3ds Max 2015 64-bit;j:\autodesk\3ds Max 2015\NVIDIA\Satellite\raysat_3dsmax2015_64server.exe;j:\autodesk\3ds Max 2015\NVIDIA\Satellite\raysat_3dsmax2015_64server.exe [x]
R4 mitsijm2015;Autodesk Simulation Moldflow MITSI 2015 Job-Manager;j:\autodesk\Inventor 2015\Moldflow\bin\mitsijm.exe;j:\autodesk\Inventor 2015\Moldflow\bin\mitsijm.exe [x]
R4 MsDepSvc;Webbereitstellungs-Agent-Dienst;c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe;c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe [x]
R4 MSSQLServerADHelper100;SQL Server Hilfsdienst für Active Directory;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [x]
R4 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\system32\DRIVERS\nvstusb.sys;c:\windows\SYSNATIVE\DRIVERS\nvstusb.sys [x]
R4 OverwolfUpdaterService;Overwolf Updater Service;c:\program files (x86)\Overwolf\OverwolfUpdater.exe;c:\program files (x86)\Overwolf\OverwolfUpdater.exe [x]
R4 RsFx0105;RsFx0105 Driver;c:\windows\system32\DRIVERS\RsFx0105.sys;c:\windows\SYSNATIVE\DRIVERS\RsFx0105.sys [x]
R4 SQLAgent$SQLEXPRESS;SQL Server-Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE;c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [x]
R4 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S0 iusb3hcs;Intel(R) USB 3.0 Hostcontroller-Switchtreiber;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S0 tclondrv;tclondrv;c:\windows\system32\DRIVERS\tclondrv.sys;c:\windows\SYSNATIVE\DRIVERS\tclondrv.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\system32\drivers\HWiNFO64A.SYS;c:\windows\SYSNATIVE\drivers\HWiNFO64A.SYS [x]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxDrv.sys [x]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxUSBMon.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe [x]
S2 Aqua Computer Service;Aqua Computer Service;c:\program files\aquasuite\AquaComputerService.exe;c:\program files\aquasuite\AquaComputerService.exe [x]
S2 avnetflt;avnetflt;c:\windows\system32\DRIVERS\avnetflt.sys;c:\windows\SYSNATIVE\DRIVERS\avnetflt.sys [x]
S2 DisplayFusionService;DisplayFusionService;c:\program files (x86)\DisplayFusion\DisplayFusionService.exe;c:\program files (x86)\DisplayFusion\DisplayFusionService.exe [x]
S2 EzPwr;EzPwr Driver;c:\program files\Intel\Power Gadget 2.0\EzPwr.sys;c:\program files\Intel\Power Gadget 2.0\EzPwr.sys [x]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
S2 NIHardwareService;NIHardwareService;c:\program files\Common Files\Native Instruments\Hardware\NIHardwareService.exe;c:\program files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [x]
S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys;c:\windows\SYSNATIVE\drivers\npf.sys [x]
S2 WTabletServiceCon;Wacom Consumer Service;c:\program files\Tablet\Pen\WTabletServiceCon.exe;c:\program files\Tablet\Pen\WTabletServiceCon.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 avmaudio;AVM Audio;c:\windows\system32\DRIVERS\avmaudio.sys;c:\windows\SYSNATIVE\DRIVERS\avmaudio.sys [x]
S3 hidkmdf;KMDF Driver;c:\windows\system32\DRIVERS\hidkmdf.sys;c:\windows\SYSNATIVE\DRIVERS\hidkmdf.sys [x]
S3 ikbevent;Intel Upper keyboard Class Filter Driver;c:\windows\system32\DRIVERS\ikbevent.sys;c:\windows\SYSNATIVE\DRIVERS\ikbevent.sys [x]
S3 imsevent;Intel Upper Mouse Class Filter Driver;c:\windows\system32\DRIVERS\imsevent.sys;c:\windows\SYSNATIVE\DRIVERS\imsevent.sys [x]
S3 iusb3hub;Intel(R) USB 3.0-Hubtreiber;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Intel(R) USB 3.0 eXtensible-Hostcontrollertreiber;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
S3 LGSHidFilt;Logitech Gaming KMDF HID Filter Driver;c:\windows\system32\DRIVERS\LGSHidFilt.Sys;c:\windows\SYSNATIVE\DRIVERS\LGSHidFilt.Sys [x]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
S3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 ta2avs;Traktor Audio 2 WDM Audio;c:\windows\system32\Drivers\ta2avs.sys;c:\windows\SYSNATIVE\Drivers\ta2avs.sys [x]
S3 ta2usb_svc;Traktor Audio 2;c:\windows\system32\Drivers\ta2usb.sys;c:\windows\SYSNATIVE\Drivers\ta2usb.sys [x]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetAdp.sys [x]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetFlt.sys [x]
S3 WacHidRouter;Wacom Hid Router;c:\windows\system32\DRIVERS\wachidrouter.sys;c:\windows\SYSNATIVE\DRIVERS\wachidrouter.sys [x]
S3 wacomrouterfilter;Wacom Router Filter Driver;c:\windows\system32\DRIVERS\wacomrouterfilter.sys;c:\windows\SYSNATIVE\DRIVERS\wacomrouterfilter.sys [x]
S3 wod0205;WeOnlyDo Network Adapter 2.5;c:\windows\system32\DRIVERS\wod0205.sys;c:\windows\SYSNATIVE\DRIVERS\wod0205.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - MBAMSWISSARMY
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
iissvcs REG_MULTI_SZ w3svc was
apphost REG_MULTI_SZ apphostsvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-06-17 11:11 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Inhalt des "geplante Tasks" Ordners
.
2014-12-01 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-21 16:24]
.
2014-12-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-09-04 19:48]
.
2014-12-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-09-04 19:48]
.
2014-11-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-734703971-1651767753-1958102793-1001Core.job
- c:\users\Fabian\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-30 15:23]
.
2014-12-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-734703971-1651767753-1958102793-1001UA.job
- c:\users\Fabian\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-30 15:23]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco1]
@="{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}"
[HKEY_CLASSES_ROOT\CLSID\{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}]
2014-02-11 02:21 644464 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco2]
@="{853B7E05-C47D-4985-909A-D0DC5C6D7303}"
[HKEY_CLASSES_ROOT\CLSID\{853B7E05-C47D-4985-909A-D0DC5C6D7303}]
2014-02-11 02:21 644464 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco3]
@="{42D38F2E-98E9-4382-B546-E24E4D6D04BB}"
[HKEY_CLASSES_ROOT\CLSID\{42D38F2E-98E9-4382-B546-E24E4D6D04BB}]
2014-02-11 02:21 644464 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2011-06-13 08:20 75544 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2014-10-21 16:52 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-10-21 16:52 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-10-21 16:52 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2014-10-21 16:52 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2014-10-21 16:52 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2014-10-21 16:52 777032 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@="{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}"
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2012-10-23 17:03 5928296 ----a-w- c:\program files\Protector Suite\farchns.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@="{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}"
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2012-10-23 17:03 5928296 ----a-w- c:\program files\Protector Suite\farchns.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2014-10-14 12697368]
"PSQLLauncher"="c:\program files\Protector Suite\launcher.exe" [2012-10-23 85352]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2012-03-20 6468712]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 190536]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.de/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local;<local>
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: Interfaces\{9B746777-9DCE-4C5A-B028-089698CC8EAA}: NameServer = 192.168.1.1,8.8.8.8
TCP: Interfaces\{DD8D61A7-E282-48D8-8D09-0BD054712A5A}: NameServer = 192.168.178.1,8.8.4.4
FF - ProfilePath - c:\users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\lm0lfxcw.default-1413032452508\
.
.
------- Dateityp-Verknüpfung -------
.
txtfile="c:\program files (x86)\PSPad editor\PSPad.exe" "%1"
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKCU-Run-RESTART_STICKY_NOTES - c:\windows\System32\StikyNot.exe
Wow6432Node-HKU-Default-Run-Sidebar - c:\program files\Windows Sidebar\sidebar.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-aquasuite5 - c:\program files\aquasuite\uninstall.exe
AddRemove-Guild Wars 2 - j:\guild wars 2\Gw2.exe
AddRemove-Native Instruments Maschine Controller - c:\programdata\{7F3144B7-67AA-4DD7-BC11-CBA9A40B430D}\Maschine Controller Setup PC.exe
AddRemove-Native Instruments Maschine Mikro - c:\programdata\{32849BA1-784B-4E0B-BB8F-AABEE988E2B0}\Maschine Mikro Setup PC.exe
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
AddRemove-{9C98989A-3A15-42DA-A3B9-D20331437D67}}_is1 - f:\games\GameforgeLive\unins000.exe
AddRemove-{A2F166A0-F031-4E27-A057-C69733219434}_is1 - f:\tera\unins000.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MsDepSvc]
"ImagePath"="\"c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe\" -runService:MsDepSvc"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\X6va008]
"ImagePath"="\??\c:\windows\SysWOW64\Drivers\X6va008"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-734703971-1651767753-1958102793-1001\Software\SecuROM\License information*]
"datasecu"=hex:f2,09,79,ce,ff,3d,38,9d,83,88,a8,d4,e7,2a,5e,72,5e,9e,12,4b,85,
71,a7,1e,c6,c6,17,a8,72,7c,28,42,a3,6c,bb,4d,06,81,5d,6a,34,b9,36,f8,af,90,\
"rkeysecu"=hex:4a,a5,25,dc,3c,02,b4,7e,ae,e6,93,80,0c,e1,a0,98
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_15_0_0_239_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_15_0_0_239_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_15_0_0_239_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_15_0_0_239_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_239.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.15"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_239.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_239.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_239.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Malwarebytes Anti-Malware\mbam.exe
c:\program files\Tablet\Pen\WacomHost.exe
c:\program files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler.exe
j:\steam\bin\steamwebhelper.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2014-12-01 13:58:52 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2014-12-01 12:58
.
Vor Suchlauf: 24 Verzeichnis(se), 12.206.673.920 Bytes frei
Nach Suchlauf: 28 Verzeichnis(se), 12.805.120.000 Bytes frei
.
- - End Of File - - F7DF033C759DF5388249ED8011C68252
A36C5E4F47E84449FF07ED3517B43A31 FRST
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-12-2014
Ran by Fabian (administrator) on YODA on 01-12-2014 14:04:24
Running from C:\Users\Fabian\Downloads
Loaded Profile: Fabian (Available profiles: Fabian & Music)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 8
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\WTabletServiceCon.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Authentec Inc.) C:\Program Files\Protector Suite\upeksvr.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe
(Aqua Computer GmbH & Co. KG) C:\Program Files\aquasuite\AquaComputerService.exe
(Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
(Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
(Wacom Technology) C:\Program Files\Tablet\Pen\WacomHost.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_Tablet.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler64.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Authentec Inc.) C:\Program Files\Protector Suite\psqltray.exe
(Valve Corporation) J:\Steam\Steam.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
() C:\Program Files (x86)\puush\puush.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDRSS.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDCountdown.exe
(Valve Corporation) J:\Steam\bin\steamwebhelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Google Inc.) C:\Users\Fabian\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Fabian\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Fabian\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Fabian\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Fabian\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Prog-Soft s.r.o.) C:\Program Files (x86)\PSPad editor\PSPad.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [12697368 2014-10-14] (Logitech Inc.)
HKLM\...\Run: [PSQLLauncher] => C:\Program Files\Protector Suite\launcher.exe [85352 2012-10-23] (Authentec Inc.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6468712 2012-03-20] (Realtek Semiconductor)
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [703736 2014-11-30] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292088 2013-02-22] (Intel Corporation)
HKLM-x32\...\Run: [ControlCenterCount] => C:\Program Files (x86)\MSI\ControlCenter\ControlCenterCount.exe [872448 2012-03-26] (MSI CO.,LTD.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-04-17] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-09-12] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3835728 2014-11-03] (LogMeIn Inc.)
HKLM-x32\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Users\Fabian\AppData\Roaming\appconf32.exe, [X]
Winlogon\Notify\psfus: C:\Program Files\Protector Suite\psqlpwd.dll (Authentec Inc.)
Winlogon\Notify\ScCertProp: wlnotify.dll [X]
HKU\S-1-5-21-734703971-1651767753-1958102793-1001\...\Run: [Steam] => J:\Steam\steam.exe [1940160 2014-11-18] (Valve Corporation)
HKU\S-1-5-21-734703971-1651767753-1958102793-1001\...\Run: [DisplayFusion] => C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe [8854880 2014-09-09] (Binary Fortress Software)
HKU\S-1-5-21-734703971-1651767753-1958102793-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [22869088 2014-10-21] (Google)
HKU\S-1-5-21-734703971-1651767753-1958102793-1001\...\Run: [Speech Recognition] => C:\Windows\Speech\Common\sapisvr.exe [44544 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-734703971-1651767753-1958102793-1001\...\Run: [puush] => C:\Program Files (x86)\puush\puush.exe [567880 2014-09-06] ()
HKU\S-1-5-21-734703971-1651767753-1958102793-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [22065760 2014-10-01] (Skype Technologies S.A.)
HKU\S-1-5-21-734703971-1651767753-1958102793-1001\...\Policies\Explorer: []
HKU\S-1-5-18\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [1208712 2014-05-14] (Autodesk, Inc.)
Lsa: [Notification Packages] scecli C:\Program Files\Protector Suite\psqlpwd.dll
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers: [1TortoiseNormal] -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [2TortoiseModified] -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [3TortoiseConflict] -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [4TortoiseLocked] -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [5TortoiseReadOnly] -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [6TortoiseDeleted] -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [7TortoiseAdded] -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [8TortoiseIgnored] -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [9TortoiseUnversioned] -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll (Autodesk, Inc.)
ShellIconOverlayIdentifiers: [Symbol-Overlay-Steuerprogramm für AutoCAD Digitale Signaturen] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll (Autodesk, Inc.)
ShellIconOverlayIdentifiers: [UEAFOverlay] -> {F2F31467-B1AC-4df0-AE79-FD5FA085E22B} => C:\Program Files\Protector Suite\farchns.dll (Authentec Inc.)
ShellIconOverlayIdentifiers: [UEAFOverlayOpen] -> {A3E208F7-0E3A-4182-A7A6-B169D5D691AA} => C:\Program Files\Protector Suite\farchns.dll (Authentec Inc.)
ShellIconOverlayIdentifiers-x32: [1TortoiseNormal] -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [2TortoiseModified] -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [3TortoiseConflict] -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [4TortoiseLocked] -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [5TortoiseReadOnly] -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [6TortoiseDeleted] -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [7TortoiseAdded] -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [8TortoiseIgnored] -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: [9TortoiseUnversioned] -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-734703971-1651767753-1958102793-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-734703971-1651767753-1958102793-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-734703971-1651767753-1958102793-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKU\S-1-5-21-734703971-1651767753-1958102793-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xE1F702029940CD01
HKU\S-1-5-21-734703971-1651767753-1958102793-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
HKU\S-1-5-21-734703971-1651767753-1958102793-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKU\S-1-5-21-734703971-1651767753-1958102793-1001 -> DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL =
SearchScopes: HKU\S-1-5-21-734703971-1651767753-1958102793-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre8\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre8\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: ArcPluginIEBHO Class -> {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} -> F:\Arc\Arc\Plugins\ArcPluginIE.dll (Perfect World Entertainment Inc)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Handler: gopher - {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\system32\urlmon.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\..\Interfaces\{9B746777-9DCE-4C5A-B028-089698CC8EAA}: [NameServer] 192.168.1.1,8.8.8.8
Tcpip\..\Interfaces\{DD8D61A7-E282-48D8-8D09-0BD054712A5A}: [NameServer] 192.168.178.1,8.8.4.4
FireFox:
========
FF ProfilePath: C:\Users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\lm0lfxcw.default-1413032452508
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_239.dll ()
FF Plugin: @esn/npbattlelog,version=2.5.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelogx64.dll (EA Digital Illusions CE AB)
FF Plugin: @java.com/DTPlugin,version=11.0.2 -> C:\Program Files\Java\jre8\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.0.2 -> C:\Program Files\Java\jre8\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @Musicnotes.com/Musicnotes Viewer -> C:\Program Files\Musicnotes\npmusicn64.dll (Musicnotes, Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.2 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF Plugin: adobe.com/AdobeAAMDetect_x86_64 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll No File
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @esn/npbattlelog,version=2.5.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @Musicnotes.com/Musicnotes Viewer -> C:\Program Files (x86)\Musicnotes\npmusicn.dll (Musicnotes, Inc.)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin -> F:\Arc\Arc\Plugins\npArcPluginFF.dll (Perfect World Entertainment Inc)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.2 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin HKU\S-1-5-21-734703971-1651767753-1958102793-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Fabian\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-734703971-1651767753-1958102793-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Fabian\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-734703971-1651767753-1958102793-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Fabian\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-734703971-1651767753-1958102793-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Plugin HKU\S-1-5-21-734703971-1651767753-1958102793-1001: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.)
FF Extension: Firebug - C:\Users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\lm0lfxcw.default-1413032452508\Extensions\firebug@software.joehewitt.com.xpi [2014-11-05]
FF Extension: Adblock Plus - C:\Users\Fabian\AppData\Roaming\Mozilla\Firefox\Profiles\lm0lfxcw.default-1413032452508\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-10-11]
FF Extension: QuickStores-Toolbar - C:\Program Files (x86)\Mozilla Firefox\extensions\quickstores@quickstores.de [2014-11-11]
Chrome:
=======
CHR HomePage: Default -> hxxp://search.babylon.com/?affID=113248&tt=060612_5_&babsrc=HP_ss&mntrId=0c3cb89d000000000000bc5ff43908f2
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\Fabian\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\Fabian\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-05-17]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Fabian\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-11-14]
CHR Extension: (YouTube) - C:\Users\Fabian\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-01-30]
CHR Extension: (Adblock Plus) - C:\Users\Fabian\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-11-16]
CHR Extension: (Google-Suche) - C:\Users\Fabian\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-01-30]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Fabian\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2014-11-14]
CHR Extension: (Google Wallet) - C:\Users\Fabian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-23]
CHR Extension: (Google Mail) - C:\Users\Fabian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-01-30]
CHR StartMenuInternet: Google Chrome - C:\Users\Fabian\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S4 AdAppMgrSvc; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [597896 2014-09-04] (Autodesk Inc.)
S4 ADExchange; C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe [43624 2012-08-14] (ArcSoft, Inc.)
S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [806704 2014-11-30] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [432888 2014-11-30] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [432888 2014-11-30] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [995064 2014-11-30] (Avira Operations GmbH & Co. KG)
S4 Apache2.4; F:\xampp\apache\bin\httpd.exe [22016 2013-11-26] (Apache Software Foundation) [File not signed]
R2 Aqua Computer Service; C:\Program Files\aquasuite\AquaComputerService.exe [559776 2014-06-19] (Aqua Computer GmbH & Co. KG)
S4 ArcService; F:\ARc\Arc\ArcService.exe [88400 2014-02-24] (Perfect World Entertainment Inc)
S4 BRSptSvc; C:\ProgramData\BitRaider\BRSptSvc.exe [477960 2014-04-14] (BitRaider, LLC)
R2 DisplayFusionService; C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe [5278064 2014-09-09] (Binary Fortress Software)
S4 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9216 2014-07-18] (Hi-Rez Studios) [File not signed]
S3 ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [160256 2011-08-30] (Intel Corporation) [File not signed]
S4 Icecast-trunk; C:\Program Files (x86)\Icecast2 Win32\icecastService.exe [417792 2008-05-24] () [File not signed]
S4 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed]
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [732160 2012-12-10] (Intel(R) Corporation) [File not signed]
S4 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-10] (Intel(R) Corporation)
S4 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [198120 2013-08-01] ()
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165336 2013-01-15] (Intel Corporation)
S4 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2009-06-17] (Hewlett-Packard Company) [File not signed]
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2014-10-21] (LogMeIn, Inc.)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation)
S4 mi-raysat_3dsmax2015_64; J:\Autodesk\3ds Max 2015\NVIDIA\Satellite\raysat_3dsmax2015_64server.exe [86016 2011-09-15] () [File not signed]
S4 mitsijm2015; J:\Autodesk\Inventor 2015\Moldflow\bin\mitsijm.exe [968480 2013-10-11] (Autodesk, Inc.)
S4 MsDepSvc; C:\Program Files\IIS\Microsoft Web Deploy\MsDepSvc.exe [80472 2012-09-06] (Microsoft Corporation)
R2 MSSQL$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [58387104 2014-07-12] (Microsoft Corporation)
S4 msvsmon90; C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe [4737024 2008-07-29] (Microsoft Corporation)
S4 mysql; F:\xampp\mysql\bin\mysqld.exe [8159744 2013-09-09] () [File not signed]
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [4797064 2013-11-05] (INCA Internet Co., Ltd.)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1900400 2014-11-27] (Electronic Arts)
S4 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [96184 2013-12-09] (Overwolf)
S4 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2014-11-30] ()
S4 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-11-29] ()
S4 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [117264 2010-06-25] (CACE Technologies, Inc.)
S4 SQLAgent$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [441504 2014-07-12] (Microsoft Corporation)
S4 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5405456 2014-11-12] (TeamViewer GmbH)
R2 WTabletServiceCon; C:\Program Files\Tablet\Pen\WTabletServiceCon.exe [619904 2012-12-11] (Wacom Technology, Corp.)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 1394hub; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 ActionReplayDS; C:\Windows\System32\Drivers\ActionReplayDS_x64.sys [51600 2007-02-08] (Thesycon GmbH, Germany)
S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [31744 2014-05-27] (Google Inc) [File not signed]
S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2014-07-07] (LG Electronics Inc.)
S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [36352 2014-07-07] (LG Electronics Inc.)
S3 andnetndis; C:\Windows\System32\DRIVERS\lgandnetndis64.sys [93696 2014-05-27] (LG Electronics Inc.)
S3 atillk64; C:\Users\Fabian\Desktop\gBIOS\atillk64.sys [14608 2006-07-19] (ATI Technologies Inc.)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2012-01-01] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-11-30] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-11-30] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-14] (Avira Operations GmbH & Co. KG)
R3 avmaudio; C:\Windows\System32\DRIVERS\avmaudio.sys [116480 2012-12-27] (AVM Berlin)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [43064 2014-11-30] (Avira Operations GmbH & Co. KG)
S3 BRDriver64; C:\ProgramData\BitRaider\BRDriver64.sys [75048 2014-04-14] (BitRaider)
R2 EzPwr; C:\Program Files\Intel\Power Gadget 2.0\EzPwr.sys [12720 2011-12-27] ()
S3 hhdspmc64; C:\Windows\System32\DRIVERS\hhdspmc64.sys [39472 2010-10-13] (HHD Software Ltd.)
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [27552 2014-09-11] (REALiX(tm))
S1 hwinterfacex64; C:\Windows\System32\Drivers\hwinterfacex64.sys [5632 2013-06-21] (Logix4u) [File not signed]
R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [21408 2013-08-01] ()
R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [21920 2013-08-01] ()
S3 INETMON; C:\Windows\System32\Drivers\INETMON.sys [29088 2013-08-01] ()
S3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [46568 2013-08-01] ()
R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)
S3 libusb0; C:\Windows\System32\DRIVERS\libusb0.sys [52832 2014-04-28] (hxxp://libusb-win32.sourceforge.net)
S3 libusb0; C:\Windows\SysWOW64\DRIVERS\libusb0.sys [16896 2010-11-18] (hxxp://libusb-win32.sourceforge.net) [File not signed]
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2012-01-01] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-10-01] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2014-12-01] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-10-01] (Malwarebytes Corporation)
S3 mc2avs; C:\Windows\System32\Drivers\mc2avs.sys [358520 2012-06-06] (Native Instruments GmbH)
S3 mc2usb_svc; C:\Windows\System32\Drivers\mc2usb.sys [81016 2012-06-06] (Native Instruments GmbH)
S3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] ()
S3 NDMSHLP; C:\Program Files (x86)\Common Files\HHD Software\Device Monitor\ndmshlp.sys [7632 2005-05-24] (HHD Software) [File not signed]
S3 NIWinCDEmu; C:\Windows\System32\DRIVERS\NIWinCDEmu.sys [111696 2012-12-19] ()
R2 NPF; C:\Windows\System32\drivers\npf.sys [35344 2010-06-25] (CACE Technologies, Inc.)
S3 NPPTNT2; C:\Windows\SysWOW64\npptNT2.sys [4682 2005-01-04] (INCA Internet Co., Ltd.) [File not signed]
S3 NTIOLib_MSISMB_CC; C:\Program Files (x86)\MSI\ControlCenter\Sleep\NTIOLib_X64.sys [13368 2012-11-09] (MSI)
S3 okdmx31; C:\Windows\SysWOW64\Drivers\okdmx31.sys [3712 2013-06-21] () [File not signed]
S3 PCAMp50a64; C:\Windows\System32\Drivers\PCAMp50a64.sys [43328 2006-11-28] (Printing Communications Assoc., Inc. (PCAUSA))
S3 PCASp50a64; C:\Windows\System32\Drivers\PCASp50a64.sys [41280 2006-11-28] (Printing Communications Assoc., Inc. (PCAUSA))
S3 rspLLL; C:\Windows\System32\DRIVERS\rspLLL64.sys [25504 2013-10-21] (Resplendence Software Projects Sp.)
S3 SaiK0CCB; C:\Windows\System32\DRIVERS\SaiK0CCB.sys [183104 2011-09-20] (Saitek)
R3 SaiMini; C:\Windows\System32\DRIVERS\SaiMini.sys [24640 2012-01-24] (Saitek)
R3 SaiNtBus; C:\Windows\System32\drivers\SaiBus.sys [52160 2012-01-24] (Saitek)
S3 SaiU0CCB; C:\Windows\System32\DRIVERS\SaiU0CCB.sys [47168 2011-09-20] (Saitek)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [560184 2012-08-01] (Duplex Secure Ltd.)
R3 ta2avs; C:\Windows\System32\Drivers\ta2avs.sys [359784 2012-12-18] (Native Instruments GmbH)
R3 ta2usb_svc; C:\Windows\System32\Drivers\ta2usb.sys [82792 2012-12-18] (Native Instruments GmbH)
R0 tclondrv; C:\Windows\System32\DRIVERS\tclondrv.sys [26856 2012-02-24] (TuneClone Software)
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2012-12-13] (Apple, Inc.) [File not signed]
S3 usbbus; C:\Windows\System32\DRIVERS\lgx64bus.sys [17920 2014-05-27] (LG Electronics Inc.)
S3 UsbDiag; C:\Windows\System32\DRIVERS\lgx64diag.sys [28160 2014-05-27] (LG Electronics Inc.)
S3 USBModem; C:\Windows\System32\DRIVERS\lgx64modem.sys [34816 2014-05-27] (LG Electronics Inc.)
S3 USBTINSP; C:\Windows\System32\DRIVERS\tinspusb.sys [142848 2010-03-29] (Texas Instruments)
S3 VASDeviceDrm; C:\Windows\System32\drivers\vasdDev.sys [1454896 2012-03-19] (ShiningMorning Inc.)
S3 VBoxUSB; C:\Windows\System32\Drivers\VBoxUSB.sys [115488 2014-05-16] (Oracle Corporation)
R2 WIBUKEY; C:\Windows\System32\DRIVERS\WibuKey64.sys [104568 2012-11-13] (WIBU-SYSTEMS AG)
R3 WinDriver6; C:\Windows\System32\drivers\windrvr6.sys [268800 2014-04-28] (Jungo Connectivity)
R3 wod0205; C:\Windows\System32\DRIVERS\wod0205.sys [33160 2011-04-23] (WeOnlyDo Software)
S1 ArcSec; system32\drivers\ArcSec.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 cpuz135; \??\C:\Users\Fabian\AppData\Local\Temp\cpuz135\cpuz135_x64.sys [X]
S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [X]
S3 GPUZ; \??\C:\Windows\TEMP\GPUZ.sys [X]
S4 NVHDA; system32\drivers\nvhda64v.sys [X]
S4 nvlddmkm; system32\DRIVERS\nvlddmkm.sys [X]
S4 NvStUSB; system32\DRIVERS\nvstusb.sys [X]
S3 SCL01164; system32\DRIVERS\SCL01164.sys [X]
S3 WPN111; system32\DRIVERS\WPN111vx.sys [X]
S3 X6va008; \??\C:\Windows\SysWOW64\Drivers\X6va008 [X]
S3 zlportio; \??\C:\Program Files (x86)\PHOENIXstudios\PC_DIMMER\zlportio.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-01 14:04 - 2014-12-01 14:04 - 00036469 _____ () C:\Users\Fabian\Downloads\FRST.txt
2014-12-01 14:04 - 2014-12-01 14:04 - 00000000 ____D () C:\Users\Fabian\Downloads\FRST-OlderVersion
2014-12-01 13:58 - 2014-12-01 13:58 - 00051295 _____ () C:\ComboFix.txt
2014-12-01 13:48 - 2014-12-01 13:58 - 00000000 ____D () C:\Qoobox
2014-12-01 13:48 - 2014-12-01 13:55 - 00000000 ____D () C:\Windows\erdnt
2014-12-01 13:48 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-12-01 13:48 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-12-01 13:48 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-12-01 13:48 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-12-01 13:48 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-12-01 13:48 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2014-12-01 13:48 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2014-12-01 13:48 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2014-12-01 13:47 - 2014-12-01 13:47 - 05600374 ____R (Swearware) C:\Users\Fabian\Desktop\ComboFix.exe
2014-12-01 13:21 - 2014-12-01 13:21 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Fabian\Downloads\revosetup95.exe
2014-12-01 13:21 - 2014-12-01 13:21 - 00001268 _____ () C:\Users\Fabian\Desktop\Revo Uninstaller.lnk
2014-12-01 13:21 - 2014-12-01 13:21 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-12-01 13:19 - 2014-12-01 13:19 - 00000000 ____D () C:\Users\Fabian\Downloads\MDK (Morgan David King) - Rise
2014-12-01 13:18 - 2014-12-01 13:18 - 108747758 _____ () C:\Users\Fabian\Downloads\MDK (Morgan David King) - Rise.zip
2014-11-30 16:57 - 2014-11-30 16:57 - 00108466 _____ () C:\Users\Fabian\Desktop\cpuz-1234.txt
2014-11-30 16:19 - 2014-11-30 16:45 - 00000000 ____D () C:\AdwCleaner
2014-11-30 16:19 - 2014-11-30 16:19 - 02148864 _____ () C:\Users\Fabian\Downloads\AdwCleaner_4.102.exe
2014-11-30 16:05 - 2014-11-30 16:05 - 00380416 _____ () C:\Users\Fabian\Downloads\Gmer-19357.exe
2014-11-30 15:35 - 2014-12-01 14:04 - 02117120 _____ (Farbar) C:\Users\Fabian\Downloads\FRST64.exe
2014-11-30 15:35 - 2014-12-01 14:04 - 00000000 ____D () C:\FRST
2014-11-30 15:33 - 2014-11-30 15:33 - 00000049 _____ () C:\Users\Fabian\Desktop\malwarebytes.txt
2014-11-30 15:18 - 2014-12-01 13:56 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-11-30 15:18 - 2014-11-30 15:18 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-11-30 15:18 - 2014-11-30 15:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-11-30 15:18 - 2014-11-30 15:18 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-11-30 15:18 - 2014-11-30 15:18 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-11-30 15:18 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-11-30 15:18 - 2014-10-01 11:11 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-11-30 15:18 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-11-30 15:17 - 2014-11-30 15:17 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Fabian\Downloads\mbam-setup-2.0.3.1025.exe
2014-11-30 14:11 - 2014-11-30 14:11 - 00000000 ____D () C:\Users\Fabian\Documents\Splashtop Whiteboard
2014-11-30 14:11 - 2014-11-30 14:11 - 00000000 ____D () C:\Users\Fabian\Documents\Splashtop Presenter
2014-11-30 13:58 - 2013-11-25 09:28 - 00041392 _____ (SeriousBit) C:\Windows\system32\Drivers\nbdrv.sys
2014-11-30 13:57 - 2014-11-30 13:58 - 05095832 _____ (SeriousBit ) C:\Users\Fabian\Downloads\NetBalancerSetup.exe
2014-11-30 12:52 - 2014-11-30 13:00 - 00000000 ____D () C:\Users\Fabian\Documents\Movie Studio Platinum 13.0 Projekte
2014-11-30 12:51 - 2014-11-30 12:51 - 00005742 _____ () C:\Windows\system32\--traceoff
2014-11-30 12:51 - 2014-11-30 12:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2014-11-30 12:51 - 2014-11-30 12:51 - 00000000 _____ () C:\Windows\system32\--debugoff
2014-11-30 12:42 - 2014-11-30 12:42 - 00000000 ____D () C:\ProgramData\Last.fm
2014-11-30 12:40 - 2014-11-30 12:40 - 14916216 _____ (Last.fm ) C:\Users\Fabian\Downloads\Last.fm-2.1.36.exe
2014-11-30 12:40 - 2014-11-30 12:40 - 00000985 _____ () C:\Users\Public\Desktop\Last.fm Scrobbler.lnk
2014-11-30 12:40 - 2014-11-30 12:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Last.fm
2014-11-30 12:40 - 2014-11-30 12:40 - 00000000 ____D () C:\Program Files (x86)\Last.fm
2014-11-30 12:34 - 2014-11-30 12:38 - 485239720 _____ (Sony Creative Software Inc.) C:\Users\Fabian\Downloads\moviestudiope13.0.932_64bit.exe
2014-11-30 04:09 - 2014-11-30 04:09 - 87883776 _____ () C:\dumpfile3.etl
2014-11-30 04:08 - 2014-11-30 04:08 - 40435712 _____ () C:\dumpfile2.etl
2014-11-30 04:07 - 2014-11-30 04:07 - 22347776 _____ () C:\dumpfile.etl
2014-11-30 04:07 - 2014-11-30 04:07 - 00000000 ____D () C:\SymCache
2014-11-30 04:06 - 2014-11-30 04:13 - 113967104 _____ () C:\kernel.etl
2014-11-30 04:06 - 2014-11-30 04:06 - 03080192 _____ () C:\dumpfile
2014-11-30 04:04 - 2014-11-30 04:04 - 00000000 ____D () C:\Users\Fabian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Windows Performance Toolkit
2014-11-30 04:04 - 2014-11-30 04:04 - 00000000 ____D () C:\Program Files\Microsoft Windows Performance Toolkit
2014-11-30 03:57 - 2014-11-30 04:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Windows SDK v7.0
2014-11-30 03:57 - 2014-11-30 03:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Debugging Tools for Windows (x64)
2014-11-30 03:57 - 2014-11-30 03:57 - 00000000 ____D () C:\Program Files\Debugging Tools for Windows (x64)
2014-11-30 03:55 - 2014-11-30 03:55 - 00003126 _____ () C:\Windows\System32\Tasks\{0D29B0E1-8936-4928-9FE8-18ACB5146BEA}
2014-11-30 03:54 - 2014-11-30 03:54 - 00504144 _____ (Microsoft Corporation) C:\Users\Fabian\Downloads\winsdk_web.exe
2014-11-30 03:45 - 2014-11-30 03:45 - 00459686 _____ () C:\Users\Fabian\Downloads\Windows6.1-KB976972-x86.msu
2014-11-30 03:29 - 2013-10-21 12:26 - 00025504 _____ (Resplendence Software Projects Sp.) C:\Windows\system32\Drivers\rspLLL64.sys
2014-11-30 03:28 - 2014-11-30 03:28 - 01956880 _____ (Resplendence Software Projects Sp. ) C:\Users\Fabian\Downloads\LatencyMon.exe
2014-11-30 03:17 - 2014-11-30 03:17 - 01188194 _____ () C:\Users\Fabian\Downloads\ProcessExplorer.zip
2014-11-29 21:15 - 2014-11-30 14:01 - 00000000 ____D () C:\Users\Fabian\AppData\Roaming\Wippien
2014-11-29 21:15 - 2014-11-30 14:01 - 00000000 ____D () C:\Program Files\Wippien
2014-11-29 21:15 - 2014-11-29 21:15 - 02133688 _____ ( ) C:\Users\Fabian\Downloads\WippienInst.exe
2014-11-29 21:15 - 2011-04-23 20:30 - 00033160 _____ (WeOnlyDo Software) C:\Windows\system32\Drivers\wod0205.sys
2014-11-29 20:22 - 2014-11-29 20:22 - 00000000 ____D () C:\SUPERDelete
2014-11-29 20:21 - 2014-12-01 13:46 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2014-11-29 20:21 - 2014-11-29 20:21 - 20621960 _____ (SUPERAntiSpyware) C:\Users\Fabian\Downloads\SUPERAntiSpyware.exe
2014-11-29 20:11 - 2014-11-29 20:12 - 67350808 _____ (Logitech Inc.) C:\Users\Fabian\Downloads\LGS_8.57.145_x64_Logitech.exe
2014-11-29 20:11 - 2014-11-29 20:11 - 02566424 _____ (Logitech) C:\Users\Fabian\Downloads\G500sFlash-64.exe
2014-11-29 20:11 - 2014-11-29 20:11 - 02050328 _____ (Logitech) C:\Users\Fabian\Downloads\G500sFlash-32.exe
2014-11-29 18:49 - 2014-11-29 18:49 - 00000887 _____ () C:\Users\Fabian\Downloads\fabian.key
2014-11-29 18:48 - 2014-11-29 18:48 - 00003919 _____ () C:\Users\Fabian\Downloads\fabian.crt
2014-11-29 18:48 - 2014-11-29 18:48 - 00000696 _____ () C:\Users\Fabian\Downloads\fabian.csr
2014-11-29 18:47 - 2014-11-29 18:47 - 00001326 _____ () C:\Users\Fabian\Downloads\ca.crt
2014-11-29 18:29 - 2014-11-29 18:29 - 11693448 _____ () C:\Users\Fabian\Downloads\SecurepointSSLVPN_v1.0.3.exe
2014-11-29 18:22 - 2014-11-29 18:22 - 01798096 _____ () C:\Users\Fabian\Downloads\openvpn-install-2.3.5-I602-x86_64.exe
2014-11-29 14:14 - 2014-11-30 14:55 - 00215416 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-11-29 14:14 - 2014-11-29 14:14 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-11-29 14:05 - 2014-11-29 14:05 - 00711649 _____ () C:\Users\Fabian\Downloads\pbsetup.zip
2014-11-29 00:28 - 2014-11-29 00:28 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies
2014-11-28 23:43 - 2014-11-28 23:43 - 00000202 _____ () C:\Users\Fabian\Desktop\PAYDAY 2.url
2014-11-28 12:09 - 2014-11-28 12:09 - 00000000 ____D () C:\ProgramData\EA Core
2014-11-28 11:27 - 2014-11-28 11:27 - 00000703 _____ () C:\Users\Public\Desktop\Bejeweled 3.lnk
2014-11-28 11:27 - 2014-11-28 11:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bejeweled 3
2014-11-27 22:17 - 2014-11-30 17:45 - 00076152 _____ () C:\Windows\system32\PnkBstrA.exe
2014-11-27 22:02 - 2014-11-27 22:03 - 00000000 ____D () C:\Users\Fabian\Documents\Battlefield 4
2014-11-27 22:01 - 2014-11-27 22:01 - 01402920 _____ () C:\Users\Fabian\Downloads\battlelog-web-plugins_2.5.1_149.exe
2014-11-27 21:32 - 2014-11-28 11:39 - 00000702 _____ () C:\Users\Public\Desktop\Battlefield 4.lnk
2014-11-27 21:32 - 2014-11-28 11:39 - 00000686 _____ () C:\Users\Public\Desktop\Battlefield 4(64 bit).lnk
2014-11-27 21:32 - 2014-11-28 11:39 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins
2014-11-27 21:32 - 2014-11-27 21:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battlefield 4
2014-11-27 20:11 - 2014-11-27 20:11 - 00000776 _____ () C:\Users\Public\Desktop\SimCity™.lnk
2014-11-27 18:08 - 2014-11-27 18:08 - 00000975 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk
2014-11-27 17:13 - 2014-11-27 17:13 - 00128848 _____ () C:\Users\Fabian\Desktop\EventManager-12.0-test.jar
2014-11-24 22:26 - 2014-11-24 22:26 - 02666496 _____ () C:\Users\Fabian\Downloads\IPCamAdapter.msi
2014-11-24 18:26 - 2014-11-24 18:26 - 02040643 _____ (tAPI Development Team ) C:\Users\Fabian\Downloads\r14a (2).exe
2014-11-24 18:10 - 2014-11-24 18:11 - 02040643 _____ (tAPI Development Team ) C:\Users\Fabian\Downloads\r14a (1).exe
2014-11-24 18:10 - 2014-11-24 18:10 - 02040643 _____ (tAPI Development Team ) C:\Users\Fabian\Downloads\r14a.exe
2014-11-22 22:44 - 2014-11-23 15:42 - 00000000 ____D () C:\Users\Fabian\Zomboid
2014-11-22 22:41 - 2014-11-22 22:41 - 00000202 _____ () C:\Users\Fabian\Desktop\Project Zomboid.url
2014-11-21 08:49 - 2014-11-21 08:49 - 00000202 _____ () C:\Users\Fabian\Desktop\No More Room in Hell.url
2014-11-20 16:19 - 2014-11-20 16:19 - 00000385 _____ () C:\Users\Fabian\Desktop\Wunschzettel.txt
2014-11-19 09:39 - 2014-11-11 04:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-11-19 09:39 - 2014-11-11 04:08 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
2014-11-19 09:39 - 2014-11-11 03:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-11-19 09:39 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll
2014-11-17 20:11 - 2014-11-29 22:19 - 00000000 ____D () C:\Users\Fabian\AppData\Roaming\.minecraft
2014-11-17 20:11 - 2014-11-17 20:11 - 00675988 _____ () C:\Users\Fabian\Downloads\Minecraft.exe
2014-11-17 20:11 - 2014-11-17 20:11 - 00000000 ____D () C:\Users\Fabian\AppData\Roaming\java
2014-11-16 20:53 - 2014-11-16 20:53 - 00046992 _____ () C:\Users\Fabian\Downloads\20141116-804690-umsatz.CSV
2014-11-14 14:01 - 2014-11-18 10:00 - 00019677 _____ () C:\Users\Fabian\Documents\Lebenslauf.odt
2014-11-13 19:24 - 2014-11-13 19:24 - 02256213 _____ () C:\Users\Fabian\Downloads\guava-18.0.jar
2014-11-12 09:37 - 2014-11-05 18:56 - 00304640 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-11-12 09:37 - 2014-11-05 18:56 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-11-12 09:37 - 2014-11-05 18:52 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-11-12 09:37 - 2014-10-14 03:16 - 00155064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-11-12 09:37 - 2014-10-14 03:13 - 00683520 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-11-12 09:37 - 2014-10-14 03:12 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-11-12 09:37 - 2014-10-14 03:09 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2014-11-12 09:37 - 2014-10-14 03:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2014-11-12 09:37 - 2014-10-14 02:50 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-11-12 09:37 - 2014-10-14 02:49 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-11-12 09:37 - 2014-10-14 02:47 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2014-11-12 09:37 - 2014-10-14 02:46 - 00681984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2014-11-12 09:36 - 2014-10-25 02:57 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-11-12 09:36 - 2014-10-25 02:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-11-12 09:36 - 2014-10-18 03:05 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2014-11-12 09:36 - 2014-10-18 02:33 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2014-11-12 09:36 - 2014-10-14 03:13 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-11-12 09:36 - 2014-10-14 02:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-11-12 09:36 - 2014-10-10 01:57 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-11-12 09:36 - 2014-10-03 03:12 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2014-11-12 09:36 - 2014-10-03 03:11 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-11-12 09:36 - 2014-10-03 03:11 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2014-11-12 09:36 - 2014-10-03 03:11 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-11-12 09:36 - 2014-10-03 03:11 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2014-11-12 09:36 - 2014-10-03 02:44 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2014-11-12 09:36 - 2014-10-03 02:44 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2014-11-12 09:36 - 2014-10-03 02:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2014-11-12 09:36 - 2014-09-19 10:42 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-11-12 09:36 - 2014-09-19 10:42 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-11-12 09:36 - 2014-09-19 10:42 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-11-12 09:36 - 2014-09-19 10:42 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-11-12 09:36 - 2014-09-19 10:42 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-11-12 09:36 - 2014-09-19 10:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-11-12 09:36 - 2014-09-19 10:23 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-11-12 09:36 - 2014-09-19 10:23 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-11-12 09:36 - 2014-09-19 10:23 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-11-12 09:36 - 2014-09-19 10:23 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-11-12 09:36 - 2014-09-19 10:23 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-11-12 09:36 - 2014-09-19 10:23 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-11-12 09:36 - 2014-08-21 07:43 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-11-12 09:36 - 2014-08-21 07:40 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-11-12 09:36 - 2014-08-21 07:26 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-11-12 09:36 - 2014-08-21 07:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-11-12 09:36 - 2014-08-12 03:02 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
2014-11-12 09:36 - 2014-08-12 02:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL
2014-11-11 16:41 - 2014-11-11 17:43 - 00224892 _____ () C:\Users\Fabian\Documents\Autodesk Flow Design.settings.json
2014-11-11 09:35 - 2014-11-11 09:35 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-11-10 10:53 - 2014-11-10 10:53 - 05308733 _____ () C:\Users\Fabian\Downloads\Sylenth1DemoWin32.zip
2014-11-09 14:57 - 2014-11-19 18:54 - 00001068 _____ () C:\Users\Fabian\Desktop\well, you hSAe ISnSFeJ to JeZCPheD the IeKKSFe. now you QuKt hSAe to wDCte ISDClyn IonDoe SnJ ZlCZU KenJ.txt
2014-11-07 23:03 - 2014-11-07 23:03 - 18662477 _____ () C:\Users\Fabian\Desktop\Mein Film.wmv
2014-11-07 21:33 - 2014-11-07 23:02 - 00000000 ____D () C:\Users\Fabian\Desktop\Camera
2014-11-07 09:44 - 2014-11-07 09:44 - 00000000 ____D () C:\Windows\SysWOW64\tmp7xzots
2014-11-05 00:45 - 2014-11-05 00:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-11-05 00:45 - 2014-11-05 00:45 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2014-11-03 13:44 - 2014-11-03 13:45 - 00018060 _____ () C:\Users\Fabian\Documents\PlayClaw.txt
2014-11-03 13:43 - 2014-11-03 13:43 - 00000566 _____ () C:\Users\Public\Desktop\Fraps.lnk
2014-11-03 13:43 - 2014-11-03 13:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps
2014-11-03 13:42 - 2014-11-03 13:42 - 02782320 _____ (Beepa Pty Ltd) C:\Users\Fabian\Downloads\setup.exe
2014-11-02 17:16 - 2014-11-02 17:17 - 00216996 _____ () C:\Users\Fabian\Documents\ElementalBoots.tapi
2014-11-02 17:16 - 2014-11-02 17:16 - 02030129 _____ (tAPI Development Team ) C:\Users\Fabian\Downloads\r13a.exe
2014-11-01 22:47 - 2014-11-01 22:47 - 00000202 _____ () C:\Users\Fabian\Desktop\Heroes & Generals.url
2014-11-01 19:20 - 2014-11-01 19:20 - 00001757 _____ () C:\Users\Public\Desktop\Autodesk Flow Design.lnk
2014-11-01 19:18 - 2014-11-01 19:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\x264vfw64
2014-11-01 19:18 - 2014-11-01 19:18 - 00000000 ____D () C:\Program Files\x264vfw64
2014-11-01 19:15 - 2014-11-01 19:15 - 10782232 _____ () C:\Users\Fabian\Downloads\Flow_Design_2014_English_WIN_64bit_R1_wi_en-US_Setup.exe
2014-11-01 19:15 - 2014-11-01 19:15 - 00000000 ____D () C:\Autodesk
2014-11-01 16:02 - 2014-11-01 16:02 - 02360667 _____ () C:\Users\Fabian\Downloads\Revitar2_01.zip
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-01 14:04 - 2012-08-05 22:17 - 00000000 ____D () C:\Users\Fabian\AppData\Roaming\NetSpeedMonitor
2014-12-01 14:03 - 2009-07-14 05:45 - 00033312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-01 14:03 - 2009-07-14 05:45 - 00033312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-01 14:00 - 2011-04-12 08:43 - 00769098 _____ () C:\Windows\system32\perfh007.dat
2014-12-01 14:00 - 2011-04-12 08:43 - 00175828 _____ () C:\Windows\system32\perfc007.dat
2014-12-01 14:00 - 2009-07-14 06:13 - 01816002 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-01 13:59 - 2012-10-10 09:37 - 01861613 _____ () C:\Windows\WindowsUpdate.log
2014-12-01 13:58 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default
2014-12-01 13:56 - 2012-09-04 16:19 - 00000000 ___RD () C:\Users\Fabian\Google Drive
2014-12-01 13:55 - 2012-04-21 10:32 - 00000000 ____D () C:\Users\Fabian\AppData\Local\Apps\2.0
2014-12-01 13:55 - 2011-12-29 12:08 - 00000000 ____D () C:\Users\Fabian\AppData\Roaming\Skype
2014-12-01 13:55 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2014-12-01 13:54 - 2013-12-28 11:31 - 00033170 _____ () C:\Windows\PFRO.log
2014-12-01 13:54 - 2013-11-14 20:10 - 00109274 _____ () C:\Windows\setupact.log
2014-12-01 13:54 - 2012-09-04 16:16 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-12-01 13:54 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-01 13:51 - 2012-06-03 11:08 - 00000000 ____D () C:\ProgramData\TEMP
2014-12-01 13:48 - 2012-09-04 16:16 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-12-01 13:45 - 2012-02-26 17:05 - 00000000 ____D () C:\Users\Fabian\AppData\Roaming\TS3Client
2014-12-01 13:45 - 2011-12-29 13:13 - 00000000 ____D () C:\Users\Fabian\Documents\Outlook-Dateien
2014-12-01 13:43 - 2011-12-31 11:16 - 00000000 ____D () C:\Users\Fabian\AppData\Roaming\IrfanView
2014-12-01 13:40 - 2014-07-28 17:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glyph
2014-12-01 13:39 - 2014-07-31 00:43 - 00000000 ____D () C:\Program Files (x86)\Sapphire TRIXX
2014-12-01 13:39 - 2011-12-30 12:27 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-12-01 13:39 - 2011-12-29 12:08 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-12-01 13:35 - 2012-03-03 20:42 - 00000000 ____D () C:\Windows\uninstall
2014-12-01 13:35 - 2012-01-01 14:47 - 00000000 ____D () C:\Users\Fabian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2014-12-01 13:35 - 2009-07-14 06:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-12-01 13:34 - 2012-06-25 13:47 - 00000000 ____D () C:\Program Files (x86)\KDiff3
2014-12-01 13:33 - 2013-11-25 12:33 - 00089038 _____ () C:\Windows\DPINST.LOG
2014-12-01 13:33 - 2012-01-30 19:32 - 00001124 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-734703971-1651767753-1958102793-1001UA.job
2014-12-01 13:32 - 2013-07-22 17:47 - 00000000 ____D () C:\Program Files (x86)\Cube World
2014-12-01 13:25 - 2013-03-03 19:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hdd Speed Test Tool
2014-12-01 13:24 - 2012-04-21 09:06 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-12-01 12:40 - 2013-04-22 17:19 - 00000000 ____D () C:\ProgramData\Origin
2014-12-01 12:40 - 2013-04-22 17:19 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-11-30 16:46 - 2012-03-16 19:47 - 00000000 ____D () C:\Windows\de
2014-11-30 15:03 - 2014-07-27 16:05 - 00000000 ____D () C:\ProgramData\aquasuite-data
2014-11-30 14:58 - 2013-05-02 14:24 - 00043064 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-11-30 14:58 - 2013-03-21 16:49 - 00131608 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-11-30 14:58 - 2013-03-21 16:49 - 00119272 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-11-30 14:51 - 2012-03-27 16:00 - 00215416 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2014-11-30 14:33 - 2012-01-30 19:32 - 00001072 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-734703971-1651767753-1958102793-1001Core.job
2014-11-30 14:21 - 2012-07-10 21:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoIt v3
2014-11-30 14:21 - 2011-04-12 08:55 - 00000000 ____D () C:\Windows\ShellNew
2014-11-30 14:12 - 2012-08-07 13:46 - 00000000 ____D () C:\Program Files (x86)\Bitcoin
2014-11-30 14:11 - 2013-03-18 16:24 - 00000000 ____D () C:\Program Files (x86)\PlayClaw4
2014-11-30 14:10 - 2012-09-10 18:48 - 00000000 ____D () C:\Program Files (x86)\DMXControl
2014-11-30 14:09 - 2014-03-10 20:14 - 00000000 ____D () C:\Program Files (x86)\LOLReplay
2014-11-30 14:09 - 2012-03-08 22:03 - 00000000 ____D () C:\Program Files\POV-Ray
2014-11-30 14:02 - 2011-12-29 12:19 - 00000000 ____D () C:\Users\Fabian\AppData\Roaming\Apple Computer
2014-11-30 14:02 - 2011-12-29 12:18 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-11-30 13:12 - 2012-10-15 21:36 - 00000000 ____D () C:\Users\Fabian\AppData\Roaming\Sony
2014-11-30 12:51 - 2012-07-12 10:03 - 00000000 ____D () C:\Program Files (x86)\Sony
2014-11-30 12:42 - 2014-10-25 12:20 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-11-30 04:03 - 2011-12-29 13:10 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-11-30 03:15 - 2014-07-06 20:34 - 00000000 ____D () C:\Users\Fabian\AppData\Roaming\quassel-irc.org
2014-11-30 01:16 - 2012-11-10 19:46 - 00000000 ____D () C:\Users\Fabian\AppData\Roaming\vlc
2014-11-29 22:51 - 2014-01-13 22:37 - 00000000 ____D () C:\Users\Fabian\Desktop\FTB
2014-11-29 20:16 - 2009-07-14 06:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-11-29 20:13 - 2014-04-15 14:09 - 00018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys
2014-11-29 20:13 - 2014-04-15 14:09 - 00003885 _____ () C:\Windows\LkmdfCoInst.log
2014-11-29 20:13 - 2011-12-31 14:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
2014-11-29 20:13 - 2011-12-31 14:17 - 00000000 ____D () C:\Program Files\Logitech Gaming Software
2014-11-29 19:54 - 2012-01-06 21:53 - 00000000 ____D () C:\Users\Fabian\AppData\Roaming\TeamViewer
2014-11-29 13:56 - 2014-08-11 22:27 - 00000000 ____D () C:\Program Files (x86)\ImDisk
2014-11-28 20:49 - 2014-07-07 13:40 - 00000000 ____D () C:\Users\Fabian\Desktop\eclipse
2014-11-28 15:45 - 2014-07-18 21:22 - 00000000 ____D () C:\Users\Fabian\workspace_2014
2014-11-28 11:41 - 2013-11-27 18:12 - 00616849 _____ () C:\Windows\DirectX.log
2014-11-28 10:28 - 2009-07-14 05:45 - 05146656 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-11-27 21:31 - 2013-01-23 16:16 - 00000000 ____D () C:\ProgramData\Package Cache
2014-11-27 20:10 - 2013-04-22 17:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
2014-11-27 18:08 - 2012-01-06 21:53 - 00000000 ____D () C:\Program Files (x86)\TeamViewer
2014-11-27 15:40 - 2011-12-29 14:09 - 00000000 ____D () C:\Users\Fabian\AppData\Roaming\FileZilla
2014-11-26 17:24 - 2012-04-21 09:06 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-11-26 17:24 - 2012-04-21 09:06 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-11-26 17:24 - 2011-12-29 14:02 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-11-24 18:11 - 2014-10-28 14:48 - 00000874 _____ () C:\Users\Public\Desktop\tAPI Builder.lnk
2014-11-24 18:11 - 2014-10-28 14:48 - 00000871 _____ () C:\Users\Public\Desktop\tAPI Server.lnk
2014-11-24 18:11 - 2014-10-28 14:48 - 00000846 _____ () C:\Users\Public\Desktop\tAPI.lnk
2014-11-23 16:44 - 2012-12-10 21:51 - 00000000 ____D () C:\Users\Fabian\AppData\Roaming\ftblauncher
2014-11-22 22:44 - 2011-12-29 11:20 - 00000000 ____D () C:\Users\Fabian
2014-11-17 16:18 - 2014-07-31 16:06 - 00000978 _____ () C:\Users\Public\Desktop\CPUID HWMonitor.lnk
2014-11-14 17:12 - 2012-01-23 15:10 - 00000000 ____D () C:\Users\Fabian\Documents\My Cheat Tables
2014-11-14 14:28 - 2012-01-30 19:32 - 00004100 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-734703971-1651767753-1958102793-1001UA
2014-11-14 14:28 - 2012-01-30 19:32 - 00003704 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-734703971-1651767753-1958102793-1001Core
2014-11-14 10:01 - 2013-09-21 10:06 - 00000000 ____D () C:\Windows\rescache
2014-11-13 11:43 - 2012-09-04 16:16 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-11-13 11:43 - 2012-09-04 16:16 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-11-13 10:44 - 2014-05-06 21:32 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-11-12 22:44 - 2011-12-30 11:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2010
2014-11-12 22:42 - 2013-08-14 22:14 - 00000000 ____D () C:\Windows\system32\MRT
2014-11-12 22:39 - 2011-12-29 11:39 - 103374192 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-11-12 09:28 - 2012-03-17 18:03 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-11-11 17:49 - 2014-08-26 09:32 - 00000000 ____D () C:\Users\Fabian\Documents\reprap
2014-11-11 15:37 - 2013-02-04 20:12 - 00000000 ____D () C:\Users\Fabian\workspace_2013
2014-11-10 10:54 - 2011-12-31 17:27 - 00000000 ____D () C:\Program Files (x86)\VstPlugins
2014-11-07 09:44 - 2012-09-04 16:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2014-11-02 17:37 - 2011-12-30 11:36 - 00000000 ____D () C:\Users\Fabian\Documents\Visual Studio 2010
2014-11-01 19:20 - 2014-08-12 12:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk
2014-11-01 19:18 - 2014-08-25 14:37 - 00000000 ____D () C:\Program Files\Autodesk
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
nointegritychecks: ==> Integrity Checks is disabled <===== ATTENTION!
LastRegBack: 2014-11-25 16:55
==================== End Of Log ============================ --- --- ---
--- --- --- |