J_Cake_Jr | 08.12.2014 22:27 | Und hier die anderen beiden:
GMER: Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-12-08 19:57:56
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 Samsung_SSD_840_Series rev.DXT06B0Q 111,79GB
Running: Gmer-19357.exe; Driver: C:\Users\Julian\AppData\Local\Temp\fxxyqaoc.sys
---- User code sections - GMER 2.1 ----
.text C:\ProgramData\IePluginServices\PluginService.exe[1824] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000077491401 2 bytes JMP 76afb21b C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\IePluginServices\PluginService.exe[1824] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000077491419 2 bytes JMP 76afb346 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\IePluginServices\PluginService.exe[1824] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000077491431 2 bytes JMP 76b78ea9 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\IePluginServices\PluginService.exe[1824] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007749144a 2 bytes CALL 76ad48ad C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\ProgramData\IePluginServices\PluginService.exe[1824] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000774914dd 2 bytes JMP 76b787a2 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\IePluginServices\PluginService.exe[1824] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000774914f5 2 bytes JMP 76b78978 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\IePluginServices\PluginService.exe[1824] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007749150d 2 bytes JMP 76b78698 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\IePluginServices\PluginService.exe[1824] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000077491525 2 bytes JMP 76b78a62 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\IePluginServices\PluginService.exe[1824] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007749153d 2 bytes JMP 76aefca8 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\IePluginServices\PluginService.exe[1824] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000077491555 2 bytes JMP 76af68ef C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\IePluginServices\PluginService.exe[1824] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007749156d 2 bytes JMP 76b78f61 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\IePluginServices\PluginService.exe[1824] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000077491585 2 bytes JMP 76b78ac2 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\IePluginServices\PluginService.exe[1824] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007749159d 2 bytes JMP 76b7865c C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\IePluginServices\PluginService.exe[1824] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000774915b5 2 bytes JMP 76aefd41 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\IePluginServices\PluginService.exe[1824] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000774915cd 2 bytes JMP 76afb2dc C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\IePluginServices\PluginService.exe[1824] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000774916b2 2 bytes JMP 76b78e24 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\IePluginServices\PluginService.exe[1824] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000774916bd 2 bytes JMP 76b785f1 C:\Windows\syswow64\kernel32.dll
.text E:\Programme\afwServ.exe[1040] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 0000000076ad8791 8 bytes [31, C0, C2, 04, 00, 90, 90, ...]
.text E:\Programme\afwServ.exe[1040] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000077491401 2 bytes JMP 76afb21b C:\Windows\syswow64\kernel32.dll
.text E:\Programme\afwServ.exe[1040] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000077491419 2 bytes JMP 76afb346 C:\Windows\syswow64\kernel32.dll
.text E:\Programme\afwServ.exe[1040] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000077491431 2 bytes JMP 76b78ea9 C:\Windows\syswow64\kernel32.dll
.text E:\Programme\afwServ.exe[1040] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007749144a 2 bytes CALL 76ad48ad C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text E:\Programme\afwServ.exe[1040] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000774914dd 2 bytes JMP 76b787a2 C:\Windows\syswow64\kernel32.dll
.text E:\Programme\afwServ.exe[1040] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000774914f5 2 bytes JMP 76b78978 C:\Windows\syswow64\kernel32.dll
.text E:\Programme\afwServ.exe[1040] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007749150d 2 bytes JMP 76b78698 C:\Windows\syswow64\kernel32.dll
.text E:\Programme\afwServ.exe[1040] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000077491525 2 bytes JMP 76b78a62 C:\Windows\syswow64\kernel32.dll
.text E:\Programme\afwServ.exe[1040] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007749153d 2 bytes JMP 76aefca8 C:\Windows\syswow64\kernel32.dll
.text E:\Programme\afwServ.exe[1040] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000077491555 2 bytes JMP 76af68ef C:\Windows\syswow64\kernel32.dll
.text E:\Programme\afwServ.exe[1040] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007749156d 2 bytes JMP 76b78f61 C:\Windows\syswow64\kernel32.dll
.text E:\Programme\afwServ.exe[1040] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000077491585 2 bytes JMP 76b78ac2 C:\Windows\syswow64\kernel32.dll
.text E:\Programme\afwServ.exe[1040] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007749159d 2 bytes JMP 76b7865c C:\Windows\syswow64\kernel32.dll
.text E:\Programme\afwServ.exe[1040] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000774915b5 2 bytes JMP 76aefd41 C:\Windows\syswow64\kernel32.dll
.text E:\Programme\afwServ.exe[1040] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000774915cd 2 bytes JMP 76afb2dc C:\Windows\syswow64\kernel32.dll
.text E:\Programme\afwServ.exe[1040] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000774916b2 2 bytes JMP 76b78e24 C:\Windows\syswow64\kernel32.dll
.text E:\Programme\afwServ.exe[1040] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000774916bd 2 bytes JMP 76b785f1 C:\Windows\syswow64\kernel32.dll
.text E:\Programme\PowerDVD\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[2228] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000077491401 2 bytes JMP 76afb21b C:\Windows\syswow64\kernel32.dll
.text E:\Programme\PowerDVD\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[2228] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000077491419 2 bytes JMP 76afb346 C:\Windows\syswow64\kernel32.dll
.text E:\Programme\PowerDVD\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[2228] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000077491431 2 bytes JMP 76b78ea9 C:\Windows\syswow64\kernel32.dll
.text E:\Programme\PowerDVD\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[2228] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007749144a 2 bytes CALL 76ad48ad C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text E:\Programme\PowerDVD\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[2228] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000774914dd 2 bytes JMP 76b787a2 C:\Windows\syswow64\kernel32.dll
.text E:\Programme\PowerDVD\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[2228] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000774914f5 2 bytes JMP 76b78978 C:\Windows\syswow64\kernel32.dll
.text E:\Programme\PowerDVD\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[2228] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007749150d 2 bytes JMP 76b78698 C:\Windows\syswow64\kernel32.dll
.text E:\Programme\PowerDVD\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[2228] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000077491525 2 bytes JMP 76b78a62 C:\Windows\syswow64\kernel32.dll
.text E:\Programme\PowerDVD\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[2228] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007749153d 2 bytes JMP 76aefca8 C:\Windows\syswow64\kernel32.dll
.text E:\Programme\PowerDVD\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[2228] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000077491555 2 bytes JMP 76af68ef C:\Windows\syswow64\kernel32.dll
.text E:\Programme\PowerDVD\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[2228] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007749156d 2 bytes JMP 76b78f61 C:\Windows\syswow64\kernel32.dll
.text E:\Programme\PowerDVD\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[2228] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000077491585 2 bytes JMP 76b78ac2 C:\Windows\syswow64\kernel32.dll
.text E:\Programme\PowerDVD\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[2228] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007749159d 2 bytes JMP 76b7865c C:\Windows\syswow64\kernel32.dll
.text E:\Programme\PowerDVD\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[2228] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000774915b5 2 bytes JMP 76aefd41 C:\Windows\syswow64\kernel32.dll
.text E:\Programme\PowerDVD\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[2228] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000774915cd 2 bytes JMP 76afb2dc C:\Windows\syswow64\kernel32.dll
.text E:\Programme\PowerDVD\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[2228] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000774916b2 2 bytes JMP 76b78e24 C:\Windows\syswow64\kernel32.dll
.text E:\Programme\PowerDVD\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe[2228] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000774916bd 2 bytes JMP 76b785f1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Conceiva\Mezzmo\MezzmoMediaServer.exe[2396] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000077491401 2 bytes JMP 76afb21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Conceiva\Mezzmo\MezzmoMediaServer.exe[2396] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000077491419 2 bytes JMP 76afb346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Conceiva\Mezzmo\MezzmoMediaServer.exe[2396] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000077491431 2 bytes JMP 76b78ea9 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Conceiva\Mezzmo\MezzmoMediaServer.exe[2396] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007749144a 2 bytes CALL 76ad48ad C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Conceiva\Mezzmo\MezzmoMediaServer.exe[2396] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000774914dd 2 bytes JMP 76b787a2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Conceiva\Mezzmo\MezzmoMediaServer.exe[2396] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000774914f5 2 bytes JMP 76b78978 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Conceiva\Mezzmo\MezzmoMediaServer.exe[2396] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007749150d 2 bytes JMP 76b78698 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Conceiva\Mezzmo\MezzmoMediaServer.exe[2396] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000077491525 2 bytes JMP 76b78a62 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Conceiva\Mezzmo\MezzmoMediaServer.exe[2396] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007749153d 2 bytes JMP 76aefca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Conceiva\Mezzmo\MezzmoMediaServer.exe[2396] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000077491555 2 bytes JMP 76af68ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Conceiva\Mezzmo\MezzmoMediaServer.exe[2396] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007749156d 2 bytes JMP 76b78f61 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Conceiva\Mezzmo\MezzmoMediaServer.exe[2396] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000077491585 2 bytes JMP 76b78ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Conceiva\Mezzmo\MezzmoMediaServer.exe[2396] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007749159d 2 bytes JMP 76b7865c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Conceiva\Mezzmo\MezzmoMediaServer.exe[2396] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000774915b5 2 bytes JMP 76aefd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Conceiva\Mezzmo\MezzmoMediaServer.exe[2396] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000774915cd 2 bytes JMP 76afb2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Conceiva\Mezzmo\MezzmoMediaServer.exe[2396] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000774916b2 2 bytes JMP 76b78e24 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Conceiva\Mezzmo\MezzmoMediaServer.exe[2396] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000774916bd 2 bytes JMP 76b785f1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2900] C:\Windows\syswow64\psapi.dll!GetModuleFileNameExW + 17 0000000077491401 2 bytes JMP 76afb21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2900] C:\Windows\syswow64\psapi.dll!EnumProcessModules + 17 0000000077491419 2 bytes JMP 76afb346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2900] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 17 0000000077491431 2 bytes JMP 76b78ea9 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2900] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 42 000000007749144a 2 bytes CALL 76ad48ad C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2900] C:\Windows\syswow64\psapi.dll!EnumDeviceDrivers + 17 00000000774914dd 2 bytes JMP 76b787a2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2900] C:\Windows\syswow64\psapi.dll!GetDeviceDriverBaseNameA + 17 00000000774914f5 2 bytes JMP 76b78978 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2900] C:\Windows\syswow64\psapi.dll!QueryWorkingSetEx + 17 000000007749150d 2 bytes JMP 76b78698 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2900] C:\Windows\syswow64\psapi.dll!GetDeviceDriverBaseNameW + 17 0000000077491525 2 bytes JMP 76b78a62 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2900] C:\Windows\syswow64\psapi.dll!GetModuleBaseNameW + 17 000000007749153d 2 bytes JMP 76aefca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2900] C:\Windows\syswow64\psapi.dll!EnumProcesses + 17 0000000077491555 2 bytes JMP 76af68ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2900] C:\Windows\syswow64\psapi.dll!GetProcessMemoryInfo + 17 000000007749156d 2 bytes JMP 76b78f61 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2900] C:\Windows\syswow64\psapi.dll!GetPerformanceInfo + 17 0000000077491585 2 bytes JMP 76b78ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2900] C:\Windows\syswow64\psapi.dll!QueryWorkingSet + 17 000000007749159d 2 bytes JMP 76b7865c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2900] C:\Windows\syswow64\psapi.dll!GetModuleBaseNameA + 17 00000000774915b5 2 bytes JMP 76aefd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2900] C:\Windows\syswow64\psapi.dll!GetModuleFileNameExA + 17 00000000774915cd 2 bytes JMP 76afb2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2900] C:\Windows\syswow64\psapi.dll!GetProcessImageFileNameW + 20 00000000774916b2 2 bytes JMP 76b78e24 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe[2900] C:\Windows\syswow64\psapi.dll!GetProcessImageFileNameW + 31 00000000774916bd 2 bytes JMP 76b785f1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe[5296] C:\Windows\syswow64\USER32.dll!GetMenu + 412 0000000076ec51dd 7 bytes JMP 000000011003ac50
.text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe[5296] C:\Windows\syswow64\USER32.dll!PeekMessageA + 407 0000000076ec610b 7 bytes JMP 000000011003b000
.text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe[5296] C:\Windows\syswow64\USER32.dll!CreateDialogIndirectParamW + 131 0000000076ecc6c1 7 bytes JMP 000000011003abc0
.text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe[5296] C:\Windows\syswow64\USER32.dll!MessageBoxIndirectA + 199 0000000076f0fc98 7 bytes JMP 000000011003af50
.text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe[5296] C:\Windows\syswow64\USER32.dll!MessageBoxIndirectW + 52 0000000076f0fcd1 7 bytes JMP 000000011003adf0
.text C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe[5296] C:\Windows\syswow64\USER32.dll!MessageBoxExA + 31 0000000076f0fcf5 7 bytes JMP 000000011003af00
.text C:\Users\Julian\AppData\Roaming\BitTorrent\BitTorrent.exe[5344] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000077491401 2 bytes JMP 76afb21b C:\Windows\syswow64\kernel32.dll
.text C:\Users\Julian\AppData\Roaming\BitTorrent\BitTorrent.exe[5344] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000077491419 2 bytes JMP 76afb346 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Julian\AppData\Roaming\BitTorrent\BitTorrent.exe[5344] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000077491431 2 bytes JMP 76b78ea9 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Julian\AppData\Roaming\BitTorrent\BitTorrent.exe[5344] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007749144a 2 bytes CALL 76ad48ad C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Users\Julian\AppData\Roaming\BitTorrent\BitTorrent.exe[5344] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000774914dd 2 bytes JMP 76b787a2 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Julian\AppData\Roaming\BitTorrent\BitTorrent.exe[5344] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000774914f5 2 bytes JMP 76b78978 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Julian\AppData\Roaming\BitTorrent\BitTorrent.exe[5344] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007749150d 2 bytes JMP 76b78698 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Julian\AppData\Roaming\BitTorrent\BitTorrent.exe[5344] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000077491525 2 bytes JMP 76b78a62 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Julian\AppData\Roaming\BitTorrent\BitTorrent.exe[5344] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007749153d 2 bytes JMP 76aefca8 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Julian\AppData\Roaming\BitTorrent\BitTorrent.exe[5344] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000077491555 2 bytes JMP 76af68ef C:\Windows\syswow64\kernel32.dll
.text C:\Users\Julian\AppData\Roaming\BitTorrent\BitTorrent.exe[5344] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007749156d 2 bytes JMP 76b78f61 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Julian\AppData\Roaming\BitTorrent\BitTorrent.exe[5344] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000077491585 2 bytes JMP 76b78ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Julian\AppData\Roaming\BitTorrent\BitTorrent.exe[5344] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007749159d 2 bytes JMP 76b7865c C:\Windows\syswow64\kernel32.dll
.text C:\Users\Julian\AppData\Roaming\BitTorrent\BitTorrent.exe[5344] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000774915b5 2 bytes JMP 76aefd41 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Julian\AppData\Roaming\BitTorrent\BitTorrent.exe[5344] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000774915cd 2 bytes JMP 76afb2dc C:\Windows\syswow64\kernel32.dll
.text C:\Users\Julian\AppData\Roaming\BitTorrent\BitTorrent.exe[5344] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000774916b2 2 bytes JMP 76b78e24 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Julian\AppData\Roaming\BitTorrent\BitTorrent.exe[5344] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000774916bd 2 bytes JMP 76b785f1 C:\Windows\syswow64\kernel32.dll
.text E:\Programme 2\FreeCountdownTimer\FreeCountdownTimer.exe[5476] C:\Windows\syswow64\PSAPI.dll!GetModuleFileNameExW + 17 0000000077491401 2 bytes JMP 76afb21b C:\Windows\syswow64\kernel32.dll
.text E:\Programme 2\FreeCountdownTimer\FreeCountdownTimer.exe[5476] C:\Windows\syswow64\PSAPI.dll!EnumProcessModules + 17 0000000077491419 2 bytes JMP 76afb346 C:\Windows\syswow64\kernel32.dll
.text E:\Programme 2\FreeCountdownTimer\FreeCountdownTimer.exe[5476] C:\Windows\syswow64\PSAPI.dll!GetModuleInformation + 17 0000000077491431 2 bytes JMP 76b78ea9 C:\Windows\syswow64\kernel32.dll
.text E:\Programme 2\FreeCountdownTimer\FreeCountdownTimer.exe[5476] C:\Windows\syswow64\PSAPI.dll!GetModuleInformation + 42 000000007749144a 2 bytes CALL 76ad48ad C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text E:\Programme 2\FreeCountdownTimer\FreeCountdownTimer.exe[5476] C:\Windows\syswow64\PSAPI.dll!EnumDeviceDrivers + 17 00000000774914dd 2 bytes JMP 76b787a2 C:\Windows\syswow64\kernel32.dll
.text E:\Programme 2\FreeCountdownTimer\FreeCountdownTimer.exe[5476] C:\Windows\syswow64\PSAPI.dll!GetDeviceDriverBaseNameA + 17 00000000774914f5 2 bytes JMP 76b78978 C:\Windows\syswow64\kernel32.dll
.text E:\Programme 2\FreeCountdownTimer\FreeCountdownTimer.exe[5476] C:\Windows\syswow64\PSAPI.dll!QueryWorkingSetEx + 17 000000007749150d 2 bytes JMP 76b78698 C:\Windows\syswow64\kernel32.dll
.text E:\Programme 2\FreeCountdownTimer\FreeCountdownTimer.exe[5476] C:\Windows\syswow64\PSAPI.dll!GetDeviceDriverBaseNameW + 17 0000000077491525 2 bytes JMP 76b78a62 C:\Windows\syswow64\kernel32.dll
.text E:\Programme 2\FreeCountdownTimer\FreeCountdownTimer.exe[5476] C:\Windows\syswow64\PSAPI.dll!GetModuleBaseNameW + 17 000000007749153d 2 bytes JMP 76aefca8 C:\Windows\syswow64\kernel32.dll
.text E:\Programme 2\FreeCountdownTimer\FreeCountdownTimer.exe[5476] C:\Windows\syswow64\PSAPI.dll!EnumProcesses + 17 0000000077491555 2 bytes JMP 76af68ef C:\Windows\syswow64\kernel32.dll
.text E:\Programme 2\FreeCountdownTimer\FreeCountdownTimer.exe[5476] C:\Windows\syswow64\PSAPI.dll!GetProcessMemoryInfo + 17 000000007749156d 2 bytes JMP 76b78f61 C:\Windows\syswow64\kernel32.dll
.text E:\Programme 2\FreeCountdownTimer\FreeCountdownTimer.exe[5476] C:\Windows\syswow64\PSAPI.dll!GetPerformanceInfo + 17 0000000077491585 2 bytes JMP 76b78ac2 C:\Windows\syswow64\kernel32.dll
.text E:\Programme 2\FreeCountdownTimer\FreeCountdownTimer.exe[5476] C:\Windows\syswow64\PSAPI.dll!QueryWorkingSet + 17 000000007749159d 2 bytes JMP 76b7865c C:\Windows\syswow64\kernel32.dll
.text E:\Programme 2\FreeCountdownTimer\FreeCountdownTimer.exe[5476] C:\Windows\syswow64\PSAPI.dll!GetModuleBaseNameA + 17 00000000774915b5 2 bytes JMP 76aefd41 C:\Windows\syswow64\kernel32.dll
.text E:\Programme 2\FreeCountdownTimer\FreeCountdownTimer.exe[5476] C:\Windows\syswow64\PSAPI.dll!GetModuleFileNameExA + 17 00000000774915cd 2 bytes JMP 76afb2dc C:\Windows\syswow64\kernel32.dll
.text E:\Programme 2\FreeCountdownTimer\FreeCountdownTimer.exe[5476] C:\Windows\syswow64\PSAPI.dll!GetProcessImageFileNameW + 20 00000000774916b2 2 bytes JMP 76b78e24 C:\Windows\syswow64\kernel32.dll
.text E:\Programme 2\FreeCountdownTimer\FreeCountdownTimer.exe[5476] C:\Windows\syswow64\PSAPI.dll!GetProcessImageFileNameW + 31 00000000774916bd 2 bytes JMP 76b785f1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray.exe[5524] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000077491401 2 bytes JMP 76afb21b C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray.exe[5524] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000077491419 2 bytes JMP 76afb346 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray.exe[5524] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000077491431 2 bytes JMP 76b78ea9 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray.exe[5524] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007749144a 2 bytes CALL 76ad48ad C:\Windows\syswow64\KERNEL32.dll
.text ... * 9
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray.exe[5524] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000774914dd 2 bytes JMP 76b787a2 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray.exe[5524] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000774914f5 2 bytes JMP 76b78978 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray.exe[5524] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007749150d 2 bytes JMP 76b78698 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray.exe[5524] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000077491525 2 bytes JMP 76b78a62 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray.exe[5524] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007749153d 2 bytes JMP 76aefca8 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray.exe[5524] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000077491555 2 bytes JMP 76af68ef C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray.exe[5524] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007749156d 2 bytes JMP 76b78f61 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray.exe[5524] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000077491585 2 bytes JMP 76b78ac2 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray.exe[5524] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007749159d 2 bytes JMP 76b7865c C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray.exe[5524] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000774915b5 2 bytes JMP 76aefd41 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray.exe[5524] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000774915cd 2 bytes JMP 76afb2dc C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray.exe[5524] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000774916b2 2 bytes JMP 76b78e24 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray.exe[5524] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000774916bd 2 bytes JMP 76b785f1 C:\Windows\syswow64\KERNEL32.dll
.text C:\Users\Julian\AppData\Roaming\Dropbox\bin\Dropbox.exe[5600] C:\Windows\syswow64\Psapi.dll!GetModuleFileNameExW + 17 0000000077491401 2 bytes JMP 76afb21b C:\Windows\syswow64\kernel32.dll
.text C:\Users\Julian\AppData\Roaming\Dropbox\bin\Dropbox.exe[5600] C:\Windows\syswow64\Psapi.dll!EnumProcessModules + 17 0000000077491419 2 bytes JMP 76afb346 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Julian\AppData\Roaming\Dropbox\bin\Dropbox.exe[5600] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 17 0000000077491431 2 bytes JMP 76b78ea9 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Julian\AppData\Roaming\Dropbox\bin\Dropbox.exe[5600] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 42 000000007749144a 2 bytes CALL 76ad48ad C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Users\Julian\AppData\Roaming\Dropbox\bin\Dropbox.exe[5600] C:\Windows\syswow64\Psapi.dll!EnumDeviceDrivers + 17 00000000774914dd 2 bytes JMP 76b787a2 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Julian\AppData\Roaming\Dropbox\bin\Dropbox.exe[5600] C:\Windows\syswow64\Psapi.dll!GetDeviceDriverBaseNameA + 17 00000000774914f5 2 bytes JMP 76b78978 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Julian\AppData\Roaming\Dropbox\bin\Dropbox.exe[5600] C:\Windows\syswow64\Psapi.dll!QueryWorkingSetEx + 17 000000007749150d 2 bytes JMP 76b78698 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Julian\AppData\Roaming\Dropbox\bin\Dropbox.exe[5600] C:\Windows\syswow64\Psapi.dll!GetDeviceDriverBaseNameW + 17 0000000077491525 2 bytes JMP 76b78a62 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Julian\AppData\Roaming\Dropbox\bin\Dropbox.exe[5600] C:\Windows\syswow64\Psapi.dll!GetModuleBaseNameW + 17 000000007749153d 2 bytes JMP 76aefca8 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Julian\AppData\Roaming\Dropbox\bin\Dropbox.exe[5600] C:\Windows\syswow64\Psapi.dll!EnumProcesses + 17 0000000077491555 2 bytes JMP 76af68ef C:\Windows\syswow64\kernel32.dll
.text C:\Users\Julian\AppData\Roaming\Dropbox\bin\Dropbox.exe[5600] C:\Windows\syswow64\Psapi.dll!GetProcessMemoryInfo + 17 000000007749156d 2 bytes JMP 76b78f61 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Julian\AppData\Roaming\Dropbox\bin\Dropbox.exe[5600] C:\Windows\syswow64\Psapi.dll!GetPerformanceInfo + 17 0000000077491585 2 bytes JMP 76b78ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Julian\AppData\Roaming\Dropbox\bin\Dropbox.exe[5600] C:\Windows\syswow64\Psapi.dll!QueryWorkingSet + 17 000000007749159d 2 bytes JMP 76b7865c C:\Windows\syswow64\kernel32.dll
.text C:\Users\Julian\AppData\Roaming\Dropbox\bin\Dropbox.exe[5600] C:\Windows\syswow64\Psapi.dll!GetModuleBaseNameA + 17 00000000774915b5 2 bytes JMP 76aefd41 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Julian\AppData\Roaming\Dropbox\bin\Dropbox.exe[5600] C:\Windows\syswow64\Psapi.dll!GetModuleFileNameExA + 17 00000000774915cd 2 bytes JMP 76afb2dc C:\Windows\syswow64\kernel32.dll
.text C:\Users\Julian\AppData\Roaming\Dropbox\bin\Dropbox.exe[5600] C:\Windows\syswow64\Psapi.dll!GetProcessImageFileNameW + 20 00000000774916b2 2 bytes JMP 76b78e24 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Julian\AppData\Roaming\Dropbox\bin\Dropbox.exe[5600] C:\Windows\syswow64\Psapi.dll!GetProcessImageFileNameW + 31 00000000774916bd 2 bytes JMP 76b785f1 C:\Windows\syswow64\kernel32.dll
.text E:\Programme\avastui.exe[5824] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 0000000076ad8791 8 bytes [31, C0, C2, 04, 00, 90, 90, ...]
---- Threads - GMER 2.1 ----
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:2756] 0000000077a43e85
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:2792] 0000000077a42e65
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:2828] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:2832] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:2836] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:2840] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:2844] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:2848] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:2852] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:2856] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:2860] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:2864] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:2908] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:2912] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:2936] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:3048] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:3052] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:3056] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:3060] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:3064] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:3068] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:2112] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:2784] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:2788] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:1504] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:3140] 0000000077a43e85
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:3232] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:3272] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:3276] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:3280] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:3284] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:3288] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:3308] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:4660] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:4664] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:4668] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:4672] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:4884] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:4812] 000000006f1429e1
Thread C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2716:4904] 000000006f1429e1
---- Processes - GMER 2.1 ----
Process C:\ProgramData\IePluginServices\PluginService.exe (*** suspicious ***) @ C:\ProgramData\IePluginServices\PluginService.exe [1824] (IePlugin Service/Cherished Technololgy LIMITED)(2014-08-28 13:50:58) 0000000000270000
Process C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe (*** suspicious ***) @ C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [1868] (WindowsProtectManger Service/Fuyu LIMITED)(2014-08-28 13:50:52) 0000000000020000
Library C:\Users\Julian\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll (*** suspicious ***) @ C:\Users\Julian\AppData\Roaming\Dropbox\bin\Dropbox.exe [5600](2014-11-13 06:49:58) 0000000003c00000
Library c:\users\julian\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpgpfdim.dll (*** suspicious ***) @ C:\Users\Julian\AppData\Roaming\Dropbox\bin\Dropbox.exe [5600](2014-12-08 18:49:11) 0000000004040000
Library C:\Users\Julian\AppData\Roaming\Dropbox\bin\libcef.dll (*** suspicious ***) @ C:\Users\Julian\AppData\Roaming\Dropbox\bin\Dropbox.exe [5600](2013-08-23 19:01:44) 0000000052770000
Library C:\Users\Julian\AppData\Roaming\Dropbox\bin\icudt.dll (*** suspicious ***) @ C:\Users\Julian\AppData\Roaming\Dropbox\bin\Dropbox.exe [5600] (ICU Data DLL/The ICU Project)(2013-08-23 19:01:42) 0000000054740000
Process \\?\C:\Windows\system32\wbem\WMIADAP.EXE (*** suspicious ***) @ \\?\C:\Windows\system32\wbem\WMIADAP.EXE [6528] (WMI Reverse Performance Adapter Maintenance Utility/Microsoft Corporation)(2012-12-13 09:09:58) 000000013f0c0000
---- EOF - GMER 2.1 ---- ADDITION: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 07-12-2014 02
Ran by Julian at 2014-12-08 19:50:21
Running from C:\Users\Julian\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus (Enabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
64 Bit HP CIO Components Installer (Version: 6.2.1 - Hewlett-Packard) Hidden
7-Zip 9.22 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0922-000001000000}) (Version: 9.22.00.0 - Igor Pavlov)
ABBYY FineReader 11 (HKLM-x32\...\{F1100000-0011-0000-0001-074957833700}) (Version: 11.0.460 - ABBYY)
abgx360 v1.0.6 (HKLM-x32\...\abgx360) (Version: - )
Ableton Live 9 Suite (HKLM\...\{F6BA3E9F-8637-4DCE-BBA8-75A6A57A9D0B}) (Version: 9.0.0.0 - Ableton)
Action! (HKLM-x32\...\Mirillis Action!) (Version: 1.13.1 - Mirillis)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 14.0.0.110 - Adobe Systems Incorporated)
Adobe Captivate Quiz Results Analyzer (HKLM-x32\...\QuizResultsAnalyzer.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1) (Version: 1.0 - Adobe Systems Incorporated)
Adobe Captivate Reviewer (HKLM-x32\...\AdobeCaptivateReviewer2.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1) (Version: 2.0 - Adobe Systems Incorporated)
Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.0.0.400 - Adobe Systems Incorporated)
Adobe Flash Media Live Encoder 3.2 (HKLM-x32\...\{0659E943-DDF4-44FC-9FEE-A13B09F8BB08}) (Version: 3.2.0 - Adobe Systems Incorporated)
Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.239 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.239 - Adobe Systems Incorporated)
Adobe Media Player (HKLM-x32\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.8 - Adobe Systems Incorporated)
Adobe Presenter 7 (HKLM-x32\...\Adobe Presenter 7) (Version: 7.0.6 - Adobe Systems)
Adobe Reader XI (11.0.09) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated)
Adobe Shockwave Player (HKLM-x32\...\{AD72CFB4-C2BF-424E-9DF0-C7BAD1F30A11}) (Version: 11.0 - Adobe Systems, Inc.)
Alien Isolation Ripley Edition MULTi2 1.0 (HKLM-x32\...\Alien Isolation Ripley Edition MULTi2 1.0) (Version: - )
Amazon Cloud Player (HKU\S-1-5-21-3333801471-2121581504-1765403736-1001\...\Amazon Amazon Cloud Player) (Version: 2.1.0.381 - Amazon Services LLC)
Amiga Forever (HKLM-x32\...\{F3626735-458B-48DD-A8E2-9746D3BB144D}) (Version: 2012.3.0 - Cloanto)
ANNO 1404 - Venedig (HKLM-x32\...\{A07B2C21-863B-47AB-AE7E-20BB00BD7D33}) (Version: 2.01.5010 - Ubisoft)
ANNO 1404 (HKLM-x32\...\{3D9CF3CA-3AB0-4A82-9853-D7C43FD1D775}) (Version: 1.02.0000 - Ubisoft)
Anno 1404 (x32 Version: 1.00.0000 - Ubisoft) Hidden
ANNO 2070 (HKLM-x32\...\{B48E264C-C8CD-4617-B0BE-46E977BAD694}) (Version: 1.0.0.0 - Ubisoft)
Another World 20th Anniversary Edition (c) Focus Home Interactive version 1 (HKLM-x32\...\QW5vdGhlciBXb3JsZA==_is1) (Version: 1 - )
Any Video Converter 5.0.9 (HKLM-x32\...\Any Video Converter_is1) (Version: - Any-Video-Converter.com)
Apple Application Support (HKLM-x32\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
AquaSoft DiaShow 7 Blue Net (HKLM-x32\...\AquaSoft DiaShow 7 Blue Net) (Version: 7.7.11 - AquaSoft)
AquaSoft DiaShow 7 Blue Net (x32 Version: 7.7.11 - AquaSoft) Hidden
Avast Internet Security (HKLM-x32\...\Avast) (Version: 10.0.2208 - AVAST Software)
Avidemux 2.6 (32-bit) (HKLM-x32\...\Avidemux 2.6) (Version: 2.6.4.8696 - )
AviSynth (HKLM-x32\...\AviSynth) (Version: 2.6.0 MT - )
B400 Series PCL Driver from OKI® Printing Solutions for Windows (HKLM-x32\...\{E327C2A5-E236-44C4-A410-B899403A49A9}) (Version: 102 - OKI® Printing Solutions)
Banished v1.0.0 64-bit (HKLM\...\{72C32B02-0B78-45F8-8528-2C93F62A7B47}) (Version: 1.0.0 - Shining Rock Software LLC)
BeadSurgeInstaller (HKLM-x32\...\{C1816FB6-2290-4251-8D11-E7ED83D0FD0F}) (Version: 1.0.0 - Default Company Name)
BitTorrent (HKU\S-1-5-21-3333801471-2121581504-1765403736-1001\...\BitTorrent) (Version: 7.9.2.35704 - BitTorrent Inc.)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
C5200 (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden
calibre 64bit (HKLM\...\{79C211A9-80D7-4E2A-A847-55BCC8F2ADCF}) (Version: 0.9.14 - Kovid Goyal)
Camtasia Studio 7 (HKLM-x32\...\{49471DB8-7F3C-42DB-89C2-AC50FA0C5290}) (Version: 7.1.0 - TechSmith Corporation)
CCleaner (HKLM\...\CCleaner) (Version: 4.11 - Piriform)
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.3.4643 - CDBurnerXP)
CdCoverCreator 2.5.3 (HKLM-x32\...\CdCoverCreator) (Version: 2.5.3 - thyanté Software)
CheckDrive (HKLM-x32\...\{B83513EC-2E4D-4621-816D-4CCF397BE702}_is1) (Version: 4.4 - Abelssoft)
Cisco AnyConnect Secure Mobility Client (HKLM-x32\...\Cisco AnyConnect Secure Mobility Client) (Version: 3.0.11042 - Cisco Systems, Inc.)
Cisco AnyConnect Secure Mobility Client (x32 Version: 3.0.11042 - Cisco Systems, Inc.) Hidden
Citavi 4 (HKLM-x32\...\{CC0A85B2-734A-45B3-B678-05F6A6499AC7}) (Version: 4.3.0.15 - Swiss Academic Software)
CLICKBIOSII (HKLM-x32\...\{EBCB111F-4907-4B28-BD03-F5BD901106D2}_is1) (Version: 1.0.107 - MSI)
CloneCD (HKLM-x32\...\CloneCD) (Version: - SlySoft)
CloneSpy 3.1 (HKLM-x32\...\CloneSpy) (Version: 3.1 - The CloneSpy Team)
ControlCenter (HKLM-x32\...\{AF14F0CD-5307-4134-BDFA-15974473C1EE}_is1) (Version: 2.5.048 - MSI)
Cry of Fear (HKLM-x32\...\Steam App 223710) (Version: - )
Cyberfox Web Browser (HKLM\...\{5EFB52C0-4EC9-46B4-80EB-8432C6599641}_is1) (Version: 20.0.1 - 8pecx Studios)
CyberLink PowerDVD 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.1905c.56 - CyberLink Corp.)
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.46.1.0327 - DT Soft Ltd)
Das Testament des Sherlock Holmes (HKLM-x32\...\{38A96559-FF39-4089-A609-BFD76C4A6C07}_is1) (Version: 1.00.0777 - Focus Home Interactive)
DayZ (HKLM-x32\...\Steam App 221100) (Version: - Bohemia Interactive)
Dolphin 4.0 (HKLM-x32\...\Dolphin) (Version: 4.0 - Dolphin Development Team)
Dropbox (HKU\S-1-5-21-3333801471-2121581504-1765403736-1001\...\Dropbox) (Version: 2.10.52 - Dropbox, Inc.)
Duke Nukem 3D Megaton Edition version 1.00 (HKLM-x32\...\Duke Nukem 3D Megaton Edition_is1) (Version: 1.00 - )
DVDFab 9.0.1.6 (14/12/2012) Qt (HKLM-x32\...\DVDFab 9_is1) (Version: - Fengtao Software Inc.)
EasyViewer (HKLM-x32\...\InstallShield_{EECD7B96-1416-4D3A-B12D-0D2512120C36}) (Version: 1.3.0.9 - MSI)
EasyViewer (x32 Version: 1.3.0.9 - MSI) Hidden
Enclave (HKLM-x32\...\Enclave_is1) (Version: - )
Euro Truck Simulator 2 Version 1.6.1 (HKLM-x32\...\Euro Truck Simulator 2_is1) (Version: 1.6.1 - SCS Software)
Exif-Viewer 2.51 (HKLM-x32\...\Exif-Viewer) (Version: 2.51 - Ralf Bibinger)
Fallout 2 (HKLM-x32\...\Fallout 2_is1) (Version: - GOG.com)
Fallout: New Vegas (HKLM-x32\...\Steam App 22380) (Version: - Obsidian Entertainment)
FormatFactory 3.3.1.0 (HKLM-x32\...\FormatFactory) (Version: 3.3.1.0 - Format Factory)
Free Countdown Timer 3.1.0 (HKLM-x32\...\{404245D0-E836-4737-9C12-D4D0034540F5}_is1) (Version: 3.1 - Comfort Software Group)
Free M4a to MP3 Converter 8.1 (HKLM-x32\...\Free M4a to MP3 Converter_is1) (Version: - ManiacTools.com)
Freeraser (HKLM-x32\...\Freeraser) (Version: 1.0.0.23 - Codyssey.com)
Freiwild-Tabs Version 1.2 (HKLM-x32\...\{1D0A4209-B251-486A-B09E-DD5A2123F814}_is1) (Version: 1.2 - Freiwild United)
Game Dev Tycoon v1.3.2 (c) Greenheart Games version 1 (HKLM-x32\...\R2FtZURldlR5Y29vbnYxMzI=_is1) (Version: 1 - )
Game of Thrones A Telltale Games Series (HKLM-x32\...\Game of Thrones A Telltale Games Series_is1) (Version: - )
GOG.com Downloader version 3.6.0 (HKLM-x32\...\{456A5815-604D-4D72-94DF-346D2B978A59}_is1) (Version: 3.6.0 - GOG.com)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 39.0.2171.71 - Google Inc.)
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Gothic (SCREENFUN-DVD November 2005) (HKLM-x32\...\Gothic_Screenfun) (Version: - )
Guitar Pro 5.2 (HKLM-x32\...\Guitar Pro 5_is1) (Version: - Arobas Music)
Half-Life 2 Complete Edition Incl. FakeFactory Cinematic Mod 2013 MULTI-2 1.0 (HKLM-x32\...\Half-Life 2 Complete Edition Incl. FakeFactory Cinematic Mod 2013 MULTI-2 1.0) (Version: - )
Harrys Filters 4.0 (Plugin) (HKLM\...\Harrys Filters 4.0 (Plugin)_is1) (Version: - The Plugin Site)
Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment)
HP Update (HKLM-x32\...\{7059BDA7-E1DB-442C-B7A1-6144596720A4}) (Version: 4.000.011.006 - Hewlett-Packard)
IBM SPSS Statistics 21 (HKLM\...\{1E26B9C2-ED08-4EEA-83C8-A786502B41E5}) (Version: 21.0.0.0 - IBM Corp)
iCloud (HKLM\...\{81E20D41-C277-4526-934D-F2380AF91B78}) (Version: 3.1.0.40 - Apple Inc.)
IcoFX 1.6.4 (HKLM-x32\...\IcoFX_is1) (Version: - )
iDevice Manager (HKLM-x32\...\FE5AE7DC-7B01-4263-A94C-B4526C276550_is1) (Version: 2.1.0.0 - Marx Softwareentwicklung)
ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.8.0 - LIGHTNING UK!)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.10.1464 - Intel Corporation)
Intel(R) Smart Connect Technology 3.0 x64 (HKLM\...\{01C324B7-3744-4EC0-9C4F-40BCCDD47CFB}) (Version: 3.0.41.1571 - Intel)
IsoBuster 3.1 (HKLM-x32\...\IsoBuster_is1) (Version: 3.1 - Smart Projects)
iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.)
Java 7 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH)
Joystick 2 Mouse 3 (HKLM-x32\...\Joystick 2 Mouse 3) (Version: - )
KProbe 2.5.2 (HKLM-x32\...\KProbe) (Version: - )
Left 4 Dead 2 (HKLM-x32\...\Steam App 550) (Version: - Valve)
Lilly Looking Through (HKLM-x32\...\GOGPACKLILLYLOOKINGTHROUGH_is1) (Version: 2.0.0.3 - GOG.com)
Live Update 5 (HKLM-x32\...\{009E5DF2-3F97-480B-89DA-F2D5E672E14A}_is1) (Version: 5.0.099 - MSI)
MAGIX Slideshow Maker 2 (HKLM-x32\...\MAGIX_MSI_Slideshow_Maker_2) (Version: 2.0.0.8 - MAGIX AG)
MAGIX Slideshow Maker 2 (x32 Version: 2.0.0.8 - MAGIX AG) Hidden
MD Adressbuch 2012 (HKLM-x32\...\MD Adressbuch 2012_is1) (Version: - Stefan Göppert Softwareentwicklung)
MechWarrior Online (HKLM-x32\...\{ffbbd184-8eba-469f-bb26-ea4e1f6bfd4c}) (Version: 1.4.1.0 - Piranha Games Inc.)
MechWarrior Online (x32 Version: 1.4.1.0 - Piranha Games Inc.) Hidden
MediaCenterPlugin Filme (HKLM-x32\...\{BC51B01C-2A33-49F3-A386-F8F7B1904757}) (Version: 1.0.1.0 - MS)
MediaInfo 0.7.67 (HKLM\...\MediaInfo) (Version: 0.7.67 - MediaArea.net)
Mezzmo (HKLM-x32\...\{9BE11DE3-4703-4482-BC77-A32D73951334}) (Version: 2.7.1.0 - Conceiva)
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 (HKLM-x32\...\Microsoft SQL Server 2005) (Version: - Microsoft Corporation)
Microsoft SQL Server Native Client (HKLM\...\{9ACF3FDB-C8E6-444C-8C64-13A221F7BFFD}) (Version: 9.00.5000.00 - Microsoft Corporation)
Microsoft SQL Server Setup Support Files (English) (HKLM-x32\...\{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}) (Version: 9.00.5000.00 - Microsoft Corporation)
Microsoft SQL Server VSS Writer (HKLM\...\{B636C9B9-A3F2-4DCE-ADCC-72E095018385}) (Version: 9.00.5000.00 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 (HKLM-x32\...\{6e8f74e0-43bd-4dce-8477-6ff6828acc07}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{90ffcee5-8608-4e94-8c18-a4feb4f83fb8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{B3B750C0-8C22-439D-B7CE-67F3ED99CC2B}) (Version: 1.20.146.0 - Microsoft)
Mittelerde Mordors Schatten Premium Edition MULTi2 1.0 (HKLM-x32\...\Mittelerde Mordors Schatten Premium Edition MULTi2 1.0) (Version: - )
Morrowind (HKLM-x32\...\{1D108D70-E7D1-4089-9A0A-99629C4D0CB8}) (Version: - )
MozBackup 1.5.1 (HKLM-x32\...\MozBackup) (Version: - Pavel Cvrcek)
Mozilla Firefox 33.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 33.1 (x86 de)) (Version: 33.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0 - Mozilla)
Mp3tag v2.58 (HKLM-x32\...\Mp3tag) (Version: v2.58 - Florian Heidenreich)
MSI SUITE (HKLM-x32\...\{1F025E3A-3074-48A3-A8F3-78E735739491}_is1) (Version: 1.0.029 - MSI)
MSVC80_x64_v2 (Version: 1.0.3.0 - Nokia) Hidden
MSVC80_x86_v2 (x32 Version: 1.0.3.0 - Nokia) Hidden
MSVC90_x64 (Version: 1.0.1.2 - Nokia) Hidden
MSVC90_x86 (x32 Version: 1.0.1.2 - Nokia) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MusicBrainz Picard (HKLM-x32\...\MusicBrainz Picard) (Version: 1.2 - MusicBrainz)
My Game Long Name (HKLM\...\UDK-0bd5954c-451b-4853-b8a9-c716bf446f85) (Version: - Epic Games, Inc.)
MyDriveConnect 3.3.0.1502 (HKLM-x32\...\MyDriveConnect) (Version: 3.3.0.1502 - TomTom)
NbuExplorer version 3.2 (HKLM-x32\...\{6C58B3E8-0822-490B-BC94-40CC02A6B37F}_is1) (Version: 3.2 - Petr Vilem)
Nero 12 (HKLM-x32\...\{560FC78C-A4B2-461D-9B47-820C1EEF87B8}) (Version: 12.0.02000 - Nero AG)
Nero Prerequisite Installer 2.0 (HKLM-x32\...\{0DBC021C-95D9-435A-A4B0-E6515AFD1A71}) (Version: 12.0.01000 - Nero AG)
nGlide 0.97 (HKLM-x32\...\nGlide) (Version: .97 - Zeus Software)
Nokia Connectivity Cable Driver (HKLM-x32\...\{29373274-977E-413C-A4DE-DC0F8E80C429}) (Version: 7.1.172.0 - Nokia)
Nokia PC Suite (HKLM-x32\...\Nokia PC Suite) (Version: 7.1.180.94 - Nokia)
Nokia PC Suite (x32 Version: 7.1.180.94 - Nokia) Hidden
Nokia Suite (HKLM-x32\...\Nokia Suite) (Version: 3.8.48.0 - Nokia)
Nokia Suite (x32 Version: 3.8.48.0 - Nokia) Hidden
Nur Entfernen der CopyTrans Suite möglich (HKU\S-1-5-21-3333801471-2121581504-1765403736-1001\...\CopyTrans Suite) (Version: 2.37 - WindSolutions)
NVIDIA 3D Vision Controller-Treiber 314.22 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 314.22 - NVIDIA Corporation)
NVIDIA Grafiktreiber 331.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 331.65 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.26.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.26.4 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.12.1031 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.1031 - NVIDIA Corporation)
NVIDIA Update 1.15.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.15.2 - NVIDIA Corporation)
O&O Defrag Professional (HKLM\...\{87CCB9C0-55B9-4110-884F-A6CB0927EF50}) (Version: 16.0.139 - O&O Software GmbH)
OlliOlli (HKLM-x32\...\1207665033_is1) (Version: 2.0.0.2 - GOG.com)
Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version: - )
Origin (HKLM-x32\...\Origin) (Version: 9.1.13.85 - Electronic Arts, Inc.)
Origin90 (HKLM-x32\...\{685A89CB-DF27-42D6-A623-34F40DBBFFB2}) (Version: 9.00.00 - OriginLab Corporation)
Outlast Version 1.0.11774 (HKLM-x32\...\Outlast_is1) (Version: 1.0.11774 - Red Barrels)
Paragon Backup and Recovery™ 2014 Free (HKLM\...\{C268B5E1-A5DA-11DF-A289-005056C00008}) (Version: 90.00.0003 - Paragon Software)
Path of Exile (HKLM-x32\...\{90A4562F-D4A1-4B65-906D-41F236CF6902}) (Version: 1.0.0.29375 - Grinding Gear Games)
PC Connectivity Solution (HKLM-x32\...\{6D01D1B1-17BD-4F10-BB11-F08F0C47D42B}) (Version: 12.0.109.0 - Nokia)
PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden
PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
PDF24 Creator 6.4.0 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org)
Portal (HKLM-x32\...\Steam App 400) (Version: - Valve)
PosteRazor (HKLM-x32\...\PosteRazor_is1) (Version: 1.5 - Alessandro Portale)
Prerequisite installer (x32 Version: 12.0.0003 - Nero AG) Hidden
Project 64 version 2.1.0.1 (HKLM-x32\...\Project 64_is1) (Version: 2.1.0.1 - )
PS3Splitter version 1.1.5.1 (HKLM-x32\...\PS3Splitter_is1) (Version: 1.1.5.1 - Karmian.org)
PSP ISO Compressor (HKLM-x32\...\{D47087E7-AA15-4D1D-8C0A-60F7E446D597}) (Version: 1.4.0 - danny_kay1710)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.53.216.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6793 - Realtek Semiconductor Corp.)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{17528CE4-C333-48FB-A9E4-D841E795CDCE}) (Version: 3.0.23.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 3.0.23.0 - Renesas Electronics Corporation) Hidden
Rosetta Stone Version 3 (HKLM-x32\...\{80F7CA44-F3A5-4853-8BA6-DDF57CD4F078}) (Version: 3.4.7.0 - Rosetta Stone Ltd.)
Roxio Express Labeler 3 (HKLM-x32\...\{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}) (Version: 3.2.1 - Roxio)
Roxio Game Capture HD PRO (HKLM-x32\...\{2DD84AB2-8BF4-49FA-9D62-E3F93D4F56FB}) (Version: 1.0 - Roxio)
schobuk 2.1 (HKLM-x32\...\schobuk_is1) (Version: schobuk 2.1 - )
ScummVM 1.6.0 (HKLM-x32\...\ScummVM_is1) (Version: - The ScummVM Team)
SDFormatter (HKLM-x32\...\{179324FF-7B16-4BA8-9836-055CAAEE4F08}) (Version: 4.0.0 - SD Association)
Secure Eraser (HKLM-x32\...\Secure Eraser_is1) (Version: 4.2.0.1 - ASCOMP Software GmbH)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Shadow Warrior (HKLM-x32\...\Shadow Warrior_is1) (Version: - Devolver Digital)
Shovel Knight (HKLM-x32\...\Shovel Knight_is1) (Version: - )
SimCity™ (HKLM-x32\...\{F70FDE4B-8F86-4eb6-8C8E-636EC89F6419}) (Version: 1.0.0.0 - Electronic Arts)
Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.)
Software Director (HKLM-x32\...\Cloanto Software Director) (Version: 3.8.9.0 - Cloanto Corporation)
SolveigMM AVI Trimmer (HKLM-x32\...\SolveigMM AVI Trimmer 2.1.1307.29) (Version: 2.1.1307.29 - Solveig Multimedia)
Sony Mobile Update Engine (HKLM-x32\...\Update Engine) (Version: 2.14.10.201407111005 - Sony Mobile Communications AB)
Sony PC Companion 2.10.236 (HKLM-x32\...\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}) (Version: 2.10.236 - Sony)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - )
Spotify (HKU\S-1-5-21-3333801471-2121581504-1765403736-1001\...\Spotify) (Version: 0.9.4.185.g7545a404 - Spotify AB)
SSDlife Pro (HKLM-x32\...\{800E31CD-E1E7-40EC-8410-5736E427F49A}) (Version: 2.3.52 - BinarySense Inc.)
StarCraft II (HKLM-x32\...\StarCraft II) (Version: - Blizzard Entertainment)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
Steinberg Drum Loop Expansion 01 (HKLM-x32\...\{490BF87E-1F75-4453-BF55-9F540543A3CA}) (Version: 1.0.0.1 - Steinberg Media Technologies GmbH)
Steinberg LoopMash Content (HKLM-x32\...\{4D454CF8-12FD-464D-B57B-B46FE27B78BB}) (Version: 1.0.0.005 - Steinberg Media Technologies GmbH)
Steinberg REVerence Content 01 (HKLM-x32\...\{532B917B-8235-4FA5-BE36-643A8BB053A5}) (Version: 1.0.0.006 - Steinberg Media Technologies GmbH)
Super-Charger (HKLM-x32\...\{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1) (Version: 1.2.016 - MSI)
Syberia 2 (HKLM-x32\...\GOGPACKSYBERIA2_is1) (Version: 2.0.0.8 - GOG.com)
Team Fortress 2 (HKLM-x32\...\Steam App 440) (Version: - Valve)
The Banner Saga (HKLM-x32\...\VGhlQmFubmVyU2FnYQ==_is1) (Version: 1 - )
The Elder Scrolls Online Beta (HKLM-x32\...\The Elder Scrolls Online Beta_is1) (Version: 0.3.4 - )
The Evil Within (HKLM-x32\...\VGhlRXZpbFdpdGhpbg==_is1) (Version: 1 - )
The Whispered World (HKLM-x32\...\{82225685-1513-4975-B624-155C10F3EE16}) (Version: 1.01 - Deep Silver)
THX TruStudio Pro (HKLM-x32\...\{4FA6CB9A-2972-4AAF-A36E-3C40FCC22395}) (Version: 1.04.03 - Creative Technology Limited)
To The Moon (HKLM-x32\...\To The Moon_is1) (Version: - )
TomTom HOME Visual Studio Merge Modules (HKLM-x32\...\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.)
Torque (HKU\S-1-5-21-3333801471-2121581504-1765403736-1001\...\Torque) (Version: 4.2.5.28819 - BitTorrent Inc.)
Torque Plugin (HKLM-x32\...\{00A3B50F-A7CA-45D5-BFAA-902CEC7A2A43}) (Version: 4.4.2 - BitTorrent, Inc)
Trend Micro SafeSync (HKLM\...\HFRS_is1) (Version: 5.1.0.1173 - Trend Micro)
Tropico 4 Modern Times V1.0.6(CREATED BY XEONKING©) (HKLM-x32\...\Tropico 4 Modern Times_is1) (Version: 1.0.6 - )
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
UltraISO Premium V9.53 (HKLM-x32\...\UltraISO_is1) (Version: - )
UnderCoverXP 1.23 (HKLM-x32\...\UnderCoverXP_is1) (Version: - Wicked & Wild Inc.)
Unigine Valley Benchmark version 1.0 (HKLM-x32\...\Unigine Valley Benchmark_is1) (Version: 1.0 - Unigine Corp.)
Unity Web Player (HKU\S-1-5-21-3333801471-2121581504-1765403736-1001\...\UnityWebPlayer) (Version: - Unity Technologies ApS)
Unlocker 1.9.2 (HKLM\...\Unlocker) (Version: 1.9.2 - Cedrick Collomb)
VideoGenie (HKLM-x32\...\{FC54FD8D-789C-406D-BB88-F7C4421B7E83}_is1) (Version: 1.0.0.12 - MSI)
Visual Studio C++ 10.0 Runtime (HKLM-x32\...\{4412F224-3849-4461-A3E9-DEEF8D252790}) (Version: 10.0.0 - TomTom International B.V.)
VLC media player 2.1.4 (HKLM\...\VLC media player) (Version: 2.1.4 - VideoLAN)
Welcome App (Start-up experience) (x32 Version: 12.0.15000 - Nero AG) Hidden
Winamp (HKLM-x32\...\Winamp) (Version: 5.63 - Nullsoft, Inc)
Winamp Erkennungs-Plug-in (HKU\S-1-5-21-3333801471-2121581504-1765403736-1001\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc)
WindowsMangerProtect20.0.0.722 (HKLM-x32\...\WindowsMangerProtect) (Version: 20.0.0.722 - WindowsProtect LIMITED) <==== ATTENTION
Windows-Treiberpaket - Nokia Modem (02/25/2011 4.7) (HKLM\...\E0AC723A3DE3A04256288CADBBB011B112AED454) (Version: 02/25/2011 4.7 - Nokia)
Windows-Treiberpaket - Nokia Modem (02/25/2011 7.01.0.9) (HKLM\...\72A50F48CC5601190B9C4E74D81161693133E7F7) (Version: 02/25/2011 7.01.0.9 - Nokia)
Windows-Treiberpaket - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0) (HKLM\...\62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F) (Version: 05/31/2012 7.1.2.0 - Nokia)
WinRAR 5.11 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.11.0 - win.rar GmbH)
XBMC (HKU\S-1-5-21-3333801471-2121581504-1765403736-1001\...\XBMC) (Version: - Team XBMC)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-3333801471-2121581504-1765403736-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Julian\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3333801471-2121581504-1765403736-1001_Classes\CLSID\{497F4457-E72A-6401-43CC-BD00574E0EE8}\InprocServer32 -> C:\Windows\system32\ole32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3333801471-2121581504-1765403736-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Julian\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3333801471-2121581504-1765403736-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Julian\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3333801471-2121581504-1765403736-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Julian\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3333801471-2121581504-1765403736-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Julian\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3333801471-2121581504-1765403736-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Julian\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3333801471-2121581504-1765403736-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Julian\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3333801471-2121581504-1765403736-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Julian\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-3333801471-2121581504-1765403736-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Julian\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
==================== Restore Points =========================
29-11-2014 13:48:20 Windows Update
01-12-2014 10:52:56 Installed PSP ISO Compressor
05-12-2014 17:44:08 Windows Update
08-12-2014 17:54:04 Sony PC Companion
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:34 - 2013-04-28 11:51 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {041CBF80-E6EF-4CD2-837D-E4028E68CCAC} - System32\Tasks\CCleanerSkipUAC => E:\Programme\CCleaner\CCleaner.exe [2014-02-20] (Piriform Ltd)
Task: {40DB3538-9F3E-484E-94B6-8CAC759CE76C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-21] (Google Inc.)
Task: {4D656BF0-0C1C-4BEC-81BA-E89E0C809B7A} - System32\Tasks\AdobeAAMUpdater-1.0-JulianDesktopPC-Julian => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04] (Adobe Systems Incorporated)
Task: {5E0B70D8-99CF-4198-8E2A-4BA419C801A0} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-26] (Adobe Systems Incorporated)
Task: {6A022FC3-240F-47AF-B42F-252DDE1AB2EC} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {7316DC84-4675-4FC6-AB2F-BDE3E7149650} - System32\Tasks\avast! Emergency Update => E:\Programme\AvastEmUpdate.exe [2014-11-16] (AVAST Software)
Task: {B15E404A-9CC9-4430-869C-2DC47EB0B041} - System32\Tasks\{021D7834-B7D5-4770-BCE2-16D667638E6A} => E:\Programme\ePSX\ePSXe.exe [2012-11-09] ()
Task: {B8D898E6-02AD-453A-B524-8DFA9EA0B39D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-21] (Google Inc.)
Task: {B9419299-4C7A-4AAE-88E0-F9C538557339} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {F8CA911B-DE69-4E8C-B8BF-038739DF3A8A} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe [2013-02-22] ()
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2013-01-18 17:00 - 2014-02-08 18:42 - 00117024 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2012-08-16 20:36 - 2012-08-16 20:36 - 00149032 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
2012-08-16 20:36 - 2012-08-16 20:36 - 00058920 _____ () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\NetworkHeuristic.dll
2013-02-23 15:21 - 2013-01-22 22:35 - 00009728 _____ () C:\MSI\MSI SUITE\MSIMonitor\MSIFileSyncMonitor.exe
2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2014-07-16 17:31 - 2012-09-07 15:57 - 00559424 _____ () C:\Program Files (x86)\ASCOMP Software\Secure Eraser\SecEraser64.dll
2014-03-07 22:32 - 2014-06-23 08:07 - 00113376 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe
2014-12-08 11:16 - 2014-12-08 11:16 - 02905088 _____ () E:\Programme\defs\14120800\algo.dll
2014-02-06 00:52 - 2014-02-06 00:52 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 13:05 - 2014-10-11 13:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2013-01-25 18:32 - 2012-06-28 09:24 - 00541683 _____ () E:\Programme\PowerDVD\PowerDVD12\Kernel\DMS\sqlite3.dll
2013-01-21 22:25 - 2010-11-25 11:11 - 00062464 ____R () C:\Program Files (x86)\Conceiva\Mezzmo\HS_REGEX.dll
2013-01-21 22:25 - 2012-08-14 11:36 - 00477696 ____R () C:\Program Files (x86)\Conceiva\Mezzmo\tag.dll
2013-01-21 22:25 - 2012-04-04 12:08 - 00839680 ____R () C:\Program Files (x86)\Conceiva\Mezzmo\LIBEAY32.dll
2013-01-21 22:25 - 2012-04-04 12:08 - 00159744 ____R () C:\Program Files (x86)\Conceiva\Mezzmo\SSLEAY32.dll
2013-01-21 22:25 - 2012-03-29 10:32 - 00060928 ____R () C:\Program Files (x86)\Conceiva\Mezzmo\extension-functions.dll
2014-03-07 22:32 - 2012-04-30 10:57 - 00039936 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\TMonitorAPI.dll
2014-03-07 22:32 - 2013-09-13 10:02 - 00208896 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\MExplorer.dll
2011-07-07 14:54 - 2011-07-07 14:54 - 00233984 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\Report.dll
2014-03-07 22:32 - 2013-05-20 11:58 - 00620718 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\sqlite3.dll
2014-03-07 22:32 - 2010-01-11 15:44 - 00053248 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\VObject.dll
2014-06-12 09:19 - 2014-06-12 09:19 - 00643584 _____ () C:\Program Files (x86)\Sony\Sony PC Companion\PhoneUpdate.dll
2014-12-08 19:49 - 2014-12-08 19:49 - 00043008 _____ () c:\users\julian\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpgpfdim.dll
2013-08-23 20:01 - 2013-08-23 20:01 - 25100288 _____ () C:\Users\Julian\AppData\Roaming\Dropbox\bin\libcef.dll
2014-11-16 10:37 - 2014-11-16 10:37 - 38562088 _____ () E:\Programme\libcef.dll
2014-11-11 11:06 - 2014-11-11 11:06 - 03649648 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2013-01-18 16:48 - 2012-03-29 06:18 - 01198872 ____R () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\Windows:7D63E91CD9ABF8BB
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^O&O Defrag Tray.lnk => C:\Windows\pss\O&O Defrag Tray.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Trend Micro SafeSync.lnk => C:\Windows\pss\Trend Micro SafeSync.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Julian^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup
MSCONFIG\startupreg: 2BB777B4D97D5CBA4F37597096A565E0D6CA792C._service_run => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=service
MSCONFIG\startupreg: Acrobat Assistant 8.0 => "E:\Programme\Adobe X Suite\Acrobat 10.0\Acrobat\Acrotray.exe"
MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
MSCONFIG\startupreg: AdobeCS5ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
MSCONFIG\startupreg: AdobeCS6ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
MSCONFIG\startupreg: Amazon Cloud Player => "C:\Users\Julian\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe"
MSCONFIG\startupreg: AppleIEDAV => E:\Programme\iCloud\AppleIEDAV.exe
MSCONFIG\startupreg: ApplePhotoStreams => E:\Programme\iCloud\ApplePhotoStreams.exe
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: Bonus.SSR.FR11 => "E:\Programme\Abbyy FineReader\Bonus.ScreenshotReader.exe" /autorun
MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
MSCONFIG\startupreg: CloneCDTray => "E:\Programme\CloneCD\CloneCDTray.exe" /s
MSCONFIG\startupreg: com.apple.dav.bookmarks.daemon => E:\Programme\iCloud\BookmarkDAV_client.exe
MSCONFIG\startupreg: ControlCenterCount => C:\Program Files (x86)\MSI\ControlCenter\ControlCenterCount.exe
MSCONFIG\startupreg: DAEMON Tools Lite => "E:\Programme\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: EADM => "E:\Programme\Origin\Origin.exe" -AutoStart
MSCONFIG\startupreg: HP Software Update => E:\Programme\HP\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: hpqSRMon => E:\Programme\HP\Digital Imaging\bin\hpqSRMon.exe
MSCONFIG\startupreg: iCloudServices => E:\Programme\iCloud\iCloudServices.exe
MSCONFIG\startupreg: iTunesHelper => "E:\Programme\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: Joystick 2 Mouse => C:\Program Files (x86)\Joystick 2 Mouse 3\Joystick 2 Mouse.exe /NoConfigure
MSCONFIG\startupreg: Live Update 5 => E:\Programme\MSI Live Update 5\Live Update 5\BootStartLiveupdate.exe /reminder
MSCONFIG\startupreg: MSI Suite => C:\MSI\MSI SUITE\StartMSISuite.exe
MSCONFIG\startupreg: PC Suite Tray => "E:\Programme\PC SUITE NOKIA 6300\Nokia PC Suite 7\PCSuite.exe" -onlytray
MSCONFIG\startupreg: PDFPrint => E:\Programme\PDF24\pdf24.exe
MSCONFIG\startupreg: Power2GoExpress => NA
MSCONFIG\startupreg: PowerDVD12Agent => "E:\Programme\PowerDVD\PowerDVD12\PowerDVD12Agent.exe"
MSCONFIG\startupreg: PowerDVD12DMREngine => "E:\Programme\PowerDVD\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe"
MSCONFIG\startupreg: Spotify Web Helper => "C:\Users\Julian\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: THX Audio Control Panel => "C:\Program Files (x86)\Creative\THX TruStudio Pro\THXAudioCP\THXAudio.exe" /r
MSCONFIG\startupreg: THXCfg64 => C:\Windows\system32\RunDLL32.exe C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64
MSCONFIG\startupreg: WinampAgent => E:\Programme\Winamp\winampa.exe
========================= Accounts: ==========================
Administrator (S-1-5-21-3333801471-2121581504-1765403736-500 - Administrator - Enabled) => C:\Users\Administrator
Gast (S-1-5-21-3333801471-2121581504-1765403736-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3333801471-2121581504-1765403736-1006 - Limited - Enabled)
Julian (S-1-5-21-3333801471-2121581504-1765403736-1001 - Administrator - Enabled) => C:\Users\Julian
==================== Faulty Device Manager Devices =============
Name: Microsoft-Teredo-Tunneling-Adapter
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: vpnva
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (12/08/2014 07:48:28 PM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT-AUTORITÄT)
Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden.
Error: (12/08/2014 07:32:01 PM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT-AUTORITÄT)
Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden.
Error: (12/08/2014 07:29:43 PM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT-AUTORITÄT)
Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden.
Error: (12/08/2014 06:49:43 PM) (Source: MsiInstaller) (EventID: 1018) (User: JulianDesktopPC)
Description: Die Anwendung "Microsoft ActiveSync" konnte nicht installiert werden, da sie mit dieser Windows-Version nicht kompatibel ist. Wenden Sie sich an den Hersteller der Anwendung, um ein Update zu erhalten.
Error: (12/08/2014 06:48:58 PM) (Source: MsiInstaller) (EventID: 1018) (User: JulianDesktopPC)
Description: Die Anwendung "Microsoft ActiveSync" konnte nicht installiert werden, da sie mit dieser Windows-Version nicht kompatibel ist. Wenden Sie sich an den Hersteller der Anwendung, um ein Update zu erhalten.
Error: (12/08/2014 11:15:49 AM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT-AUTORITÄT)
Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden.
Error: (12/08/2014 01:01:30 AM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT-AUTORITÄT)
Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden.
Error: (12/07/2014 07:00:01 PM) (Source: Windows Backup) (EventID: 4103) (User: )
Description: Die Sicherung wurde aufgrund eines Fehlers beim Schreiben am Sicherungsspeicherort "F:\" nicht abgeschlossen. Fehler: "Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und den Sicherungsort. (0x81000006)"
Error: (12/07/2014 00:45:53 PM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT-AUTORITÄT)
Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden.
Error: (12/07/2014 00:36:22 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 998
System errors:
=============
Error: (12/08/2014 07:48:27 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
ASPI32
Error: (12/08/2014 07:48:26 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Util ClearThink" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (12/08/2014 07:48:26 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Update ClearThink" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (12/08/2014 07:48:18 PM) (Source: Microsoft-Windows-BitLocker-Driver) (EventID: 24620) (User: NT-AUTORITÄT)
Description: Überprüfung des verschlüsselten Volumes: Die Volumeinformationen auf "M:" können nicht gelesen werden.
Error: (12/08/2014 07:48:13 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\Drivers\ASPI32.SYS nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten.
Error: (12/08/2014 07:32:01 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
ASPI32
Error: (12/08/2014 07:31:53 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Util ClearThink" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (12/08/2014 07:31:53 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Update ClearThink" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (12/08/2014 07:31:44 PM) (Source: Microsoft-Windows-BitLocker-Driver) (EventID: 24620) (User: NT-AUTORITÄT)
Description: Überprüfung des verschlüsselten Volumes: Die Volumeinformationen auf "M:" können nicht gelesen werden.
Error: (12/08/2014 07:31:41 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\Drivers\ASPI32.SYS nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten.
Microsoft Office Sessions:
=========================
Error: (12/08/2014 07:48:28 PM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT-AUTORITÄT)
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/08/2014 07:32:01 PM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT-AUTORITÄT)
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/08/2014 07:29:43 PM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT-AUTORITÄT)
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/08/2014 06:49:43 PM) (Source: MsiInstaller) (EventID: 1018) (User: JulianDesktopPC)
Description: Microsoft ActiveSync(NULL)(NULL)(NULL)(NULL)(NULL)
Error: (12/08/2014 06:48:58 PM) (Source: MsiInstaller) (EventID: 1018) (User: JulianDesktopPC)
Description: Microsoft ActiveSync(NULL)(NULL)(NULL)(NULL)(NULL)
Error: (12/08/2014 11:15:49 AM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT-AUTORITÄT)
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/08/2014 01:01:30 AM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT-AUTORITÄT)
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/07/2014 07:00:01 PM) (Source: Windows Backup) (EventID: 4103) (User: )
Description: F:\Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und den Sicherungsort. (0x81000006)
Error: (12/07/2014 00:45:53 PM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT-AUTORITÄT)
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (12/07/2014 00:36:22 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 998
CodeIntegrity Errors:
===================================
Date: 2014-03-23 13:28:18.898
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-03-23 11:39:13.184
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-03-22 22:15:15.244
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-03-22 10:17:37.190
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-03-22 03:40:57.180
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-03-22 00:16:58.336
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-03-21 11:08:21.689
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-03-20 23:37:52.444
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-03-20 23:13:50.131
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-03-20 21:59:21.404
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i5-3570K CPU @ 3.40GHz
Percentage of memory in use: 17%
Total physical RAM: 16335.52 MB
Available physical RAM: 13502.16 MB
Total Pagefile: 32669.21 MB
Available Pagefile: 29892.1 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:111.69 GB) (Free:10.86 GB) NTFS
Drive e: (Volume) (Fixed) (Total:1863.01 GB) (Free:353.03 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive h: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.03 GB) NTFS ==>[System with boot components (obtained from reading drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 111.8 GB) (Disk ID: EC8F2F72)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=111.7 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: CC96EFA6)
Partition 1: (Active) - (Size=1863 GB) - (Type=07 NTFS)
========================================================
Disk: 3 (Size: 2 KB) (Disk ID: 00000000)
Partition: GPT Partition Type.
==================== End Of Log ============================ |