platinum6161 | 06.01.2014 16:00 |
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-01-2014
Ran by kerim (administrator) on KERIM on 06-01-2014 15:58:15
Running from C:\Users\kerim\Downloads
Windows 8 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe
(Infowatch) C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\ComUpdatus.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(cyberlink) C:\Program Files (x86)\CyberLink\Shared files\brs.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13192848 2012-08-20] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1215632 2012-08-17] (Realtek Semiconductor)
HKLM\...\Run: [BtTray] - C:\Program Files (x86)\Bluetooth Suite\BtTray.exe [765056 2012-09-29] (Qualcomm Atheros)
HKLM\...\Run: [BtvStack] - C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [127616 2012-09-29] (Atheros Communications)
HKLM\...\Run: [ACMON] - C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [107192 2012-08-24] (ASUS)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028896 2013-07-27] (NVIDIA Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\reader_sl.exe [40312 2013-09-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ASUS InstantKey] - C:\Program Files (x86)\ASUS\ASUS Instant Key\Ikey_start.exe [20456 2012-02-20] (ASUS)
HKLM-x32\...\Run: [UpdatePSTShortCut] - C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe [222504 2012-07-03] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.)
HKLM-x32\...\Run: [BDRegion] - C:\Program Files (x86)\CyberLink\Shared files\brs.exe [78352 2012-05-23] (cyberlink)
HKLM-x32\...\Run: [ASUSWebStorage] - C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\AsusWSPanel.exe [3417984 2012-08-28] (ASUS Cloud Corporation)
HKLM-x32\...\Run: [AVP] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe [202328 2012-08-30] (Kaspersky Lab ZAO)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\klogon: C:\Windows\System32\klogon.dll (Kaspersky Lab ZAO)
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd)
MountPoints2: {6e38d51d-0141-11e3-be79-dc85dea536ca} - "F:\start.exe"
MountPoints2: {caab1d62-1811-11e3-be82-dc85dea536ca} - "F:\HTC_Sync_Manager_PC.exe"
AppInit_DLLs: C:\Program Files\NVIDIA Corporation\NvStreamSrv\rxinput.dll [653600 2013-07-27] (NVIDIA Corporation)
AppInit_DLLs-x32: c:\progra~2\nvidia~1\3dvisi~1\nvstinit.dll c:\windows\syswow64\nvinit.dll c:\progra~2\nvidia~1\nvstre~1\rxinput.dll [593696 2013-07-27] (NVIDIA Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus13.msn.com
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www1.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=C4E8DC85DEA536CA&affID=121240&tsp=4985
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: IEVkbdBHO Class - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\x64\ievkbd.dll (Kaspersky Lab ZAO)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: FilterBHO Class - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\x64\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: IEVkbdBHO Class - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\ievkbd.dll (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: FilterBHO Class - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\klwtbbho.dll (Kaspersky Lab ZAO)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\office15\MSOSB.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.188.1
FireFox:
========
FF ProfilePath: C:\Users\kerim\AppData\Roaming\Mozilla\Firefox\Profiles\5mflxf4c.default
FF Homepage: google.de
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.8 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Adblock Edge - C:\Users\kerim\AppData\Roaming\Mozilla\Firefox\Profiles\5mflxf4c.default\Extensions\{fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi
FF HKLM-x32\...\Firefox\Extensions: [linkfilter@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\FFExt\linkfilter@kaspersky.ru
FF Extension: Modul zur Link-Untersuchung - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\FFExt\linkfilter@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [virtualKeyboard@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\FFExt\virtualKeyboard@kaspersky.ru
FF Extension: Virtuelle Tastatur - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\FFExt\virtualKeyboard@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [KavAntiBanner@Kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\FFExt\KavAntiBanner@Kaspersky.ru
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\FFExt\KavAntiBanner@Kaspersky.ru
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Extension: () - C:\Users\kerim\AppData\Local\Google\Chrome\User Data\Default\Extensions\mphpbdjcljebbcnfopfngmfdackbbdgf\3.5.0.0
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\ChromeExt\urladvisor.crx
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\ChromeExt\virtkbd.crx
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\ChromeExt\ab.crx
==================== Services (Whitelisted) =================
R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [220288 2012-09-29] (Qualcomm Atheros Commnucations)
R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe [202328 2012-08-30] (Kaspersky Lab ZAO)
S2 CLKMSVC10_38F51D56; C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [243728 2012-05-23] (CyberLink)
R2 CSObjectsSrv; C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe [743992 2009-12-21] (Infowatch)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14984480 2013-07-27] (NVIDIA Corporation)
R2 OfficeSvc; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [1907896 2013-09-06] (Microsoft Corporation)
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2009-04-17] ()
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2012-09-29] (Atheros)
==================== Drivers (Whitelisted) ====================
R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [61824 2012-10-31] (ASUS Corporation)
R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [76952 2012-09-29] (Qualcomm Atheros)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
R0 CSCrySec; C:\Windows\System32\DRIVERS\CSCrySec.sys [85048 2009-12-14] (Infowatch)
R1 CSVirtualDiskDrv; C:\Windows\system32\DRIVERS\CSVirtualDiskDrv.sys [66104 2009-12-14] (Infowatch)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283200 2013-08-10] (DT Soft Ltd)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( )
R0 KL1; C:\Windows\system32\DRIVERS\kl1.sys [458032 2011-10-20] (Kaspersky Lab ZAO)
R1 kl2; C:\Windows\system32\DRIVERS\kl2.sys [13616 2011-10-20] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [636760 2013-08-09] (Kaspersky Lab)
R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [29488 2011-03-10] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [22544 2009-11-02] (Kaspersky Lab)
R1 nvkflt; C:\Windows\system32\DRIVERS\nvkflt.sys [284448 2013-06-21] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [39712 2013-05-14] (NVIDIA Corporation)
U0 msahci;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-06 15:58 - 2014-01-06 15:58 - 00018081 _____ C:\Users\kerim\Downloads\FRST.txt
2014-01-06 15:57 - 2014-01-06 15:57 - 01931762 _____ (Farbar) C:\Users\kerim\Downloads\FRST64.exe
2014-01-06 15:57 - 2014-01-06 15:57 - 00000000 ____D C:\FRST
2014-01-03 18:44 - 2014-01-03 18:44 - 00000000 ____D C:\opt
2014-01-03 18:00 - 2014-01-03 18:41 - 00000000 ____D C:\Users\kerim\.android
2014-01-03 18:00 - 2013-10-30 14:49 - 00357814 _____ C:\Users\kerim\Desktop\SDK Manager.exe
2014-01-03 17:59 - 2014-01-03 18:19 - 00000000 ____D C:\Users\kerim\Desktop\sdk
2014-01-03 17:34 - 2013-12-29 13:05 - 1971781632 _____ C:\Users\kerim\Desktop\Video-Training.iso
2014-01-01 21:10 - 2014-01-01 21:10 - 00002562 _____ C:\Windows\diagwrn.xml
2014-01-01 21:10 - 2014-01-01 21:10 - 00001908 _____ C:\Windows\diagerr.xml
2013-12-28 19:55 - 2013-12-28 19:55 - 00001149 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-12-28 19:55 - 2013-12-28 19:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-12-27 00:26 - 2013-12-27 22:29 - 00000000 ____D C:\Users\kerim\Desktop\Tom Clancy's Splinter Cell® Blacklist™
2013-12-27 00:26 - 2013-12-27 01:47 - 00000000 ____D C:\Program Files (x86)\Ubisoft
2013-12-26 22:05 - 2013-12-26 22:42 - 00000000 ____D C:\Program Files (x86)\SQUARE ENIX
2013-12-22 23:31 - 2013-12-22 23:39 - 00000000 ____D C:\Users\kerim\AppData\Roaming\Apple Computer
2013-12-22 23:31 - 2013-12-22 23:31 - 00000000 ____D C:\Users\kerim\AppData\Local\Apple Computer
2013-12-22 23:30 - 2013-12-22 23:45 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-12-22 23:30 - 2013-12-22 23:30 - 00000000 ____D C:\Users\kerim\AppData\Local\Apple
2013-12-22 23:30 - 2013-12-22 23:30 - 00000000 ____D C:\ProgramData\Apple Computer
2013-12-22 23:29 - 2013-12-22 23:30 - 00000000 ____D C:\ProgramData\Apple
2013-12-20 13:43 - 2013-12-20 13:43 - 00000000 ____D C:\Users\kerim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2013-12-20 13:43 - 2013-12-20 13:43 - 00000000 ____D C:\Users\kerim\AppData\Local\Ubisoft Game Launcher
2013-12-20 00:42 - 2013-12-20 00:42 - 00000021 _____ C:\Users\kerim\AppData\Roaming\my_intel.sys
2013-12-18 14:14 - 2013-12-18 14:14 - 00000000 ____D C:\ProgramData\ASUS
2013-12-17 22:17 - 2013-12-17 23:49 - 00000000 ____D C:\Users\kerim\AppData\Roaming\de.3m5.wendel.flcd.FLCDB
2013-12-17 22:17 - 2013-12-17 22:17 - 00001113 _____ C:\Users\Public\Desktop\Fragen-Lern-CD 4.4.lnk
2013-12-17 22:11 - 2013-11-26 18:25 - 00000000 ____D C:\Users\kerim\Desktop\Fragen-Lern-CD 4.4
2013-12-15 12:59 - 2013-12-15 12:59 - 00000000 ____D C:\Users\kerim\Documents\Assassin's Creed IV Black Flag
2013-12-13 21:38 - 2013-12-13 23:58 - 00000000 ____D C:\Program Files (x86)\Activision
2013-12-13 13:25 - 2013-12-13 13:25 - 00000000 ____D C:\Users\kerim\Documents\Battlefield 4
2013-12-13 13:23 - 2013-12-13 13:23 - 00000000 ____D C:\ProgramData\Origin
2013-12-13 12:12 - 2013-12-13 12:13 - 00000000 ____D C:\ProgramData\Package Cache
==================== One Month Modified Files and Folders =======
2014-01-06 15:58 - 2014-01-06 15:58 - 00018081 _____ C:\Users\kerim\Downloads\FRST.txt
2014-01-06 15:58 - 2013-08-25 14:58 - 00000302 _____ C:\Windows\Tasks\Dealply.job
2014-01-06 15:57 - 2014-01-06 15:57 - 01931762 _____ (Farbar) C:\Users\kerim\Downloads\FRST64.exe
2014-01-06 15:57 - 2014-01-06 15:57 - 00000000 ____D C:\FRST
2014-01-06 15:38 - 2013-11-16 00:36 - 01803626 _____ C:\Windows\WindowsUpdate.log
2014-01-06 15:38 - 2013-08-09 17:47 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2014-01-06 15:29 - 2013-09-11 16:56 - 00000300 _____ C:\Windows\Tasks\AutoKMS.job
2014-01-06 15:29 - 2012-11-24 05:46 - 00000000 ____D C:\ProgramData\NVIDIA
2014-01-06 15:29 - 2012-07-26 08:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-06 15:22 - 2012-07-26 06:26 - 00262144 ___SH C:\Windows\system32\config\BBI
2014-01-06 15:00 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\system32\sru
2014-01-06 14:23 - 2013-09-02 22:51 - 00000000 ____D C:\Users\kerim\Desktop\kerim
2014-01-06 14:14 - 2013-08-09 17:45 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-06 14:07 - 2013-08-10 11:15 - 00000000 ____D C:\Users\kerim\AppData\Local\CrashDumps
2014-01-06 04:24 - 2013-08-09 16:09 - 00003596 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-11796182-3876703279-3499078659-1002
2014-01-06 04:15 - 2013-10-24 00:49 - 00000000 ____D C:\Users\kerim\Desktop\lieder
2014-01-06 04:10 - 2013-08-10 20:14 - 00000000 ____D C:\Users\kerim\AppData\Roaming\vlc
2014-01-06 01:58 - 2013-09-02 22:25 - 00000000 ____D C:\Users\kerim\AppData\Roaming\TS3Client
2014-01-05 22:27 - 2013-08-28 17:54 - 00077824 ___SH C:\Users\kerim\Downloads\Thumbs.db
2014-01-05 14:40 - 2013-08-10 20:10 - 00000000 ____D C:\Users\kerim\AppData\Roaming\DAEMON Tools Lite
2014-01-05 03:00 - 2013-08-09 23:33 - 01524224 ___SH C:\Users\kerim\Desktop\Thumbs.db
2014-01-04 19:46 - 2013-11-16 22:10 - 00000000 ____D C:\Users\kerim\AppData\Local\Eclipse
2014-01-04 00:58 - 2013-08-25 15:11 - 00000112 _____ C:\Users\kerim\AppData\Roaming\WB.CFG
2014-01-03 18:47 - 2013-11-16 22:10 - 00000000 ____D C:\Users\kerim\Desktop\Projekte
2014-01-03 18:44 - 2014-01-03 18:44 - 00000000 ____D C:\opt
2014-01-03 18:41 - 2014-01-03 18:00 - 00000000 ____D C:\Users\kerim\.android
2014-01-03 18:19 - 2014-01-03 17:59 - 00000000 ____D C:\Users\kerim\Desktop\sdk
2014-01-03 18:00 - 2013-08-09 16:00 - 00000000 ____D C:\Users\kerim
2014-01-02 01:06 - 2013-11-01 15:28 - 00000000 ____D C:\Program Files (x86)\GameforgeLive
2014-01-01 21:12 - 2012-08-03 00:02 - 00753134 _____ C:\Windows\system32\perfh007.dat
2014-01-01 21:12 - 2012-08-03 00:02 - 00155826 _____ C:\Windows\system32\perfc007.dat
2014-01-01 21:12 - 2012-07-26 08:28 - 01745416 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-01 21:10 - 2014-01-01 21:10 - 00002562 _____ C:\Windows\diagwrn.xml
2014-01-01 21:10 - 2014-01-01 21:10 - 00001908 _____ C:\Windows\diagerr.xml
2013-12-29 13:05 - 2014-01-03 17:34 - 1971781632 _____ C:\Users\kerim\Desktop\Video-Training.iso
2013-12-28 19:55 - 2013-12-28 19:55 - 00001149 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-12-28 19:55 - 2013-12-28 19:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-12-28 19:55 - 2013-08-09 17:33 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-28 00:30 - 2013-08-09 16:01 - 00000000 ____D C:\Users\kerim\AppData\Local\VirtualStore
2013-12-27 22:29 - 2013-12-27 00:26 - 00000000 ____D C:\Users\kerim\Desktop\Tom Clancy's Splinter Cell® Blacklist™
2013-12-27 01:47 - 2013-12-27 00:26 - 00000000 ____D C:\Program Files (x86)\Ubisoft
2013-12-27 00:26 - 2012-11-24 05:41 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-12-27 00:15 - 2013-08-10 11:25 - 00002004 _____ C:\ProgramData\flcd_proxy.log
2013-12-26 22:42 - 2013-12-26 22:05 - 00000000 ____D C:\Program Files (x86)\SQUARE ENIX
2013-12-26 22:02 - 2013-09-07 23:49 - 00000000 ____D C:\Users\kerim\AppData\Local\SKIDROW
2013-12-23 17:58 - 2013-08-09 16:03 - 00000515 _____ C:\Users\kerim\AppData\Roaming\sp_data.sys
2013-12-23 12:44 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\system32\NDF
2013-12-22 23:45 - 2013-12-22 23:30 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-12-22 23:39 - 2013-12-22 23:31 - 00000000 ____D C:\Users\kerim\AppData\Roaming\Apple Computer
2013-12-22 23:31 - 2013-12-22 23:31 - 00000000 ____D C:\Users\kerim\AppData\Local\Apple Computer
2013-12-22 23:30 - 2013-12-22 23:30 - 00000000 ____D C:\Users\kerim\AppData\Local\Apple
2013-12-22 23:30 - 2013-12-22 23:30 - 00000000 ____D C:\ProgramData\Apple Computer
2013-12-22 23:30 - 2013-12-22 23:29 - 00000000 ____D C:\ProgramData\Apple
2013-12-20 13:43 - 2013-12-20 13:43 - 00000000 ____D C:\Users\kerim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2013-12-20 13:43 - 2013-12-20 13:43 - 00000000 ____D C:\Users\kerim\AppData\Local\Ubisoft Game Launcher
2013-12-20 00:42 - 2013-12-20 00:42 - 00000021 _____ C:\Users\kerim\AppData\Roaming\my_intel.sys
2013-12-18 14:14 - 2013-12-18 14:14 - 00000000 ____D C:\ProgramData\ASUS
2013-12-18 14:14 - 2013-08-09 16:00 - 00000000 ____D C:\Users\kerim\AppData\Local\ASUS
2013-12-17 23:49 - 2013-12-17 22:17 - 00000000 ____D C:\Users\kerim\AppData\Roaming\de.3m5.wendel.flcd.FLCDB
2013-12-17 22:58 - 2013-08-10 11:21 - 00000000 ____D C:\Program Files (x86)\Wendel-Verlag
2013-12-17 22:17 - 2013-12-17 22:17 - 00001113 _____ C:\Users\Public\Desktop\Fragen-Lern-CD 4.4.lnk
2013-12-15 12:59 - 2013-12-15 12:59 - 00000000 ____D C:\Users\kerim\Documents\Assassin's Creed IV Black Flag
2013-12-15 12:59 - 2013-09-07 20:02 - 00000000 ____D C:\ProgramData\Orbit
2013-12-13 23:58 - 2013-12-13 21:38 - 00000000 ____D C:\Program Files (x86)\Activision
2013-12-13 13:25 - 2013-12-13 13:25 - 00000000 ____D C:\Users\kerim\Documents\Battlefield 4
2013-12-13 13:23 - 2013-12-13 13:23 - 00000000 ____D C:\ProgramData\Origin
2013-12-13 12:13 - 2013-12-13 12:12 - 00000000 ____D C:\ProgramData\Package Cache
2013-12-11 21:42 - 2013-08-09 17:25 - 00000000 ___RD C:\Users\kerim\Desktop\Asus
2013-12-10 20:14 - 2013-08-09 17:45 - 00003772 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
Files to move or delete:
====================
C:\ProgramData\SetStretch.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-12-29 14:36
==================== End Of Log ============================ --- --- ---
Addition Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 05-01-2014
Ran by kerim at 2014-01-06 15:58:41
Running from C:\Users\kerim\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Kaspersky PURE 2.0 (Enabled - Up to date) {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Kaspersky PURE 2.0 (Enabled - Up to date) {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
7-Zip 9.21 (x32 Version: 9.21.00.0 - Igor Pavlov)
Adobe AIR (x32 Version: 3.9.0.1380 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 3.9.0.1380 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.170 - Adobe Systems Incorporated)
Adobe Reader X (10.1.8) MUI (x32 Version: 10.1.8 - Adobe Systems Incorporated)
Alcor Micro USB Card Reader (x32 Version: 3.9.142.62248 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 3.9.142.62248 - Alcor Micro Corp.) Hidden
ASUS Instant Connect (x32 Version: 1.2.8 - ASUS)
ASUS Instant Key (x32 Version: 1.0.5 - ASUS)
ASUS InstantOn (x32 Version: 3.0.2 - ASUS)
ASUS LifeFrame3 (x32 Version: 3.1.9 - ASUS)
ASUS Live Update (x32 Version: 3.1.8 - ASUS)
ASUS N Series Demo (x32 Version: 1.0.0002 - ASUS)
ASUS Power4Gear Hybrid (Version: 2.0.4 - ASUS)
ASUS Product Demo Movie (x32 Version: 1.0.3 - ASUS )
ASUS Smart Gesture (x32 Version: 1.0.35 - ASUS)
ASUS Splendid Video Enhancement Technology (x32 Version: 1.03.0004 - ASUS)
ASUS Tutor (x32 Version: 1.0.7 - ASUS)
ASUS USB Charger Plus (x32 Version: 2.1.4 - ASUS)
ASUS Video Magic (x32 Version: 6.0.4712 - CyberLink Corp.)
ASUS Video Magic (x32 Version: 6.0.4712 - CyberLink Corp.) Hidden
ASUS WebStorage Sync Agent (x32 Version: 1.1.9.120 - ASUS Cloud Corporation)
ASUSDVD (x32 Version: 10.0.4126.52 - CyberLink Corp.)
ASUSDVD (x32 Version: 10.0.4126.52 - CyberLink Corp.) Hidden
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (x32 Version: 2.1.0.7 - Atheros Communications Inc.)
ATK Package (x32 Version: 1.0.0023 - ASUS)
CCleaner (Version: 4.04 - Piriform)
CyberLink MediaEspresso 6.5 (x32 Version: 6.5.3019_44673 - CyberLink Corp.)
CyberLink MediaEspresso 6.5 (x32 Version: 6.5.3019_44673 - CyberLink Corp.) Hidden
CyberLink PowerDirector (x32 Version: 8.0.4905d - CyberLink Corp.)
CyberLink PowerDirector (x32 Version: 8.0.4905d - CyberLink Corp.) Hidden
DAEMON Tools Lite (x32 Version: 4.47.1.0333 - Disc Soft Ltd)
Fragen-Lern-CD 4.4 (x32 Version: 4.4.5 - Wendel-Verlag GmbH)
Fragen-Lern-CD 4.4 (x32 Version: 4.4.5 - Wendel-Verlag GmbH) Hidden
Free Studio version 2013 (x32 Version: 6.1.10.812 - DVDVideoSoft Ltd.)
Google Update Helper (x32 Version: 1.3.23.0 - DealPly Technologies Ltd) Hidden <==== ATTENTION
Intel(R) Management Engine Components (x32 Version: 8.1.0.1252 - Intel Corporation)
Intel(R) Processor Graphics (x32 Version: 9.17.10.2828 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (x32 Version: 2.0.0.37149 - Intel Corporation)
Intel® Trusted Connect Service Client (Version: 1.24.388.1 - Intel Corporation) Hidden
Java 7 Update 25 (x32 Version: 7.0.250 - Oracle)
Java 7 Update 45 (64-bit) (Version: 7.0.450 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.5 - Sun Microsystems, Inc.) Hidden
Java SE Development Kit 7 Update 45 (64-bit) (Version: 1.7.0.450 - Oracle)
Kaspersky PURE 2.0 (x32 Version: 12.0.2.733 - Kaspersky Lab)
Kaspersky PURE 2.0 (x32 Version: 12.0.2.733 - Kaspersky Lab) Hidden
League of Legends (x32 Version: 3.0.1 - Riot Games)
League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden
Microsoft Office 365 Home Premium - de-de (Version: 15.0.4535.1511 - Microsoft Corporation)
Microsoft SkyDrive (HKCU Version: 17.0.2003.1112 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (x32 Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (x32 Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (x32 Version: 11.0.60610 - Microsoft Corporation) Hidden
Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0 - Mozilla)
Mozilla Maintenance Service (x32 Version: 26.0 - Mozilla)
MyFreeCodec (HKCU Version: - )
NVIDIA 3D Vision Treiber 320.49 (Version: 320.49 - NVIDIA Corporation)
NVIDIA GeForce Experience 1.6 (Version: 1.6 - NVIDIA Corporation)
NVIDIA Grafiktreiber 320.49 (Version: 320.49 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.24.2 (Version: 1.3.24.2 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.131.854 - NVIDIA Corporation) Hidden
NVIDIA Optimus 7.2.17 (Version: 7.2.17 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.12.1031 - NVIDIA Corporation)
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.2049 - NVIDIA Corporation) Hidden
NVIDIA Systemsteuerung 320.49 (Version: 320.49 - NVIDIA Corporation) Hidden
NVIDIA Update 7.2.17 (Version: 7.2.17 - NVIDIA Corporation) Hidden
NVIDIA Update Components (Version: 7.2.17 - NVIDIA Corporation) Hidden
NVIDIA Virtual Audio 1.2.1 (Version: 1.2.1 - NVIDIA Corporation)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4535.1004 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4535.1004 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4535.1004 - Microsoft Corporation) Hidden
Qualcomm Atheros Bluetooth Suite (64) (Version: 8.0.0.210 - Qualcomm Atheros Communications)
Qualcomm Atheros Client Installation Program (x32 Version: 10.0 - Qualcomm Atheros)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6710 - Realtek Semiconductor Corp.)
SHIELD Streaming (Version: 1.05.19 - NVIDIA Corporation) Hidden
TeamSpeak 3 Client (HKCU Version: 3.0.13.1 - TeamSpeak Systems GmbH)
TeamViewer 8 (x32 Version: 8.0.22298 - TeamViewer)
Tom Clancy's Splinter Cell® Blacklist™ (x32 Version: 1.01 - Ubisoft)
Uplay (x32 Version: 3.0 - Ubisoft)
VLC media player 2.0.8 (Version: 2.0.8 - VideoLAN)
Windows-Treiberpaket - ASUS (ATP) Mouse (10/29/2012 1.0.0.148) (Version: 10/29/2012 1.0.0.148 - ASUS)
WinFlash (x32 Version: 2.41.1 - ASUS)
WinRAR 4.20 (32-Bit) (x32 Version: 4.20.0 - win.rar GmbH)
Zip Opener Packages (HKCU Version: - ) <==== ATTENTION
==================== Restore Points =========================
22-12-2013 22:30:10 Installed iTunes
26-12-2013 23:25:07 Entfernt Tom Clancy's Splinter Cell® Blacklist™
03-01-2014 16:53:45 Removed Java SE Development Kit 7 Update 45 (64-bit)
==================== Hosts content: ==========================
2012-07-26 06:26 - 2012-07-26 06:26 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {22AE688C-2FA7-4FDA-9CB3-42CA80F74404} - System32\Tasks\AutoKMS => C:\Users\kerim\Desktop\AutoKMS\AutoKMS.exe
Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {27C2031E-528C-4C0E-99A6-B755A8AE4499} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [2012-08-24] (ASUS)
Task: {4778C0E8-CBD3-40BF-8B18-36FC1E6FCEAB} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2013-09-11] (Microsoft Corporation)
Task: {75B3CF74-79CF-45F5-8ECB-6D3F344C4B2C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-10] (Adobe Systems Incorporated)
Task: {80A95F3C-DBB7-4304-B16B-D5896FB896E1} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2012-07-25] (ASUSTeK Computer Inc.)
Task: {9E52E26E-C91F-4A80-886B-4F99536AFA70} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [2013-09-06] (Microsoft Corporation)
Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {C2C99FC4-4FB1-4CFA-8CE7-211B71F15303} - System32\Tasks\Dealply => C:\Users\kerim\AppData\Roaming\Dealply\UpdateProc\UpdateTask.exe [2013-08-25] () <==== ATTENTION
Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {F2CDBAB0-7FCF-4E3B-A74C-E1449FA4BD18} - System32\Tasks\ASUS Touchpad Launcher (x64) => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [2012-10-31] (AsusTek)
Task: {F3494E67-488A-4A8D-8587-A4854BB3D65B} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2012-07-24] (ASUSTek Computer Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\AutoKMS.job => C:\Users\kerim\Desktop\AutoKMS\AutoKMS.exe
Task: C:\Windows\Tasks\Dealply.job => C:\Users\kerim\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
==================== Loaded Modules (whitelisted) =============
2012-08-24 18:26 - 2012-08-24 18:26 - 00031360 _____ () C:\Program Files\ASUS\P4G\DevMng.dll
2013-08-10 16:34 - 2013-08-10 16:37 - 00176048 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\ModernShared\ErrorReporting\ErrorReporting.dll
2013-09-11 17:15 - 2013-08-21 20:56 - 00386216 _____ () C:\Program Files\Microsoft Office 15\ClientX64\c2rui.dll
2013-09-11 17:15 - 2013-08-21 20:55 - 00520872 _____ () C:\Program Files\Microsoft Office 15\ClientX64\c2r64.dll
2012-08-30 21:23 - 2012-08-30 21:23 - 00459192 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\dblite.dll
2012-08-30 21:24 - 2012-08-30 21:24 - 02126264 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\QtCore4.dll
2012-08-30 21:24 - 2012-08-30 21:24 - 07422392 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\QtGui4.dll
2012-08-30 21:24 - 2012-08-30 21:24 - 02453944 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\QtDeclarative4.dll
2012-08-30 21:24 - 2012-08-30 21:24 - 00795064 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\QtNetwork4.dll
2012-08-30 21:24 - 2012-08-30 21:24 - 01270200 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\QtScript4.dll
2012-08-30 21:24 - 2012-08-30 21:24 - 00192952 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\QtSql4.dll
2012-11-24 05:45 - 2012-09-17 10:27 - 00004096 _____ () C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll
2011-09-05 18:36 - 2011-09-05 18:36 - 00025088 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\imageformats\qgif4.dll
2011-09-05 18:36 - 2011-09-05 18:36 - 00180224 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\imageformats\qjpeg4.dll
2012-11-24 05:41 - 2012-06-25 11:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2013-12-28 19:55 - 2013-12-05 20:36 - 03559024 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\ProgramData\Temp:373E1720
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (01/06/2014 03:29:36 PM) (Source: NvStreamSvc) (User: )
Description: NvStreamSvcUnregistering VAD endpoint [0]
Error: (01/06/2014 03:29:33 PM) (Source: NvStreamSvc) (User: )
Description: NvStreamSvcNvVAD endpoint registered successfully [0]
Error: (01/06/2014 03:21:26 PM) (Source: NvStreamSvc) (User: )
Description: NvStreamSvcUnregistering VAD endpoint [0]
Error: (01/06/2014 03:21:24 PM) (Source: NvStreamSvc) (User: )
Description: NvStreamSvcNvVAD endpoint registered successfully [0]
Error: (01/06/2014 02:06:40 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: svchost.exe, Version: 6.2.9200.16420, Zeitstempel: 0x505a96c3
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x76a65f8c
ID des fehlerhaften Prozesses: 0x1dcc
Startzeit der fehlerhaften Anwendung: 0xsvchost.exe0
Pfad der fehlerhaften Anwendung: svchost.exe1
Pfad des fehlerhaften Moduls: svchost.exe2
Berichtskennung: svchost.exe3
Vollständiger Name des fehlerhaften Pakets: svchost.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: svchost.exe5
Error: (01/06/2014 01:35:01 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 6.2.9200.16628, Zeitstempel: 0x51a94434
Name des fehlerhaften Moduls: explorerframe.dll, Version: 6.2.9200.16384, Zeitstempel: 0x50108d4c
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000000000000bcf8
ID des fehlerhaften Prozesses: 0x1a6c
Startzeit der fehlerhaften Anwendung: 0xexplorer.exe0
Pfad der fehlerhaften Anwendung: explorer.exe1
Pfad des fehlerhaften Moduls: explorer.exe2
Berichtskennung: explorer.exe3
Vollständiger Name des fehlerhaften Pakets: explorer.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: explorer.exe5
Error: (01/06/2014 01:35:01 AM) (Source: .NET Runtime) (User: )
Description: Anwendung: explorer.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet.
Ausnahmeinformationen: Ausnahmecode c0000005, Ausnahmeadresse 000007FFD7A3BCF8
Error: (01/06/2014 01:09:54 AM) (Source: Office 2013 Licensing Service) (User: )
Description: Subscription licensing service failed: -1073415161
Error: (01/05/2014 10:55:09 PM) (Source: Customer Experience Improvement Program) (User: )
Description: 80070005
Error: (01/05/2014 10:36:42 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: Blacklist_game.exe, Version: 0.0.0.0, Zeitstempel: 0x520696fa
Name des fehlerhaften Moduls: Blacklist_game.exe, Version: 0.0.0.0, Zeitstempel: 0x520696fa
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00370fea
ID des fehlerhaften Prozesses: 0x1eb0
Startzeit der fehlerhaften Anwendung: 0xBlacklist_game.exe0
Pfad der fehlerhaften Anwendung: Blacklist_game.exe1
Pfad des fehlerhaften Moduls: Blacklist_game.exe2
Berichtskennung: Blacklist_game.exe3
Vollständiger Name des fehlerhaften Pakets: Blacklist_game.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Blacklist_game.exe5
System errors:
=============
Error: (01/06/2014 03:21:55 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "SSDP-Suche" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1069
Error: (01/06/2014 03:21:55 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "SSDPSRV" konnte sich nicht als "NT AUTHORITY\LocalService" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden:
%%50
Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC).
Error: (01/06/2014 03:21:06 PM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am 06.01.2014 um 15:04:13 unerwartet heruntergefahren.
Error: (01/06/2014 03:07:57 PM) (Source: DCOM) (User: KERIM)
Description: C:\Windows\System32\ThumbnailExtractionHost.exe -Embedding5{4545DEA0-2DFC-4906-A728-6D986BA399A9}Nicht verfügbarNicht verfügbar
Error: (01/06/2014 03:07:57 PM) (Source: DCOM) (User: KERIM)
Description: C:\Windows\System32\ThumbnailExtractionHost.exe -Embedding5{4545DEA0-2DFC-4906-A728-6D986BA399A9}Nicht verfügbarNicht verfügbar
Error: (01/06/2014 03:03:30 PM) (Source: DCOM) (User: KERIM)
Description: C:\Windows\system32\DllHost.exe /Processid:{478B41E6-3257-4519-BDA8-E971F9843849}5{581333F6-28DB-41BE-BC7A-FF201F12F3F6}NT AuthorityLocalService
Error: (01/06/2014 03:03:22 PM) (Source: DCOM) (User: KERIM)
Description: C:\Windows\system32\DllHost.exe /Processid:{478B41E6-3257-4519-BDA8-E971F9843849}5{581333F6-28DB-41BE-BC7A-FF201F12F3F6}NT AuthorityLocalService
Error: (01/06/2014 03:03:02 PM) (Source: DCOM) (User: KERIM)
Description: C:\Windows\system32\DllHost.exe /Processid:{478B41E6-3257-4519-BDA8-E971F9843849}5{581333F6-28DB-41BE-BC7A-FF201F12F3F6}NT AuthorityLocalService
Error: (01/06/2014 03:02:54 PM) (Source: DCOM) (User: KERIM)
Description: C:\Windows\system32\DllHost.exe /Processid:{478B41E6-3257-4519-BDA8-E971F9843849}5{581333F6-28DB-41BE-BC7A-FF201F12F3F6}NT AuthorityLocalService
Error: (01/06/2014 03:02:42 PM) (Source: DCOM) (User: KERIM)
Description: C:\Windows\System32\ThumbnailExtractionHost.exe -Embedding5{4545DEA0-2DFC-4906-A728-6D986BA399A9}Nicht verfügbarNicht verfügbar
Microsoft Office Sessions:
=========================
Error: (01/06/2014 03:29:36 PM) (Source: NvStreamSvc)(User: )
Description: NvStreamSvcUnregistering VAD endpoint [0]
Error: (01/06/2014 03:29:33 PM) (Source: NvStreamSvc)(User: )
Description: NvStreamSvcNvVAD endpoint registered successfully [0]
Error: (01/06/2014 03:21:26 PM) (Source: NvStreamSvc)(User: )
Description: NvStreamSvcUnregistering VAD endpoint [0]
Error: (01/06/2014 03:21:24 PM) (Source: NvStreamSvc)(User: )
Description: NvStreamSvcNvVAD endpoint registered successfully [0]
Error: (01/06/2014 02:06:40 PM) (Source: Application Error)(User: )
Description: svchost.exe6.2.9200.16420505a96c3unknown0.0.0.000000000c000000576a65f8c1dcc01cf0ae01ef3a3bcC:\Windows\SysWOW64\svchost.exeunknown61824f6c-76d3-11e3-be94-dc85dea536ca
Error: (01/06/2014 01:35:01 AM) (Source: Application Error)(User: )
Description: explorer.exe6.2.9200.1662851a94434explorerframe.dll6.2.9200.1638450108d4cc0000005000000000000bcf81a6c01cf0a17e89387d3C:\Windows\explorer.exeC:\Windows\system32\explorerframe.dll603fe4de-766a-11e3-be94-dc85dea536ca
Error: (01/06/2014 01:35:01 AM) (Source: .NET Runtime)(User: )
Description: Anwendung: explorer.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet.
Ausnahmeinformationen: Ausnahmecode c0000005, Ausnahmeadresse 000007FFD7A3BCF8
Error: (01/06/2014 01:09:54 AM) (Source: Office 2013 Licensing Service)(User: )
Description: Subscription licensing service failed: -1073415161
Error: (01/05/2014 10:55:09 PM) (Source: Customer Experience Improvement Program)(User: )
Description: 80070005
Error: (01/05/2014 10:36:42 PM) (Source: Application Error)(User: )
Description: Blacklist_game.exe0.0.0.0520696faBlacklist_game.exe0.0.0.0520696fac000000500370fea1eb001cf0a5db41e27cbC:\Users\kerim\Desktop\Tom Clancy's Splinter Cell® Blacklist™\src\SYSTEM\Blacklist_game.exeC:\Users\kerim\Desktop\Tom Clancy's Splinter Cell® Blacklist™\src\SYSTEM\Blacklist_game.exe7775eea5-7651-11e3-be94-dc85dea536ca
==================== Memory info ===========================
Percentage of memory in use: 27%
Total physical RAM: 8077.47 MB
Available physical RAM: 5859.13 MB
Total Pagefile: 9293.47 MB
Available Pagefile: 7135.55 MB
Total Virtual: 8192 MB
Available Virtual: 8191.74 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:372.6 GB) (Free:261.99 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (Data) (Fixed) (Total:537.89 GB) (Free:474.85 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 932 GB) (Disk ID: CDFAD22C)
Partition: GPT Partition Type
==================== End Of Log ============================ |