Hier die Logfiles
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-01-2015 02
Ran by Sabri (administrator) on SABRI-PC on 13-01-2015 12:03:28
Running from C:\Users\Sabri\Desktop\PC-SCHUTZ
Loaded Profiles: Sabri & (Available profiles: Sabri)
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(AVG Technologies) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(AVG Technologies) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Disc Soft Ltd) C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7570136 2014-04-14] (Realtek Semiconductor)
HKLM\...\Run: [MBCfg64] => C:\WINDOWS\system32\RunDLL32.exe C:\WINDOWS\system32\MBCfg64.dll,RunDLLEntry MBCfg64
HKLM\...\Run: [ISCT Tray] => C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe [5860656 2014-04-03] (Intel Corporation)
HKLM\...\Run: [Samsung Link] => C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe [607584 2014-12-16] (Copyright 2013 SAMSUNG)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161984 2014-04-20] (IvoSoft)
HKLM-x32\...\Run: [Sound Blaster Cinema] => C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe [711680 2013-08-16] (Creative Technology Ltd)
HKLM-x32\...\Run: [UpdReg] => C:\WINDOWS\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\...\Run: [Super Charger] => C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe [1047536 2014-04-08] (MSI)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-12-06] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2015-01-09] (AVAST Software)
HKU\S-1-5-21-3822476009-2779597456-3556243849-1001\...\Run: [HydraVisionDesktopManager] => C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [389120 2013-12-06] (AMD)
HKU\S-1-5-21-3822476009-2779597456-3556243849-1001\...\Run: [DAEMON Tools Pro Agent] => C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe [3761424 2014-11-10] (Disc Soft Ltd)
HKU\S-1-5-21-3822476009-2779597456-3556243849-1001\...\MountPoints2: {68882223-83b2-11e4-826b-448a5ba4cf02} - "E:\setup.exe"
HKU\S-1-5-21-3822476009-2779597456-3556243849-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [HydraVisionDesktopManager] => C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [389120 2013-12-06] (AMD)
HKU\S-1-5-21-3822476009-2779597456-3556243849-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [DAEMON Tools Pro Agent] => C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe [3761424 2014-11-10] (Disc Soft Ltd)
HKU\S-1-5-21-3822476009-2779597456-3556243849-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {68882223-83b2-11e4-826b-448a5ba4cf02} - "E:\setup.exe"
AppInit_DLLs-x32: Ȅ獒瑬 => "Ȅ獒瑬" File Not Found
IFEO\AcroRd32.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\adobe air application installer.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\appvlp.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\dtagent.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\dtimgeditor.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\dtpro.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\excel.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\gputweak.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\groove.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\infopath.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\isctmodernui.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\lync.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\msaccess.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\msoev.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\msotd.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\msouc.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\mspub.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\ocpubmgr.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\onenote.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\onenotem.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\origin.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\originer.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\outlook.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\powerpnt.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\samsung link menu start.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\setlang.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\super charger.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\unins000.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\winword.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-3822476009-2779597456-3556243849-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo13.msn.com/?pc=LCJB
HKU\S-1-5-21-3822476009-2779597456-3556243849-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com/?pc=LCJB
HKU\S-1-5-21-3822476009-2779597456-3556243849-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
HKU\S-1-5-21-3822476009-2779597456-3556243849-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
HKU\S-1-5-21-3822476009-2779597456-3556243849-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo13.msn.com/?pc=LCJB
HKU\S-1-5-21-3822476009-2779597456-3556243849-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com/?pc=LCJB
HKU\S-1-5-21-3822476009-2779597456-3556243849-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
HKU\S-1-5-21-3822476009-2779597456-3556243849-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3822476009-2779597456-3556243849-1001 -> DefaultScope {B68BE3AA-F549-498C-99A8-3F297020C2E9} URL =
SearchScopes: HKU\S-1-5-21-3822476009-2779597456-3556243849-1001 -> {B68BE3AA-F549-498C-99A8-3F297020C2E9} URL =
SearchScopes: HKU\S-1-5-21-3822476009-2779597456-3556243849-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {B68BE3AA-F549-498C-99A8-3F297020C2E9} URL =
SearchScopes: HKU\S-1-5-21-3822476009-2779597456-3556243849-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {B68BE3AA-F549-498C-99A8-3F297020C2E9} URL =
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll (IvoSoft)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Sabri\AppData\Roaming\Mozilla\Firefox\Profiles\0w5lwyf0.default
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_16_0_0_235.dll ()
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_235.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin -> C:\Program Files (x86)\Arc\Plugins\npArcPluginFF.dll (Perfect World Entertainment Inc)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Sabri\AppData\Roaming\Mozilla\Firefox\Profiles\0w5lwyf0.default\searchplugins\google-images.xml
FF SearchPlugin: C:\Users\Sabri\AppData\Roaming\Mozilla\Firefox\Profiles\0w5lwyf0.default\searchplugins\google-maps.xml
FF Extension: Adblock Plus - C:\Users\Sabri\AppData\Roaming\Mozilla\Firefox\Profiles\0w5lwyf0.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-01-06]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-12-27]
Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2014-12-27]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-12-27]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S4 AllShare Framework DMS; C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe [404360 2013-12-21] (Samsung) [File not signed]
S3 ArcService; C:\Program Files (x86)\Arc\ArcService.exe [88400 2015-01-04] (Perfect World Entertainment Inc)
S4 ASGT; C:\Windows\SysWOW64\ASGT.exe [55296 2012-01-17] () [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-12-27] (AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [104416 2014-12-27] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4012248 2014-12-27] (Avast Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [448384 2014-12-04] ()
S4 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2449592 2014-11-12] (Microsoft Corporation)
S4 Disc Soft Bus Service; C:\Program Files (x86)\DAEMON Tools Pro\DiscSoftBusService.exe [2216208 2014-11-10] (Disc Soft Ltd)
S3 EasyAntiCheat; C:\WINDOWS\SysWOW64\EasyAntiCheat.exe [175136 2015-01-09] (EasyAntiCheat Ltd)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
S4 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [209712 2014-04-03] ()
S4 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [154584 2014-04-03] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
S4 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe [162800 2014-03-17] (MSI)
S4 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1900400 2014-12-06] (Electronic Arts)
R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [76888 2014-12-06] ()
S4 Samsung Link Service; C:\Program Files\Samsung\Samsung Link\Samsung Link.exe [616288 2014-12-16] (Copyright 2013 SAMSUNG)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2604856 2014-11-24] (AVG Technologies)
S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [762320 2014-11-04] (Tunngle.net GmbH)
R2 UxTuneUp; C:\Windows\System32\uxtuneup.dll [42808 2014-11-24] (AVG Technologies)
R2 UxTuneUp; C:\Windows\SysWOW64\uxtuneup.dll [35640 2014-11-24] (AVG Technologies)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)
S3 COMSysApp; %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [21160 2012-09-23] (Advanced Micro Devices, Inc.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-12-27] ()
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28184 2014-12-27] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2014-12-27] (AVAST Software)
R0 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [449936 2014-12-27] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-12-27] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-12-27] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2014-12-27] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2014-12-27] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2014-12-27] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2014-12-27] ()
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2014-03-11] (Advanced Micro Devices)
R3 dtscsibus; C:\Windows\system32\DRIVERS\dtscsibus.sys [29864 2014-12-14] (Disc Soft Ltd)
S3 GeneStor; C:\Windows\System32\drivers\GeneStor.sys [103656 2013-10-21] (GenesysLogic)
R3 ikbevent; C:\Windows\system32\DRIVERS\ikbevent.sys [22216 2014-02-03] ()
R3 imsevent; C:\Windows\system32\DRIVERS\imsevent.sys [22728 2014-02-03] ()
S3 INETMON; C:\WINDOWS\System32\Drivers\INETMON.sys [25800 2014-04-03] ()
R3 ISCT; C:\Windows\System32\drivers\ISCTD.sys [44744 2014-02-03] ()
R1 mbamchameleon; C:\WINDOWS\system32\drivers\mbamchameleon.sys [93400 2014-11-21] (Malwarebytes Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [129752 2015-01-13] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2014-11-21] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [118272 2014-04-03] (Intel Corporation)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [3344352 2013-07-08] (Intel Corporation)
S3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [1936088 2013-07-31] (Realtek Semiconductor Corporation )
R3 tap0901t; C:\Windows\system32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [14112 2014-08-28] (TuneUp Software)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [271752 2014-12-27] (Avast Software)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)
S3 ALSysIO; \??\C:\Users\Sabri\AppData\Local\Temp\ALSysIO64.sys [X]
S3 MSICDSetup; \??\D:\CDriver64.sys [X]
S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [X]
S3 RwDrv; \??\C:\WINDOWS\system32\Drivers\RwDrv.sys [X]
U3 agdcypob; \??\C:\Users\Sabri\AppData\Local\Temp\agdcypob.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-13 11:56 - 2015-01-13 11:56 - 59797360 _____ (AVAST Software) C:\Users\Sabri\Downloads\vpsupd.exe
2015-01-13 11:52 - 2015-01-13 11:52 - 00000488 _____ () C:\Users\Sabri\Desktop\gmerlogfile.log
2015-01-13 11:48 - 2015-01-13 11:48 - 01174816 _____ () C:\Users\Sabri\Downloads\Gmer-19357 - CHIP-Installer.exe
2015-01-13 11:41 - 2015-01-13 12:03 - 00000000 ____D () C:\FRST
2015-01-13 11:12 - 2015-01-13 11:12 - 00001338 _____ () C:\Users\Sabri\Desktop\JRT.txt
2015-01-13 11:08 - 2015-01-13 11:08 - 00000000 ____D () C:\WINDOWS\ERUNT
2015-01-13 11:00 - 2015-01-13 11:03 - 00000000 ____D () C:\Program Files (x86)\SpywareBlaster
2015-01-13 11:00 - 2015-01-13 11:00 - 04095448 _____ (BrightFort LLC ) C:\Users\Sabri\Downloads\spywareblastersetup50.exe
2015-01-13 11:00 - 2015-01-13 11:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpywareBlaster
2015-01-13 11:00 - 2015-01-13 11:00 - 00000000 ____D () C:\ProgramData\Licenses
2015-01-13 11:00 - 2011-11-04 05:13 - 01070352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSCOMCTL.OCX
2015-01-13 11:00 - 2009-03-24 12:52 - 00129872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSSTDFMT.DLL
2015-01-13 10:49 - 2015-01-13 12:03 - 00000000 ____D () C:\Users\Sabri\Desktop\PC-SCHUTZ
2015-01-13 10:39 - 2015-01-13 10:39 - 00010893 _____ () C:\Users\Sabri\Desktop\hijackthis.log
2015-01-12 19:48 - 2015-01-12 19:48 - 00017475 _____ () C:\WINDOWS\DirectX.log
2015-01-12 19:47 - 2015-01-12 21:53 - 00000000 ____D () C:\Program Files (x86)\Neverwinter_de
2015-01-12 19:46 - 2015-01-12 19:47 - 00000000 ___HD () C:\ArcTemp
2015-01-12 19:45 - 2015-01-12 19:45 - 00003182 _____ () C:\WINDOWS\System32\Tasks\{C45421BB-DF42-408D-9F00-EA4FDB9E7020}
2015-01-12 19:44 - 2015-01-12 19:45 - 00000000 ____D () C:\Users\Sabri\AppData\Roaming\Arc
2015-01-12 19:44 - 2015-01-12 19:44 - 00000000 ____D () C:\Users\Public\Documents\Arc
2015-01-12 17:50 - 2015-01-12 17:50 - 00000000 _____ () C:\WINDOWS\setupact.log
2015-01-12 14:21 - 2015-01-13 11:14 - 00000000 ____D () C:\Program Files (x86)\Arc
2015-01-12 14:21 - 2015-01-12 14:21 - 00001604 _____ () C:\Users\Public\Desktop\Arc.lnk
2015-01-12 14:21 - 2015-01-12 14:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Perfect World Entertainment
2015-01-12 14:19 - 2015-01-12 14:20 - 00000000 ____D () C:\Program Files (x86)\Tunngle
2015-01-12 14:19 - 2015-01-12 14:19 - 10306616 _____ (Perfect World Entertainment) C:\Users\Sabri\Downloads\ArcInstall_NW_20141223.exe
2015-01-12 14:19 - 2015-01-12 14:19 - 00001018 _____ () C:\Users\Public\Desktop\Tunngle.lnk
2015-01-12 14:19 - 2015-01-12 14:19 - 00000000 ____D () C:\Users\Sabri\Documents\Tunngle
2015-01-12 14:19 - 2015-01-12 14:19 - 00000000 ____D () C:\Users\Sabri\AppData\Roaming\Tunngle
2015-01-12 14:19 - 2015-01-12 14:19 - 00000000 ____D () C:\Users\Public\Documents\Tunngle
2015-01-12 14:19 - 2015-01-12 14:19 - 00000000 ____D () C:\ProgramData\Tunngle
2015-01-12 14:19 - 2015-01-12 14:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tunngle
2015-01-12 14:19 - 2009-09-16 07:02 - 00031232 _____ (Tunngle.net) C:\WINDOWS\system32\Drivers\tap0901t.sys
2015-01-12 14:15 - 2015-01-12 14:15 - 04501720 _____ (Tunngle.net GmbH ) C:\Users\Sabri\Downloads\Tunngle_Setup_v5.0.exe
2015-01-11 16:04 - 2015-01-11 16:04 - 00000000 ____D () C:\Users\Sabri\AppData\Roaming\Steam
2015-01-11 15:59 - 2015-01-11 15:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Evil Within
2015-01-11 15:35 - 2015-01-11 15:59 - 00000000 ____D () C:\Program Files (x86)\The Evil Within
2015-01-11 13:48 - 2015-01-11 14:28 - 00000000 ____D () C:\Users\Sabri\Downloads\The Evil Within
2015-01-11 13:46 - 2015-01-12 14:32 - 00000000 ____D () C:\Users\Sabri\Desktop\Spiele
2015-01-11 13:27 - 2015-01-11 13:27 - 00000000 ____D () C:\Users\Sabri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FreeArc
2015-01-11 13:27 - 2015-01-11 13:27 - 00000000 ____D () C:\Users\Sabri\AppData\Roaming\FreeArc
2015-01-11 13:27 - 2015-01-11 13:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeArc
2015-01-11 13:27 - 2015-01-11 13:27 - 00000000 ____D () C:\Program Files (x86)\FreeArc
2015-01-11 13:02 - 2015-01-11 13:02 - 00000000 _____ () C:\WINDOWS\setuperr.log
2015-01-10 23:15 - 2015-01-10 23:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ryse Son of Rome
2015-01-10 23:04 - 2015-01-10 23:25 - 00000000 ____D () C:\Program Files (x86)\Ryse Son of Rome
2015-01-10 08:32 - 2015-01-10 08:32 - 00002762 _____ () C:\WINDOWS\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013
2015-01-09 22:03 - 2015-01-09 22:03 - 00000000 ____D () C:\Users\Sabri\AppData\Roaming\Fatshark
2015-01-09 22:00 - 2015-01-09 21:36 - 00175136 _____ (EasyAntiCheat Ltd) C:\WINDOWS\SysWOW64\EasyAntiCheat.exe
2015-01-09 20:02 - 2015-01-10 20:10 - 00000000 ____D () C:\Users\Sabri\Downloads\Ryse_ Son of Rome
2015-01-07 19:17 - 2015-01-07 19:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Styx Master of Shadows
2015-01-07 19:11 - 2015-01-07 19:17 - 00000000 ____D () C:\Program Files (x86)\Styx Master of Shadows
2015-01-07 19:10 - 2015-01-07 19:10 - 00000000 ____D () C:\Users\Public\Documents\DAEMON Tools Images
2015-01-06 12:11 - 2015-01-06 12:12 - 00000197 _____ () C:\WINDOWS\system32\2015-01-06-11-11-36.057-AvastVBoxSVC.exe-3268.log
2015-01-06 12:10 - 2015-01-06 12:10 - 00002934 _____ () C:\WINDOWS\PFRO.log
2015-01-06 12:03 - 2015-01-06 12:16 - 00003706 _____ () C:\WINDOWS\System32\Tasks\Java Platform SE Auto Updater
2015-01-06 11:59 - 2014-11-24 12:48 - 00042808 _____ (AVG Technologies) C:\WINDOWS\system32\uxtuneup.dll
2015-01-06 11:59 - 2014-11-24 12:48 - 00035640 _____ (AVG Technologies) C:\WINDOWS\SysWOW64\uxtuneup.dll
2015-01-06 11:53 - 2015-01-06 11:53 - 00002244 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp 2015.lnk
2015-01-06 11:53 - 2015-01-06 11:53 - 00000000 ____D () C:\Users\Sabri\AppData\Roaming\AVG
2015-01-06 11:53 - 2015-01-06 11:53 - 00000000 ____D () C:\Users\Sabri\AppData\Local\Avg
2015-01-06 11:53 - 2015-01-06 11:53 - 00000000 ____D () C:\Program Files (x86)\AVG
2015-01-06 11:53 - 2014-11-24 12:48 - 00040248 _____ (AVG Technologies) C:\WINDOWS\system32\TURegOpt.exe
2015-01-06 11:53 - 2014-11-24 12:48 - 00029496 _____ (AVG Technologies) C:\WINDOWS\system32\authuitu.dll
2015-01-06 11:53 - 2014-11-24 12:48 - 00025400 _____ (AVG Technologies) C:\WINDOWS\SysWOW64\authuitu.dll
2015-01-06 11:52 - 2015-01-13 11:49 - 00000000 ____D () C:\Users\Sabri\AppData\Roaming\ClassicShell
2015-01-06 11:52 - 2015-01-06 11:53 - 00000000 ____D () C:\ProgramData\AVG
2015-01-06 11:52 - 2015-01-06 11:52 - 00000000 ____D () C:\ProgramData\ClassicShell
2015-01-06 11:49 - 2015-01-06 11:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Shell
2015-01-06 11:49 - 2015-01-06 11:49 - 00000000 ____D () C:\Program Files\Classic Shell
2015-01-05 17:27 - 2015-01-13 11:40 - 01551339 _____ () C:\WINDOWS\WindowsUpdate.log
2015-01-05 16:37 - 2015-01-05 16:37 - 00003886 _____ () C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2015-01-05 14:50 - 2015-01-13 11:15 - 00129752 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-01-05 14:49 - 2015-01-05 14:49 - 00001129 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-01-05 14:49 - 2015-01-05 14:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-01-05 14:49 - 2015-01-05 14:49 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-01-05 14:49 - 2015-01-05 14:49 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-01-05 14:49 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-01-05 14:49 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-01-05 14:49 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-01-05 14:16 - 2015-01-05 14:16 - 00002457 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-01-04 20:20 - 2014-12-03 21:08 - 00000000 ____D () C:\Users\Sabri\Downloads\Styx Master of Shadows 1.02
2014-12-27 11:06 - 2014-12-27 11:06 - 00000247 _____ () C:\WINDOWS\system32\2014-12-27-10-06-16.041-aswFe.exe-1796.log
2014-12-27 11:03 - 2014-12-27 11:06 - 00000247 _____ () C:\WINDOWS\system32\2014-12-27-10-03-13.088-aswFe.exe-1672.log
2014-12-27 11:03 - 2014-12-27 11:03 - 00000197 _____ () C:\WINDOWS\system32\2014-12-27-10-03-12.097-AvastVBoxSVC.exe-5736.log
2014-12-27 10:57 - 2015-01-13 11:16 - 00004182 _____ () C:\WINDOWS\System32\Tasks\avast! Emergency Update
2014-12-27 10:57 - 2014-12-27 10:57 - 01050432 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsnx.sys
2014-12-27 10:57 - 2014-12-27 10:57 - 00001997 _____ () C:\Users\Public\Desktop\Avast Internet Security.lnk
2014-12-27 10:57 - 2014-12-27 10:57 - 00000000 ____D () C:\Users\Sabri\AppData\Roaming\AVAST Software
2014-12-27 10:57 - 2014-12-27 10:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2014-12-27 10:57 - 2014-12-27 10:56 - 00436624 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2014-12-27 10:57 - 2014-12-27 10:56 - 00364512 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2014-12-27 10:57 - 2014-12-27 10:56 - 00267632 _____ () C:\WINDOWS\system32\Drivers\aswVmm.sys
2014-12-27 10:57 - 2014-12-27 10:56 - 00116728 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2014-12-27 10:57 - 2014-12-27 10:56 - 00093568 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2014-12-27 10:57 - 2014-12-27 10:56 - 00083280 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2014-12-27 10:57 - 2014-12-27 10:56 - 00065776 _____ () C:\WINDOWS\system32\Drivers\aswRvrt.sys
2014-12-27 10:57 - 2014-12-27 10:56 - 00029208 _____ () C:\WINDOWS\system32\Drivers\aswHwid.sys
2014-12-27 10:57 - 2014-12-27 10:56 - 00028184 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys
2014-12-27 10:56 - 2014-12-27 10:56 - 00449936 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswNdisFlt.sys
2014-12-27 10:56 - 2014-12-27 10:56 - 00043152 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2014-12-27 10:56 - 2014-12-27 10:56 - 00000000 ____D () C:\Program Files\AVAST Software
2014-12-27 10:54 - 2014-12-27 10:56 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-12-25 15:30 - 2014-12-25 15:30 - 00000773 _____ () C:\WINDOWS\removeep.cmd
2014-12-25 15:28 - 2014-12-25 15:28 - 00000000 ____D () C:\Users\Sabri\AppData\Roaming\reaper
2014-12-21 01:08 - 2014-12-21 01:08 - 00000000 ____D () C:\Program Files (x86)\Lenovo
2014-12-19 22:30 - 2015-01-06 12:03 - 00000000 ____D () C:\Users\Sabri\AppData\Roaming\Skype
2014-12-19 22:30 - 2014-12-19 22:30 - 00000000 ____D () C:\Users\Sabri\AppData\Local\Skype
2014-12-19 20:07 - 2014-10-30 23:37 - 00129536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2014-12-19 20:07 - 2014-10-30 23:34 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2014-12-19 14:39 - 2015-01-06 11:37 - 00000000 ____D () C:\ProgramData\Skype
2014-12-18 18:49 - 2014-12-18 18:49 - 00000000 ____D () C:\Users\Sabri\AppData\Roaming\Nitro
2014-12-18 18:42 - 2014-12-23 15:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2014-12-18 18:42 - 2014-12-23 15:08 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2014-12-16 17:41 - 2014-12-16 17:42 - 00000000 ____D () C:\AdwCleaner
2014-12-16 15:22 - 2014-12-16 15:23 - 00000000 ____D () C:\Users\Sabri\AppData\Local\SmartView2
2014-12-16 15:22 - 2014-12-16 15:22 - 00000000 ____D () C:\Program Files (x86)\SmartView2
2014-12-16 15:17 - 2014-12-16 15:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2014-12-16 15:17 - 2014-12-16 15:17 - 00000000 ____D () C:\Program Files (x86)\K-Lite Codec Pack
2014-12-16 14:48 - 2014-12-27 10:48 - 00000000 ____D () C:\Users\Sabri\Documents\Sabri
2014-12-16 01:33 - 2014-12-26 19:08 - 00000000 ____D () C:\Users\Sabri\Desktop\FM cata
2014-12-16 01:33 - 2014-12-16 01:33 - 00000000 ____D () C:\Users\Sabri\AppData\Roaming\Nitro PDF
2014-12-15 19:34 - 2014-12-15 19:36 - 00001887 _____ () C:\Users\Sabri\Desktop\Samsung Link sabri_9@web.de.lnk
2014-12-15 19:34 - 2014-12-15 19:34 - 00000000 ____D () C:\Users\Sabri\Samsung Link
2014-12-15 19:34 - 2014-12-15 19:34 - 00000000 ____D () C:\Users\Sabri\AppData\Roaming\SAMSUNG
2014-12-14 23:32 - 2014-12-14 23:32 - 00000000 ____D () C:\Users\Sabri\Documents\Spiele
2014-12-14 23:18 - 2014-12-14 23:18 - 00000000 ____D () C:\Users\Sabri\AppData\Local\Risen3
2014-12-14 23:07 - 2014-12-14 23:07 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-12-14 23:07 - 2014-12-14 23:07 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies
2014-12-14 23:04 - 2014-12-14 23:15 - 00000000 ____D () C:\Program Files (x86)\Risen 3 - Titan Lords
2014-12-14 19:25 - 2014-12-18 23:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
2014-12-14 19:06 - 2015-01-06 17:44 - 00000000 ____D () C:\Users\Sabri\AppData\Roaming\DAEMON Tools Pro
2014-12-14 19:06 - 2014-12-14 19:07 - 00000000 ____D () C:\Program Files (x86)\DAEMON Tools Pro
2014-12-14 19:06 - 2014-12-14 19:06 - 00029864 _____ (Disc Soft Ltd) C:\WINDOWS\system32\Drivers\dtscsibus.sys
2014-12-14 19:06 - 2014-12-14 19:06 - 00001959 _____ () C:\Users\Public\Desktop\DAEMON Tools Pro.lnk
2014-12-14 19:06 - 2014-12-14 19:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Pro
2014-12-14 19:06 - 2014-12-14 19:06 - 00000000 ____D () C:\ProgramData\DAEMON Tools Pro
2014-12-14 18:32 - 2014-12-14 18:32 - 00000000 ____D () C:\Users\Sabri\AppData\Local\Skyrim
2014-12-14 18:32 - 2014-12-14 18:32 - 00000000 ____D () C:\ProgramData\Steam
2014-12-14 18:01 - 2014-12-14 18:01 - 00000000 ____D () C:\Users\Sabri\AppData\Local\Disc_Soft_Ltd
2014-12-14 18:00 - 2014-12-14 18:01 - 00000000 ____D () C:\Users\Sabri\AppData\Roaming\DAEMON Tools Ultra
2014-12-14 18:00 - 2014-12-14 18:00 - 00000000 ____D () C:\ProgramData\DAEMON Tools Ultra
2014-12-14 17:59 - 2014-12-14 17:59 - 00000000 ____D () C:\Users\Sabri\AppData\Roaming\WinRAR
2014-12-14 17:59 - 2014-12-14 17:59 - 00000000 ____D () C:\Users\Sabri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-12-14 17:59 - 2014-12-14 17:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-12-14 17:59 - 2014-12-14 17:59 - 00000000 ____D () C:\Program Files\WinRAR
2014-12-14 17:43 - 2014-12-14 17:47 - 00000000 ____D () C:\ProgramData\DAEMON Tools Lite
2014-12-14 17:27 - 2014-12-14 19:25 - 00000000 ____D () C:\Program Files\Samsung
2014-12-14 17:27 - 2014-12-14 17:27 - 00000000 ____D () C:\Users\Sabri\AppData\Local\SAMSUNG
2014-12-14 17:27 - 2014-12-14 17:27 - 00000000 ____D () C:\Users\Sabri\.swt
2014-12-14 17:27 - 2014-12-14 17:27 - 00000000 ____D () C:\Upload
2014-12-14 17:27 - 2014-12-14 17:27 - 00000000 ____D () C:\ProgramData\SAMSUNG
2014-12-14 16:49 - 2015-01-09 12:08 - 00000000 ____D () C:\Users\Sabri\AppData\Roaming\vlc
2014-12-14 16:01 - 2014-12-14 16:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-12-14 16:01 - 2014-12-14 16:01 - 00000000 ____D () C:\Program Files\VideoLAN
2014-12-14 15:29 - 2014-12-14 15:29 - 00002135 _____ () C:\Users\Sabri\Desktop\JDownloader 2.lnk
2014-12-14 15:29 - 2014-12-14 15:29 - 00000000 ____D () C:\Users\Sabri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\JDownloader
2014-12-14 15:28 - 2015-01-11 15:33 - 00000000 ____D () C:\Users\Sabri\AppData\Local\JDownloader 2.0
2014-12-14 15:21 - 2014-12-14 15:21 - 00098216 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2014-12-14 15:21 - 2014-12-14 15:21 - 00000000 ____D () C:\ProgramData\Sun
2014-12-14 15:21 - 2014-12-14 15:21 - 00000000 ____D () C:\ProgramData\Oracle
2014-12-14 15:21 - 2014-12-14 15:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-12-14 15:21 - 2014-12-14 15:21 - 00000000 ____D () C:\Program Files (x86)\Java
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-13 12:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2015-01-13 11:28 - 2013-08-22 16:20 - 00000000 ____D () C:\WINDOWS\CbsTemp
2015-01-13 11:26 - 2014-12-09 20:42 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-01-13 11:15 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-01-13 11:15 - 2013-08-22 15:44 - 00492384 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2015-01-13 11:14 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2015-01-13 11:03 - 2014-07-18 16:05 - 00000000 ____D () C:\ProgramData\Temp
2015-01-13 10:37 - 2014-12-05 02:10 - 00000000 ____D () C:\Users\Sabri\AppData\Local\VirtualStore
2015-01-12 14:32 - 2014-12-04 22:04 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-01-12 14:26 - 2014-12-05 02:16 - 00003600 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3822476009-2779597456-3556243849-1001
2015-01-12 14:21 - 2014-07-18 15:47 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-01-12 14:04 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2015-01-11 20:47 - 2014-12-06 18:17 - 00000000 ____D () C:\Users\Sabri\AppData\Roaming\TS3Client
2015-01-09 22:02 - 2014-07-18 15:46 - 00000000 ____D () C:\ProgramData\Package Cache
2015-01-07 19:40 - 2014-12-09 23:40 - 00000000 ____D () C:\Users\Sabri\Documents\My Games
2015-01-06 12:15 - 2014-12-09 05:50 - 00009730 _____ () C:\WINDOWS\SysWOW64\Gms.log
2015-01-06 11:46 - 2014-12-05 02:10 - 00000000 ____D () C:\Users\Sabri\AppData\Local\Pokki
2015-01-06 11:40 - 2014-12-05 02:10 - 00000000 ____D () C:\Users\Sabri\AppData\Local\Packages
2015-01-05 14:25 - 2014-07-18 16:09 - 00000000 ____D () C:\ProgramData\Adobe
2015-01-05 14:17 - 2014-12-05 02:10 - 00000000 ____D () C:\Users\Sabri\AppData\Roaming\Adobe
2015-01-05 14:17 - 2014-12-04 20:21 - 00000000 ____D () C:\Users\Sabri\AppData\Local\Adobe
2015-01-05 14:16 - 2014-07-18 16:09 - 00000000 ____D () C:\Program Files (x86)\Adobe
2015-01-05 14:16 - 2014-07-18 16:04 - 00000000 ____D () C:\ProgramData\McAfee
2014-12-29 18:22 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\NDF
2014-12-26 22:26 - 2014-07-19 01:37 - 00765378 _____ () C:\WINDOWS\system32\perfh007.dat
2014-12-26 22:26 - 2014-07-19 01:37 - 00159696 _____ () C:\WINDOWS\system32\perfc007.dat
2014-12-26 22:26 - 2013-08-31 16:40 - 01780340 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-12-25 15:30 - 2014-12-05 02:11 - 00000000 ____D () C:\Users\Sabri\AppData\Local\Lenovo
2014-12-25 15:30 - 2014-07-18 16:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo
2014-12-21 01:08 - 2014-07-18 16:09 - 00000000 ____D () C:\WINDOWS\System32\Tasks\Lenovo
2014-12-21 01:08 - 2014-07-18 16:09 - 00000000 ____D () C:\WINDOWS\Downloaded Installations
2014-12-18 23:43 - 2014-12-05 02:10 - 00000000 ____D () C:\Users\Sabri
2014-12-14 19:42 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\rescache
Some content of TEMP:
====================
C:\Users\Sabri\AppData\Local\Temp\proxy_vole5857646728128945627.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-01-12 14:03
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-01-2015 02
Ran by Sabri at 2015-01-13 12:03:49
Running from C:\Users\Sabri\Desktop\PC-SCHUTZ
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus (Enabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 15.0.0.356 - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.235 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
AllShare Framework DMS (HKLM\...\{83232C27-8C3F-44A5-9EB2-BB7161228ADD}) (Version: 1.3.23 - Samsung)
AMD Catalyst Install Manager (HKLM\...\{FE5435AB-9AA0-367E-2DD5-622D7998420A}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
Arc (HKLM-x32\...\{CED8E25B-122A-4E80-B612-7F99B93284B3}) (Version: 1.0.0.9668 - Perfect World Entertainment)
ASUS GPU Tweak (HKLM-x32\...\InstallShield_{532F6E8A-AF97-41C3-915F-39F718EC07D1}) (Version: 2.5.7.6 - ASUSTek COMPUTER INC.)
ASUS GPU Tweak (x32 Version: 2.5.7.6 - ASUSTek COMPUTER INC.) Hidden
ASUS Product Register Program (HKLM-x32\...\{C87D79F6-F813-4812-B7A9-CCCAAB8B1188}) (Version: 1.0.025 - ASUSTek Computer Inc.)
Avast Internet Security (HKLM-x32\...\Avast) (Version: 10.0.2208 - AVAST Software)
AVG PC TuneUp 2015 (de-DE) (x32 Version: 15.0.1001.185 - AVG Technologies) Hidden
AVG PC TuneUp 2015 (HKLM-x32\...\AVG PC TuneUp) (Version: 15.0.1001.238 - AVG Technologies)
AVG PC TuneUp 2015 (x32 Version: 15.0.1001.238 - AVG Technologies) Hidden
Classic Shell (HKLM\...\{840C85B7-D3D6-4143-9AF9-DAE80FD54CFC}) (Version: 4.1.0 - IvoSoft)
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve)
CPUID CPU-Z 1.71.1 (HKLM\...\CPUID CPU-Z_is1) (Version: - )
CPUID HWMonitor 1.26 (HKLM\...\CPUID HWMonitor_is1) (Version: - )
DAEMON Tools Pro (HKLM-x32\...\DAEMON Tools Pro) (Version: 6.0.0.0444 - Disc Soft Ltd)
DayZ (HKLM-x32\...\Steam App 221100) (Version: - Bohemia Interactive)
Fraps (HKLM-x32\...\Fraps) (Version: - )
FreeArc 0.666 (HKLM-x32\...\FreeArc) (Version: 0.666 - Bulat Ziganshin)
Genesys USB Mass Storage Device (HKLM-x32\...\{959B7F35-2819-40C5-A0CD-3C53B5FCC935}) (Version: 4.1.2.2 - Genesys Logic)
Hitman: Absolution (HKLM-x32\...\Steam App 203140) (Version: - IO Interactive)
HydraVision (x32 Version: 4.2.252.0 - Advanced Micro Devices, Inc.) Hidden
ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.8.0 - LIGHTNING UK!)
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 10.0.1.1000 - Intel Corporation)
Intel(R) Smart Connect Technology (HKLM\...\{7228EFBA-512B-4EB3-B8A7-E2C331475DF4}) (Version: 5.0.10.2808 - Intel Corporation)
Intel® Chipsatz-Gerätesoftware (x32 Version: 10.0.14 - Intel(R) Corporation) Hidden
Java 8 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH)
K-Lite Codec Pack 9.3.0 (Basic) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 9.3.0 - )
Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Metric Collection SDK 35 (x32 Version: 1.2.0006.00 - Lenovo Group Limited) Hidden
Microsoft Office Professional Plus 2013 - de-de (HKLM\...\ProPlusRetail - de-de) (Version: 15.0.4675.1003 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Mozilla Firefox 34.0.5 (x86 de) (HKLM-x32\...\Mozilla Firefox 34.0.5 (x86 de)) (Version: 34.0.5 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 34.0.5 - Mozilla)
MSI Super Charger (HKLM-x32\...\{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1) (Version: 1.2.025 - MSI)
MURDERED: SOUL SUSPECT™ (HKLM-x32\...\Steam App 233290) (Version: - Airtight Games)
NVIDIA PhysX (HKLM-x32\...\{80407BA7-7763-4395-AB98-5233F1B34E65}) (Version: 9.13.1220 - NVIDIA Corporation)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4675.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4675.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4675.1003 - Microsoft Corporation) Hidden
Origin (HKLM-x32\...\Origin) (Version: 9.5.2.2829 - Electronic Arts, Inc.)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.989 - Even Balance, Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.23.1126.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7224 - Realtek Semiconductor Corp.)
Risen 3 - Titan Lords (HKLM-x32\...\Risen 3 - Titan Lords_is1) (Version: - Deep Silver)
Ryse Son of Rome (HKLM-x32\...\Ryse Son of Rome_is1) (Version: - )
Samsung Link 2.0.0.1412161531 (HKLM\...\8474-7877-9059-0204) (Version: 2.0.0.1412161531 - Copyright 2013 SAMSUNG)
Smart View 2.0 (HKLM-x32\...\{FBAAAFAE-08A8-4C63-87EA-4AEA9DEE53E1}) (Version: 1.0.0.0 - Samsung)
Sniper Elite 3 (HKLM-x32\...\Steam App 238090) (Version: - Rebellion)
Sound Blaster Cinema (HKLM-x32\...\{8801CA65-921A-4CCC-9D63-879D1D0BAA97}) (Version: 1.00.05 - Creative Technology Limited)
SpywareBlaster 5.0 (HKLM-x32\...\SpywareBlaster_is1) (Version: 5.0.0 - BrightFort LLC)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Styx Master of Shadows Version 1.02 u2 (HKLM-x32\...\Styx Master of Shadows_is1) (Version: 1.02 u2 - Focus Home Interactive)
TeamSpeak 3 Client (HKU\S-1-5-21-3822476009-2779597456-3556243849-1001\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
TeamSpeak 3 Client (HKU\S-1-5-21-3822476009-2779597456-3556243849-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
The Evil Within Version 1.03 (HKLM-x32\...\The Evil Within_is1) (Version: 1.03 - Bethesda Softworks)
Tunngle Version Tunngle (HKLM-x32\...\Tunngle_is1) (Version: Tunngle - Tunngle.net GmbH)
VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN)
War of the Vikings (HKLM-x32\...\Steam App 234530) (Version: - Fatshark)
WinRAR 5.20 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.20.0 - win.rar GmbH)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
==================== Restore Points =========================
27-12-2014 10:56:15 avast! antivirus system restore point
05-01-2015 14:42:40 Removed Nitro Pro 9
06-01-2015 17:58:05 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610
06-01-2015 17:58:32 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727
12-01-2015 19:48:04 DirectX wurde installiert
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {06F0A4F7-5C0E-4A4E-9891-115D8BB1BB7A} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {0820C623-FAEF-4BEA-98FF-732ABF99DDF1} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-12-27] (AVAST Software)
Task: {3F44F165-1715-49CC-88CE-E76605977750} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-09] (Adobe Systems Incorporated)
Task: {578BD0C1-382A-4707-BC5A-2C6444ACCC0D} - System32\Tasks\Lenovo\LSC\Time72Task => C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCService.exe
Task: {5B034B70-7E9F-4AC1-AF28-BDA1204BC398} - System32\Tasks\ASUS\ASUS Product Register Service => C:\Program Files (x86)\ASUS\APRP\aprp.exe [2013-08-27] (ASUSTek Computer Inc.)
Task: {667EB267-19D6-464F-AB94-B5970AD11301} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2014-12-23] (Microsoft Corporation)
Task: {6B766908-6524-445F-9D09-E63DD6C122AA} - System32\Tasks\{C45421BB-DF42-408D-9F00-EA4FDB9E7020} => pcalua.exe -a "C:\Program Files (x86)\Arc\ArcLauncher.exe" -d C:\Users\Sabri\Desktop\Spiele -c gamecustom nw
Task: {A29D5B8F-3F8A-4DAF-9AD4-20BAD5FE47F0} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2014-12-11] (Microsoft Corporation)
Task: {AB04FA19-5ABC-481D-B557-FE121BB7AFE6} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program => C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe
Task: {B702E6A5-40CE-4B91-AA32-B2E46397F4ED} - System32\Tasks\Lenovo\LSC\RebootCountTask => C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCService.exe
Task: {BD104CDA-FDB0-4046-A822-7850673AFDAF} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 35 => C:\Program Files (x86)\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe [2014-09-10] (Lenovo)
Task: {BD35275C-3A96-4FA1-B4E7-09846E9F2C6F} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-10-07] (Oracle Corporation)
Task: {CB840FF7-B16D-469A-9F23-C17040DDA721} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\AVG\AVG PC TuneUp\OneClick.exe [2014-11-24] (AVG Technologies)
Task: {D7868CD5-D4B0-48CD-A98B-4FD0EC5F1154} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2014-11-04] (Microsoft Corporation)
Task: {E77BB68C-4E4F-4178-8E32-7C45DCDD73EF} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2014-12-23] (Microsoft Corporation)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Loaded Modules (whitelisted) =============
2014-12-06 20:35 - 2014-12-06 21:14 - 00076888 _____ () C:\WINDOWS\SysWOW64\PnkBstrA.exe
2014-11-24 12:48 - 2014-11-24 12:48 - 00713528 _____ () C:\Program Files (x86)\AVG\AVG PC TuneUp\avgrepliba.dll
2014-12-27 10:56 - 2014-12-27 10:56 - 00388208 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxDDU.dll
2014-12-27 10:56 - 2014-12-27 10:56 - 05851328 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxRT.dll
2014-11-24 12:49 - 2014-11-24 12:49 - 00856888 _____ () C:\Program Files (x86)\AVG\AVG PC TuneUp\tulnga.dll
2014-12-09 05:45 - 2012-11-01 11:23 - 00089600 _____ () C:\WINDOWS\SYSTEM32\CmdRtr64.DLL
2014-12-09 05:45 - 2012-11-01 11:21 - 00325120 _____ () C:\WINDOWS\SYSTEM32\APOMgr64.DLL
2013-06-05 15:51 - 2013-06-05 15:51 - 00430080 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\BrandingNet4.dll
2013-06-05 15:51 - 2013-06-05 15:51 - 00032768 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\BrandingResourcesNet4.dll
2015-01-13 10:43 - 2015-01-13 10:43 - 02909696 _____ () C:\Program Files\AVAST Software\Avast\defs\15011300\algo.dll
2014-12-27 10:56 - 2014-12-27 10:56 - 04495336 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\x86\VBoxRT-x86.dll
2014-12-27 10:56 - 2014-12-27 10:56 - 38562088 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-12-04 20:28 - 2014-11-26 17:40 - 03758192 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2014-12-14 19:07 - 2014-11-18 18:45 - 00002048 _____ () C:\Program Files (x86)\DAEMON Tools Pro\MSIMG32.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\ProgramData\Temp:5C321E34
AlternateDataStreams: C:\Users\Sabri\SkyDrive:ms-properties
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
MSCONFIG\Services: LSCWinService => 3
MSCONFIG\Services: MaxthonUpdateSvc => 2
MSCONFIG\Services: NitroDriverReadSpool9 => 2
MSCONFIG\Services: nlsX86cc => 2
MSCONFIG\Services: RichVideo64 => 2
HKLM\...\StartupApproved\Run: => "ISCT Tray"
HKLM\...\StartupApproved\Run: => "Samsung Link"
HKLM\...\StartupApproved\Run32: => "UpdReg"
HKLM\...\StartupApproved\Run32: => "Sound Blaster Cinema"
HKLM\...\StartupApproved\Run32: => "Super Charger"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKU\S-1-5-21-3822476009-2779597456-3556243849-1001\...\StartupApproved\Run: => "HydraVisionDesktopManager"
HKU\S-1-5-21-3822476009-2779597456-3556243849-1001\...\StartupApproved\Run: => "DAEMON Tools Pro Agent"
HKU\S-1-5-21-3822476009-2779597456-3556243849-1001\...\StartupApproved\Run: => "Skype"
HKU\S-1-5-21-3822476009-2779597456-3556243849-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\Run: => "HydraVisionDesktopManager"
HKU\S-1-5-21-3822476009-2779597456-3556243849-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\Run: => "DAEMON Tools Pro Agent"
HKU\S-1-5-21-3822476009-2779597456-3556243849-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\Run: => "Skype"
========================= Accounts: ==========================
Administrator (S-1-5-21-3822476009-2779597456-3556243849-500 - Administrator - Disabled)
Gast (S-1-5-21-3822476009-2779597456-3556243849-501 - Limited - Disabled)
Sabri (S-1-5-21-3822476009-2779597456-3556243849-1001 - Administrator - Enabled) => C:\Users\Sabri
==================== Faulty Device Manager Devices =============
Name: Microsoft PS/2-Maus
Description: Microsoft PS/2-Maus
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
Name: Standardtastatur (PS/2)
Description: Standardtastatur (PS/2)
Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standardtastaturen)
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
==================== Event log errors: =========================
Application errors:
==================
Error: (01/13/2015 11:50:44 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: DTShellHlp.exe, Version: 6.0.0.444, Zeitstempel: 0x54608b99
Name des fehlerhaften Moduls: DTShellHlp.exe, Version: 6.0.0.444, Zeitstempel: 0x54608b99
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00005391
ID des fehlerhaften Prozesses: 0x16c8
Startzeit der fehlerhaften Anwendung: 0xDTShellHlp.exe0
Pfad der fehlerhaften Anwendung: DTShellHlp.exe1
Pfad des fehlerhaften Moduls: DTShellHlp.exe2
Berichtskennung: DTShellHlp.exe3
Vollständiger Name des fehlerhaften Pakets: DTShellHlp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: DTShellHlp.exe5
Error: (01/13/2015 11:49:01 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Gmer-19357.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Name des fehlerhaften Moduls: Gmer-19357.exe, Version: 2.1.19357.0, Zeitstempel: 0x52e7ea83
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000011aa
ID des fehlerhaften Prozesses: 0x1700
Startzeit der fehlerhaften Anwendung: 0xGmer-19357.exe0
Pfad der fehlerhaften Anwendung: Gmer-19357.exe1
Pfad des fehlerhaften Moduls: Gmer-19357.exe2
Berichtskennung: Gmer-19357.exe3
Vollständiger Name des fehlerhaften Pakets: Gmer-19357.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Gmer-19357.exe5
Error: (01/13/2015 11:47:42 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm Gmer-19357.exe, Version 2.1.19357.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 16f4
Startzeit: 01d02f1e435f5af2
Endzeit: 0
Anwendungspfad: C:\Users\Sabri\Desktop\PC-SCHUTZ\Gmer-19357.exe
Berichts-ID: 97ab3f27-9b11-11e4-8270-448a5ba4cf02
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (01/13/2015 11:46:45 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm Gmer-19357.exe, Version 2.1.19357.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 1548
Startzeit: 01d02f1e2550b8eb
Endzeit: 0
Anwendungspfad: C:\Users\Sabri\Desktop\PC-SCHUTZ\Gmer-19357.exe
Berichts-ID: 76123c31-9b11-11e4-8270-448a5ba4cf02
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (01/13/2015 11:46:08 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: DTShellHlp.exe, Version: 6.0.0.444, Zeitstempel: 0x54608b99
Name des fehlerhaften Moduls: DTShellHlp.exe, Version: 6.0.0.444, Zeitstempel: 0x54608b99
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00005391
ID des fehlerhaften Prozesses: 0x8bc
Startzeit der fehlerhaften Anwendung: 0xDTShellHlp.exe0
Pfad der fehlerhaften Anwendung: DTShellHlp.exe1
Pfad des fehlerhaften Moduls: DTShellHlp.exe2
Berichtskennung: DTShellHlp.exe3
Vollständiger Name des fehlerhaften Pakets: DTShellHlp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: DTShellHlp.exe5
Error: (01/13/2015 11:46:03 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: DTShellHlp.exe, Version: 6.0.0.444, Zeitstempel: 0x54608b99
Name des fehlerhaften Moduls: DTShellHlp.exe, Version: 6.0.0.444, Zeitstempel: 0x54608b99
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00005391
ID des fehlerhaften Prozesses: 0x1674
Startzeit der fehlerhaften Anwendung: 0xDTShellHlp.exe0
Pfad der fehlerhaften Anwendung: DTShellHlp.exe1
Pfad des fehlerhaften Moduls: DTShellHlp.exe2
Berichtskennung: DTShellHlp.exe3
Vollständiger Name des fehlerhaften Pakets: DTShellHlp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: DTShellHlp.exe5
Error: (01/13/2015 11:45:58 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: DTShellHlp.exe, Version: 6.0.0.444, Zeitstempel: 0x54608b99
Name des fehlerhaften Moduls: DTShellHlp.exe, Version: 6.0.0.444, Zeitstempel: 0x54608b99
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00005391
ID des fehlerhaften Prozesses: 0x988
Startzeit der fehlerhaften Anwendung: 0xDTShellHlp.exe0
Pfad der fehlerhaften Anwendung: DTShellHlp.exe1
Pfad des fehlerhaften Moduls: DTShellHlp.exe2
Berichtskennung: DTShellHlp.exe3
Vollständiger Name des fehlerhaften Pakets: DTShellHlp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: DTShellHlp.exe5
Error: (01/13/2015 11:45:54 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm Gmer-19357.exe, Version 2.1.19357.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 46c
Startzeit: 01d02f1e0df0cd72
Endzeit: 15
Anwendungspfad: C:\Users\Sabri\Desktop\PC-SCHUTZ\Gmer-19357.exe
Berichts-ID: 578e1d5a-9b11-11e4-8270-448a5ba4cf02
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (01/13/2015 11:45:13 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: DTShellHlp.exe, Version: 6.0.0.444, Zeitstempel: 0x54608b99
Name des fehlerhaften Moduls: DTShellHlp.exe, Version: 6.0.0.444, Zeitstempel: 0x54608b99
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00005391
ID des fehlerhaften Prozesses: 0x152c
Startzeit der fehlerhaften Anwendung: 0xDTShellHlp.exe0
Pfad der fehlerhaften Anwendung: DTShellHlp.exe1
Pfad des fehlerhaften Moduls: DTShellHlp.exe2
Berichtskennung: DTShellHlp.exe3
Vollständiger Name des fehlerhaften Pakets: DTShellHlp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: DTShellHlp.exe5
Error: (01/13/2015 11:45:07 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: DTShellHlp.exe, Version: 6.0.0.444, Zeitstempel: 0x54608b99
Name des fehlerhaften Moduls: DTShellHlp.exe, Version: 6.0.0.444, Zeitstempel: 0x54608b99
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00005391
ID des fehlerhaften Prozesses: 0x17fc
Startzeit der fehlerhaften Anwendung: 0xDTShellHlp.exe0
Pfad der fehlerhaften Anwendung: DTShellHlp.exe1
Pfad des fehlerhaften Moduls: DTShellHlp.exe2
Berichtskennung: DTShellHlp.exe3
Vollständiger Name des fehlerhaften Pakets: DTShellHlp.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: DTShellHlp.exe5
System errors:
=============
Error: (01/13/2015 11:27:00 AM) (Source: DCOM) (EventID: 10010) (User: SABRI-PC)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}
Error: (01/13/2015 11:26:30 AM) (Source: DCOM) (EventID: 10010) (User: SABRI-PC)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}
Error: (01/13/2015 11:14:24 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "Superfetch" wurde mit folgendem Fehler beendet:
%%1062
Error: (01/13/2015 11:14:22 AM) (Source: Service Control Manager) (EventID: 7043) (User: )
Description: Der Dienst Windows Update konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden.
Microsoft Office Sessions:
=========================
Error: (01/13/2015 11:50:44 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: DTShellHlp.exe6.0.0.44454608b99DTShellHlp.exe6.0.0.44454608b99c00000050000539116c801d02f1ec67341dcC:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exeC:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe057db475-9b12-11e4-8270-448a5ba4cf02
Error: (01/13/2015 11:49:01 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Gmer-19357.exe2.1.19357.052e7ea83Gmer-19357.exe2.1.19357.052e7ea83c0000005000011aa170001d02f1e8431d7edC:\Users\Sabri\AppData\Local\Temp\DMR\Downloads\fc14996dfa99adfc7baae624196888c5\7b485ad519eff9d7d5dd42c4b366b648\Gmer-19357.exeC:\Users\Sabri\AppData\Local\Temp\DMR\Downloads\fc14996dfa99adfc7baae624196888c5\7b485ad519eff9d7d5dd42c4b366b648\Gmer-19357.exec85dd16a-9b11-11e4-8270-448a5ba4cf02
Error: (01/13/2015 11:47:42 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Gmer-19357.exe2.1.19357.016f401d02f1e435f5af20C:\Users\Sabri\Desktop\PC-SCHUTZ\Gmer-19357.exe97ab3f27-9b11-11e4-8270-448a5ba4cf02
Error: (01/13/2015 11:46:45 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Gmer-19357.exe2.1.19357.0154801d02f1e2550b8eb0C:\Users\Sabri\Desktop\PC-SCHUTZ\Gmer-19357.exe76123c31-9b11-11e4-8270-448a5ba4cf02
Error: (01/13/2015 11:46:08 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: DTShellHlp.exe6.0.0.44454608b99DTShellHlp.exe6.0.0.44454608b99c0000005000053918bc01d02f1e22379bceC:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exeC:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe614c313a-9b11-11e4-8270-448a5ba4cf02
Error: (01/13/2015 11:46:03 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: DTShellHlp.exe6.0.0.44454608b99DTShellHlp.exe6.0.0.44454608b99c000000500005391167401d02f1e1f00fe99C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exeC:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe5e17f794-9b11-11e4-8270-448a5ba4cf02
Error: (01/13/2015 11:45:58 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: DTShellHlp.exe6.0.0.44454608b99DTShellHlp.exe6.0.0.44454608b99c00000050000539198801d02f1e1c0f8266C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exeC:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe5b241818-9b11-11e4-8270-448a5ba4cf02
Error: (01/13/2015 11:45:54 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Gmer-19357.exe2.1.19357.046c01d02f1e0df0cd7215C:\Users\Sabri\Desktop\PC-SCHUTZ\Gmer-19357.exe578e1d5a-9b11-11e4-8270-448a5ba4cf02
Error: (01/13/2015 11:45:13 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: DTShellHlp.exe6.0.0.44454608b99DTShellHlp.exe6.0.0.44454608b99c000000500005391152c01d02f1e017bd89aC:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exeC:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe408e0c13-9b11-11e4-8270-448a5ba4cf02
Error: (01/13/2015 11:45:07 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: DTShellHlp.exe6.0.0.44454608b99DTShellHlp.exe6.0.0.44454608b99c00000050000539117fc01d02f1dfd997acbC:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exeC:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe3cb53d3b-9b11-11e4-8270-448a5ba4cf02
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i5-4460 CPU @ 3.20GHz
Percentage of memory in use: 25%
Total physical RAM: 8143.91 MB
Available physical RAM: 6030.52 MB
Total Pagefile: 9423.91 MB
Available Pagefile: 6437.26 MB
Total Virtual: 131072 MB
Available Virtual: 131071.83 MB
==================== Drives ================================
Drive c: (Windows8_OS) (Fixed) (Total:905.25 GB) (Free:302.17 GB) NTFS ==>[System with boot components (obtained from reading drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 01FE9960)
Partition: GPT Partition Type.
==================== End Of Log ============================ krieg ich heute noch eine antwort? |