Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 22.02.2015
Scan Time: 01:08:41
Logfile: Malwarebytes Pup.Optional..txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2015.02.21.10
Rootkit Database: v2015.02.20.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 8.1
CPU: x64
File System: NTFS
User: Nuanda
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 401301
Time Elapsed: 35 min, 58 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 1
PUP.Optional.WebInstr.A, C:\Windows\System32\drivers\Msft_Kernel_webinstr_01009.Wdf, Quarantined, [48d640e1a3e7251126c3b8e32dd6be42],
Physical Sectors: 0
(No malicious items detected)
(end) Code:
C:\FreeYouTubeToMP3Converter.exe Variante von Win32/OpenCandy.C potenziell unsichere Anwendung gelöscht - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\fohkdoejokheafajmnaejelfclgidijm\2.0\DneJyA3zA9.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\fohkdoejokheafajmnaejelfclgidijm\2.0\lsdb.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\picgkalabbbpolgopohihdhacpegdaaf\2.0\lsdb.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\picgkalabbbpolgopohihdhacpegdaaf\2.0\qsns.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fohkdoejokheafajmnaejelfclgidijm\2.0\DneJyA3zA9.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fohkdoejokheafajmnaejelfclgidijm\2.0\lsdb.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\picgkalabbbpolgopohihdhacpegdaaf\2.0\lsdb.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\picgkalabbbpolgopohihdhacpegdaaf\2.0\qsns.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Administrator\AppData\Local\torch\User Data\Default\Extensions\fohkdoejokheafajmnaejelfclgidijm\2.0\DneJyA3zA9.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Administrator\AppData\Local\torch\User Data\Default\Extensions\fohkdoejokheafajmnaejelfclgidijm\2.0\lsdb.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Administrator\AppData\Local\torch\User Data\Default\Extensions\picgkalabbbpolgopohihdhacpegdaaf\2.0\lsdb.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Administrator\AppData\Local\torch\User Data\Default\Extensions\picgkalabbbpolgopohihdhacpegdaaf\2.0\qsns.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Gast\AppData\Local\Chromatic Browser\User Data\Default\Extensions\fohkdoejokheafajmnaejelfclgidijm\2.0\DneJyA3zA9.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Gast\AppData\Local\Chromatic Browser\User Data\Default\Extensions\fohkdoejokheafajmnaejelfclgidijm\2.0\lsdb.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Gast\AppData\Local\Chromatic Browser\User Data\Default\Extensions\picgkalabbbpolgopohihdhacpegdaaf\2.0\lsdb.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Gast\AppData\Local\Chromatic Browser\User Data\Default\Extensions\picgkalabbbpolgopohihdhacpegdaaf\2.0\qsns.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\fohkdoejokheafajmnaejelfclgidijm\2.0\DneJyA3zA9.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\fohkdoejokheafajmnaejelfclgidijm\2.0\lsdb.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\picgkalabbbpolgopohihdhacpegdaaf\2.0\lsdb.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\picgkalabbbpolgopohihdhacpegdaaf\2.0\qsns.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Gast\AppData\Local\torch\User Data\Default\Extensions\fohkdoejokheafajmnaejelfclgidijm\2.0\DneJyA3zA9.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Gast\AppData\Local\torch\User Data\Default\Extensions\fohkdoejokheafajmnaejelfclgidijm\2.0\lsdb.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Gast\AppData\Local\torch\User Data\Default\Extensions\picgkalabbbpolgopohihdhacpegdaaf\2.0\lsdb.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Gast\AppData\Local\torch\User Data\Default\Extensions\picgkalabbbpolgopohihdhacpegdaaf\2.0\qsns.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Nuanda\AppData\Local\Chromatic Browser\User Data\Default\Extensions\fohkdoejokheafajmnaejelfclgidijm\2.0\DneJyA3zA9.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Nuanda\AppData\Local\Chromatic Browser\User Data\Default\Extensions\fohkdoejokheafajmnaejelfclgidijm\2.0\lsdb.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Nuanda\AppData\Local\Chromatic Browser\User Data\Default\Extensions\picgkalabbbpolgopohihdhacpegdaaf\2.0\lsdb.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Nuanda\AppData\Local\Chromatic Browser\User Data\Default\Extensions\picgkalabbbpolgopohihdhacpegdaaf\2.0\qsns.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Nuanda\AppData\Local\Google\Chrome\User Data\Default\Extensions\fohkdoejokheafajmnaejelfclgidijm\2.0\DneJyA3zA9.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Nuanda\AppData\Local\Google\Chrome\User Data\Default\Extensions\fohkdoejokheafajmnaejelfclgidijm\2.0\lsdb.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Nuanda\AppData\Local\Google\Chrome\User Data\Default\Extensions\picgkalabbbpolgopohihdhacpegdaaf\2.0\lsdb.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Nuanda\AppData\Local\Google\Chrome\User Data\Default\Extensions\picgkalabbbpolgopohihdhacpegdaaf\2.0\qsns.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Nuanda\AppData\Local\torch\User Data\Default\Extensions\fohkdoejokheafajmnaejelfclgidijm\2.0\DneJyA3zA9.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Nuanda\AppData\Local\torch\User Data\Default\Extensions\fohkdoejokheafajmnaejelfclgidijm\2.0\lsdb.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Nuanda\AppData\Local\torch\User Data\Default\Extensions\picgkalabbbpolgopohihdhacpegdaaf\2.0\lsdb.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Nuanda\AppData\Local\torch\User Data\Default\Extensions\picgkalabbbpolgopohihdhacpegdaaf\2.0\qsns.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Nuanda\AppData\Roaming\Mozilla\Firefox\Profiles\ag7ill37.default\Extensions\sf0@cBAM.net\content\bg.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\AdwCleaner\Quarantine\C\Users\Nuanda\AppData\Roaming\Mozilla\Firefox\Profiles\ag7ill37.default\Extensions\WAL@Df0cbzE.com\content\bg.js.vir JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\fohkdoejokheafajmnaejelfclgidijm\2.0\lsdb.js JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\picgkalabbbpolgopohihdhacpegdaaf\2.0\lsdb.js JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\fohkdoejokheafajmnaejelfclgidijm\2.0\lsdb.js JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\picgkalabbbpolgopohihdhacpegdaaf\2.0\lsdb.js JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\Users\Gast\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\fohkdoejokheafajmnaejelfclgidijm\2.0\lsdb.js JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\Users\Gast\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\picgkalabbbpolgopohihdhacpegdaaf\2.0\lsdb.js JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\Users\Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\fohkdoejokheafajmnaejelfclgidijm\2.0\lsdb.js JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\Users\Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\picgkalabbbpolgopohihdhacpegdaaf\2.0\lsdb.js JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\Users\Nuanda\AppData\Local\nseF811.tmp Win32/VOPackage.BC evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert
C:\Users\Nuanda\AppData\Local\nspAD9D.tmp Win32/VOPackage.BC evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert
C:\Users\Nuanda\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\fohkdoejokheafajmnaejelfclgidijm\2.0\lsdb.js JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\Users\Nuanda\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\picgkalabbbpolgopohihdhacpegdaaf\2.0\lsdb.js JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\Users\Nuanda\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\fohkdoejokheafajmnaejelfclgidijm\2.0\lsdb.js JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\Users\Nuanda\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\picgkalabbbpolgopohihdhacpegdaaf\2.0\lsdb.js JS/Kryptik.ATB Trojaner Gesäubert durch Löschen - in Quarantäne kopiert
C:\Users\Nuanda\Downloads\avira_free_antivirus_de_14.0.2.286.exe Variante von Win32/Bundled.Toolbar.Ask.D potenziell unsichere Anwendung gelöscht - in Quarantäne kopiert
C:\Users\Nuanda\Downloads\avira_free_antivirus_de_14b411.exe Variante von Win32/Bundled.Toolbar.Ask.D potenziell unsichere Anwendung gelöscht - in Quarantäne kopiert
C:\Users\Nuanda\Downloads\DivXInstaller1001.exe Win32/Toolbar.Conduit.AN evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert
C:\Users\Nuanda\Downloads\FreeYouTubeToMP3Converter1122.exe Variante von Win32/OpenCandy.C potenziell unsichere Anwendung gelöscht - in Quarantäne kopiert
C:\Users\Nuanda\Downloads\FreeYouTubeToMP3Converter3.12.17.1127.exe Win32/OpenCandy potenziell unsichere Anwendung gelöscht - in Quarantäne kopiert
C:\Users\Nuanda\Downloads\PDFCreator-1_7_3_setup.exe Win32/InstallMonetizer.AQ evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert
C:\Users\Nuanda\Pictures\internetzch\ccsetup416.exe Win32/Bundled.Toolbar.Google.D potenziell unsichere Anwendung gelöscht - in Quarantäne kopiert
C:\Users\Nuanda\Pictures\internetzch\Eraser - CHIP-Installer.exe Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert
C:\Users\Nuanda\Pictures\internetzch\Malwarebytes Anti Malware Malware Scanner - CHIP-Installer.exe Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert
C:\Users\Nuanda\Pictures\internetzch\PDF24 Creator - CHIP-Installer.exe Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert
C:\Users\Nuanda\Pictures\internetzch\PDFCreator-1_7_3_setup.exe Win32/InstallMonetizer.AQ evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert
C:\Users\Nuanda\Pictures\internetzch\Revo Uninstaller - CHIP-Installer.exe Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert
C:\Users\Nuanda\Pictures\internetzch\Samsung-USB-Smartphone-Treiber-lnstall.exe Variante von Win32/WinloadSDA.I evtl. unerwünschte Anwendung gelöscht - in Quarantäne kopiert
C:\Windows\Installer\MSI5534.tmp Variante von Win32/Bundled.Toolbar.Ask.F potenziell unsichere Anwendung gelöscht - in Quarantäne kopiert
C:\Windows\Installer\MSIDBE0.tmp Variante von Win32/Bundled.Toolbar.Ask.F potenziell unsichere Anwendung gelöscht - in Quarantäne kopiert
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-02-2015
Ran by Nuanda (administrator) on COMPUTER on 22-02-2015 18:03:26
Running from C:\Users\Nuanda\Downloads
Loaded Profiles: Nuanda (Available profiles: Nuanda)
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe
(IObit) C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect 2\creator-ws.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe
(The Eraser Project) C:\Program Files\Eraser\Eraser.exe
() C:\Users\Nuanda\AppData\Local\Amazon Music\Amazon Music Helper.exe
(ICQ) C:\Users\Nuanda\AppData\Roaming\ICQM\icq.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Acer) C:\Program Files (x86)\Acer Remote\ArcServer.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13425224 2013-03-05] (Realtek Semiconductor)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [Eraser] => C:\Program Files\Eraser\Eraser.exe [980920 2012-05-22] (The Eraser Project)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766688 2014-07-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [448856 2014-08-19] (DivX, LLC)
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2024800 2014-06-04] (Wondershare)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2015-01-27] (AVAST Software)
HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [191528 2014-07-04] (Geek Software GmbH)
HKU\S-1-5-21-854577947-2758613332-2902503031-1001\...\Run: [Amazon Music] => C:\Users\Nuanda\AppData\Local\Amazon Music\Amazon Music Helper.exe [6281024 2014-10-15] ()
HKU\S-1-5-21-854577947-2758613332-2902503031-1001\...\Run: [icq] => C:\Users\Nuanda\AppData\Roaming\ICQM\icq.exe [36705800 2015-01-28] (ICQ)
HKU\S-1-5-21-854577947-2758613332-2902503031-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [31087200 2015-01-23] (Skype Technologies S.A.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer Remote.lnk
ShortcutTarget: Acer Remote.lnk -> C:\Program Files (x86)\Acer Remote\ArcServer.exe (Acer)
Startup: C:\Users\Nuanda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Deskjet 3520 series.lnk
ShortcutTarget: Tintenwarnungen überwachen - HP Deskjet 3520 series.lnk -> C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR HKU\S-1-5-21-854577947-2758613332-2902503031-1001\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-854577947-2758613332-2902503031-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-854577947-2758613332-2902503031-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
HKU\S-1-5-21-854577947-2758613332-2902503031-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=AV01
HKU\S-1-5-21-854577947-2758613332-2902503031-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.msn.com/?pc=AV01
URLSearchHook: HKLM-x32 - (No Name) - {6dad39c6-f4ac-4984-8e9b-f666269b9eb1} - No File
SearchScopes: HKLM-x32 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-854577947-2758613332-2902503031-1001 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll (IObit)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Toolbar: HKU\S-1-5-21-854577947-2758613332-2902503031-1001 -> No Name - {6DAD39C6-F4AC-4984-8E9B-F666269B9EB1} - No File
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Nuanda\AppData\Roaming\Mozilla\Firefox\Profiles\bgtfb6o3.default-1424567276864
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.31211.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File
FF Plugin-x32: PDF Architect 2 -> C:\Program Files (x86)\PDF Architect 2\np-previewer.dll (pdfforge GmbH)
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-09-12]
FF HKU\S-1-5-21-854577947-2758613332-2902503031-1001\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\Nuanda\AppData\Local\Google\Chrome\User Data\default
CHR Extension: (Google Slides) - C:\Users\Nuanda\AppData\Local\Google\Chrome\User Data\default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-12]
CHR Extension: (Google Docs) - C:\Users\Nuanda\AppData\Local\Google\Chrome\User Data\default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-09-12]
CHR Extension: (Google Drive) - C:\Users\Nuanda\AppData\Local\Google\Chrome\User Data\default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-12]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Nuanda\AppData\Local\Google\Chrome\User Data\default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-10-18]
CHR Extension: (YouTube) - C:\Users\Nuanda\AppData\Local\Google\Chrome\User Data\default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-09-12]
CHR Extension: (Google Search) - C:\Users\Nuanda\AppData\Local\Google\Chrome\User Data\default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-09-12]
CHR Extension: (Google Sheets) - C:\Users\Nuanda\AppData\Local\Google\Chrome\User Data\default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-12]
CHR Extension: (Avira Browser Safety) - C:\Users\Nuanda\AppData\Local\Google\Chrome\User Data\default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2015-02-22]
CHR Extension: (avast! Online Security) - C:\Users\Nuanda\AppData\Local\Google\Chrome\User Data\default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-09-12]
CHR Extension: (Skype Click to Call) - C:\Users\Nuanda\AppData\Local\Google\Chrome\User Data\default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2015-02-22]
CHR Extension: (Google Wallet) - C:\Users\Nuanda\AppData\Local\Google\Chrome\User Data\default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-12]
CHR Extension: (Gmail) - C:\Users\Nuanda\AppData\Local\Google\Chrome\User Data\default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-09-12]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-11-25]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-07-04] (Advanced Micro Devices, Inc.) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-11-25] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4012248 2014-11-25] (Avast Software)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2615368 2013-02-19] (Acer Incorporated)
R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2724128 2015-01-16] (IObit)
S2 McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [200728 2012-05-11] (McAfee, Inc.)
S3 PDF Architect 2; C:\Program Files (x86)\PDF Architect 2\ws.exe [1771560 2014-06-26] (pdfforge GmbH)
R2 PDF Architect 2 Creator; C:\Program Files (x86)\PDF Architect 2\creator-ws.exe [738856 2014-06-26] (pdfforge GmbH)
S3 pdfforge CrashHandler; C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe [861736 2014-06-26] (pdfforge GmbH)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 Andbus; C:\Windows\System32\drivers\lgandbus64.sys [19456 2012-03-02] (LG Electronics Inc.)
R3 AndDiag; C:\Windows\system32\DRIVERS\lganddiag64.sys [27648 2012-03-02] (LG Electronics Inc.)
R3 AndGps; C:\Windows\system32\DRIVERS\lgandgps64.sys [27136 2012-03-02] (LG Electronics Inc.)
R3 ANDModem; C:\Windows\system32\DRIVERS\lgandmodem64.sys [34304 2012-03-02] (LG Electronics Inc.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-11-25] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2014-11-25] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-11-25] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-11-25] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2014-11-25] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2014-11-25] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2014-11-25] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2014-11-25] ()
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [94208 2013-02-14] (Advanced Micro Devices)
S3 cleanhlp; C:\EEK\BIN\cleanhlp64.sys [57024 2014-10-06] (Emsisoft GmbH)
R2 RtkIOAC60; C:\Windows\system32\DRIVERS\RtkIOAC60.sys [38504 2012-04-16] (Windows (R) Codename Longhorn DDK provider)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [271752 2014-11-25] (Avast Software)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-22 18:03 - 2015-02-22 18:03 - 00017565 _____ () C:\Users\Nuanda\Downloads\FRST.txt
2015-02-22 18:02 - 2015-02-22 18:03 - 00000000 ____D () C:\FRST
2015-02-22 18:01 - 2015-02-22 18:01 - 02087424 _____ (Farbar) C:\Users\Nuanda\Downloads\FRST64.exe
2015-02-22 16:42 - 2015-02-22 16:42 - 00000797 _____ () C:\WINDOWS\setupact.log
2015-02-22 16:42 - 2015-02-22 16:42 - 00000000 _____ () C:\WINDOWS\setuperr.log
2015-02-22 16:25 - 2015-02-22 16:25 - 00001171 _____ () C:\Users\Nuanda\Documents\Malwarebytes Pup.Optional..txt
2015-02-22 15:49 - 2015-02-22 15:49 - 00013479 _____ () C:\Users\Nuanda\Documents\Trojaner Kryptic.txt
2015-02-22 03:36 - 2015-02-22 03:36 - 00000000 ____D () C:\Program Files (x86)\ESET
2015-02-22 03:35 - 2015-02-22 03:35 - 02347384 _____ (ESET) C:\Users\Nuanda\Downloads\esetsmartinstaller_deu.exe
2015-02-22 03:31 - 2015-02-22 03:31 - 00000197 _____ () C:\WINDOWS\system32\2015-02-22-02-31-03.099-AvastVBoxSVC.exe-3032.log
2015-02-22 02:32 - 2015-02-22 02:32 - 02126848 _____ () C:\Users\Nuanda\Downloads\adwcleaner_4.111(2).exe
2015-02-22 02:31 - 2015-02-22 02:31 - 00000197 _____ () C:\WINDOWS\system32\2015-02-22-01-31-28.003-AvastVBoxSVC.exe-2932.log
2015-02-22 02:25 - 2015-02-22 02:25 - 02126848 _____ () C:\Users\Nuanda\Downloads\adwcleaner_4.111.exe
2015-02-22 02:25 - 2015-02-22 02:25 - 02126848 _____ () C:\Users\Nuanda\Downloads\adwcleaner_4.111(1).exe
2015-02-22 02:08 - 2015-02-22 02:08 - 00000000 ____D () C:\Users\Nuanda\Desktop\Alte Firefox-Daten
2015-02-22 01:53 - 2015-02-22 01:53 - 00000000 ____D () C:\WINDOWS\Tasks\ImCleanDisabled
2015-02-22 01:53 - 2015-02-22 01:53 - 00000000 ____D () C:\ProgramData\{BAF091CA-86C4-4627-ADA1-897E2621C1B0}
2015-02-22 01:52 - 2015-02-22 01:52 - 00000000 ____D () C:\Users\Nuanda\AppData\Roaming\ProductData
2015-02-22 01:51 - 2015-02-22 16:45 - 00002400 _____ () C:\WINDOWS\System32\Tasks\Uninstaller_SkipUac_Nuanda
2015-02-22 01:51 - 2015-02-22 16:45 - 00000298 _____ () C:\WINDOWS\Tasks\Uninstaller_SkipUac_Nuanda.job
2015-02-22 01:51 - 2015-02-22 01:59 - 00000000 ____D () C:\Program Files (x86)\IObit
2015-02-22 01:51 - 2015-02-22 01:53 - 00000000 ____D () C:\Users\Nuanda\AppData\Roaming\IObit
2015-02-22 01:51 - 2015-02-22 01:53 - 00000000 ____D () C:\ProgramData\ProductData
2015-02-22 01:51 - 2015-02-22 01:53 - 00000000 ____D () C:\ProgramData\IObit
2015-02-22 01:51 - 2015-02-22 01:51 - 00001272 _____ () C:\Users\Nuanda\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk
2015-02-22 01:51 - 2015-02-22 01:51 - 00001248 _____ () C:\Users\Public\Desktop\IObit Uninstaller.lnk
2015-02-22 01:51 - 2015-02-22 01:51 - 00000000 ____D () C:\Users\Nuanda\AppData\IObit
2015-02-22 00:41 - 2015-02-22 00:41 - 00000197 _____ () C:\WINDOWS\system32\2015-02-21-23-41-22.082-AvastVBoxSVC.exe-2248.log
2015-02-15 18:46 - 2015-02-15 18:46 - 00000197 _____ () C:\WINDOWS\system32\2015-02-15-17-46-12.019-AvastVBoxSVC.exe-2260.log
2015-02-14 21:53 - 2015-02-14 21:53 - 00000197 _____ () C:\WINDOWS\system32\2015-02-14-20-53-31.063-AvastVBoxSVC.exe-2272.log
2015-02-12 21:09 - 2015-01-23 05:41 - 06041600 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-02-12 21:09 - 2015-01-23 04:17 - 04300800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-02-12 19:04 - 2015-02-12 19:05 - 00000197 ____N () C:\WINDOWS\system32\2015-02-12-18-04-09.078-AvastVBoxSVC.exe-2280.log
2015-02-11 04:43 - 2015-01-15 23:43 - 00563504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2015-02-11 04:43 - 2015-01-15 23:43 - 00177984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2015-02-11 04:43 - 2015-01-14 05:22 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2015-02-11 04:43 - 2015-01-14 04:53 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2015-02-11 04:43 - 2015-01-13 23:11 - 01762840 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2015-02-11 04:43 - 2015-01-13 23:04 - 01489072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2015-02-11 04:43 - 2015-01-10 10:10 - 07472960 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-02-11 04:43 - 2015-01-10 10:10 - 01733440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-02-11 04:43 - 2015-01-10 09:28 - 01498360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-02-11 04:43 - 2015-01-10 08:00 - 00430080 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2015-02-11 04:43 - 2015-01-10 07:38 - 00359424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2015-02-11 04:43 - 2014-12-19 09:57 - 00788680 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2015-02-11 04:43 - 2014-12-19 09:25 - 00602776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2015-02-11 04:43 - 2014-12-09 04:45 - 00393728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scesrv.dll
2015-02-11 04:43 - 2014-12-09 02:56 - 00538624 _____ (Microsoft Corporation) C:\WINDOWS\system32\scesrv.dll
2015-02-11 04:43 - 2014-12-09 00:12 - 00391526 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2015-02-11 04:43 - 2014-10-29 03:51 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msaudite.dll
2015-02-11 04:43 - 2014-10-29 03:50 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll
2015-02-11 04:43 - 2014-10-29 03:06 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adtschema.dll
2015-02-11 04:43 - 2014-10-29 03:06 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msaudite.dll
2015-02-11 04:43 - 2014-10-29 03:02 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2015-02-11 04:43 - 2014-10-29 03:02 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64cpu.dll
2015-02-11 04:43 - 2014-10-29 02:57 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntvdm64.dll
2015-02-11 04:43 - 2014-10-29 02:31 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2015-02-11 04:43 - 2014-10-29 02:15 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntvdm64.dll
2015-02-11 04:43 - 2014-10-29 02:15 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wow32.dll
2015-02-11 04:43 - 2014-10-29 02:14 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user.exe
2015-02-11 04:43 - 2014-10-29 02:13 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setup16.exe
2015-02-11 04:43 - 2014-10-29 02:13 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\instnm.exe
2015-02-11 04:42 - 2015-01-19 19:42 - 01487976 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2015-02-11 04:42 - 2015-01-12 04:09 - 25056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-02-11 04:42 - 2015-01-12 03:48 - 02885632 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-02-11 04:42 - 2015-01-12 03:48 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-02-11 04:42 - 2015-01-12 03:47 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2015-02-11 04:42 - 2015-01-12 03:34 - 00816128 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-02-11 04:42 - 2015-01-12 03:25 - 19740160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-02-11 04:42 - 2015-01-12 03:21 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2015-02-11 04:42 - 2015-01-12 03:08 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-02-11 04:42 - 2015-01-12 03:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2015-02-11 04:42 - 2015-01-12 03:05 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2015-02-11 04:42 - 2015-01-12 03:02 - 02277888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-02-11 04:42 - 2015-01-12 02:58 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-02-11 04:42 - 2015-01-12 02:55 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-02-11 04:42 - 2015-01-12 02:51 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2015-02-11 04:42 - 2015-01-12 02:48 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-02-11 04:42 - 2015-01-12 02:48 - 00718848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2015-02-11 04:42 - 2015-01-12 02:48 - 00374272 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2015-02-11 04:42 - 2015-01-12 02:46 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-02-11 04:42 - 2015-01-12 02:45 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2015-02-11 04:42 - 2015-01-12 02:43 - 14401024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-02-11 04:42 - 2015-01-12 02:34 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2015-02-11 04:42 - 2015-01-12 02:30 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-02-11 04:42 - 2015-01-12 02:27 - 02865152 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2015-02-11 04:42 - 2015-01-12 02:27 - 02358272 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-02-11 04:42 - 2015-01-12 02:25 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2015-02-11 04:42 - 2015-01-12 02:23 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2015-02-11 04:42 - 2015-01-12 02:23 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-02-11 04:42 - 2015-01-12 02:23 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2015-02-11 04:42 - 2015-01-12 02:14 - 12829184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-02-11 04:42 - 2015-01-12 02:14 - 01548288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-02-11 04:42 - 2015-01-12 02:02 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-02-11 04:42 - 2015-01-12 02:00 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-02-11 04:42 - 2015-01-12 01:56 - 01307136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-02-11 04:42 - 2015-01-12 01:55 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-02-11 04:41 - 2015-02-04 00:38 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
2015-02-11 04:41 - 2015-02-04 00:08 - 00761856 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2015-02-11 04:41 - 2015-02-04 00:08 - 00414208 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2015-02-11 04:41 - 2015-02-03 00:11 - 01098752 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2015-02-11 04:41 - 2015-02-03 00:11 - 00894464 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2015-02-11 04:41 - 2015-02-03 00:11 - 00609280 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2015-02-11 04:41 - 2015-01-10 09:22 - 04175872 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-02-07 15:32 - 2015-02-06 15:18 - 00015507 _____ () C:\Users\Nuanda\Documents\untitled_1_2.odt
2015-01-29 01:18 - 2015-01-29 01:18 - 00000000 ____D () C:\Users\Nuanda\Documents\ICQ Dateien
2015-01-28 23:21 - 2015-02-22 02:33 - 00000000 ____D () C:\Users\Nuanda\AppData\Roaming\Skype
2015-01-28 23:21 - 2015-01-29 00:31 - 00000000 ____D () C:\ProgramData\Skype
2015-01-28 23:21 - 2015-01-28 23:23 - 00000000 ___RD () C:\Program Files (x86)\Skype
2015-01-28 23:21 - 2015-01-28 23:21 - 00002715 _____ () C:\Users\Public\Desktop\Skype.lnk
2015-01-28 23:21 - 2015-01-28 23:21 - 00000000 ____D () C:\Users\Nuanda\AppData\Local\Skype
2015-01-28 23:21 - 2015-01-28 23:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-01-28 23:20 - 2015-01-28 23:20 - 00001817 _____ () C:\Users\Nuanda\Desktop\ICQ.lnk
2015-01-28 23:20 - 2015-01-28 23:20 - 00001675 _____ () C:\Users\Nuanda\AppData\Roaming\Microsoft\Windows\Start Menu\ICQ.lnk
2015-01-28 23:20 - 2015-01-28 23:20 - 00000000 ____D () C:\Users\Nuanda\voip
2015-01-28 23:20 - 2015-01-28 23:20 - 00000000 ____D () C:\Users\Nuanda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ICQ
2015-01-28 23:19 - 2015-01-29 01:17 - 00000000 ____D () C:\Users\Nuanda\AppData\Roaming\ICQM
2015-01-28 23:19 - 2015-01-29 00:00 - 00000000 ____D () C:\Users\Nuanda\AppData\Roaming\ICQ-Profile
2015-01-28 17:30 - 2015-01-28 17:31 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-22 18:02 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2015-02-22 18:01 - 2014-10-20 08:51 - 01673396 _____ () C:\WINDOWS\WindowsUpdate.log
2015-02-22 17:31 - 2013-12-08 22:06 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-02-22 17:20 - 2014-09-12 11:03 - 00001128 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-22 16:43 - 2014-09-24 07:17 - 01776918 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2015-02-22 16:43 - 2014-09-24 06:43 - 00764340 _____ () C:\WINDOWS\system32\perfh007.dat
2015-02-22 16:43 - 2014-09-24 06:43 - 00159160 _____ () C:\WINDOWS\system32\perfc007.dat
2015-02-22 16:15 - 2014-10-07 22:36 - 00129752 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-02-22 03:28 - 2014-09-12 11:03 - 00001124 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-22 03:28 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-02-22 03:26 - 2014-10-08 09:37 - 00000000 ____D () C:\AdwCleaner
2015-02-22 02:28 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2015-02-22 02:27 - 2014-10-20 08:59 - 00000000 ____D () C:\Users\Nuanda
2015-02-22 02:15 - 2013-11-10 09:38 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-854577947-2758613332-2902503031-1001
2015-02-22 02:00 - 2013-07-29 14:39 - 00000000 ____D () C:\Program Files (x86)\Acer Remote
2015-02-22 01:56 - 2013-07-29 14:16 - 00000000 ____D () C:\ProgramData\OEM
2015-02-22 01:56 - 2013-07-29 14:16 - 00000000 ____D () C:\Program Files\Acer
2015-02-22 01:56 - 2013-04-03 07:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer
2015-02-22 01:54 - 2014-10-02 18:18 - 00000000 ____D () C:\Users\Nuanda\AppData\Roaming\Apple Computer
2015-02-22 01:50 - 2014-10-07 22:30 - 00002456 _____ () C:\Users\Nuanda\Desktop\Rkill.txt
2015-02-22 01:07 - 2014-10-07 23:42 - 00000000 ____D () C:\Program Files\HitmanPro
2015-02-22 00:52 - 2014-09-12 11:05 - 00004182 _____ () C:\WINDOWS\System32\Tasks\avast! Emergency Update
2015-02-20 09:39 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2015-02-15 18:41 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\NDF
2015-02-12 23:55 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\rescache
2015-02-12 21:37 - 2012-07-26 08:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2015-02-12 14:36 - 2014-10-18 13:01 - 00000000 ____D () C:\Users\Nuanda\Documents\Soziologische Theorien
2015-02-11 18:16 - 2014-10-20 08:51 - 00000000 ____D () C:\ProgramData\Package Cache
2015-02-11 15:08 - 2013-08-22 15:44 - 00370272 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2015-02-11 15:05 - 2014-12-13 16:51 - 00000000 ____D () C:\WINDOWS\system32\appraiser
2015-02-11 15:05 - 2014-09-24 08:43 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel
2015-02-11 15:05 - 2013-11-11 15:18 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-02-11 14:58 - 2013-11-11 15:18 - 116773704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-02-07 04:35 - 2014-10-08 10:41 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-02-05 12:48 - 2013-11-09 16:12 - 00000000 ____D () C:\Users\Nuanda\AppData\Local\VirtualStore
2015-02-04 21:34 - 2013-12-08 22:06 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-02-03 20:31 - 2014-10-23 19:10 - 00714720 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-02-03 20:31 - 2014-10-23 19:10 - 00106976 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
==================== Files in the root of some directories =======
2014-08-10 19:02 - 2014-08-10 19:02 - 4096000 _____ () C:\Program Files (x86)\GUT234C.tmp
2014-10-10 19:18 - 2014-10-17 23:18 - 0000128 _____ () C:\Users\Nuanda\AppData\Roaming\WB.CFG
2014-10-12 10:18 - 2014-10-12 10:18 - 0000001 _____ () C:\Users\Nuanda\AppData\Local\DSI.DAT
2013-11-14 11:59 - 2013-11-14 11:59 - 0000057 _____ () C:\ProgramData\Ament.ini
Some content of TEMP:
====================
C:\Users\Nuanda\AppData\Local\Temp\HitmanPro.exe
C:\Users\Nuanda\AppData\Local\Temp\Quarantine.exe
C:\Users\Nuanda\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-02-22 13:08
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-02-2015
Ran by Nuanda at 2015-02-22 18:05:28
Running from C:\Users\Nuanda\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: McAfee Firewall (Disabled) {959DA8E2-3527-57D1-4915-924367AD4FE9}
FW: avast! Antivirus (Disabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
clear.fi SDK - Video 2 (x32 Version: 2.1.2606 - CyberLink Corp.) Hidden
clear.fi SDK- Movie 2 (x32 Version: 2.1.2606 - CyberLink Corp.) Hidden
Acer Recovery Management (HKLM\...\{07F2005A-8CAC-4A4B-83A2-DA98A722CA61}) (Version: 6.00.3016 - Acer Incorporated)
Acer Remote (HKLM-x32\...\Acer Remote1.0) (Version: 1.0 - Acer Inc.)
AcerCloud Docs (HKLM-x32\...\{CA4FE8B0-298C-4E5D-A486-F33B126D6A0A}) (Version: 1.01.2008 - Acer Incorporated)
AcerCloud Portal (HKLM-x32\...\{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}) (Version: 2.02.2021 - Acer Incorporated)
Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Amazon Music (HKU\S-1-5-21-854577947-2758613332-2902503031-1001\...\Amazon Amazon Music) (Version: 3.6.0.671 - Amazon Services LLC)
AMD Catalyst Install Manager (HKLM\...\{E3AB2F4D-B540-437B-4E4F-3A3C344C3B2A}) (Version: 8.0.911.0 - Advanced Micro Devices, Inc.)
Apple Application Support (HKLM-x32\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{B678797F-DF38-4556-8A31-8B818E261868}) (Version: 8.0.0.23 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
AudibleManager (HKLM-x32\...\AudibleManager) (Version: 18414980.4759644.48.2005940040 - Audible, Inc.)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.0.2208 - AVAST Software)
Bing Bar (HKLM-x32\...\{3365E735-48A6-4194-9988-CE59AC5AE503}) (Version: 7.3.132.0 - Microsoft Corporation)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD)
CCleaner (HKLM\...\CCleaner) (Version: 4.16 - Piriform)
CHIP Updater (HKLM-x32\...\CHIP Updater_is1) (Version: 2.31 - Abelssoft)
clear.fi Media (HKLM-x32\...\{E9AF1707-3F3A-49E2-8345-4F2D629D0876}) (Version: 2.02.2012 - Acer Incorporated)
clear.fi Photo (HKLM-x32\...\{B5AD89F2-03D3-4206-8487-018298007DD0}) (Version: 2.02.2012 - Acer Incorporated)
DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.3.80 - DivX, LLC)
Eraser 6.0.10.2620 (HKLM\...\{6E5159B4-A519-41EF-80EF-AD58371515DF}) (Version: 6.0.2620 - The Eraser Project)
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 37.0.2062.124 - Google Inc.)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
Hotkey Utility (HKLM-x32\...\{A6DC88AD-501A-44BC-884D-57435F972E2C}) (Version: 3.00.3005 - Acer Incorporated)
HP Deskjet 3520 series - Grundlegende Software für das Gerät (HKLM\...\{15B2F0E3-3FAC-4495-B0FD-398EECFA4100}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Deskjet 3520 series Hilfe (HKLM-x32\...\{6B953497-169C-4929-9AA9-A9F510347468}) (Version: 27.0.0 - Hewlett Packard)
HP Deskjet 3520 series Setup Guide (HKLM-x32\...\{AEEDCEB7-00B8-4BE1-B492-AB04803D5F1E}) (Version: 27.0.0 - Hewlett Packard)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard)
ICQ 8.3 (build 7317) (HKU\S-1-5-21-854577947-2758613332-2902503031-1001\...\ICQ) (Version: 8.3.7317.0 - ICQ)
Identity Card (HKLM-x32\...\{3D9CB654-99AD-4301-89C6-0D12A790767C}) (Version: 2.00.3005 - Acer Incorporated)
IObit Uninstaller (HKLM-x32\...\IObitUninstall) (Version: 4.2.6.1 - IObit)
iTunes (HKLM\...\{F46AA0F1-E284-4878-A462-5F11B9166C0E}) (Version: 11.4.0.18 - Apple Inc.)
LG United Mobile Driver (HKLM-x32\...\{2A3A4BD6-6CE0-4e2a-80D2-1D0FF6ACBFBA}) (Version: 3.11.3.0 - LG Electronics)
Live Updater (HKLM-x32\...\{EE26E302-876A-48D9-9058-3129E5B99999}) (Version: 2.00.3008 - Acer Incorporated)
Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.31211.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Mozilla Firefox 35.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 35.0.1 (x86 de)) (Version: 35.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 32.0.3 - Mozilla)
Nero BackItUp 12 Essentials OEM.a01 (HKLM-x32\...\{4CA8F973-6377-4ABF-9ED5-CC2323B3C000}) (Version: 12.5.00500 - Nero AG)
Office Addin (HKLM-x32\...\{6D2BBE1D-E600-4695-BA37-0B0E605542CC}) (Version: 2.02.2008 - Acer)
OpenOffice 4.0.1 (HKLM-x32\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation)
PDF Architect 2 (HKLM-x32\...\PDF Architect 2) (Version: 2.0.24.16092 - pdfforge GmbH)
PDF Architect 2 Create Module (HKLM-x32\...\{03EC56DE-6424-43D7-A020-1EEE3E8159DE}) (Version: 2.0.17.17583 - pdfforge GmbH)
PDF Architect 2 Edit Module (HKLM-x32\...\{8528EEBC-9EBE-44A7-9DFB-EE401BA916C7}) (Version: 2.0.17.17583 - pdfforge GmbH)
PDF Architect 2 View Module (HKLM-x32\...\{C960FF38-431D-429D-AD1F-FBD12A45B7C5}) (Version: 2.0.17.17583 - pdfforge GmbH)
PDF24 Creator 6.7.0 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org)
PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.3 - pdfforge)
Prerequisite installer (x32 Version: 12.0.0003 - Nero AG) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.13.314.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6859 - Realtek Semiconductor Corp.)
Realtek USB Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.2.9200.39036 - Realtek Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
Sitecom WiFi USB adapter N150 Driver (HKLM-x32\...\{B20F9D1C-A0A5-4cd8-8306-DE95842311B1}) (Version: 1.00.0187.1 - Sitecom Europe BV)
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
Skype™ 7.1 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.1.105 - Skype Technologies S.A.)
Spotify (HKLM-x32\...\Spotify) (Version: 0.8.4.99.ga249b5f1 - Spotify AB)
Studie zur Verbesserung von HP Deskjet 3520 series Produkten (HKLM\...\{A5BB6A58-BC1A-48A7-BB19-1768A80CF9C9}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
Visual Studio 2005 Tools for Office Second Edition Runtime (HKLM-x32\...\Microsoft Visual Studio 2005 Tools for Office Runtime) (Version: - Microsoft Corporation)
Visual Studio Tools for the Office system 3.0 Runtime (HKLM-x32\...\Visual Studio Tools for the Office system 3.0 Runtime) (Version: - Microsoft Corporation)
Visual Studio Tools for the Office system 3.0 Runtime Service Pack 1 (KB949258) (HKLM-x32\...\{8FB53850-246A-3507-8ADE-0060093FFEA6}.KB949258) (Version: 1 - Microsoft Corporation)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
==================== Restore Points =========================
05-02-2015 13:15:42 Geplanter Prüfpunkt
11-02-2015 14:56:50 Windows Update
18-02-2015 17:54:10 Geplanter Prüfpunkt
22-02-2015 01:04:59 Prüfpunkt von HitmanPro
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {0680B5A5-78B3-4CD6-9E2A-E3B5EBE1E3FC} - System32\Tasks\HP-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [2011-10-28] (Hewlett-Packard)
Task: {1AFF6BA3-4DBD-42B1-BCC8-4B0C44AB708F} - System32\Tasks\DivX-Online-Aktualisierungsprogramm => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [2014-01-10] ()
Task: {2F947BC4-4262-4BBF-A78F-003E94166000} - System32\Tasks\ALUAgent => C:\Program Files (x86)\Acer\Live Updater\liveupdater_agent.exe [2013-01-22] ()
Task: {35196DC0-D30D-4777-8040-E22C737F24EB} - System32\Tasks\HP AR Program Upload - 37c52034431b436cb6b5d51eae4a56c2752f7456cfe6451f81ca29cb97319bc4 => C:\Program Files\HP\HP Deskjet 3520 series\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {38D627A8-780B-4F4A-855B-A9D72829A755} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {51230ABB-3562-4C35-AF72-4D0ED83BB585} - System32\Tasks\Hotkey Utility => C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe [2013-02-27] (Acer Incorporated)
Task: {52A72D6F-ECC9-4C2A-9EC1-5872147D7541} - System32\Tasks\Uninstaller_SkipUac_Nuanda => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2015-02-22] (IObit)
Task: {5BE04924-7EC6-403F-A297-27586827AF27} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-04] (Adobe Systems Incorporated)
Task: {700C62FD-DEAF-47A6-B149-94A12A074B40} - System32\Tasks\Abelssoft\Updater scan => C:\Program Files (x86)\CHIP Updater\CHIPUpdater.exe [2014-09-02] (CHIP)
Task: {71421D87-94C3-4218-AC2C-BB1E9F832FEF} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-07-23] (Piriform Ltd)
Task: {788A311A-52D0-4E77-9EB8-980592CEC03D} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {A24E08FC-54EC-4E08-A5F4-6351CCD8F67F} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-11-25] (AVAST Software)
Task: {A4146A88-59A2-4AE2-8080-10D0E22F3558} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-02-11] (Microsoft Corporation)
Task: {B3DA909E-FA42-4FC3-A3EA-95F0B6AF80E6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {CEF228B7-5617-405E-A2A5-779324F1E0F1} - System32\Tasks\Recovery Management\Notification => C:\Program Files\Acer\Acer Recovery Management\Notification\Notification.exe [2013-01-23] (Acer Incorporated)
Task: {D401150B-38DE-428C-B82E-6A01E52C50A0} - System32\Tasks\HPCustParticipation HP Deskjet 3520 series => C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPCustPartic.exe [2012-10-17] (Hewlett-Packard Co.)
Task: {EFFC61C4-952D-4522-A024-9BFACF08B987} - System32\Tasks\{6880E9B3-22F8-4717-9CE5-51B6E555F566} => pcalua.exe -a "C:\Users\Nuanda\AppData\Roaming\0S1P1R2Y1C1P1Q0D1F2W1G1I1F1T1Q\Gratis downloaden &amp; installieren Packages\uninstaller.exe" -c /Uninstall /NM="Gratis downloaden &amp; installieren Packages" /AN="0S1P1R2Y1C1P1Q0D1F2W1G1I1F1T1Q" /MBN="Gratis downloaden &amp; installieren Packages"
Task: {FB46942C-D91E-4919-80C5-158CD0AE790F} - System32\Tasks\ALU => C:\Program Files (x86)\Acer\Live Updater\updater.exe [2013-02-22] ()
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Uninstaller_SkipUac_Nuanda.job => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe
==================== Loaded Modules (whitelisted) ==============
2014-07-04 20:33 - 2014-07-04 20:33 - 00127488 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
2014-11-25 14:23 - 2014-11-25 14:23 - 00388208 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxDDU.dll
2014-11-25 14:23 - 2014-11-25 14:23 - 05851328 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxRT.dll
2014-09-19 10:59 - 2014-10-15 06:35 - 06281024 _____ () C:\Users\Nuanda\AppData\Local\Amazon Music\Amazon Music Helper.exe
2014-07-04 20:33 - 2014-07-04 20:33 - 00102400 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2015-02-21 17:37 - 2015-02-21 17:37 - 02911744 _____ () C:\Program Files\AVAST Software\Avast\defs\15022100\algo.dll
2014-11-25 14:23 - 2014-11-25 14:23 - 04495336 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\x86\VBoxRT-x86.dll
2015-02-22 15:56 - 2015-02-22 15:56 - 02911744 _____ () C:\Program Files\AVAST Software\Avast\defs\15022201\algo.dll
2014-07-31 11:16 - 2014-07-31 11:16 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-07-31 11:16 - 2014-07-31 11:16 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2015-02-22 01:51 - 2015-02-22 01:51 - 00622880 _____ () C:\Program Files (x86)\IObit\LiveUpdate\ProductStatistics.dll
2013-02-06 09:06 - 2013-02-06 06:14 - 00055368 _____ () C:\Program Files (x86)\Acer Remote\plugins\general.dll
2013-02-06 09:06 - 2013-02-06 06:14 - 00041032 _____ () C:\Program Files (x86)\Acer Remote\plugins\ITunesBase.dll
2013-02-06 09:06 - 2013-02-06 06:14 - 00040520 _____ () C:\Program Files (x86)\Acer Remote\plugins\WinEight.dll
2013-02-06 09:06 - 2013-02-06 06:14 - 00111176 _____ () C:\Program Files (x86)\Acer Remote\plugins\WMPBase.dll
2013-02-06 09:06 - 2013-02-06 06:14 - 00041032 _____ () C:\Program Files (x86)\Acer Remote\plugins\YTBBase.dll
2014-08-25 14:12 - 2014-06-04 09:21 - 00571904 _____ () C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\DAQExp.dll
2014-08-25 14:12 - 2014-05-19 16:19 - 00137728 _____ () C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\CBSCreateVC.dll
2014-11-25 14:23 - 2014-11-25 14:23 - 38562088 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2015-01-28 17:30 - 2015-01-28 17:31 - 03925104 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-854577947-2758613332-2902503031-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Nuanda\Pictures\SCAN\nebelfleck, sterne 159589.jpg
DNS Servers: 192.168.0.1
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
HKLM\...\StartupApproved\Run32: => "DivXUpdate"
HKLM\...\StartupApproved\Run32: => "HP Software Update"
HKLM\...\StartupApproved\Run32: => "AnyProtect Scanner"
==================== Accounts: =============================
Administrator (S-1-5-21-854577947-2758613332-2902503031-500 - Administrator - Disabled)
Gast (S-1-5-21-854577947-2758613332-2902503031-501 - Limited - Disabled)
Nuanda (S-1-5-21-854577947-2758613332-2902503031-1001 - Administrator - Enabled) => C:\Users\Nuanda
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (02/22/2015 04:48:39 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.
Error: (02/22/2015 04:48:36 PM) (Source: Microsoft-Windows-LocationProvider) (EventID: 2006) (User: NT-AUTORITÄT)
Description: There was an error with the Windows Location Provider database
Error: (02/22/2015 01:58:18 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 2000
Error: (02/22/2015 01:58:18 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 2000
Error: (02/22/2015 01:58:18 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (02/22/2015 07:44:34 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9203
Error: (02/22/2015 07:44:34 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 9203
Error: (02/22/2015 07:44:34 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (02/22/2015 07:44:32 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 7062
Error: (02/22/2015 07:44:32 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 7062
System errors:
=============
Error: (02/22/2015 05:31:50 PM) (Source: DCOM) (EventID: 10010) (User: Computer)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}
Error: (02/22/2015 03:28:47 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "McAfee SiteAdvisor Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (02/22/2015 03:28:46 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst McAfee SiteAdvisor Service erreicht.
Error: (02/22/2015 03:26:49 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Volumeschattenkopie" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (02/22/2015 03:26:49 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Nero Update" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (02/22/2015 03:26:49 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (02/22/2015 03:26:49 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "iPod-Dienst" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (02/22/2015 03:26:49 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "LiveUpdate" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (02/22/2015 03:26:49 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "PDF Architect 2 Creator" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (02/22/2015 03:26:49 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Druckwarteschlange" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 5000 Millisekunden durchgeführt: Neustart des Diensts.
Microsoft Office Sessions:
=========================
Error: (02/22/2015 04:48:39 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Users\Nuanda\Downloads\esetsmartinstaller_deu.exe
Error: (02/22/2015 04:48:36 PM) (Source: Microsoft-Windows-LocationProvider) (EventID: 2006) (User: NT-AUTORITÄT)
Description: -2147024883
Error: (02/22/2015 01:58:18 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 2000
Error: (02/22/2015 01:58:18 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 2000
Error: (02/22/2015 01:58:18 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (02/22/2015 07:44:34 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9203
Error: (02/22/2015 07:44:34 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 9203
Error: (02/22/2015 07:44:34 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (02/22/2015 07:44:32 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 7062
Error: (02/22/2015 07:44:32 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 7062
==================== Memory info ===========================
Processor: AMD E1-2500 APU with Radeon(TM) HD Graphics
Percentage of memory in use: 43%
Total physical RAM: 3517.86 MB
Available physical RAM: 2003.13 MB
Total Pagefile: 4733.86 MB
Available Pagefile: 2319.57 MB
Total Virtual: 131072 MB
Available Virtual: 131071.79 MB
==================== Drives ================================
Drive c: (Acer) (Fixed) (Total:222.16 GB) (Free:163.5 GB) NTFS
Drive d: (DATA) (Fixed) (Total:223.36 GB) (Free:222.96 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 5251266A)
Partition: GPT Partition Type.
==================== End Of Log ============================ |