Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 08-09-2017
Administrator (S-1-5-21-1066935764-1894680920-224314404-500 - Administrator - Enabled) => C:\Users\Administrator
(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)
Age of Empires II HD The Rise of the Rajas GERMAN (HKLM\...\YWdlb2ZlbXBpcmVzaWloZA_is1) (Version: 1 - )
Any Video Converter Ultimate 6.1.3 (HKLM-x32\...\Any Video Converter Ultimate_is1) (Version: - Any-Video-Converter.com)
ASUS Xonar DG Audio Driver (HKLM\...\C-Media Oxygen HD Audio Driver) (Version: - )
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden
Gothic II - Gold Edition (HKLM-x32\...\Gothic II - Gold Edition_is1) (Version: - )
GTA San Andreas (HKLM-x32\...\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}) (Version: 1.00.00001 - Rockstar Games)
Heaven Benchmark version 4.0 (HKLM-x32\...\Unigine Heaven Benchmark (Basic Edition)_is1) (Version: 4.0 - Unigine Corp.)
Heritage of Kings - The Settlers (HKLM-x32\...\1207658793_is1) (Version: 2.2.0.8 - GOG.com)
K-Lite Codec Pack 13.1.6 Standard (HKLM-x32\...\KLiteCodecPack_is1) (Version: 13.1.6 - KLCP)
Malwarebytes version 3.2.2.2018 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.2.2.2018 - Malwarebytes)
Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{b341426f-8543-4e0d-96c3-e976f8ec5ab6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{4fd02573-5f12-4ae4-8027-c63f8e1115af}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{82f2609e-68ba-408d-963f-530ad8809435}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{577ff5ba-39aa-4d8c-a3a9-f95012763438}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23506 (HKLM-x32\...\{23daf363-3020-4059-b3ae-dc4ad39fed19}) (Version: 14.0.23506.0 - Microsoft Corporation)
MotioninJoy Gamepad tool 0.7.1001 (HKLM\...\{330DAC67-5B62-452A-A0E4-6B4A5923940F}_is1) (Version: 0.7.1001 - www.motioninjoy.com)
NVIDIA Graphics Driver 342.01 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 342.01 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation)
OpenOffice 4.1.3 (HKLM-x32\...\{8D5FCC56-BB9F-4122-923C-71753F50F6F5}) (Version: 4.13.9783 - Apache Software Foundation)
Port Forward Network Utilities (HKLM-x32\...\{4C109C49-5A19-458B-8DF6-A2C469A92679}) (Version: 3.0.30 - Portforward, LLC)
Quake III Mod: Beyond the Portals (HKLM-x32\...\Quake3BTPUninstallKey_is1) (Version: 1.0 - Activision)
Quake III Mod: Challenge ProMode Arena (HKLM-x32\...\Quake3CPMAUninstallKey_is1) (Version: 1.47 - Activision)
Quake III Mod: Excessive Plus (HKLM-x32\...\Quake3EXPlusUninstallKey_is1) (Version: 1.03 - Activision)
Quake III Mod: Invasion (HKLM-x32\...\Quake3InvasionUninstallKey_is1) (Version: 2.8 Beta - Activision)
Quake III Mod: Lego Carnage (HKLM-x32\...\Quake3LegoCUninstallKey_is1) (Version: 3.0 - Activision)
Quake III Mod: Lost Arena (HKLM-x32\...\Quake3LostArenaUninstallKey_is1) (Version: 1.0 - Activision)
Quake III Mod: Matrix (HKLM-x32\...\Quake3MatrixUninstallKey_is1) (Version: 2.4 Beta - Activision)
Quake III Mod: Mega Man X Zero (HKLM-x32\...\Quake3mmzeroxUninstallKey_is1) (Version: Alpha 01 - Activision)
Quake III Mod: Monkey Kombat (HKLM-x32\...\Quake3MonkeyUninstallKey_is1) (Version: 0.05 - Activision)
Quake III Mod: OSP Tourney Q3A (HKLM-x32\...\Quake3OSPUninstallKey_is1) (Version: 1.33 - Activision)
Quake III Mod: PainKeep Arena (HKLM-x32\...\Quake3PKAUninstallKey_is1) (Version: 3.1 - Activision)
Quake III Mod: Quake 3 Rally (HKLM-x32\...\Quake3RallyUninstallKey_is1) (Version: 1.3 - Activision)
Quake III: Arena (HKLM-x32\...\Quake3UninstallKey_is1) (Version: 1.32c - Activision)
S.T.A.L.K.E.R. Call of Pripyat (HKLM-x32\...\GOGPACKSTALKERCOP_is1) (Version: 2.0.0.12 - GOG.com)
S.T.A.L.K.E.R. Clear Sky (HKLM-x32\...\GOGPACKSTALKERSTCS_is1) (Version: 2.0.0.8 - GOG.com)
S.T.A.L.K.E.R. Shadow of Chernobyl (HKLM-x32\...\GOGPACKSTALKERSHOC_is1) (Version: 2.0.0.5 - GOG.com)
SimCity 3000 Unlimited (HKLM-x32\...\2086050016_is1) (Version: 2.0.0.3 - GOG.com)
Söldner Secret Wars - Community Edition version 33980 (HKLM-x32\...\{F3AF62F5-665E-4B3E-8899-5C46D1793391}_is1) (Version: 33980 - soldnersecretwars.de)
Söldner Secret Wars Language Pack German Version 1.1 (HKLM-x32\...\{7D27AC27-37F4-4A30-A1FC-53D22549F468}_is1) (Version: 1.1 - soldnersecretwars.de)
The Elder Scrolls V Skyrim - Legendary Edition (HKLM-x32\...\The Elder Scrolls V Skyrim - Legendary Edition_is1) (Version: - )
Titan Quest Anniversary Edition (HKLM-x32\...\Titan Quest Anniversary Edition_is1) (Version: - )
Wildlife Park 3 Dino Invasion (HKLM-x32\...\Wildlife Park 3 Dino Invasion_is1) (Version: - )
==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2015-02-15] (Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2015-02-15] (Alexander Roshal)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2016-11-14] (NVIDIA Corporation)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2015-02-15] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2015-02-15] (Alexander Roshal)
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {1BD678B2-B7A1-4F65-90DA-E15AEA92A94E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-05-21] (Google Inc.)
Task: {50E98B7C-FAED-44B3-A498-05F30E39A6E1} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-05-21] (Google Inc.)
Task: {65703FE2-8247-41C7-A797-8339F2069948} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2017-05-10] ()
Task: {DC7DA04C-3E95-42C3-8299-1DF0B1C0163C} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-01-21] (Piriform Ltd)
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============
2017-05-21 18:22 - 2016-11-14 13:15 - 000135224 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2017-08-05 17:15 - 2017-08-02 09:39 - 002692952 _____ () C:\Program Files (x86)\Google\Chrome\Application\60.0.3112.90\swiftshader\libglesv2.dll
2017-08-05 17:15 - 2017-08-02 09:39 - 000137048 _____ () C:\Program Files (x86)\Google\Chrome\Application\60.0.3112.90\swiftshader\libegl.dll
==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========
==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)
==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)
(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)
2009-07-14 04:34 - 2017-05-24 00:12 - 000000917 ____R C:\Windows\system32\Drivers\etc\hosts
HKU\S-1-5-21-1066935764-1894680920-224314404-500\Control Panel\Desktop\\Wallpaper -> C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
mpsdrv => Firewall Dienst läuft nicht.
MpsSvc => Firewall Dienst läuft nicht.
bfe => Firewall Dienst läuft nicht.
MSCONFIG\startupreg: Cmaudio8788 => C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cmicnfgp.dll,CMICtrlWnd
==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
FirewallRules: [{474DA6FE-FFF3-4DF9-958C-A69D71CB5188}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{1649E0C7-817A-4920-A92C-F13AF54FE07E}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{392D15F8-7B83-40D7-AE56-C13A59CC2111}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{95C057FD-8540-48FF-8235-95E335C59C33}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{B9F38802-253B-4CF7-8765-19A21181787A}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
Überprüfen Sie den "winmgmt" Dienst oder reparieren Sie den WMI.
Konnte Geräte nicht auflisten. Überprüfen Sie den "winmgmt" Dienst oder reparieren Sie den WMI.
==================== Fehlereinträge in der Ereignisanzeige: =========================
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (05/21/2017 05:31:46 PM) (Source: MsiInstaller) (EventID: 11309) (User: NT-AUTORITÄT)
Description: Produkt: Microsoft .NET Framework 4.5.2 (DEU) -- Fehler 1309. Fehler beim Lesen der Datei: C:\windows\setup\scripts\Windows\Microsoft.NET\Framework64\v4\de\AddInUtil.resources.dll. Systemfehler 3. Stellen Sie sicher, dass die Datei vorhanden ist, und Sie darauf zugreifen können.
Error: (09/10/2017 01:53:17 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Malwarebytes Service service depends on the Windows Management Instrumentation service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Error: (09/10/2017 01:53:16 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Malwarebytes Service service depends on the Windows Management Instrumentation service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Error: (09/10/2017 01:53:02 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Malwarebytes Service service depends on the Windows Management Instrumentation service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Error: (09/10/2017 01:53:01 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Malwarebytes Service service depends on the Windows Management Instrumentation service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Error: (09/10/2017 01:53:00 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Malwarebytes Service service depends on the Windows Management Instrumentation service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Error: (09/10/2017 01:52:59 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Malwarebytes Service service depends on the Windows Management Instrumentation service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Error: (09/10/2017 01:52:58 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Malwarebytes Service service depends on the Windows Management Instrumentation service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Error: (09/10/2017 01:52:57 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Malwarebytes Service service depends on the Windows Management Instrumentation service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Error: (09/10/2017 01:52:56 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Malwarebytes Service service depends on the Windows Management Instrumentation service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Error: (09/10/2017 01:52:55 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Malwarebytes Service service depends on the Windows Management Instrumentation service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
OTL logfile created on: 10.09.2017 15:33:39 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Administrator\Downloads
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17843)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,25 Gb Total Physical Memory | 2,49 Gb Available Physical Memory | 76,57% Memory free
3,25 Gb Paging File | 2,60 Gb Available in Paging File | 80,08% Paging File free
Paging file location(s): [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 232,88 Gb Total Space | 60,16 Gb Free Space | 25,83% Space Free | Partition Type: NTFS
Drive D: | 19,58 Gb Total Space | 4,04 Gb Free Space | 20,64% Space Free | Partition Type: NTFS
Drive E: | 184,01 Gb Total Space | 38,81 Gb Free Space | 21,09% Space Free | Partition Type: NTFS
Drive F: | 29,20 Gb Total Space | 8,57 Gb Free Space | 29,36% Space Free | Partition Type: NTFS
Computer Name: INTEL775-PC | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2017.09.10 14:59:13 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Administrator\Downloads\OTL.exe
========== Modules (No Company Name) ==========
========== Services (SafeList) ==========
SRV:64bit: - [2017.08.21 07:32:12 | 006,058,960 | ---- | M] (Malwarebytes) [Auto | Stopped] -- C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe -- (MBAMService)
SRV:64bit: - [2015.06.10 07:04:20 | 001,255,424 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\diagtrack.dll -- (DiagTrack)
SRV:64bit: - [2015.06.10 06:48:03 | 001,011,712 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2015.06.10 06:40:39 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2009.07.14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2017.09.07 06:51:50 | 001,610,016 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2017.06.27 11:49:17 | 000,411,096 | ---- | M] (ASUSTeK Computer Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\ASUS\AXSP\2.00.09\atkexComSvc.exe -- (asComSvc)
SRV - [2017.06.01 16:24:11 | 000,975,832 | ---- | M] (ASUSTeK Computer Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\ASUS\AAHM\1.00.31\aaHMSvc.exe -- (asHmComSvc)
SRV - [2015.11.05 20:36:48 | 000,105,144 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2015.06.10 06:52:00 | 000,067,224 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2017.08.27 20:52:50 | 000,283,480 | ---- | M] (Sysprogs OU) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BazisPortableCDBus.sys -- (BazisPortableCDBus)
DRV:64bit: - [2015.06.10 17:07:05 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2015.06.10 17:07:05 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2015.06.10 06:47:19 | 000,056,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2015.06.10 06:47:19 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2015.06.10 06:43:13 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2015.06.10 06:42:25 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:64bit: - [2015.06.10 06:42:25 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012.05.12 12:31:00 | 000,121,416 | ---- | M] (MotioninJoy) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\MijXfilt.sys -- (MotioninJoyXFilter)
DRV:64bit: - [2011.12.20 08:59:12 | 002,727,936 | ---- | M] (C-Media Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\cmudaxp.sys -- (cmudaxp)
DRV:64bit: - [2011.12.07 20:42:28 | 000,074,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xusb21.sys -- (xusb21)
DRV:64bit: - [2010.11.21 05:23:48 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tsusbhub.sys -- (tsusbhub)
DRV:64bit: - [2010.11.21 05:23:48 | 000,088,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc)
DRV:64bit: - [2010.11.21 05:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2010.11.21 05:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009.09.28 09:22:00 | 000,395,264 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)
DRV:64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2005.03.29 01:30:38 | 000,008,192 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1066935764-1894680920-224314404-500\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.com
IE - HKU\S-1-5-21-1066935764-1894680920-224314404-500\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://www.google.com[binary data]
IE - HKU\S-1-5-21-1066935764-1894680920-224314404-500\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1066935764-1894680920-224314404-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll (Google Inc.)
========== Chrome ==========
CHR - Extension: No name found = C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\
CHR - Extension: No name found = C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\
CHR - Extension: No name found = C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\
CHR - Extension: No name found = C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\
CHR - Extension: No name found = C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm\1.14.8_0\
CHR - Extension: No name found = C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\
CHR - Extension: No name found = C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_1\
CHR - Extension: No name found = C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_0\
CHR - Extension: No name found = C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\
CHR - Extension: No name found = C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6017.605.1.4_0\
O1 HOSTS File: ([2017.05.24 00:12:12 | 000,000,917 | R--- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 q4master.idsoftware.com
O1 - Hosts: 127.0.0.1 idnet.ua-corp.com
O4 - HKU\S-1-5-19..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun File not found
O4 - HKU\S-1-5-20..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\S-1-5-21-1066935764-1894680920-224314404-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{00946D43-86E9-423C-96E9-FF3239925EE2}: DhcpNameServer = 192.168.0.1
O20:64bit: - AppInit_DLLs: (prio.dll) - C:\Program Files\Prio\prio.dll (O&K Software)
O20 - AppInit_DLLs: (prio32.dll) - C:\Program Files\Prio\prio32.dll (O&K Software)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2017.09.10 14:14:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
[2017.09.10 14:13:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2017.09.10 14:00:02 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Local\ESET
[2017.09.10 13:52:32 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes
[2017.09.10 13:12:39 | 000,000,000 | ---D | C] -- C:\Program Files\WebDiscoverBrowser
[2017.09.10 13:12:26 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Local\{B5F70934-5E12-42d2-882D-62D42EA1FA67}
[2017.09.10 13:08:33 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\youtubejs
[2017.09.10 13:08:33 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Documents\Bigasoft Video Downloader Pro
[2017.09.10 13:08:33 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\Bigasoft Video Downloader Pro
[2017.09.10 13:06:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bigasoft
[2017.09.10 12:57:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\YouTubeSongDownloader
[2017.08.31 22:58:34 | 000,000,000 | ---D | C] -- C:\Program Files\AISuite
[2017.08.31 22:52:09 | 000,028,672 | ---- | C] (ASUSTek Computer Inc.) -- C:\Windows\SysWow64\AsIO.dll
[2017.08.31 22:52:09 | 000,000,000 | ---D | C] -- C:\ProgramData\ASUS
[2017.08.31 22:52:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ASUS
[2017.08.31 22:51:29 | 000,000,000 | ---D | C] -- C:\Program Files\ASUS AI Suite
[2017.08.27 20:53:21 | 000,000,000 | ---D | C] -- C:\Program Files\Tabletop Simulator
[2017.08.25 00:07:25 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Local\Futuremark
[2017.08.13 16:41:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Titan Quest Anniversary Edition
[2017.08.13 16:34:44 | 000,283,480 | ---- | C] (Sysprogs OU) -- C:\Windows\SysNative\drivers\BazisPortableCDBus.sys
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Program Files (x86)\*.tmp files -> C:\Program Files (x86)\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2017.09.10 14:15:19 | 000,000,874 | ---- | M] () -- C:\Users\Administrator\AppData\Roaming\prio.ini
[2017.09.10 14:14:55 | 000,002,020 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes.lnk
[2017.09.10 13:45:24 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2017.09.10 13:22:06 | 000,298,968 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2017.09.10 13:17:39 | 000,001,884 | ---- | M] () -- C:\Users\Administrator\Documents\cc_20170910_131737.reg
[2017.09.08 21:58:55 | 007,499,574 | ---- | M] () -- C:\Users\Administrator\Desktop\New Bitmap Image.bmp
[2017.09.02 09:12:21 | 000,000,259 | ---- | M] () -- C:\Windows\prio.ini
[2017.08.31 14:54:32 | 000,000,135 | ---- | M] () -- C:\Users\Administrator\Desktop\RandomRambo - Twitch.url
[2017.08.27 20:52:50 | 000,283,480 | ---- | M] (Sysprogs OU) -- C:\Windows\SysNative\drivers\BazisPortableCDBus.sys
[2017.08.27 01:40:26 | 000,004,809 | ---- | M] () -- C:\Users\Administrator\Desktop\avatar92.jpg
[2017.08.24 16:17:54 | 000,000,061 | ---- | M] () -- C:\Users\Administrator\Desktop\AndyMilonakis - Twitch.url
[2017.08.24 11:27:36 | 000,077,440 | ---- | M] () -- C:\Windows\SysNative\drivers\mbae64.sys
[2017.08.24 10:27:20 | 000,003,558 | ---- | M] () -- C:\Users\Administrator\Documents\cc_20170824_102718.reg
[2017.08.22 18:35:57 | 000,001,881 | ---- | M] () -- C:\Users\Administrator\Desktop\csgo - Shortcut.lnk
[2017.08.22 18:35:44 | 000,001,651 | ---- | M] () -- C:\Users\Administrator\Desktop\nvidiaInspector.exe - Shortcut.lnk
[2017.08.21 19:35:17 | 000,001,503 | ---- | M] () -- C:\Users\Administrator\Desktop\csgo.exe - Shortcut.lnk
[2017.08.21 19:34:23 | 000,000,219 | ---- | M] () -- C:\Users\Administrator\Desktop\Counter-Strike Global Offensive.url
[2017.08.20 10:56:19 | 000,001,638 | ---- | M] () -- C:\Users\Administrator\Documents\cc_20170820_105617.reg
[2017.08.20 00:10:04 | 000,728,064 | ---- | M] () -- C:\Users\Administrator\AppData\Local\file__0.localstorage
[2017.08.15 13:30:42 | 000,002,450 | ---- | M] () -- C:\Users\Administrator\Documents\cc_20170815_133040.reg
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Program Files (x86)\*.tmp files -> C:\Program Files (x86)\*.tmp -> ]
========== Files Created - No Company Name ==========
[2017.09.10 14:14:04 | 000,002,020 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes.lnk
[2017.09.10 14:14:03 | 000,077,440 | ---- | C] () -- C:\Windows\SysNative\drivers\mbae64.sys
[2017.09.10 13:17:39 | 000,001,884 | ---- | C] () -- C:\Users\Administrator\Documents\cc_20170910_131737.reg
[2017.09.08 20:59:48 | 007,499,574 | ---- | C] () -- C:\Users\Administrator\Desktop\New Bitmap Image.bmp
[2017.08.31 22:52:09 | 000,015,232 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsIO.sys
[2017.08.27 01:40:26 | 000,004,809 | ---- | C] () -- C:\Users\Administrator\Desktop\avatar92.jpg
[2017.08.24 16:17:54 | 000,000,061 | ---- | C] () -- C:\Users\Administrator\Desktop\AndyMilonakis - Twitch.url
[2017.08.24 10:27:19 | 000,003,558 | ---- | C] () -- C:\Users\Administrator\Documents\cc_20170824_102718.reg
[2017.08.22 23:19:35 | 000,000,135 | ---- | C] () -- C:\Users\Administrator\Desktop\RandomRambo - Twitch.url
[2017.08.22 18:35:57 | 000,001,881 | ---- | C] () -- C:\Users\Administrator\Desktop\csgo - Shortcut.lnk
[2017.08.22 18:35:44 | 000,001,651 | ---- | C] () -- C:\Users\Administrator\Desktop\nvidiaInspector.exe - Shortcut.lnk
[2017.08.21 19:35:17 | 000,001,503 | ---- | C] () -- C:\Users\Administrator\Desktop\csgo.exe - Shortcut.lnk
[2017.08.21 19:34:23 | 000,000,219 | ---- | C] () -- C:\Users\Administrator\Desktop\Counter-Strike Global Offensive.url
[2017.08.20 10:56:18 | 000,001,638 | ---- | C] () -- C:\Users\Administrator\Documents\cc_20170820_105617.reg
[2017.08.15 13:30:41 | 000,002,450 | ---- | C] () -- C:\Users\Administrator\Documents\cc_20170815_133040.reg
[2017.05.24 18:57:09 | 000,728,064 | ---- | C] () -- C:\Users\Administrator\AppData\Local\file__0.localstorage
[2017.05.24 00:29:06 | 000,000,934 | ---- | C] () -- C:\Windows\QIII.INI
[2017.05.24 00:29:06 | 000,000,032 | ---- | C] () -- C:\Windows\Q3version.ini
[2017.05.24 00:29:06 | 000,000,031 | ---- | C] () -- C:\Windows\Q3CDKey.ini
[2017.05.24 00:12:11 | 000,685,102 | -HS- | C] () -- C:\Users\Administrator\AppData\Roaming\unhosts.exe
[2017.05.23 19:07:51 | 000,000,000 | ---- | C] () -- C:\Windows\PowerReg.dat
[2017.05.22 11:17:34 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2017.05.21 20:18:56 | 000,000,874 | ---- | C] () -- C:\Users\Administrator\AppData\Roaming\prio.ini
[2017.05.21 19:45:52 | 000,000,259 | ---- | C] () -- C:\Windows\prio.ini
[2017.05.21 18:29:50 | 000,200,704 | ---- | C] () -- C:\Windows\SysWow64\HsMgr.exe
[2017.05.21 18:29:50 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\VmixP8.dll
[2017.05.21 18:29:50 | 000,000,049 | ---- | C] () -- C:\Windows\SysWow64\cmasiop.ini
[2017.05.21 18:29:44 | 000,044,950 | ---- | C] () -- C:\Windows\Cmicnfgp.ini.cfl
[2017.05.21 18:29:39 | 000,000,907 | ---- | C] () -- C:\Windows\Cmicnfgp.ini.imi
[2017.05.21 18:29:37 | 000,005,066 | ---- | C] () -- C:\Windows\Cmicnfgp.ini.cfg
[2017.05.21 18:29:35 | 000,000,594 | ---- | C] () -- C:\Windows\cmudaxp.ini
[2017.05.21 17:24:12 | 001,591,896 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
========== ZeroAccess Check ==========
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2015.06.10 07:01:12 | 014,177,280 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2015.06.10 07:01:12 | 012,875,264 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 05:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
< End of report >
OTL Extras logfile created on: 10.09.2017 15:29:24 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Administrator\Downloads
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17843)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,25 Gb Total Physical Memory | 2,52 Gb Available Physical Memory | 77,57% Memory free
3,25 Gb Paging File | 2,62 Gb Available in Paging File | 80,53% Paging File free
Paging file location(s): [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 232,88 Gb Total Space | 60,16 Gb Free Space | 25,83% Space Free | Partition Type: NTFS
Drive D: | 19,58 Gb Total Space | 4,04 Gb Free Space | 20,64% Space Free | Partition Type: NTFS
Drive E: | 184,01 Gb Total Space | 38,81 Gb Free Space | 21,09% Space Free | Partition Type: NTFS
Drive F: | 29,20 Gb Total Space | 8,57 Gb Free Space | 29,36% Space Free | Partition Type: NTFS
Computer Name: INTEL775-PC | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- Reg Error: Key error.
htmlfile [opennew] -- Reg Error: Key error.
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [mplayerc64.enqueue] -- "C:\Program Files (x86)\K-Lite Codec Pack\MPC-HC64\mpc-hc64.exe" /add "%1" (MPC-HC Team)
Directory [mplayerc64.play] -- "C:\Program Files (x86)\K-Lite Codec Pack\MPC-HC64\mpc-hc64.exe" "%1" (MPC-HC Team)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- Reg Error: Key error.
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Key error.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- Reg Error: Key error.
htmlfile [opennew] -- Reg Error: Key error.
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [mplayerc64.enqueue] -- "C:\Program Files (x86)\K-Lite Codec Pack\MPC-HC64\mpc-hc64.exe" /add "%1" (MPC-HC Team)
Directory [mplayerc64.play] -- "C:\Program Files (x86)\K-Lite Codec Pack\MPC-HC64\mpc-hc64.exe" "%1" (MPC-HC Team)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- Reg Error: Key error.
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Key error.
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{474DA6FE-FFF3-4DF9-958C-A69D71CB5188}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1649E0C7-817A-4920-A92C-F13AF54FE07E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{392D15F8-7B83-40D7-AE56-C13A59CC2111}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{95C057FD-8540-48FF-8235-95E335C59C33}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\bin\cef\cef.win7\steamwebhelper.exe |
"{B9F38802-253B-4CF7-8765-19A21181787A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\bin\cef\cef.win7\steamwebhelper.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{330DAC67-5B62-452A-A0E4-6B4A5923940F}_is1" = MotioninJoy Gamepad tool 0.7.1001
"{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1" = Malwarebytes version 3.2.2.2018
"{37B8F9C7-03FB-3253-8781-2517C99D7C00}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030
"{50A2BC33-C9CD-3BF1-A8FF-53C10A0B183C}" = Microsoft Visual C++ 2015 x64 Minimum Runtime - 14.0.24215
"{5740BD44-B58D-321A-AFC0-6D3D4556DD6C}" = Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.40660
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.6.1
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 342.01
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 342.01
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.16.0318
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{BD6F5371-DAC1-30F0-9DDE-CAC6791E28C3}" = Microsoft .NET Framework 4.6.1
"{CB0836EC-B072-368D-82B2-D3470BF95707}" = Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.40660
"{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030
"{EF1EC6A9-17DE-3DA9-B040-686A1E8A8B04}" = Microsoft Visual C++ 2015 x64 Additional Runtime - 14.0.24215
"CCleaner" = CCleaner
"C-Media Oxygen HD Audio Driver" = ASUS Xonar DG Audio Driver
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.79
"CPUID HWMonitor_is1" = CPUID HWMonitor 1.31
"Prio" = Prio
"Steam App 10" = Counter-Strike
"Steam App 232910" = TrackMania² Stadium
"Steam App 24960" = Battlefield: Bad Company 2
"Steam App 730" = Counter-Strike: Global Offensive
"WinRAR archiver" = WinRAR 5.21 (64-Bit)
"YWdlb2ZlbXBpcmVzaWloZA_is1" = Age of Empires II HD The Rise of the Rajas GERMAN
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{050d4fc8-5d48-4b8f-8972-47c82c46020f}" = Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501
"{1045AB6F-6151-3634-8C2C-EE308AA1A6A7}" = Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.23506
"{23daf363-3020-4059-b3ae-dc4ad39fed19}" = Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23506
"{4C109C49-5A19-458B-8DF6-A2C469A92679}" = Port Forward Network Utilities
"{4fd02573-5f12-4ae4-8027-c63f8e1115af}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
"{577ff5ba-39aa-4d8c-a3a9-f95012763438}" = Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660
"{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}" = Google Update Helper
"{65AD78AD-D23D-3A1E-9305-3AE65CD522C2}" = Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.23506
"{7D27AC27-37F4-4A30-A1FC-53D22549F468}_is1" = Söldner Secret Wars Language Pack German Version 1.1
"{7DAD0258-515C-3DD4-8964-BD714199E0F7}" = Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.40660
"{82f2609e-68ba-408d-963f-530ad8809435}" = Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660
"{8D5FCC56-BB9F-4122-923C-71753F50F6F5}" = OpenOffice 4.1.3
"{B175520C-86A2-35A7-8619-86DC379688B9}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030
"{b341426f-8543-4e0d-96c3-e976f8ec5ab6}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030
"{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030
"{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}" = GTA San Andreas
"{d992c12e-cab2-426f-bde3-fb8c53950b0d}" = Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215
"{E30D8B21-D82D-3211-82CC-0F0A5D1495E8}" = Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.40660
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F3AF62F5-665E-4B3E-8899-5C46D1793391}_is1" = Söldner Secret Wars - Community Edition version 33980
"{f65db027-aff3-4070-886a-0d87064aabb1}" = Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501
"1207658715_is1" = Painkiller Black
"1207658793_is1" = Heritage of Kings - The Settlers
"1207667043_is1" = Mortal Kombat
"1207667053_is1" = Mortal Kombat 2
"1207667063_is1" = Mortal Kombat 3
"2086050016_is1" = SimCity 3000 Unlimited
"AdiIRC" = AdiIRC
"Any Video Converter Ultimate_is1" = Any Video Converter Ultimate 6.1.3
"FINAL FANTASY IX_is1" = FINAL FANTASY IX
"Final Fantasy VIII_is1" = Final Fantasy VIII
"Fraps" = Fraps
"GOGPACKSTALKERCOP_is1" = S.T.A.L.K.E.R. Call of Pripyat
"GOGPACKSTALKERSHOC_is1" = S.T.A.L.K.E.R. Shadow of Chernobyl
"GOGPACKSTALKERSTCS_is1" = S.T.A.L.K.E.R. Clear Sky
"Google Chrome" = Google Chrome
"Gothic II - Gold Edition_is1" = Gothic II - Gold Edition
"KLiteCodecPack_is1" = K-Lite Codec Pack 13.1.6 Standard
"OpenAL" = OpenAL
"pcsx2" = PCSX2 - Playstation 2 Emulator
"Quake3BTPUninstallKey_is1" = Quake III Mod: Beyond the Portals
"Quake3CPMAUninstallKey_is1" = Quake III Mod: Challenge ProMode Arena
"Quake3EXPlusUninstallKey_is1" = Quake III Mod: Excessive Plus
"Quake3InvasionUninstallKey_is1" = Quake III Mod: Invasion
"Quake3LegoCUninstallKey_is1" = Quake III Mod: Lego Carnage
"Quake3LostArenaUninstallKey_is1" = Quake III Mod: Lost Arena
"Quake3MatrixUninstallKey_is1" = Quake III Mod: Matrix
"Quake3mmzeroxUninstallKey_is1" = Quake III Mod: Mega Man X Zero
"Quake3MonkeyUninstallKey_is1" = Quake III Mod: Monkey Kombat
"Quake3OSPUninstallKey_is1" = Quake III Mod: OSP Tourney Q3A
"Quake3PKAUninstallKey_is1" = Quake III Mod: PainKeep Arena
"Quake3RallyUninstallKey_is1" = Quake III Mod: Quake 3 Rally
"Quake3UninstallKey_is1" = Quake III: Arena
"Quake4UninstallKey_is1" = Quake 4
"Steam" = Steam
"The Elder Scrolls V Skyrim - Legendary Edition_is1" = The Elder Scrolls V Skyrim - Legendary Edition
"Titan Quest Anniversary Edition_is1" = Titan Quest Anniversary Edition
"Unigine Heaven Benchmark (Basic Edition)_is1" = Heaven Benchmark version 4.0
"Wildlife Park 3 Dino Invasion_is1" = Wildlife Park 3 Dino Invasion
========== Last 20 Event Log Errors ==========
[ Application Events ]
OTL encountered an error while reading this event log. It may be corrupt.
OTL encountered an error while reading this event log. It may be corrupt.
OTL encountered an error while reading this event log. It may be corrupt.
OTL encountered an error while reading this event log. It may be corrupt.
OTL encountered an error while reading this event log. It may be corrupt.
OTL encountered an error while reading this event log. It may be corrupt.
OTL encountered an error while reading this event log. It may be corrupt.
< End of report >