|
Plagegeister aller Art und deren Bekämpfung: Avast häufige Meldung "bösartige Website gefunden" (nach voherigen PC Problemen)Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
29.07.2013, 11:39 | #1 |
| Avast häufige Meldung "bösartige Website gefunden" (nach voherigen PC Problemen) Hallo, ich bin froh, auf euer Forum gestossen zu sein und hoffe, ihr könnt mir weiterhelfen. Ich habe folgendes Problem: Seit drei Tagen meldet mir mein installiertes Avast Antivirenprogramm (7.0 version) sehr häufig (bei jeder neu aufgerufenen Website) folgendes: "Bösartige Website wurde gefunden". Dazu wird angezeigt: URL: hxxp://irgendeinseitencode... Prozess: C:\... Infektion: URL:Mal Das Problem ähnelt sehr stark der Schilderung dieses Eintrages hier: http://www.trojaner-board.de/133457-...iet-avast.html Ich konnte im Internet keine andere Lösung finden und wende mich daher an euch. Als erstes habe ich die von euch empfohlenen Schritte befolgt und Defogger, OTL und GMER auf dem Destop installiert, um die Log Files zu erhalten die ich hier auch mit anfüge. Nach dem GMER Schritt (genau nach Anleitung befolgt) habe ich wieder Firewall und WLAN aktiviert und die neue Version von Avast (8.0) installiert... Die alte hatte ich zuvor (vor Anwendung von GMER) deinstalliert da ich sie nicht deaktivieren konnte. Jetzt taucht die Meldung "Bösartige Website wurde gefunden" nicht mehr auf, aber ich weiss nicht, ob das Problem gelöst wurde. Folgende Fakten sind zur Klärung des Problems eventuell noch relevant, oder auch nicht: 1.) Vor ca. zwei Wochen hatte ich Probleme mit beschädigten JPG-Files (Fotos von eigener Digi-Cam). Habe ich bestimmte Fotos geöffnet gab es einen System Crash. Kurz darauf erfolgte der Crash sogar, wenn ich nur den Ordner öffnete in dem sie steckten. Ich habe im Internet nach Lösungen gesucht und hilfreiche Einträge gefunden in denen empfohlen wurde, neu installierte Software zu deinstallieren. Nachdem ich einen kürzlich geladenen Converter deinstalliert hatte (OX Converter von hxxp://download.chip.eu/de/OX-PDF-to-TIFF-Converter_16078880.html), war das Problem weg. Ich habe die zuvor fehlerhaften JPG-Dateien einfach gelöscht und die Ordner umstrukturiert. Dann war wieder Ruhe und alles lief. Vor drei Tagen tauchte dann das oben beschriebene Problem auf. 2.) Heute tauchte ein neues Problem auf: Ich habe auf fast allen Seiten dich ich aufrufe, eiteninterne Links die erscheinen. Einzelne Wörter (oder Teile der Wörter) sind doppelt grün unterstrichen. Wenn man mit dem Curser auf die Wörter geht, erscheint ein kleines Werbefenster (das man irgendwas downloaden kann) in dessen Ecke steht "MusicBvld.com" und in der andern "click here" (was ich natürlich nicht angeklickt habe). Auch diese Links nerven TIERISCH und ich will sie unbedingt loswerden. Ich habe "AdBlock Plus 2.3.1" und "AdBlock Plus Pop-Up Addon 0.8" installiert und alles neu gestartet, aber die Links sind immernoch da. Dies sind keine zusätzlichen Problembeschreibungen. Ich poste diese beiden Punkte nur, weil ich glaube, dass sie etwas mit dem eigentlichem Problem ("Avast") zu tun haben könnten und weil ich einfach vermeiden möchte, Daten zu verlieren oder einem Virus zum Opfer zu fallen. Zu meinem System (aus Systeminformationen): Betriebssystem (einziges): Windows 7 Professional Version: 6.1.7601 Service Pack 1 Build 7601 Systemtyp: x-64 basierter Systemtyp PC Art: Dell Vostro 3350 Notebook Zuletzt habe ich den PC im Januar neu aufgesetzt und alle (aktuellen) Treiber nach Vorschrift (Dell Homepage) neu installiert. Seitdem lief er okay und ohne Probleme. Die letzten Wochen war ich auf einer Konferenz im Ausland (Costa Rica) und habe mit dem Notebook gearbeitet (Internet Recherche, keine Spielseiten oder "unseriöse Seiten" besucht). Es gab keinen Kontakt mit fremden Datenträgern (USB´s etc.). Ich hoffe, ich konnte euch mein Problem deutlich genug schildern und ihr könnt mir weiterhelfen bzw. dabei helfen, wieder einen sauberen PC zu haben mit dem ich unbesorgt arbeiten kann. Vielen herzlichen Dank!! Bea PS: Das OTL File war zu gross (102 KB), daher habe ich es als ZIP-Ordner angehängt. |
29.07.2013, 11:45 | #2 |
/// the machine /// TB-Ausbilder | Avast häufige Meldung "bösartige Website gefunden" (nach voherigen PC Problemen) hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
29.07.2013, 11:52 | #3 |
| Avast häufige Meldung "bösartige Website gefunden" (nach voherigen PC Problemen) Hallo!
__________________Vielen Dank für die schnelle Antwort. Hier die beiden Files 1. FRST LOG FILE FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-07-2013 Ran by DoppelAnton (administrator) on 29-07-2013 12:47:19 Running from C:\Users\DoppelAnton\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe (Validity Sensors, Inc.) C:\Windows\system32\vcsFPService.exe (Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe (Atheros) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\Ath_CoexAgent.exe (Atheros Commnucations) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\adminservice.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe () C:\ProgramData\DatacardService\HWDeviceService64.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe () C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Atheros Communications) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe (Atheros Commnucations) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\AthBtTray.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Ericsson AB) C:\Program Files (x86)\Dell\Dell Mobile Broadband Manager\WirelessManager.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Huawei Technologies Co., Ltd.) C:\Users\DoppelAnton\AppData\Roaming\Ge org Internet Manager\ouc.exe (Dropbox, Inc.) C:\Users\DoppelAnton\AppData\Roaming\Dropbox\bin\Dropbox.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [FreeFallProtection] - C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe [686704 2010-12-15] () HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1128448 2011-05-27] (IDT, Inc.) HKLM\...\Run: [QuickSet] - C:\Program Files\Dell\QuickSet\QuickSet.exe [3668336 2011-03-24] (Dell Inc.) HKLM\...\Run: [BTMTrayAgent] - rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp [x] HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2480936 2010-12-15] (Synaptics Incorporated) HKLM\...\Run: [IntelTBRunOnce] - C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs [4526 2010-11-29] () HKLM\...\Run: [AtherosBtStack] - C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe [627360 2011-05-20] (Atheros Communications) HKLM\...\Run: [AthBtTray] - C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\AthBtTray.exe [379552 2011-05-20] (Atheros Commnucations) HKCU\...\Run: [WirelessManager] - C:\Program Files (x86)\Dell\Dell Mobile Broadband Manager\WirelessManager.exe [194600 2010-07-28] (Ericsson AB) HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.) HKCU\...\Run: [HW_OPENEYE_OUC_Ge org Internet Manager] - C:\Program Files (x86)\Ge org Internet Manager\UpdateDog\ouc.exe [110592 2009-12-31] (Huawei Technologies Co., Ltd.) MountPoints2: {49674710-d1bf-11e2-98ae-3859f93b766e} - H:\AutoRun.exe MountPoints2: {49674723-d1bf-11e2-98ae-3859f93b766e} - H:\AutoRun.exe MountPoints2: {6f94f44b-694c-11e2-921e-806e6f6e6963} - F:\autoRcd.exe MountPoints2: {e2470b43-6d64-11e2-bba2-3859f93b766e} - I:\HTC_Sync_Manager_PC.exe HKLM-x32\...\Run: [NUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-06] (Intel Corporation) HKLM-x32\...\Run: [Dell Webcam Central] - C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [487561 2010-08-11] (Creative Technology Ltd) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-03-24] (Hewlett-Packard) HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [163000 2012-12-12] (Geek Software GmbH) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [DataCardMonitor] - C:\Program Files (x86)\Ge org Internet Manager\DataCardMonitor.exe [253952 2013-06-12] (Huawei Technologies Co., Ltd.) HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software) Startup: C:\Users\DoppelAnton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\DoppelAnton\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\DoppelAnton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) Startup: C:\Users\DoppelAnton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Photosmart 5510 series.lnk ShortcutTarget: Tintenwarnungen überwachen - HP Photosmart 5510 series.lnk -> C:\Program Files\HP\HP Photosmart 5510 series\bin\HPStatusBL.dll (Hewlett-Packard Co.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.dell.com HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.delta-search.com/?q={searchTerms}&affID=119816&tt=gc_&babsrc=SP_ss&mntrId=94823859F93B766E SearchScopes: HKCU - {30133017-D648-4850-93E9-087DDC3EAA87} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000029&src=kw&q={searchTerms}&locale=de_EU&apn_ptnrs=^U4&apn_dtid=^OSJ000^YY^SK&apn_uid=7DF644B9-C7BF-484D-9590-F9202584C055&apn_sauid=80F623D7-07F5-4FB9-B698-7DF0B7EE0EAC BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 134.76.10.46 134.76.33.21 FireFox: ======== FF ProfilePath: C:\Users\DoppelAnton\AppData\Roaming\Mozilla\Firefox\Profiles\58iu00y1.default FF user.js: detected! => C:\Users\DoppelAnton\AppData\Roaming\Mozilla\Firefox\Profiles\58iu00y1.default\user.js FF NewTab: hxxp://www.google.com/firefox FF SelectedSearchEngine: Google FF Homepage: hxxp://www.google.com/firefox FF Keyword.URL: hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.0.6 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\DoppelAnton\AppData\Roaming\Mozilla\Firefox\Profiles\58iu00y1.default\searchplugins\askcom.xml FF SearchPlugin: C:\Users\DoppelAnton\AppData\Roaming\Mozilla\Firefox\Profiles\58iu00y1.default\searchplugins\babylon.xml FF SearchPlugin: C:\Users\DoppelAnton\AppData\Roaming\Mozilla\Firefox\Profiles\58iu00y1.default\searchplugins\delta.xml FF SearchPlugin: C:\Users\DoppelAnton\AppData\Roaming\Mozilla\Firefox\Profiles\58iu00y1.default\searchplugins\sweetim.xml FF Extension: adblockpopups - C:\Users\DoppelAnton\AppData\Roaming\Mozilla\Firefox\Profiles\58iu00y1.default\Extensions\adblockpopups@jessehakanen.net.xpi FF Extension: zotero - C:\Users\DoppelAnton\AppData\Roaming\Mozilla\Firefox\Profiles\58iu00y1.default\Extensions\zotero@chnm.gmu.edu.xpi FF Extension: No Name - C:\Users\DoppelAnton\AppData\Roaming\Mozilla\Firefox\Profiles\58iu00y1.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM-x32\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] C:\Program Files\T-Mobile\InternetManager_H\OCx64\addon FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF FF HKCU\...\Firefox\Extensions: [lrcspal@xinghao.net] C:\Program Files (x86)\XingHaoLyrics\FF\ FF Extension: No Name - C:\Program Files (x86)\XingHaoLyrics\FF\ ==================== Services (Whitelisted) ================= R2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\Ath_CoexAgent.exe [146592 2011-05-20] (Atheros) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software) R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [339456 2010-11-16] () ==================== Drivers (Whitelisted) ==================== R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software) S0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] () S1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-07-29] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-07-29] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-07-29] () R0 BMLoad; C:\Windows\System32\drivers\BMLoad.sys [16512 2009-12-15] (Bytemobile, Inc.) S3 pfc; C:\Windows\SysWow64\drivers\pfc.sys [14604 2003-08-11] (Padus, Inc.) R1 tcpipBM; C:\Windows\system32\drivers\tcpipBM.sys [39552 2009-12-15] (Bytemobile, Inc.) R1 tcpipBM; C:\Windows\system32\drivers\tcpipBM.sys [39552 2009-12-15] (Bytemobile, Inc.) S3 pfc; system32\drivers\pfc.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-29 12:46 - 2013-07-29 12:46 - 00000000 ____D C:\FRST 2013-07-29 12:37 - 2013-07-29 12:37 - 00015318 _____ C:\Users\DoppelAnton\Desktop\OTL.zip 2013-07-29 11:58 - 2013-07-29 12:08 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-29 11:58 - 2013-07-29 12:08 - 00001116 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-29 11:58 - 2013-07-29 12:03 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-07-29 11:58 - 2013-07-29 12:03 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-07-29 11:58 - 2013-07-29 12:03 - 00189936 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-07-29 11:58 - 2013-07-29 12:03 - 00004116 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-07-29 11:58 - 2013-07-29 12:03 - 00003864 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-07-29 11:58 - 2013-07-29 11:58 - 00003924 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-07-29 11:58 - 2013-05-09 10:59 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-07-29 11:58 - 2013-05-09 10:59 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-07-29 11:58 - 2013-05-09 10:59 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-07-29 11:58 - 2013-05-09 10:59 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-07-29 11:58 - 2013-05-09 10:59 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-07-29 11:57 - 2013-05-09 10:58 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-07-29 11:55 - 2013-07-29 11:55 - 00000000 ___RD C:\Users\DoppelAnton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2013-07-29 11:54 - 2013-07-29 11:54 - 00002739 _____ C:\Users\DoppelAnton\Desktop\gmer.txt 2013-07-29 10:59 - 2013-07-29 10:59 - 00377856 _____ C:\Users\DoppelAnton\Desktop\gmer_2.1.19163.exe 2013-07-29 07:41 - 2013-07-29 07:41 - 00049680 _____ C:\Users\DoppelAnton\Desktop\Extras.Txt 2013-07-29 07:40 - 2013-07-29 08:20 - 00104976 _____ C:\Users\DoppelAnton\Desktop\OTL.Txt 2013-07-29 07:32 - 2013-07-29 07:32 - 00602112 _____ (OldTimer Tools) C:\Users\DoppelAnton\Desktop\OTL.exe 2013-07-29 07:31 - 2013-07-29 07:31 - 00000484 _____ C:\Users\DoppelAnton\Desktop\defogger_disable.log 2013-07-29 07:31 - 2013-07-29 07:31 - 00000000 _____ C:\Users\DoppelAnton\defogger_reenable 2013-07-29 07:30 - 2013-07-29 07:30 - 00050477 _____ C:\Users\DoppelAnton\Desktop\Defogger.exe 2013-07-25 15:00 - 2013-07-25 15:02 - 00000000 ____D C:\Windows\system32\MRT 2013-07-21 01:26 - 2013-07-26 17:33 - 00000000 ____D C:\Users\DoppelAnton\Desktop\1st REVIEW ECOLOGY LETTERS 2013-07-20 01:18 - 2013-07-20 01:19 - 00575708 _____ C:\Users\DoppelAnton\Downloads\Fig.2.tif 2013-07-19 20:05 - 2013-07-19 20:07 - 00000000 ____D C:\Program Files (x86)\Dell Wireless 2013-07-19 20:04 - 2013-07-19 20:04 - 00000000 ____D C:\Windows\Options 2013-07-19 20:04 - 2011-05-25 23:18 - 00008090 _____ C:\Windows\system32\athrextx.cat 2013-07-19 20:04 - 2011-04-22 04:17 - 02727424 _____ (Atheros Communications, Inc.) C:\Windows\system32\Drivers\athrx.sys 2013-07-19 20:04 - 2011-04-22 04:17 - 02727424 _____ (Atheros Communications, Inc.) C:\Windows\system32\athrx.sys 2013-07-19 19:20 - 2013-07-19 19:20 - 00000000 __SHD C:\found.000 2013-07-19 18:55 - 2013-07-19 18:55 - 00000000 ____D C:\Windows\system32\appmgmt 2013-07-19 01:30 - 2013-07-29 12:03 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum 2013-07-19 01:30 - 2013-07-29 12:03 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum 2013-07-19 01:30 - 2013-07-29 12:03 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum 2013-07-18 15:55 - 2013-07-18 15:55 - 00000000 ____D C:\Users\DoppelAnton\AppData\Roaming\Apple Computer 2013-07-18 06:11 - 2013-07-18 06:11 - 00000000 ____D C:\Users\DOPPEL~1\AppData\Local\Apple 2013-07-18 06:10 - 2013-07-18 06:10 - 00000000 ____D C:\ProgramData\Apple 2013-07-18 05:48 - 2013-07-18 06:05 - 00000000 ____D C:\Users\DoppelAnton\Documents\Any Video Converter 2013-07-18 05:48 - 2013-07-18 05:48 - 00000000 ____D C:\Users\DoppelAnton\AppData\Roaming\AnvSoft 2013-07-14 01:08 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-07-14 01:08 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-07-14 01:08 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-07-14 01:08 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-07-14 01:08 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-07-14 01:08 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-07-14 01:08 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-07-14 01:08 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-07-14 01:08 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-07-14 01:08 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-07-14 01:08 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-07-14 01:08 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-07-14 01:08 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-14 01:08 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-14 01:08 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-14 01:08 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-14 01:08 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-14 01:08 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-14 01:08 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-14 01:08 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-14 01:08 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-14 01:08 - 2013-06-12 01:25 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-14 01:08 - 2013-06-12 01:25 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-14 01:08 - 2013-06-12 01:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-14 01:08 - 2013-06-12 01:25 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-14 01:08 - 2013-06-12 01:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-14 01:08 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-07-14 01:08 - 2013-06-12 00:50 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-07-14 01:08 - 2013-06-07 05:22 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-14 01:08 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-07-14 01:07 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-07-10 18:39 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-10 18:39 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2013-07-10 18:39 - 2013-05-06 08:03 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-10 18:39 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-07-10 18:28 - 2013-06-05 05:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-10 18:26 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-07-10 18:26 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-07-06 07:28 - 2013-07-06 07:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-07-02 03:23 - 2013-07-02 03:23 - 00008242 _____ C:\Users\DOPPEL~1\AppData\Local\recently-used.xbel 2013-06-29 21:40 - 2013-06-30 19:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 107 ==================== One Month Modified Files and Folders ======= 2013-07-29 12:46 - 2013-07-29 12:46 - 01780547 _____ (Farbar) C:\Users\DoppelAnton\Desktop\FRST64.exe 2013-07-29 12:46 - 2013-07-29 12:46 - 00000000 ____D C:\FRST 2013-07-29 12:45 - 2013-01-28 21:27 - 00000000 ____D C:\Neuinstallation_starter programme 2013-07-29 12:45 - 2013-01-28 21:18 - 00000000 ____D C:\Users\DoppelAnton\AppData\Roaming\Skype 2013-07-29 12:37 - 2013-07-29 12:37 - 00015318 _____ C:\Users\DoppelAnton\Desktop\OTL.zip 2013-07-29 12:08 - 2013-07-29 11:58 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-29 12:08 - 2013-07-29 11:58 - 00001116 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-29 12:04 - 2013-01-29 00:11 - 00654236 _____ C:\Windows\system32\perfh007.dat 2013-07-29 12:04 - 2013-01-29 00:11 - 00130076 _____ C:\Windows\system32\perfc007.dat 2013-07-29 12:04 - 2009-07-14 07:13 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI 2013-07-29 12:03 - 2013-07-29 11:58 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-07-29 12:03 - 2013-07-29 11:58 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-07-29 12:03 - 2013-07-29 11:58 - 00189936 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-07-29 12:03 - 2013-07-29 11:58 - 00004116 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-07-29 12:03 - 2013-07-29 11:58 - 00003864 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-07-29 12:03 - 2013-07-19 01:30 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum 2013-07-29 12:03 - 2013-07-19 01:30 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum 2013-07-29 12:03 - 2013-07-19 01:30 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum 2013-07-29 12:03 - 2013-03-15 10:41 - 00000000 ____D C:\Users\DoppelAnton\AppData\Roaming\Dropbox 2013-07-29 12:02 - 2013-03-15 10:42 - 00000000 ___RD C:\Users\DoppelAnton\Dropbox 2013-07-29 12:02 - 2009-07-14 06:45 - 00021312 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-29 12:02 - 2009-07-14 06:45 - 00021312 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-29 12:01 - 2013-01-29 15:48 - 00000268 _____ C:\Windows\Tasks\HP Photo Creations Messager.job 2013-07-29 11:58 - 2013-07-29 11:58 - 00003924 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-07-29 11:58 - 2013-01-28 21:32 - 00000000 ____D C:\Program Files (x86)\Google 2013-07-29 11:58 - 2013-01-28 21:32 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-07-29 11:57 - 2013-01-28 21:32 - 00000000 ____D C:\ProgramData\AVAST Software 2013-07-29 11:57 - 2013-01-28 21:32 - 00000000 ____D C:\Program Files\AVAST Software 2013-07-29 11:55 - 2013-07-29 11:55 - 00000000 ___RD C:\Users\DoppelAnton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2013-07-29 11:55 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-07-29 11:55 - 2009-07-14 06:51 - 00068265 _____ C:\Windows\setupact.log 2013-07-29 11:54 - 2013-07-29 11:54 - 00002739 _____ C:\Users\DoppelAnton\Desktop\gmer.txt 2013-07-29 11:54 - 2013-01-28 15:16 - 01095817 _____ C:\Windows\WindowsUpdate.log 2013-07-29 11:51 - 2013-02-03 21:55 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-29 11:15 - 2010-11-21 05:47 - 00052068 _____ C:\Windows\PFRO.log 2013-07-29 10:59 - 2013-07-29 10:59 - 00377856 _____ C:\Users\DoppelAnton\Desktop\gmer_2.1.19163.exe 2013-07-29 08:20 - 2013-07-29 07:40 - 00104976 _____ C:\Users\DoppelAnton\Desktop\OTL.Txt 2013-07-29 07:41 - 2013-07-29 07:41 - 00049680 _____ C:\Users\DoppelAnton\Desktop\Extras.Txt 2013-07-29 07:32 - 2013-07-29 07:32 - 00602112 _____ (OldTimer Tools) C:\Users\DoppelAnton\Desktop\OTL.exe 2013-07-29 07:31 - 2013-07-29 07:31 - 00000484 _____ C:\Users\DoppelAnton\Desktop\defogger_disable.log 2013-07-29 07:31 - 2013-07-29 07:31 - 00000000 _____ C:\Users\DoppelAnton\defogger_reenable 2013-07-29 07:31 - 2013-01-28 16:29 - 00000000 ____D C:\Users\DoppelAnton 2013-07-29 07:30 - 2013-07-29 07:30 - 00050477 _____ C:\Users\DoppelAnton\Desktop\Defogger.exe 2013-07-28 12:42 - 2013-01-29 18:00 - 00000000 ____D C:\Users\DoppelAnton\AppData\Roaming\vlc 2013-07-28 12:40 - 2013-02-17 22:37 - 00000000 ____D C:\Users\DoppelAnton\AppData\Roaming\dvdcss 2013-07-26 17:34 - 2013-01-29 17:51 - 00000000 ___RD C:\Users\DoppelAnton\Desktop\zeug 2013-07-26 17:33 - 2013-07-21 01:26 - 00000000 ____D C:\Users\DoppelAnton\Desktop\1st REVIEW ECOLOGY LETTERS 2013-07-26 14:25 - 2013-05-24 10:46 - 00000000 ____D C:\Users\DoppelAnton\Desktop\submission_SCISSI_paper 2013-07-25 15:02 - 2013-07-25 15:00 - 00000000 ____D C:\Windows\system32\MRT 2013-07-22 19:35 - 2013-06-25 17:39 - 00000000 ____D C:\Users\DoppelAnton\Desktop\RE_SUBM_ECOLLETT_Maas2013 2013-07-22 03:51 - 2013-06-14 14:42 - 00001755 _____ C:\Users\DoppelAnton\AppData\Roaming\WWB7_32.DAT 2013-07-21 20:00 - 2013-05-30 20:21 - 00000000 ____D C:\Users\DoppelAnton\Desktop\RAnalyse_Birds 2013-07-21 02:12 - 2013-05-26 14:06 - 00000000 ____D C:\Users\DoppelAnton\Desktop\alldata_NEW_BIRDpap 2013-07-20 01:19 - 2013-07-20 01:18 - 00575708 _____ C:\Users\DoppelAnton\Downloads\Fig.2.tif 2013-07-19 20:19 - 2013-01-28 21:17 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-07-19 20:19 - 2013-01-28 21:17 - 00000000 ____D C:\ProgramData\Skype 2013-07-19 20:07 - 2013-07-19 20:05 - 00000000 ____D C:\Program Files (x86)\Dell Wireless 2013-07-19 20:05 - 2011-05-20 19:07 - 00246804 _____ C:\Windows\system32\Drivers\AtherosBt.bin 2013-07-19 20:04 - 2013-07-19 20:04 - 00000000 ____D C:\Windows\Options 2013-07-19 20:04 - 2013-01-28 19:21 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-07-19 20:00 - 2013-01-28 21:11 - 00018752 _____ C:\Windows\DPINST.LOG 2013-07-19 19:20 - 2013-07-19 19:20 - 00000000 __SHD C:\found.000 2013-07-19 19:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF 2013-07-19 18:55 - 2013-07-19 18:55 - 00000000 ____D C:\Windows\system32\appmgmt 2013-07-19 18:44 - 2013-06-23 13:24 - 00000000 ____D C:\Users\DoppelAnton\Desktop\Maas_2013_HarvestPaper 2013-07-19 03:45 - 2013-01-28 19:23 - 00000000 ____D C:\Neuinstallation_Dell Treiber 2013-07-19 03:38 - 2013-05-24 08:32 - 00000000 ____D C:\Program Files (x86)\XingHaoLyrics 2013-07-19 00:59 - 2013-01-29 17:56 - 00000000 ____D C:\Users\DOPPEL~1\AppData\Local\CrashDumps 2013-07-18 15:55 - 2013-07-18 15:55 - 00000000 ____D C:\Users\DoppelAnton\AppData\Roaming\Apple Computer 2013-07-18 06:11 - 2013-07-18 06:11 - 00000000 ____D C:\Users\DOPPEL~1\AppData\Local\Apple 2013-07-18 06:10 - 2013-07-18 06:10 - 00000000 ____D C:\ProgramData\Apple 2013-07-18 06:05 - 2013-07-18 05:48 - 00000000 ____D C:\Users\DoppelAnton\Documents\Any Video Converter 2013-07-18 05:48 - 2013-07-18 05:48 - 00000000 ____D C:\Users\DoppelAnton\AppData\Roaming\AnvSoft 2013-07-14 01:50 - 2009-07-14 06:45 - 00400432 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-14 01:49 - 2010-11-21 09:17 - 00000000 ____D C:\Program Files\Windows Journal 2013-07-14 01:49 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender 2013-07-14 01:49 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2013-07-14 01:13 - 2013-01-29 15:04 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-07-07 19:04 - 2013-01-28 21:36 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-07-06 07:28 - 2013-07-06 07:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-07-02 03:23 - 2013-07-02 03:23 - 00008242 _____ C:\Users\DOPPEL~1\AppData\Local\recently-used.xbel 2013-07-01 22:16 - 2013-02-12 20:54 - 00000000 ____D C:\Users\DoppelAnton\Desktop\BIRDpap_alldata 2013-06-30 21:27 - 2013-03-14 13:14 - 00000000 ____D C:\Users\DoppelAnton\Desktop\STATISTICS 2013-06-30 19:12 - 2013-06-29 21:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-24 02:33 ==================== End Of Log ============================ [/CODE] 2. Addition File Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-07-2013 Ran by DoppelAnton at 2013-07-29 12:47:47 Running from C:\Users\DoppelAnton\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= 7-Zip 9.20 (x64 edition) (Version: 9.20.00.0) AccelerometerP11 (x32 Version: 2.00.10.21) Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.224) Adobe Premiere Pro (x32 Version: 7.0) Adobe Reader XI (11.0.03) - Deutsch (x32 Version: 11.0.03) Advanced Audio FX Engine (x32 Version: 1.12.05) Amazon Kindle (HKCU) ArcGIS Desktop Evaluation Edition (x32 Version: 9.3.3000) ATI Catalyst Install Manager (Version: 3.0.808.0) avast! Free Antivirus (x32 Version: 8.0.1489.0) Bing Bar (x32 Version: 7.1.391.0) Bluetooth Win7 Suite (64) (Version: 7.2.0.83) Bundled software uninstaller (x32) CDBurnerXP (x32 Version: 4.5.1.3868) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32) Dell Backup and Recovery Manager (Version: 1.3.1) Dell Mobile Broadband Manager (x32 Version: 6.1.24.2) Dell Resource CD (x32 Version: 1.00.0000) Dell Touchpad (Version: 15.2.5.2) Dell Webcam Central (x32 Version: 2.00.33) Dell WLAN and Bluetooth Client Installation (x32 Version: 9.0) Delta Chrome Toolbar (x32) Dropbox (HKCU Version: 2.0.22) eaner (Version: 3.27) EstimateS Win 8.20 (x32) Free WAV to MP3 Converter (x32) Free WMA to MP3 Converter 1.16 (x32) Ge org Internet Manager (x32 Version: 11.301.05.02.852) GIMP 2.8.2 (Version: 2.8.2) Google Update Helper (x32 Version: 1.3.21.153) HP Photo Creations (x32 Version: 1.0.0.5192) HP Photosmart 5510 series - Grundlegende Software für das Gerät (Version: 24.0.342.0) HP Photosmart 5510 series Hilfe (x32 Version: 140.0.2.2) HP Update (x32 Version: 5.003.000.004) IDT Audio (x32 Version: 1.0.6341.0) Inkscape 0.48.4 (x32 Version: 0.48.4) Intel(R) Control Center (x32 Version: 1.2.1.1007) Intel(R) Display Audio Driver (x32 Version: 6.14.00.3074) Intel(R) Management Engine Components (x32 Version: 7.0.0.1118) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (Version: 1.0.0.0454) Intel(R) Rapid Storage Technology (x32 Version: 10.1.0.1008) IrfanView (remove only) (x32 Version: 4.35) Java 7 Update 21 (x32 Version: 7.0.210) Java Auto Updater (x32 Version: 2.1.9.5) jetAudio Basic VX (x32 Version: 8.0.17) Logitech Unifying-Software 2.10 (Version: 2.10.37) LyricsPal (x32) Mendeley Desktop 1.7.1 (x32 Version: 1.7.1) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Office 2010 Service Pack 1 (SP1) (x32) Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Home and Student 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Office 64-bit Components 2010 (Version: 14.0.6029.1000) Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (English) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (French) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Single Image 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (x32 Version: 10.0.30319) MozBackup 1.5.1 (x32) Mozilla Firefox 22.0 (x86 de) (x32 Version: 22.0) Mozilla Maintenance Service (x32 Version: 22.0) Mozilla Thunderbird 17.0.7 (x86 de) (x32 Version: 17.0.7) MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0) PDF24 Creator 5.2.0 (x32) Python 2.5 numpy-1.0.3 (x32) Python 2.5.1 (x32) Quantum GIS Lisboa 1.8.0 Lisboa (x32 Version: 1.8.0-r${SVN_REVISION}-2) Quickset64 (Version: 10.09.25) R for Windows 2.15.2 (Version: 2.15.2) Ralink RT2870 Wireless LAN Card (x32 Version: 1.5.13.0) Realtek Ethernet Controller Driver (x32 Version: 7.31.1025.2010) Realtek USB 2.0 Card Reader (x32 Version: 6.1.7600.30126) Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.32.0) RStudio (x32 Version: 0.97.312) Skype™ 6.6 (x32 Version: 6.6.106) SoulSeek 157 NS 13e (x32) STATISTICA (x32 Version: 7.00.0000) Studie zur Verbesserung von HP Photosmart 5510 series Produkten (Version: 24.0.342.0) Total Commander 64-bit (Remove or Repair) (Version: 8.01) Überwachungstool für die Intel® Turbo-Boost-Technik 2.0 (Version: 2.1.23.0) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1) Update for Microsoft Office 2010 (KB2553065) (x32) Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2553378) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2566458) (x32) Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition (x32) Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition (x32) Update for Microsoft Outlook 2010 (KB2597090) 32-Bit Edition (x32) Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition (x32) Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition (x32) Update for Microsoft PowerPoint 2010 (KB2598240) 32-Bit Edition (x32) Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition (x32) Validity Sensors DDK (Version: 4.3.108.0) Visual Basic for Applications (R) Core - English (x32 Version: 6.5.10.32) Visual Basic for Applications (R) Core (x32 Version: 6.5.10.32) VLC media player 2.0.6 (Version: 2.0.6) WAV To MP3 V2 (x32) ==================== Restore Points ========================= 23-07-2013 20:06:41 Windows Update 26-07-2013 21:00:12 Windows Update 29-07-2013 09:13:54 avast! Free Antivirus Setup 29-07-2013 09:57:13 avast! Free Antivirus Setup ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {14B28B77-69A6-449F-B24C-A1EEE975F5B8} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-29] (Google Inc.) Task: {19B9606A-7689-4982-A6E0-942504E89EFF} - System32\Tasks\HP Photo Creations Messager => C:\ProgramData\HP Photo Creations\MessageCheck.exe [2011-02-15] () Task: {2C0AEC4F-7BE9-43C8-AADC-D900DE799769} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-01-23] (Piriform Ltd) Task: {2E62A6B3-7AC2-4966-9CDB-A4F8DD598092} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-05-09] (AVAST Software) Task: {3BCAF203-11DD-469A-80D1-D84386273DB2} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {8664EB7C-8733-4B61-BE25-3D512B0CFE61} - System32\Tasks\EPUpdater => C:\Users\DOPPEL~1\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe [2013-05-09] () Task: {A237C9D7-75C9-48C3-AC4C-2A9ABCF586A4} - System32\Tasks\{B637BD52-4E7B-428C-B367-32AD767718D6} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2013-06-21] (Skype Technologies S.A.) Task: {BAE3731F-538B-4894-84D3-4DB78723243F} - System32\Tasks\HPCustParticipation HP Photosmart 5510 series => C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPCustPartic.exe [2011-05-25] (Hewlett-Packard Co.) Task: {CB558070-015F-4F84-BF57-DCA1D8D85320} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-12] (Adobe Systems Incorporated) Task: {D8B1A9F1-6CD1-4320-8134-40622EAAF32E} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2010-11-21] (Microsoft Corporation) Task: {EEDD5C87-9B7E-48E6-B564-33E4D8FE9235} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-29] (Google Inc.) Task: {F76F2988-BB54-4F2A-A93C-7512F6345C57} - System32\Tasks\{00375640-5A9D-48B8-93A2-E714CEC2C3AA} => C:\Users\DoppelAnton\AppData\Roaming\Dropbox\bin\Dropbox.exe [2013-05-25] (Dropbox, Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\HP Photo Creations Messager.job => C:\ProgramData\HP Photo Creations\MessageCheck.exe ==================== Faulty Device Manager Devices ============= Name: Bluetooth Server Description: Bluetooth Server Class Guid: {34446e8e-37b4-4b16-9da6-bea2db33465a} Manufacturer: Intel Corporation Service: btmaux Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (07/29/2013 11:55:30 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/29/2013 11:15:47 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/28/2013 03:10:00 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "x64" des "processorArchitecture"-Attributs im assemblyIdentity-Element ist ungültig. Error: (07/28/2013 01:15:22 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/28/2013 01:12:46 AM) (Source: Application Hang) (User: ) Description: Programm JetAudio.exe, Version 8.0.17.2010 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1468 Startzeit: 01ce8b13cb06a726 Endzeit: 60000 Anwendungspfad: C:\Program Files (x86)\JetAudio\JetAudio.exe Berichts-ID: cc06baf3-f711-11e2-9720-3859f93b766e Error: (07/27/2013 08:36:20 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "x64" des "processorArchitecture"-Attributs im assemblyIdentity-Element ist ungültig. Error: (07/27/2013 07:47:44 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "x64" des "processorArchitecture"-Attributs im assemblyIdentity-Element ist ungültig. Error: (07/26/2013 01:26:10 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/26/2013 03:39:14 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/25/2013 03:00:17 PM) (Source: System Restore) (User: ) Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\Windows\system32\svchost.exe -k netsvcs; Beschreibung = Windows Update; Fehler = 0x81000101). System errors: ============= Error: (07/29/2013 11:55:03 AM) (Source: Application Popup) (User: ) Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\drivers\pfc.sys nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error: (07/29/2013 11:15:16 AM) (Source: Application Popup) (User: ) Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\drivers\pfc.sys nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error: (07/29/2013 09:58:28 AM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. Error: (07/29/2013 09:58:28 AM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. Error: (07/29/2013 09:58:27 AM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. Error: (07/29/2013 09:58:26 AM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. Error: (07/29/2013 09:58:25 AM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. Error: (07/29/2013 09:58:25 AM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. Error: (07/29/2013 09:58:24 AM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. Error: (07/29/2013 09:58:24 AM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. Microsoft Office Sessions: ========================= Error: (07/29/2013 11:55:30 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/29/2013 11:15:47 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/28/2013 03:10:00 AM) (Source: SideBySide)(User: ) Description: assemblyIdentityprocessorArchitecturex64c:\program files\R\r-2.15.2\Tcl\bin64\tk85.dllc:\program files\R\r-2.15.2\Tcl\bin64\tk85.dll9 Error: (07/28/2013 01:15:22 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/28/2013 01:12:46 AM) (Source: Application Hang)(User: ) Description: JetAudio.exe8.0.17.2010146801ce8b13cb06a72660000C:\Program Files (x86)\JetAudio\JetAudio.execc06baf3-f711-11e2-9720-3859f93b766e Error: (07/27/2013 08:36:20 AM) (Source: SideBySide)(User: ) Description: assemblyIdentityprocessorArchitecturex64c:\program files\R\r-2.15.2\Tcl\bin64\tk85.dllc:\program files\R\r-2.15.2\Tcl\bin64\tk85.dll9 Error: (07/27/2013 07:47:44 AM) (Source: SideBySide)(User: ) Description: assemblyIdentityprocessorArchitecturex64c:\program files\R\r-2.15.2\Tcl\bin64\tk85.dllc:\program files\R\r-2.15.2\Tcl\bin64\tk85.dll9 Error: (07/26/2013 01:26:10 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/26/2013 03:39:14 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/25/2013 03:00:17 PM) (Source: System Restore)(User: ) Description: C:\Windows\system32\svchost.exe -k netsvcsWindows Update0x81000101 ==================== Memory info =========================== Percentage of memory in use: 40% Total physical RAM: 6051.18 MB Available physical RAM: 3585.78 MB Total Pagefile: 12100.54 MB Available Pagefile: 9485.53 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: (System) (Fixed) (Total:100.1 GB) (Free:18.63 GB) NTFS (Disk=0 Partition=2) Drive d: (BACKUP files) (Fixed) (Total:249.02 GB) (Free:191.96 GB) NTFS (Disk=0 Partition=3) Drive e: (Data and PhD) (Fixed) (Total:249.02 GB) (Free:125.75 GB) NTFS (Disk=0 Partition=4) Drive g: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS (Disk=0 Partition=1) ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 699 GB) (Disk ID: 3D500F99) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=100 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=249 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=249 GB) - (Type=07 NTFS) ==================== End Of Log ============================ bea |
29.07.2013, 15:16 | #4 |
/// the machine /// TB-Ausbilder | Avast häufige Meldung "bösartige Website gefunden" (nach voherigen PC Problemen) Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
29.07.2013, 23:38 | #5 |
| Avast häufige Meldung "bösartige Website gefunden" (nach voherigen PC Problemen) Hi, hier die drei Files: 1. Adw Cleaner AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v2.306 - Datei am 29/07/2013 um 16:56:09 erstellt # Aktualisiert am 19/07/2013 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzer : DoppelAnton - DOPPELANTON-PC # Bootmodus : Normal # Ausgeführt unter : C:\Users\DoppelAnton\Desktop\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** Datei Gelöscht : C:\Users\DoppelAnton\AppData\Roaming\Mozilla\Firefox\Profiles\58iu00y1.default\searchplugins\Askcom.xml Datei Gelöscht : C:\Users\DoppelAnton\AppData\Roaming\Mozilla\Firefox\Profiles\58iu00y1.default\searchplugins\Babylon.xml Datei Gelöscht : C:\Users\DoppelAnton\AppData\Roaming\Mozilla\Firefox\Profiles\58iu00y1.default\searchplugins\delta.xml Datei Gelöscht : C:\Users\DoppelAnton\AppData\Roaming\Mozilla\Firefox\Profiles\58iu00y1.default\searchplugins\SweetIm.xml Ordner Gelöscht : C:\Program Files (x86)\XingHaoLyrics Ordner Gelöscht : C:\ProgramData\Ask Ordner Gelöscht : C:\ProgramData\Babylon Ordner Gelöscht : C:\Users\DOPPEL~1\AppData\Local\Temp\OCS Ordner Gelöscht : C:\Users\DoppelAnton\AppData\Roaming\BabSolution Ordner Gelöscht : C:\Users\DoppelAnton\AppData\Roaming\Babylon ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\XingHaoLyrics Schlüssel Gelöscht : HKCU\Software\BabSolution Schlüssel Gelöscht : HKCU\Software\BI Schlüssel Gelöscht : HKCU\Software\DataMngr Schlüssel Gelöscht : HKCU\Software\DataMngr_Toolbar Schlüssel Gelöscht : HKCU\Software\delta LTD Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A3DAEB01-4C15-4AC6-A689-6406FD954EE0} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A3DAEB01-4C15-4AC6-A689-6406FD954EE0} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKCU\Software\522d6dbb13fee49 Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Schlüssel Gelöscht : HKLM\Software\Babylon Schlüssel Gelöscht : HKLM\Software\BabylonToolbar Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\90C64EA18BA25EE488BF80DCF07F2FFD Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\90C64EA18BA25EE488BF80DCF07F2FFD Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap Schlüssel Gelöscht : HKLM\Software\DataMngr Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\522d6dbb13fee49 Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A3DAEB01-4C15-4AC6-A689-6406FD954EE0} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eooncjejnppfjjklapaamhcdmjbilmde Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1AE46C09-2AB8-4EE5-88FB-08CD0FF7F2DF} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\bi_uninstaller Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Delta Chrome Toolbar Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\lrcspal@xinghao.net Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}] Wert Gelöscht : HKCU\Software\Mozilla\Firefox\extensions [lrcspal@xinghao.net] Wert Gelöscht : HKLM\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist [1] ***** [Internet Browser] ***** -\\ Internet Explorer v10.0.9200.16635 [OK] Die Registrierungsdatenbank ist sauber. -\\ Mozilla Firefox v22.0 (de) Datei : C:\Users\DoppelAnton\AppData\Roaming\Mozilla\Firefox\Profiles\58iu00y1.default\prefs.js C:\Users\DoppelAnton\AppData\Roaming\Mozilla\Firefox\Profiles\58iu00y1.default\user.js ... Gelöscht ! [OK] Die Datei ist sauber. ************************* AdwCleaner[S1].txt - [4266 octets] - [29/07/2013 16:56:09] ########## EOF - C:\AdwCleaner[S1].txt - [4326 octets] ########## [/CODE] 2. JRT File Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 5.2.7 (07.29.2013:1) OS: Windows 7 Professional x64 Ran by DoppelAnton on 29.07.2013 at 23:02:17,19 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{30133017-D648-4850-93E9-087DDC3EAA87} ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\DoppelAnton\AppData\Roaming\mozilla\firefox\profiles\58iu00y1.default\minidumps [81 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 29.07.2013 at 23:08:09,49 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-07-2013 Ran by DoppelAnton (administrator) on 30-07-2013 00:31:45 Running from C:\Users\DoppelAnton\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe (Validity Sensors, Inc.) C:\Windows\system32\vcsFPService.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe (Atheros) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\Ath_CoexAgent.exe (Atheros Commnucations) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\adminservice.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe () C:\ProgramData\DatacardService\HWDeviceService64.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe () C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Atheros Communications) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Atheros Commnucations) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\AthBtTray.exe (Ericsson AB) C:\Program Files (x86)\Dell\Dell Mobile Broadband Manager\WirelessManager.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Huawei Technologies Co., Ltd.) C:\Users\DoppelAnton\AppData\Roaming\Ge org Internet Manager\ouc.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Dropbox, Inc.) C:\Users\DoppelAnton\AppData\Roaming\Dropbox\bin\Dropbox.exe (Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [FreeFallProtection] - C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe [686704 2010-12-15] () HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1128448 2011-05-27] (IDT, Inc.) HKLM\...\Run: [QuickSet] - C:\Program Files\Dell\QuickSet\QuickSet.exe [3668336 2011-03-24] (Dell Inc.) HKLM\...\Run: [BTMTrayAgent] - rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp [x] HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2480936 2010-12-15] (Synaptics Incorporated) HKLM\...\Run: [IntelTBRunOnce] - C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs [4526 2010-11-29] () HKLM\...\Run: [AtherosBtStack] - C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe [627360 2011-05-20] (Atheros Communications) HKLM\...\Run: [AthBtTray] - C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\AthBtTray.exe [379552 2011-05-20] (Atheros Commnucations) HKCU\...\Run: [WirelessManager] - C:\Program Files (x86)\Dell\Dell Mobile Broadband Manager\WirelessManager.exe [194600 2010-07-28] (Ericsson AB) HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.) HKCU\...\Run: [HW_OPENEYE_OUC_Ge org Internet Manager] - C:\Program Files (x86)\Ge org Internet Manager\UpdateDog\ouc.exe [110592 2009-12-31] (Huawei Technologies Co., Ltd.) MountPoints2: {49674710-d1bf-11e2-98ae-3859f93b766e} - H:\AutoRun.exe MountPoints2: {49674723-d1bf-11e2-98ae-3859f93b766e} - H:\AutoRun.exe MountPoints2: {6f94f44b-694c-11e2-921e-806e6f6e6963} - F:\autoRcd.exe MountPoints2: {e2470b43-6d64-11e2-bba2-3859f93b766e} - I:\HTC_Sync_Manager_PC.exe HKLM-x32\...\Run: [NUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-06] (Intel Corporation) HKLM-x32\...\Run: [Dell Webcam Central] - C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [487561 2010-08-11] (Creative Technology Ltd) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-03-24] (Hewlett-Packard) HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [163000 2012-12-12] (Geek Software GmbH) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [DataCardMonitor] - C:\Program Files (x86)\Ge org Internet Manager\DataCardMonitor.exe [253952 2013-06-12] (Huawei Technologies Co., Ltd.) HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software) Startup: C:\Users\DoppelAnton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\DoppelAnton\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\DoppelAnton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) Startup: C:\Users\DoppelAnton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Photosmart 5510 series.lnk ShortcutTarget: Tintenwarnungen überwachen - HP Photosmart 5510 series.lnk -> C:\Program Files\HP\HP Photosmart 5510 series\bin\HPStatusBL.dll (Hewlett-Packard Co.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.dell.com HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com SearchScopes: HKLM - DefaultScope value is missing. BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\DoppelAnton\AppData\Roaming\Mozilla\Firefox\Profiles\58iu00y1.default FF NewTab: hxxp://www.google.com/firefox FF SelectedSearchEngine: Google FF Homepage: hxxp://www.google.com/firefox FF Keyword.URL: hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.0.6 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Extension: adblockpopups - C:\Users\DoppelAnton\AppData\Roaming\Mozilla\Firefox\Profiles\58iu00y1.default\Extensions\adblockpopups@jessehakanen.net.xpi FF Extension: zotero - C:\Users\DoppelAnton\AppData\Roaming\Mozilla\Firefox\Profiles\58iu00y1.default\Extensions\zotero@chnm.gmu.edu.xpi FF Extension: No Name - C:\Users\DoppelAnton\AppData\Roaming\Mozilla\Firefox\Profiles\58iu00y1.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM-x32\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] C:\Program Files\T-Mobile\InternetManager_H\OCx64\addon FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF ==================== Services (Whitelisted) ================= R2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\Ath_CoexAgent.exe [146592 2011-05-20] (Atheros) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software) R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [339456 2010-11-16] () ==================== Drivers (Whitelisted) ==================== R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-07-29] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-07-29] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-07-29] () R0 BMLoad; C:\Windows\System32\drivers\BMLoad.sys [16512 2009-12-15] (Bytemobile, Inc.) S3 pfc; C:\Windows\SysWow64\drivers\pfc.sys [14604 2003-08-11] (Padus, Inc.) R1 tcpipBM; C:\Windows\system32\drivers\tcpipBM.sys [39552 2009-12-15] (Bytemobile, Inc.) R1 tcpipBM; C:\Windows\system32\drivers\tcpipBM.sys [39552 2009-12-15] (Bytemobile, Inc.) S3 pfc; system32\drivers\pfc.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-29 23:02 - 2013-07-29 23:02 - 00000000 ____D C:\Windows\ERUNT 2013-07-29 17:03 - 2013-07-29 17:03 - 00562353 _____ (Oleg N. Scherbakov) C:\Users\DoppelAnton\Desktop\JRT.exe 2013-07-29 17:00 - 2013-07-29 17:00 - 00004391 _____ C:\Users\DoppelAnton\Desktop\AdwCleaner[S1].txt 2013-07-29 16:58 - 2013-07-29 16:58 - 00000000 ___RD C:\Users\DoppelAnton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2013-07-29 16:56 - 2013-07-29 16:56 - 00004391 _____ C:\AdwCleaner[S1].txt 2013-07-29 16:52 - 2013-07-29 16:52 - 00666633 _____ C:\Users\DoppelAnton\Desktop\adwcleaner.exe 2013-07-29 12:47 - 2013-07-29 12:47 - 00019222 _____ C:\Users\DoppelAnton\Desktop\Addition.txt 2013-07-29 12:46 - 2013-07-29 12:46 - 01780547 _____ (Farbar) C:\Users\DoppelAnton\Desktop\FRST64.exe 2013-07-29 12:46 - 2013-07-29 12:46 - 00000000 ____D C:\FRST 2013-07-29 12:37 - 2013-07-29 12:37 - 00015318 _____ C:\Users\DoppelAnton\Desktop\OTL.zip 2013-07-29 11:58 - 2013-07-30 00:26 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-29 11:58 - 2013-07-29 16:58 - 00001116 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-29 11:58 - 2013-07-29 12:03 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-07-29 11:58 - 2013-07-29 12:03 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-07-29 11:58 - 2013-07-29 12:03 - 00189936 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-07-29 11:58 - 2013-07-29 12:03 - 00004116 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-07-29 11:58 - 2013-07-29 12:03 - 00003864 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-07-29 11:58 - 2013-07-29 11:58 - 00003924 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-07-29 11:58 - 2013-05-09 10:59 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-07-29 11:58 - 2013-05-09 10:59 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-07-29 11:58 - 2013-05-09 10:59 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-07-29 11:58 - 2013-05-09 10:59 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-07-29 11:58 - 2013-05-09 10:59 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-07-29 11:57 - 2013-05-09 10:58 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-07-29 11:54 - 2013-07-29 11:54 - 00002739 _____ C:\Users\DoppelAnton\Desktop\gmer.txt 2013-07-29 10:59 - 2013-07-29 10:59 - 00377856 _____ C:\Users\DoppelAnton\Desktop\gmer_2.1.19163.exe 2013-07-29 07:41 - 2013-07-29 07:41 - 00049680 _____ C:\Users\DoppelAnton\Desktop\Extras.Txt 2013-07-29 07:40 - 2013-07-29 08:20 - 00104976 _____ C:\Users\DoppelAnton\Desktop\OTL.Txt 2013-07-29 07:32 - 2013-07-29 07:32 - 00602112 _____ (OldTimer Tools) C:\Users\DoppelAnton\Desktop\OTL.exe 2013-07-29 07:31 - 2013-07-29 07:31 - 00000484 _____ C:\Users\DoppelAnton\Desktop\defogger_disable.log 2013-07-29 07:31 - 2013-07-29 07:31 - 00000000 _____ C:\Users\DoppelAnton\defogger_reenable 2013-07-29 07:30 - 2013-07-29 07:30 - 00050477 _____ C:\Users\DoppelAnton\Desktop\Defogger.exe 2013-07-25 15:00 - 2013-07-25 15:02 - 00000000 ____D C:\Windows\system32\MRT 2013-07-21 01:26 - 2013-07-29 15:45 - 00000000 ____D C:\Users\DoppelAnton\Desktop\1st REVIEW ECOLOGY LETTERS 2013-07-20 01:18 - 2013-07-20 01:19 - 00575708 _____ C:\Users\DoppelAnton\Downloads\Fig.2.tif 2013-07-19 20:05 - 2013-07-19 20:07 - 00000000 ____D C:\Program Files (x86)\Dell Wireless 2013-07-19 20:04 - 2013-07-19 20:04 - 00000000 ____D C:\Windows\Options 2013-07-19 20:04 - 2011-05-25 23:18 - 00008090 _____ C:\Windows\system32\athrextx.cat 2013-07-19 20:04 - 2011-04-22 04:17 - 02727424 _____ (Atheros Communications, Inc.) C:\Windows\system32\Drivers\athrx.sys 2013-07-19 20:04 - 2011-04-22 04:17 - 02727424 _____ (Atheros Communications, Inc.) C:\Windows\system32\athrx.sys 2013-07-19 19:20 - 2013-07-19 19:20 - 00000000 __SHD C:\found.000 2013-07-19 18:55 - 2013-07-19 18:55 - 00000000 ____D C:\Windows\system32\appmgmt 2013-07-19 01:30 - 2013-07-29 12:03 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum 2013-07-19 01:30 - 2013-07-29 12:03 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum 2013-07-19 01:30 - 2013-07-29 12:03 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum 2013-07-18 15:55 - 2013-07-18 15:55 - 00000000 ____D C:\Users\DoppelAnton\AppData\Roaming\Apple Computer 2013-07-18 06:11 - 2013-07-18 06:11 - 00000000 ____D C:\Users\DOPPEL~1\AppData\Local\Apple 2013-07-18 06:10 - 2013-07-18 06:10 - 00000000 ____D C:\ProgramData\Apple 2013-07-18 05:48 - 2013-07-18 06:05 - 00000000 ____D C:\Users\DoppelAnton\Documents\Any Video Converter 2013-07-18 05:48 - 2013-07-18 05:48 - 00000000 ____D C:\Users\DoppelAnton\AppData\Roaming\AnvSoft 2013-07-14 01:08 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-07-14 01:08 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-07-14 01:08 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-07-14 01:08 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-07-14 01:08 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-07-14 01:08 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-07-14 01:08 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-07-14 01:08 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-07-14 01:08 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-07-14 01:08 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-07-14 01:08 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-07-14 01:08 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-07-14 01:08 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-14 01:08 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-14 01:08 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-14 01:08 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-14 01:08 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-14 01:08 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-14 01:08 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-14 01:08 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-14 01:08 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-14 01:08 - 2013-06-12 01:25 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-14 01:08 - 2013-06-12 01:25 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-14 01:08 - 2013-06-12 01:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-14 01:08 - 2013-06-12 01:25 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-14 01:08 - 2013-06-12 01:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-14 01:08 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-07-14 01:08 - 2013-06-12 00:50 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-07-14 01:08 - 2013-06-07 05:22 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-14 01:08 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-07-14 01:07 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-07-10 18:39 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-10 18:39 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2013-07-10 18:39 - 2013-05-06 08:03 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-10 18:39 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-07-10 18:28 - 2013-06-05 05:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-10 18:26 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-07-10 18:26 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-07-06 07:28 - 2013-07-06 07:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-07-02 03:23 - 2013-07-02 03:23 - 00008242 _____ C:\Users\DOPPEL~1\AppData\Local\recently-used.xbel 113 ==================== One Month Modified Files and Folders ======= 2013-07-30 00:27 - 2013-01-29 00:11 - 00654236 _____ C:\Windows\system32\perfh007.dat 2013-07-30 00:27 - 2013-01-29 00:11 - 00130076 _____ C:\Windows\system32\perfc007.dat 2013-07-30 00:27 - 2013-01-28 15:16 - 01182909 _____ C:\Windows\WindowsUpdate.log 2013-07-30 00:27 - 2009-07-14 07:13 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI 2013-07-30 00:26 - 2013-07-29 23:08 - 00000916 _____ C:\Users\DoppelAnton\Desktop\JRT.txt 2013-07-30 00:26 - 2013-07-29 11:58 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-30 00:26 - 2013-02-03 21:55 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-30 00:26 - 2013-01-29 15:48 - 00000268 _____ C:\Windows\Tasks\HP Photo Creations Messager.job 2013-07-29 23:02 - 2013-07-29 23:02 - 00000000 ____D C:\Windows\ERUNT 2013-07-29 23:01 - 2013-01-28 21:18 - 00000000 ____D C:\Users\DoppelAnton\AppData\Roaming\Skype 2013-07-29 17:04 - 2009-07-14 06:45 - 00021312 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-29 17:04 - 2009-07-14 06:45 - 00021312 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-29 17:03 - 2013-07-29 17:03 - 00562353 _____ (Oleg N. Scherbakov) C:\Users\DoppelAnton\Desktop\JRT.exe 2013-07-29 17:02 - 2013-03-15 10:42 - 00000000 ___RD C:\Users\DoppelAnton\Dropbox 2013-07-29 17:02 - 2013-03-15 10:41 - 00000000 ____D C:\Users\DoppelAnton\AppData\Roaming\Dropbox 2013-07-29 17:00 - 2013-07-29 17:00 - 00004391 _____ C:\Users\DoppelAnton\Desktop\AdwCleaner[S1].txt 2013-07-29 16:58 - 2013-07-29 16:58 - 00000000 ___RD C:\Users\DoppelAnton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2013-07-29 16:58 - 2013-07-29 11:58 - 00001116 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-29 16:57 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-07-29 16:57 - 2009-07-14 06:51 - 00068321 _____ C:\Windows\setupact.log 2013-07-29 16:56 - 2013-07-29 16:56 - 00004391 _____ C:\AdwCleaner[S1].txt 2013-07-29 16:52 - 2013-07-29 16:52 - 00666633 _____ C:\Users\DoppelAnton\Desktop\adwcleaner.exe 2013-07-29 15:45 - 2013-07-21 01:26 - 00000000 ____D C:\Users\DoppelAnton\Desktop\1st REVIEW ECOLOGY LETTERS 2013-07-29 12:47 - 2013-07-29 12:47 - 00019222 _____ C:\Users\DoppelAnton\Desktop\Addition.txt 2013-07-29 12:46 - 2013-07-29 12:46 - 01780547 _____ (Farbar) C:\Users\DoppelAnton\Desktop\FRST64.exe 2013-07-29 12:46 - 2013-07-29 12:46 - 00000000 ____D C:\FRST 2013-07-29 12:45 - 2013-01-28 21:27 - 00000000 ____D C:\Neuinstallation_starter programme 2013-07-29 12:37 - 2013-07-29 12:37 - 00015318 _____ C:\Users\DoppelAnton\Desktop\OTL.zip 2013-07-29 12:03 - 2013-07-29 11:58 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-07-29 12:03 - 2013-07-29 11:58 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-07-29 12:03 - 2013-07-29 11:58 - 00189936 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-07-29 12:03 - 2013-07-29 11:58 - 00004116 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-07-29 12:03 - 2013-07-29 11:58 - 00003864 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-07-29 12:03 - 2013-07-19 01:30 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum 2013-07-29 12:03 - 2013-07-19 01:30 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum 2013-07-29 12:03 - 2013-07-19 01:30 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum 2013-07-29 11:58 - 2013-07-29 11:58 - 00003924 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-07-29 11:58 - 2013-01-28 21:32 - 00000000 ____D C:\Program Files (x86)\Google 2013-07-29 11:58 - 2013-01-28 21:32 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-07-29 11:57 - 2013-01-28 21:32 - 00000000 ____D C:\ProgramData\AVAST Software 2013-07-29 11:57 - 2013-01-28 21:32 - 00000000 ____D C:\Program Files\AVAST Software 2013-07-29 11:54 - 2013-07-29 11:54 - 00002739 _____ C:\Users\DoppelAnton\Desktop\gmer.txt 2013-07-29 11:15 - 2010-11-21 05:47 - 00052068 _____ C:\Windows\PFRO.log 2013-07-29 10:59 - 2013-07-29 10:59 - 00377856 _____ C:\Users\DoppelAnton\Desktop\gmer_2.1.19163.exe 2013-07-29 08:20 - 2013-07-29 07:40 - 00104976 _____ C:\Users\DoppelAnton\Desktop\OTL.Txt 2013-07-29 07:41 - 2013-07-29 07:41 - 00049680 _____ C:\Users\DoppelAnton\Desktop\Extras.Txt 2013-07-29 07:32 - 2013-07-29 07:32 - 00602112 _____ (OldTimer Tools) C:\Users\DoppelAnton\Desktop\OTL.exe 2013-07-29 07:31 - 2013-07-29 07:31 - 00000484 _____ C:\Users\DoppelAnton\Desktop\defogger_disable.log 2013-07-29 07:31 - 2013-07-29 07:31 - 00000000 _____ C:\Users\DoppelAnton\defogger_reenable 2013-07-29 07:31 - 2013-01-28 16:29 - 00000000 ____D C:\Users\DoppelAnton 2013-07-29 07:30 - 2013-07-29 07:30 - 00050477 _____ C:\Users\DoppelAnton\Desktop\Defogger.exe 2013-07-28 12:42 - 2013-01-29 18:00 - 00000000 ____D C:\Users\DoppelAnton\AppData\Roaming\vlc 2013-07-28 12:40 - 2013-02-17 22:37 - 00000000 ____D C:\Users\DoppelAnton\AppData\Roaming\dvdcss 2013-07-26 17:34 - 2013-01-29 17:51 - 00000000 ___RD C:\Users\DoppelAnton\Desktop\zeug 2013-07-26 14:25 - 2013-05-24 10:46 - 00000000 ____D C:\Users\DoppelAnton\Desktop\submission_SCISSI_paper 2013-07-25 15:02 - 2013-07-25 15:00 - 00000000 ____D C:\Windows\system32\MRT 2013-07-22 19:35 - 2013-06-25 17:39 - 00000000 ____D C:\Users\DoppelAnton\Desktop\RE_SUBM_ECOLLETT_Maas2013 2013-07-22 03:51 - 2013-06-14 14:42 - 00001755 _____ C:\Users\DoppelAnton\AppData\Roaming\WWB7_32.DAT 2013-07-21 20:00 - 2013-05-30 20:21 - 00000000 ____D C:\Users\DoppelAnton\Desktop\RAnalyse_Birds 2013-07-21 02:12 - 2013-05-26 14:06 - 00000000 ____D C:\Users\DoppelAnton\Desktop\alldata_NEW_BIRDpap 2013-07-20 01:19 - 2013-07-20 01:18 - 00575708 _____ C:\Users\DoppelAnton\Downloads\Fig.2.tif 2013-07-19 20:19 - 2013-01-28 21:17 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-07-19 20:19 - 2013-01-28 21:17 - 00000000 ____D C:\ProgramData\Skype 2013-07-19 20:07 - 2013-07-19 20:05 - 00000000 ____D C:\Program Files (x86)\Dell Wireless 2013-07-19 20:05 - 2011-05-20 19:07 - 00246804 _____ C:\Windows\system32\Drivers\AtherosBt.bin 2013-07-19 20:04 - 2013-07-19 20:04 - 00000000 ____D C:\Windows\Options 2013-07-19 20:04 - 2013-01-28 19:21 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-07-19 20:00 - 2013-01-28 21:11 - 00018752 _____ C:\Windows\DPINST.LOG 2013-07-19 19:20 - 2013-07-19 19:20 - 00000000 __SHD C:\found.000 2013-07-19 19:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF 2013-07-19 18:55 - 2013-07-19 18:55 - 00000000 ____D C:\Windows\system32\appmgmt 2013-07-19 18:44 - 2013-06-23 13:24 - 00000000 ____D C:\Users\DoppelAnton\Desktop\Maas_2013_HarvestPaper 2013-07-19 03:45 - 2013-01-28 19:23 - 00000000 ____D C:\Neuinstallation_Dell Treiber 2013-07-19 00:59 - 2013-01-29 17:56 - 00000000 ____D C:\Users\DOPPEL~1\AppData\Local\CrashDumps 2013-07-18 15:55 - 2013-07-18 15:55 - 00000000 ____D C:\Users\DoppelAnton\AppData\Roaming\Apple Computer 2013-07-18 06:11 - 2013-07-18 06:11 - 00000000 ____D C:\Users\DOPPEL~1\AppData\Local\Apple 2013-07-18 06:10 - 2013-07-18 06:10 - 00000000 ____D C:\ProgramData\Apple 2013-07-18 06:05 - 2013-07-18 05:48 - 00000000 ____D C:\Users\DoppelAnton\Documents\Any Video Converter 2013-07-18 05:48 - 2013-07-18 05:48 - 00000000 ____D C:\Users\DoppelAnton\AppData\Roaming\AnvSoft 2013-07-14 01:50 - 2009-07-14 06:45 - 00400432 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-14 01:49 - 2010-11-21 09:17 - 00000000 ____D C:\Program Files\Windows Journal 2013-07-14 01:49 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender 2013-07-14 01:49 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2013-07-14 01:13 - 2013-01-29 15:04 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-07-07 19:04 - 2013-01-28 21:36 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-07-06 07:28 - 2013-07-06 07:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-07-02 03:23 - 2013-07-02 03:23 - 00008242 _____ C:\Users\DOPPEL~1\AppData\Local\recently-used.xbel 2013-07-01 22:16 - 2013-02-12 20:54 - 00000000 ____D C:\Users\DoppelAnton\Desktop\BIRDpap_alldata 2013-06-30 21:27 - 2013-03-14 13:14 - 00000000 ____D C:\Users\DoppelAnton\Desktop\STATISTICS 2013-06-30 19:12 - 2013-06-29 21:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-24 02:33 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-07-2013 Ran by DoppelAnton at 2013-07-30 00:32:17 Running from C:\Users\DoppelAnton\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= 7-Zip 9.20 (x64 edition) (Version: 9.20.00.0) AccelerometerP11 (x32 Version: 2.00.10.21) Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.224) Adobe Premiere Pro (x32 Version: 7.0) Adobe Reader XI (11.0.03) - Deutsch (x32 Version: 11.0.03) Advanced Audio FX Engine (x32 Version: 1.12.05) Amazon Kindle (HKCU) ArcGIS Desktop Evaluation Edition (x32 Version: 9.3.3000) ATI Catalyst Install Manager (Version: 3.0.808.0) avast! Free Antivirus (x32 Version: 8.0.1489.0) Bluetooth Win7 Suite (64) (Version: 7.2.0.83) CDBurnerXP (x32 Version: 4.5.1.3868) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32) Dell Backup and Recovery Manager (Version: 1.3.1) Dell Mobile Broadband Manager (x32 Version: 6.1.24.2) Dell Resource CD (x32 Version: 1.00.0000) Dell Touchpad (Version: 15.2.5.2) Dell Webcam Central (x32 Version: 2.00.33) Dell WLAN and Bluetooth Client Installation (x32 Version: 9.0) Dropbox (HKCU Version: 2.0.22) eaner (Version: 3.27) EstimateS Win 8.20 (x32) Free WAV to MP3 Converter (x32) Free WMA to MP3 Converter 1.16 (x32) Ge org Internet Manager (x32 Version: 11.301.05.02.852) GIMP 2.8.2 (Version: 2.8.2) Google Update Helper (x32 Version: 1.3.21.153) HP Photo Creations (x32 Version: 1.0.0.5192) HP Photosmart 5510 series - Grundlegende Software für das Gerät (Version: 24.0.342.0) HP Photosmart 5510 series Hilfe (x32 Version: 140.0.2.2) HP Update (x32 Version: 5.003.000.004) IDT Audio (x32 Version: 1.0.6341.0) Inkscape 0.48.4 (x32 Version: 0.48.4) Intel(R) Control Center (x32 Version: 1.2.1.1007) Intel(R) Display Audio Driver (x32 Version: 6.14.00.3074) Intel(R) Management Engine Components (x32 Version: 7.0.0.1118) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (Version: 1.0.0.0454) Intel(R) Rapid Storage Technology (x32 Version: 10.1.0.1008) IrfanView (remove only) (x32 Version: 4.35) Java 7 Update 21 (x32 Version: 7.0.210) Java Auto Updater (x32 Version: 2.1.9.5) jetAudio Basic VX (x32 Version: 8.0.17) Logitech Unifying-Software 2.10 (Version: 2.10.37) Mendeley Desktop 1.7.1 (x32 Version: 1.7.1) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Office 2010 Service Pack 1 (SP1) (x32) Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Home and Student 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Office 64-bit Components 2010 (Version: 14.0.6029.1000) Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (English) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (French) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Single Image 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (x32 Version: 10.0.30319) MozBackup 1.5.1 (x32) Mozilla Firefox 22.0 (x86 de) (x32 Version: 22.0) Mozilla Maintenance Service (x32 Version: 22.0) Mozilla Thunderbird 17.0.7 (x86 de) (x32 Version: 17.0.7) MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0) PDF24 Creator 5.2.0 (x32) Python 2.5 numpy-1.0.3 (x32) Python 2.5.1 (x32) Quantum GIS Lisboa 1.8.0 Lisboa (x32 Version: 1.8.0-r${SVN_REVISION}-2) Quickset64 (Version: 10.09.25) R for Windows 2.15.2 (Version: 2.15.2) Ralink RT2870 Wireless LAN Card (x32 Version: 1.5.13.0) Realtek Ethernet Controller Driver (x32 Version: 7.31.1025.2010) Realtek USB 2.0 Card Reader (x32 Version: 6.1.7600.30126) Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.32.0) RStudio (x32 Version: 0.97.312) Skype™ 6.6 (x32 Version: 6.6.106) SoulSeek 157 NS 13e (x32) STATISTICA (x32 Version: 7.00.0000) Studie zur Verbesserung von HP Photosmart 5510 series Produkten (Version: 24.0.342.0) Total Commander 64-bit (Remove or Repair) (Version: 8.01) Überwachungstool für die Intel® Turbo-Boost-Technik 2.0 (Version: 2.1.23.0) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1) Update for Microsoft Office 2010 (KB2553065) (x32) Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2553378) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2566458) (x32) Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition (x32) Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition (x32) Update for Microsoft Outlook 2010 (KB2597090) 32-Bit Edition (x32) Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition (x32) Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition (x32) Update for Microsoft PowerPoint 2010 (KB2598240) 32-Bit Edition (x32) Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition (x32) Validity Sensors DDK (Version: 4.3.108.0) Visual Basic for Applications (R) Core - English (x32 Version: 6.5.10.32) Visual Basic for Applications (R) Core (x32 Version: 6.5.10.32) VLC media player 2.0.6 (Version: 2.0.6) WAV To MP3 V2 (x32) ==================== Restore Points ========================= 23-07-2013 20:06:41 Windows Update 26-07-2013 21:00:12 Windows Update 29-07-2013 09:13:54 avast! Free Antivirus Setup 29-07-2013 09:57:13 avast! Free Antivirus Setup ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {14B28B77-69A6-449F-B24C-A1EEE975F5B8} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-29] (Google Inc.) Task: {19B9606A-7689-4982-A6E0-942504E89EFF} - System32\Tasks\HP Photo Creations Messager => C:\ProgramData\HP Photo Creations\MessageCheck.exe [2011-02-15] () Task: {2C0AEC4F-7BE9-43C8-AADC-D900DE799769} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-01-23] (Piriform Ltd) Task: {2E62A6B3-7AC2-4966-9CDB-A4F8DD598092} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-05-09] (AVAST Software) Task: {8664EB7C-8733-4B61-BE25-3D512B0CFE61} - System32\Tasks\EPUpdater => C:\Users\DOPPEL~1\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe No File Task: {8A2BFB50-DFF0-45D9-A2D3-FD038A1BE4A2} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {A237C9D7-75C9-48C3-AC4C-2A9ABCF586A4} - System32\Tasks\{B637BD52-4E7B-428C-B367-32AD767718D6} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2013-06-21] (Skype Technologies S.A.) Task: {BAE3731F-538B-4894-84D3-4DB78723243F} - System32\Tasks\HPCustParticipation HP Photosmart 5510 series => C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPCustPartic.exe [2011-05-25] (Hewlett-Packard Co.) Task: {CB558070-015F-4F84-BF57-DCA1D8D85320} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-12] (Adobe Systems Incorporated) Task: {D8B1A9F1-6CD1-4320-8134-40622EAAF32E} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2010-11-21] (Microsoft Corporation) Task: {EEDD5C87-9B7E-48E6-B564-33E4D8FE9235} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-29] (Google Inc.) Task: {F76F2988-BB54-4F2A-A93C-7512F6345C57} - System32\Tasks\{00375640-5A9D-48B8-93A2-E714CEC2C3AA} => C:\Users\DoppelAnton\AppData\Roaming\Dropbox\bin\Dropbox.exe [2013-05-25] (Dropbox, Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\HP Photo Creations Messager.job => C:\ProgramData\HP Photo Creations\MessageCheck.exe ==================== Faulty Device Manager Devices ============= Name: Dell Wireless 1702 802.11b/g/n Description: Dell Wireless 1702 802.11b/g/n Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Atheros Communications Inc. Service: athr Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Bluetooth Server Description: Bluetooth Server Class Guid: {34446e8e-37b4-4b16-9da6-bea2db33465a} Manufacturer: Intel Corporation Service: btmaux Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Error: (07/30/2013 00:25:57 AM) (Source: DCOM) (User: ) Description: {995C996E-D918-4A8C-A302-45719A6F4EA7} Microsoft Office Sessions: ========================= ==================== Memory info =========================== Percentage of memory in use: 35% Total physical RAM: 6051.18 MB Available physical RAM: 3903.84 MB Total Pagefile: 12100.54 MB Available Pagefile: 9745.63 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: (System) (Fixed) (Total:100.1 GB) (Free:18.22 GB) NTFS (Disk=0 Partition=2) Drive d: (BACKUP files) (Fixed) (Total:249.02 GB) (Free:191.96 GB) NTFS (Disk=0 Partition=3) Drive e: (Data and PhD) (Fixed) (Total:249.02 GB) (Free:125.75 GB) NTFS (Disk=0 Partition=4) Drive g: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS (Disk=0 Partition=1) ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 699 GB) (Disk ID: 3D500F99) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=100 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=249 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=249 GB) - (Type=07 NTFS) ==================== End Of Log ============================ nochmal vielen Dank für die schnelle Hilfe!! lG, bma |
30.07.2013, 07:31 | #6 |
/// the machine /// TB-Ausbilder | Avast häufige Meldung "bösartige Website gefunden" (nach voherigen PC Problemen)ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> Avast häufige Meldung "bösartige Website gefunden" (nach voherigen PC Problemen) |
30.07.2013, 12:46 | #7 |
| Avast häufige Meldung "bösartige Website gefunden" (nach voherigen PC Problemen) Hallo, der erste scan hat fast zwei Stunden gedauert, aber hier nun der output der files. Dieser threat hier wurde im übrigen von ESET gefunden: C:\Users\DoppelAnton\AppData\Local\Temp\che727B.tmp Win32/Adware.AddLyrics.F application 1. ESET log Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=369cfde83b36a843a0abd6d8b164dfd1 # engine=14584 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-07-30 11:23:48 # local_time=2013-07-30 01:23:48 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=774 16777213 85 91 91197 151893300 0 0 # compatibility_mode=5893 16776573 100 94 73632 126813278 0 0 # scanned=259991 # found=1 # cleaned=0 # scan_time=6989 sh=E5227CF6BD15DDF966E5285A629E2F45ADE211E9 ft=0 fh=0000000000000000 vn="Win32/Adware.AddLyrics.F application" ac=I fn="C:\Users\DoppelAnton\AppData\Local\Temp\che727B.tmp" Code:
ATTFilter Results of screen317's Security Check version 0.99.71 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 10 ``````````````Antivirus/Firewall Check:`````````````` avast! Antivirus Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Java 7 Update 21 Java version out of Date! Adobe Flash Player 11.7.700.224 Adobe Reader XI Mozilla Firefox (22.0) Mozilla Thunderbird (17.0.7) ````````Process Check: objlist.exe by Laurent```````` AVAST Software Avast AvastSvc.exe AVAST Software Avast AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` 3. frisches FRST log mit ADDITION FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-07-2013 Ran by DoppelAnton (administrator) on 30-07-2013 13:33:13 Running from C:\Users\DoppelAnton\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe (Validity Sensors, Inc.) C:\Windows\system32\vcsFPService.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe (Atheros) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\Ath_CoexAgent.exe (Atheros Commnucations) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\adminservice.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe () C:\ProgramData\DatacardService\HWDeviceService64.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe () C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Atheros Communications) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe (Atheros Commnucations) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\AthBtTray.exe (Ericsson AB) C:\Program Files (x86)\Dell\Dell Mobile Broadband Manager\WirelessManager.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Huawei Technologies Co., Ltd.) C:\Users\DoppelAnton\AppData\Roaming\Ge org Internet Manager\ouc.exe (Dropbox, Inc.) C:\Users\DoppelAnton\AppData\Roaming\Dropbox\bin\Dropbox.exe (Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [FreeFallProtection] - C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe [686704 2010-12-15] () HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1128448 2011-05-27] (IDT, Inc.) HKLM\...\Run: [QuickSet] - C:\Program Files\Dell\QuickSet\QuickSet.exe [3668336 2011-03-24] (Dell Inc.) HKLM\...\Run: [BTMTrayAgent] - rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp [x] HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2480936 2010-12-15] (Synaptics Incorporated) HKLM\...\Run: [IntelTBRunOnce] - C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs [4526 2010-11-29] () HKLM\...\Run: [AtherosBtStack] - C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe [627360 2011-05-20] (Atheros Communications) HKLM\...\Run: [AthBtTray] - C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\AthBtTray.exe [379552 2011-05-20] (Atheros Commnucations) HKCU\...\Run: [WirelessManager] - C:\Program Files (x86)\Dell\Dell Mobile Broadband Manager\WirelessManager.exe [194600 2010-07-28] (Ericsson AB) HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.) HKCU\...\Run: [HW_OPENEYE_OUC_Ge org Internet Manager] - C:\Program Files (x86)\Ge org Internet Manager\UpdateDog\ouc.exe [110592 2009-12-31] (Huawei Technologies Co., Ltd.) MountPoints2: {49674710-d1bf-11e2-98ae-3859f93b766e} - H:\AutoRun.exe MountPoints2: {49674723-d1bf-11e2-98ae-3859f93b766e} - H:\AutoRun.exe MountPoints2: {6f94f44b-694c-11e2-921e-806e6f6e6963} - F:\autoRcd.exe MountPoints2: {e2470b43-6d64-11e2-bba2-3859f93b766e} - I:\HTC_Sync_Manager_PC.exe HKLM-x32\...\Run: [NUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-06] (Intel Corporation) HKLM-x32\...\Run: [Dell Webcam Central] - C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [487561 2010-08-11] (Creative Technology Ltd) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-03-24] (Hewlett-Packard) HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [163000 2012-12-12] (Geek Software GmbH) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [DataCardMonitor] - C:\Program Files (x86)\Ge org Internet Manager\DataCardMonitor.exe [253952 2013-06-12] (Huawei Technologies Co., Ltd.) HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software) Startup: C:\Users\DoppelAnton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\DoppelAnton\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\DoppelAnton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) Startup: C:\Users\DoppelAnton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Photosmart 5510 series.lnk ShortcutTarget: Tintenwarnungen überwachen - HP Photosmart 5510 series.lnk -> C:\Program Files\HP\HP Photosmart 5510 series\bin\HPStatusBL.dll (Hewlett-Packard Co.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.dell.com HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com SearchScopes: HKLM - DefaultScope value is missing. BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 134.76.10.46 134.76.33.21 FireFox: ======== FF ProfilePath: C:\Users\DoppelAnton\AppData\Roaming\Mozilla\Firefox\Profiles\58iu00y1.default FF NewTab: hxxp://www.google.com/firefox FF SelectedSearchEngine: Google FF Homepage: hxxp://www.google.com/firefox FF Keyword.URL: hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.0.6 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Extension: adblockpopups - C:\Users\DoppelAnton\AppData\Roaming\Mozilla\Firefox\Profiles\58iu00y1.default\Extensions\adblockpopups@jessehakanen.net.xpi FF Extension: zotero - C:\Users\DoppelAnton\AppData\Roaming\Mozilla\Firefox\Profiles\58iu00y1.default\Extensions\zotero@chnm.gmu.edu.xpi FF Extension: No Name - C:\Users\DoppelAnton\AppData\Roaming\Mozilla\Firefox\Profiles\58iu00y1.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM-x32\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] C:\Program Files\T-Mobile\InternetManager_H\OCx64\addon FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF ==================== Services (Whitelisted) ================= R2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\Ath_CoexAgent.exe [146592 2011-05-20] (Atheros) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software) R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [339456 2010-11-16] () ==================== Drivers (Whitelisted) ==================== R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-07-29] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-07-29] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-07-29] () R0 BMLoad; C:\Windows\System32\drivers\BMLoad.sys [16512 2009-12-15] (Bytemobile, Inc.) S3 pfc; C:\Windows\SysWow64\drivers\pfc.sys [14604 2003-08-11] (Padus, Inc.) R1 tcpipBM; C:\Windows\system32\drivers\tcpipBM.sys [39552 2009-12-15] (Bytemobile, Inc.) R1 tcpipBM; C:\Windows\system32\drivers\tcpipBM.sys [39552 2009-12-15] (Bytemobile, Inc.) S3 pfc; system32\drivers\pfc.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-30 13:28 - 2013-07-30 13:28 - 00891098 _____ C:\Users\DoppelAnton\Desktop\SecurityCheck.exe 2013-07-30 13:25 - 2013-07-30 13:25 - 00000090 _____ C:\Users\DoppelAnton\Desktop\threats found.txt 2013-07-30 11:23 - 2013-07-30 11:23 - 02347384 _____ (ESET) C:\Users\DoppelAnton\Desktop\esetsmartinstaller_enu.exe 2013-07-30 10:16 - 2013-07-30 10:16 - 00000000 ___RD C:\Users\DoppelAnton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2013-07-30 00:32 - 2013-07-30 00:32 - 00032623 _____ C:\Users\DoppelAnton\Desktop\FRST2.txt 2013-07-30 00:32 - 2013-07-30 00:32 - 00012724 _____ C:\Users\DoppelAnton\Desktop\Addition2.txt 2013-07-29 23:08 - 2013-07-30 00:26 - 00000916 _____ C:\Users\DoppelAnton\Desktop\JRT.txt 2013-07-29 23:02 - 2013-07-29 23:02 - 00000000 ____D C:\Windows\ERUNT 2013-07-29 17:03 - 2013-07-29 17:03 - 00562353 _____ (Oleg N. Scherbakov) C:\Users\DoppelAnton\Desktop\JRT.exe 2013-07-29 17:00 - 2013-07-29 17:00 - 00004391 _____ C:\Users\DoppelAnton\Desktop\AdwCleaner[S1].txt 2013-07-29 16:56 - 2013-07-29 16:56 - 00004391 _____ C:\AdwCleaner[S1].txt 2013-07-29 16:52 - 2013-07-29 16:52 - 00666633 _____ C:\Users\DoppelAnton\Desktop\adwcleaner.exe 2013-07-29 12:47 - 2013-07-30 00:32 - 00012724 _____ C:\Users\DoppelAnton\Desktop\Addition.txt 2013-07-29 12:46 - 2013-07-29 12:46 - 01780547 _____ (Farbar) C:\Users\DoppelAnton\Desktop\FRST64.exe 2013-07-29 12:46 - 2013-07-29 12:46 - 00000000 ____D C:\FRST 2013-07-29 12:37 - 2013-07-29 12:37 - 00015318 _____ C:\Users\DoppelAnton\Desktop\OTL.zip 2013-07-29 11:58 - 2013-07-30 13:08 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-29 11:58 - 2013-07-30 12:08 - 00001116 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-29 11:58 - 2013-07-29 12:03 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-07-29 11:58 - 2013-07-29 12:03 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-07-29 11:58 - 2013-07-29 12:03 - 00189936 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-07-29 11:58 - 2013-07-29 12:03 - 00004116 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-07-29 11:58 - 2013-07-29 12:03 - 00003864 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-07-29 11:58 - 2013-07-29 11:58 - 00003924 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-07-29 11:58 - 2013-05-09 10:59 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-07-29 11:58 - 2013-05-09 10:59 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-07-29 11:58 - 2013-05-09 10:59 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-07-29 11:58 - 2013-05-09 10:59 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-07-29 11:58 - 2013-05-09 10:59 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-07-29 11:57 - 2013-05-09 10:58 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-07-29 11:54 - 2013-07-29 11:54 - 00002739 _____ C:\Users\DoppelAnton\Desktop\gmer.txt 2013-07-29 10:59 - 2013-07-29 10:59 - 00377856 _____ C:\Users\DoppelAnton\Desktop\gmer_2.1.19163.exe 2013-07-29 07:41 - 2013-07-29 07:41 - 00049680 _____ C:\Users\DoppelAnton\Desktop\Extras.Txt 2013-07-29 07:40 - 2013-07-29 08:20 - 00104976 _____ C:\Users\DoppelAnton\Desktop\OTL.Txt 2013-07-29 07:32 - 2013-07-29 07:32 - 00602112 _____ (OldTimer Tools) C:\Users\DoppelAnton\Desktop\OTL.exe 2013-07-29 07:31 - 2013-07-29 07:31 - 00000484 _____ C:\Users\DoppelAnton\Desktop\defogger_disable.log 2013-07-29 07:31 - 2013-07-29 07:31 - 00000000 _____ C:\Users\DoppelAnton\defogger_reenable 2013-07-29 07:30 - 2013-07-29 07:30 - 00050477 _____ C:\Users\DoppelAnton\Desktop\Defogger.exe 2013-07-25 15:00 - 2013-07-25 15:02 - 00000000 ____D C:\Windows\system32\MRT 2013-07-21 01:26 - 2013-07-29 15:45 - 00000000 ____D C:\Users\DoppelAnton\Desktop\1st REVIEW ECOLOGY LETTERS 2013-07-20 01:18 - 2013-07-20 01:19 - 00575708 _____ C:\Users\DoppelAnton\Downloads\Fig.2.tif 2013-07-19 20:05 - 2013-07-19 20:07 - 00000000 ____D C:\Program Files (x86)\Dell Wireless 2013-07-19 20:04 - 2013-07-19 20:04 - 00000000 ____D C:\Windows\Options 2013-07-19 20:04 - 2011-05-25 23:18 - 00008090 _____ C:\Windows\system32\athrextx.cat 2013-07-19 20:04 - 2011-04-22 04:17 - 02727424 _____ (Atheros Communications, Inc.) C:\Windows\system32\Drivers\athrx.sys 2013-07-19 20:04 - 2011-04-22 04:17 - 02727424 _____ (Atheros Communications, Inc.) C:\Windows\system32\athrx.sys 2013-07-19 19:20 - 2013-07-19 19:20 - 00000000 __SHD C:\found.000 2013-07-19 18:55 - 2013-07-19 18:55 - 00000000 ____D C:\Windows\system32\appmgmt 2013-07-19 01:30 - 2013-07-29 12:03 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum 2013-07-19 01:30 - 2013-07-29 12:03 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum 2013-07-19 01:30 - 2013-07-29 12:03 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum 2013-07-18 15:55 - 2013-07-18 15:55 - 00000000 ____D C:\Users\DoppelAnton\AppData\Roaming\Apple Computer 2013-07-18 06:11 - 2013-07-18 06:11 - 00000000 ____D C:\Users\DOPPEL~1\AppData\Local\Apple 2013-07-18 06:10 - 2013-07-18 06:10 - 00000000 ____D C:\ProgramData\Apple 2013-07-18 05:48 - 2013-07-18 06:05 - 00000000 ____D C:\Users\DoppelAnton\Documents\Any Video Converter 2013-07-18 05:48 - 2013-07-18 05:48 - 00000000 ____D C:\Users\DoppelAnton\AppData\Roaming\AnvSoft 2013-07-14 01:08 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-07-14 01:08 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-07-14 01:08 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-07-14 01:08 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-07-14 01:08 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-07-14 01:08 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-07-14 01:08 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-07-14 01:08 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-07-14 01:08 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-07-14 01:08 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-07-14 01:08 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-07-14 01:08 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-07-14 01:08 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-14 01:08 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-14 01:08 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-14 01:08 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-14 01:08 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-14 01:08 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-14 01:08 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-14 01:08 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-14 01:08 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-14 01:08 - 2013-06-12 01:25 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-14 01:08 - 2013-06-12 01:25 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-14 01:08 - 2013-06-12 01:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-14 01:08 - 2013-06-12 01:25 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-14 01:08 - 2013-06-12 01:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-14 01:08 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-07-14 01:08 - 2013-06-12 00:50 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-07-14 01:08 - 2013-06-07 05:22 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-14 01:08 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-07-14 01:07 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-07-10 18:39 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-10 18:39 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2013-07-10 18:39 - 2013-05-06 08:03 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-10 18:39 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-07-10 18:28 - 2013-06-05 05:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-10 18:26 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-07-10 18:26 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-07-06 07:28 - 2013-07-06 07:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-07-02 03:23 - 2013-07-02 03:23 - 00008242 _____ C:\Users\DOPPEL~1\AppData\Local\recently-used.xbel 120 ==================== One Month Modified Files and Folders ======= 2013-07-30 13:32 - 2013-07-30 13:32 - 00000832 _____ C:\Users\DoppelAnton\Desktop\checkup.txt 2013-07-30 13:28 - 2013-07-30 13:28 - 00891098 _____ C:\Users\DoppelAnton\Desktop\SecurityCheck.exe 2013-07-30 13:25 - 2013-07-30 13:25 - 00000090 _____ C:\Users\DoppelAnton\Desktop\threats found.txt 2013-07-30 13:08 - 2013-07-29 11:58 - 00001120 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-30 13:01 - 2013-01-29 15:48 - 00000268 _____ C:\Windows\Tasks\HP Photo Creations Messager.job 2013-07-30 12:51 - 2013-02-03 21:55 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-30 12:36 - 2013-01-28 15:16 - 01266063 _____ C:\Windows\WindowsUpdate.log 2013-07-30 12:08 - 2013-07-29 11:58 - 00001116 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-30 11:25 - 2013-01-28 21:18 - 00000000 ____D C:\Users\DoppelAnton\AppData\Roaming\Skype 2013-07-30 11:23 - 2013-07-30 11:23 - 02347384 _____ (ESET) C:\Users\DoppelAnton\Desktop\esetsmartinstaller_enu.exe 2013-07-30 11:21 - 2013-01-29 00:11 - 00654236 _____ C:\Windows\system32\perfh007.dat 2013-07-30 11:21 - 2013-01-29 00:11 - 00130076 _____ C:\Windows\system32\perfc007.dat 2013-07-30 11:21 - 2009-07-14 07:13 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI 2013-07-30 10:37 - 2013-03-15 10:42 - 00000000 ___RD C:\Users\DoppelAnton\Dropbox 2013-07-30 10:37 - 2013-03-15 10:41 - 00000000 ____D C:\Users\DoppelAnton\AppData\Roaming\Dropbox 2013-07-30 10:22 - 2009-07-14 06:45 - 00021312 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-30 10:22 - 2009-07-14 06:45 - 00021312 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-30 10:16 - 2013-07-30 10:16 - 00000000 ___RD C:\Users\DoppelAnton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2013-07-30 10:15 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-07-30 10:15 - 2009-07-14 06:51 - 00068433 _____ C:\Windows\setupact.log 2013-07-30 00:32 - 2013-07-30 00:32 - 00032623 _____ C:\Users\DoppelAnton\Desktop\FRST2.txt 2013-07-30 00:32 - 2013-07-30 00:32 - 00012724 _____ C:\Users\DoppelAnton\Desktop\Addition2.txt 2013-07-30 00:32 - 2013-07-29 12:47 - 00012724 _____ C:\Users\DoppelAnton\Desktop\Addition.txt 2013-07-30 00:26 - 2013-07-29 23:08 - 00000916 _____ C:\Users\DoppelAnton\Desktop\JRT.txt 2013-07-29 23:02 - 2013-07-29 23:02 - 00000000 ____D C:\Windows\ERUNT 2013-07-29 17:03 - 2013-07-29 17:03 - 00562353 _____ (Oleg N. Scherbakov) C:\Users\DoppelAnton\Desktop\JRT.exe 2013-07-29 17:00 - 2013-07-29 17:00 - 00004391 _____ C:\Users\DoppelAnton\Desktop\AdwCleaner[S1].txt 2013-07-29 16:56 - 2013-07-29 16:56 - 00004391 _____ C:\AdwCleaner[S1].txt 2013-07-29 16:52 - 2013-07-29 16:52 - 00666633 _____ C:\Users\DoppelAnton\Desktop\adwcleaner.exe 2013-07-29 15:45 - 2013-07-21 01:26 - 00000000 ____D C:\Users\DoppelAnton\Desktop\1st REVIEW ECOLOGY LETTERS 2013-07-29 12:46 - 2013-07-29 12:46 - 01780547 _____ (Farbar) C:\Users\DoppelAnton\Desktop\FRST64.exe 2013-07-29 12:46 - 2013-07-29 12:46 - 00000000 ____D C:\FRST 2013-07-29 12:45 - 2013-01-28 21:27 - 00000000 ____D C:\Neuinstallation_starter programme 2013-07-29 12:37 - 2013-07-29 12:37 - 00015318 _____ C:\Users\DoppelAnton\Desktop\OTL.zip 2013-07-29 12:03 - 2013-07-29 11:58 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-07-29 12:03 - 2013-07-29 11:58 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-07-29 12:03 - 2013-07-29 11:58 - 00189936 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-07-29 12:03 - 2013-07-29 11:58 - 00004116 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-07-29 12:03 - 2013-07-29 11:58 - 00003864 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-07-29 12:03 - 2013-07-19 01:30 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum 2013-07-29 12:03 - 2013-07-19 01:30 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum 2013-07-29 12:03 - 2013-07-19 01:30 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum 2013-07-29 11:58 - 2013-07-29 11:58 - 00003924 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-07-29 11:58 - 2013-01-28 21:32 - 00000000 ____D C:\Program Files (x86)\Google 2013-07-29 11:58 - 2013-01-28 21:32 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-07-29 11:57 - 2013-01-28 21:32 - 00000000 ____D C:\ProgramData\AVAST Software 2013-07-29 11:57 - 2013-01-28 21:32 - 00000000 ____D C:\Program Files\AVAST Software 2013-07-29 11:54 - 2013-07-29 11:54 - 00002739 _____ C:\Users\DoppelAnton\Desktop\gmer.txt 2013-07-29 11:15 - 2010-11-21 05:47 - 00052068 _____ C:\Windows\PFRO.log 2013-07-29 10:59 - 2013-07-29 10:59 - 00377856 _____ C:\Users\DoppelAnton\Desktop\gmer_2.1.19163.exe 2013-07-29 08:20 - 2013-07-29 07:40 - 00104976 _____ C:\Users\DoppelAnton\Desktop\OTL.Txt 2013-07-29 07:41 - 2013-07-29 07:41 - 00049680 _____ C:\Users\DoppelAnton\Desktop\Extras.Txt 2013-07-29 07:32 - 2013-07-29 07:32 - 00602112 _____ (OldTimer Tools) C:\Users\DoppelAnton\Desktop\OTL.exe 2013-07-29 07:31 - 2013-07-29 07:31 - 00000484 _____ C:\Users\DoppelAnton\Desktop\defogger_disable.log 2013-07-29 07:31 - 2013-07-29 07:31 - 00000000 _____ C:\Users\DoppelAnton\defogger_reenable 2013-07-29 07:31 - 2013-01-28 16:29 - 00000000 ____D C:\Users\DoppelAnton 2013-07-29 07:30 - 2013-07-29 07:30 - 00050477 _____ C:\Users\DoppelAnton\Desktop\Defogger.exe 2013-07-28 12:42 - 2013-01-29 18:00 - 00000000 ____D C:\Users\DoppelAnton\AppData\Roaming\vlc 2013-07-28 12:40 - 2013-02-17 22:37 - 00000000 ____D C:\Users\DoppelAnton\AppData\Roaming\dvdcss 2013-07-26 17:34 - 2013-01-29 17:51 - 00000000 ___RD C:\Users\DoppelAnton\Desktop\zeug 2013-07-26 14:25 - 2013-05-24 10:46 - 00000000 ____D C:\Users\DoppelAnton\Desktop\submission_SCISSI_paper 2013-07-25 15:02 - 2013-07-25 15:00 - 00000000 ____D C:\Windows\system32\MRT 2013-07-22 19:35 - 2013-06-25 17:39 - 00000000 ____D C:\Users\DoppelAnton\Desktop\RE_SUBM_ECOLLETT_Maas2013 2013-07-22 03:51 - 2013-06-14 14:42 - 00001755 _____ C:\Users\DoppelAnton\AppData\Roaming\WWB7_32.DAT 2013-07-21 20:00 - 2013-05-30 20:21 - 00000000 ____D C:\Users\DoppelAnton\Desktop\RAnalyse_Birds 2013-07-21 02:12 - 2013-05-26 14:06 - 00000000 ____D C:\Users\DoppelAnton\Desktop\alldata_NEW_BIRDpap 2013-07-20 01:19 - 2013-07-20 01:18 - 00575708 _____ C:\Users\DoppelAnton\Downloads\Fig.2.tif 2013-07-19 20:19 - 2013-01-28 21:17 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-07-19 20:19 - 2013-01-28 21:17 - 00000000 ____D C:\ProgramData\Skype 2013-07-19 20:07 - 2013-07-19 20:05 - 00000000 ____D C:\Program Files (x86)\Dell Wireless 2013-07-19 20:05 - 2011-05-20 19:07 - 00246804 _____ C:\Windows\system32\Drivers\AtherosBt.bin 2013-07-19 20:04 - 2013-07-19 20:04 - 00000000 ____D C:\Windows\Options 2013-07-19 20:04 - 2013-01-28 19:21 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-07-19 20:00 - 2013-01-28 21:11 - 00018752 _____ C:\Windows\DPINST.LOG 2013-07-19 19:20 - 2013-07-19 19:20 - 00000000 __SHD C:\found.000 2013-07-19 19:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF 2013-07-19 18:55 - 2013-07-19 18:55 - 00000000 ____D C:\Windows\system32\appmgmt 2013-07-19 18:44 - 2013-06-23 13:24 - 00000000 ____D C:\Users\DoppelAnton\Desktop\Maas_2013_HarvestPaper 2013-07-19 03:45 - 2013-01-28 19:23 - 00000000 ____D C:\Neuinstallation_Dell Treiber 2013-07-19 00:59 - 2013-01-29 17:56 - 00000000 ____D C:\Users\DOPPEL~1\AppData\Local\CrashDumps 2013-07-18 15:55 - 2013-07-18 15:55 - 00000000 ____D C:\Users\DoppelAnton\AppData\Roaming\Apple Computer 2013-07-18 06:11 - 2013-07-18 06:11 - 00000000 ____D C:\Users\DOPPEL~1\AppData\Local\Apple 2013-07-18 06:10 - 2013-07-18 06:10 - 00000000 ____D C:\ProgramData\Apple 2013-07-18 06:05 - 2013-07-18 05:48 - 00000000 ____D C:\Users\DoppelAnton\Documents\Any Video Converter 2013-07-18 05:48 - 2013-07-18 05:48 - 00000000 ____D C:\Users\DoppelAnton\AppData\Roaming\AnvSoft 2013-07-14 01:50 - 2009-07-14 06:45 - 00400432 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-14 01:49 - 2010-11-21 09:17 - 00000000 ____D C:\Program Files\Windows Journal 2013-07-14 01:49 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender 2013-07-14 01:49 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2013-07-14 01:13 - 2013-01-29 15:04 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-07-07 19:04 - 2013-01-28 21:36 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-07-06 07:28 - 2013-07-06 07:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-07-02 03:23 - 2013-07-02 03:23 - 00008242 _____ C:\Users\DOPPEL~1\AppData\Local\recently-used.xbel 2013-07-01 22:16 - 2013-02-12 20:54 - 00000000 ____D C:\Users\DoppelAnton\Desktop\BIRDpap_alldata 2013-06-30 21:27 - 2013-03-14 13:14 - 00000000 ____D C:\Users\DoppelAnton\Desktop\STATISTICS 2013-06-30 19:12 - 2013-06-29 21:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-24 02:33 ==================== End Of Log ============================ --- --- --- Addition Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-07-2013 Ran by DoppelAnton at 2013-07-30 13:33:49 Running from C:\Users\DoppelAnton\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= 7-Zip 9.20 (x64 edition) (Version: 9.20.00.0) AccelerometerP11 (x32 Version: 2.00.10.21) Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.224) Adobe Premiere Pro (x32 Version: 7.0) Adobe Reader XI (11.0.03) - Deutsch (x32 Version: 11.0.03) Advanced Audio FX Engine (x32 Version: 1.12.05) Amazon Kindle (HKCU) ArcGIS Desktop Evaluation Edition (x32 Version: 9.3.3000) ATI Catalyst Install Manager (Version: 3.0.808.0) avast! Free Antivirus (x32 Version: 8.0.1489.0) Bluetooth Win7 Suite (64) (Version: 7.2.0.83) CDBurnerXP (x32 Version: 4.5.1.3868) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32) Dell Backup and Recovery Manager (Version: 1.3.1) Dell Mobile Broadband Manager (x32 Version: 6.1.24.2) Dell Resource CD (x32 Version: 1.00.0000) Dell Touchpad (Version: 15.2.5.2) Dell Webcam Central (x32 Version: 2.00.33) Dell WLAN and Bluetooth Client Installation (x32 Version: 9.0) Dropbox (HKCU Version: 2.0.22) eaner (Version: 3.27) EstimateS Win 8.20 (x32) Free WAV to MP3 Converter (x32) Free WMA to MP3 Converter 1.16 (x32) Ge org Internet Manager (x32 Version: 11.301.05.02.852) GIMP 2.8.2 (Version: 2.8.2) Google Update Helper (x32 Version: 1.3.21.153) HP Photo Creations (x32 Version: 1.0.0.5192) HP Photosmart 5510 series - Grundlegende Software für das Gerät (Version: 24.0.342.0) HP Photosmart 5510 series Hilfe (x32 Version: 140.0.2.2) HP Update (x32 Version: 5.003.000.004) IDT Audio (x32 Version: 1.0.6341.0) Inkscape 0.48.4 (x32 Version: 0.48.4) Intel(R) Control Center (x32 Version: 1.2.1.1007) Intel(R) Display Audio Driver (x32 Version: 6.14.00.3074) Intel(R) Management Engine Components (x32 Version: 7.0.0.1118) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (Version: 1.0.0.0454) Intel(R) Rapid Storage Technology (x32 Version: 10.1.0.1008) IrfanView (remove only) (x32 Version: 4.35) Java 7 Update 21 (x32 Version: 7.0.210) Java Auto Updater (x32 Version: 2.1.9.5) jetAudio Basic VX (x32 Version: 8.0.17) Logitech Unifying-Software 2.10 (Version: 2.10.37) Mendeley Desktop 1.7.1 (x32 Version: 1.7.1) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Office 2010 Service Pack 1 (SP1) (x32) Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Home and Student 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Office 64-bit Components 2010 (Version: 14.0.6029.1000) Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (English) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (French) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Single Image 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (x32 Version: 10.0.30319) MozBackup 1.5.1 (x32) Mozilla Firefox 22.0 (x86 de) (x32 Version: 22.0) Mozilla Maintenance Service (x32 Version: 22.0) Mozilla Thunderbird 17.0.7 (x86 de) (x32 Version: 17.0.7) MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0) PDF24 Creator 5.2.0 (x32) Python 2.5 numpy-1.0.3 (x32) Python 2.5.1 (x32) Quantum GIS Lisboa 1.8.0 Lisboa (x32 Version: 1.8.0-r${SVN_REVISION}-2) Quickset64 (Version: 10.09.25) R for Windows 2.15.2 (Version: 2.15.2) Ralink RT2870 Wireless LAN Card (x32 Version: 1.5.13.0) Realtek Ethernet Controller Driver (x32 Version: 7.31.1025.2010) Realtek USB 2.0 Card Reader (x32 Version: 6.1.7600.30126) Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.32.0) RStudio (x32 Version: 0.97.312) Skype™ 6.6 (x32 Version: 6.6.106) SoulSeek 157 NS 13e (x32) STATISTICA (x32 Version: 7.00.0000) Studie zur Verbesserung von HP Photosmart 5510 series Produkten (Version: 24.0.342.0) Total Commander 64-bit (Remove or Repair) (Version: 8.01) Überwachungstool für die Intel® Turbo-Boost-Technik 2.0 (Version: 2.1.23.0) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1) Update for Microsoft Office 2010 (KB2553065) (x32) Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2553378) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2566458) (x32) Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition (x32) Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition (x32) Update for Microsoft Outlook 2010 (KB2597090) 32-Bit Edition (x32) Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition (x32) Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition (x32) Update for Microsoft PowerPoint 2010 (KB2598240) 32-Bit Edition (x32) Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition (x32) Validity Sensors DDK (Version: 4.3.108.0) Visual Basic for Applications (R) Core - English (x32 Version: 6.5.10.32) Visual Basic for Applications (R) Core (x32 Version: 6.5.10.32) VLC media player 2.0.6 (Version: 2.0.6) WAV To MP3 V2 (x32) ==================== Restore Points ========================= 23-07-2013 20:06:41 Windows Update 26-07-2013 21:00:12 Windows Update 29-07-2013 09:13:54 avast! Free Antivirus Setup 29-07-2013 09:57:13 avast! Free Antivirus Setup ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {14B28B77-69A6-449F-B24C-A1EEE975F5B8} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-29] (Google Inc.) Task: {19B9606A-7689-4982-A6E0-942504E89EFF} - System32\Tasks\HP Photo Creations Messager => C:\ProgramData\HP Photo Creations\MessageCheck.exe [2011-02-15] () Task: {2C0AEC4F-7BE9-43C8-AADC-D900DE799769} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-01-23] (Piriform Ltd) Task: {2E62A6B3-7AC2-4966-9CDB-A4F8DD598092} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-05-09] (AVAST Software) Task: {8664EB7C-8733-4B61-BE25-3D512B0CFE61} - System32\Tasks\EPUpdater => C:\Users\DOPPEL~1\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe No File Task: {A237C9D7-75C9-48C3-AC4C-2A9ABCF586A4} - System32\Tasks\{B637BD52-4E7B-428C-B367-32AD767718D6} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2013-06-21] (Skype Technologies S.A.) Task: {BAE3731F-538B-4894-84D3-4DB78723243F} - System32\Tasks\HPCustParticipation HP Photosmart 5510 series => C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPCustPartic.exe [2011-05-25] (Hewlett-Packard Co.) Task: {CB558070-015F-4F84-BF57-DCA1D8D85320} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-12] (Adobe Systems Incorporated) Task: {D8B1A9F1-6CD1-4320-8134-40622EAAF32E} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2010-11-21] (Microsoft Corporation) Task: {EEDD5C87-9B7E-48E6-B564-33E4D8FE9235} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-29] (Google Inc.) Task: {F76F2988-BB54-4F2A-A93C-7512F6345C57} - System32\Tasks\{00375640-5A9D-48B8-93A2-E714CEC2C3AA} => C:\Users\DoppelAnton\AppData\Roaming\Dropbox\bin\Dropbox.exe [2013-05-25] (Dropbox, Inc.) Task: {F93A292F-8FF8-4AFD-B4FC-FDFB7F27B04B} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\HP Photo Creations Messager.job => C:\ProgramData\HP Photo Creations\MessageCheck.exe ==================== Faulty Device Manager Devices ============= Name: Bluetooth Server Description: Bluetooth Server Class Guid: {34446e8e-37b4-4b16-9da6-bea2db33465a} Manufacturer: Intel Corporation Service: btmaux Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (07/30/2013 01:29:03 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (07/30/2013 01:29:02 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (07/30/2013 01:26:11 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (07/30/2013 11:25:22 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (07/30/2013 11:25:20 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (07/30/2013 11:25:20 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (07/30/2013 11:23:38 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (07/30/2013 10:16:33 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/30/2013 01:05:20 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (07/30/2013 11:20:29 AM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. Error: (07/30/2013 11:20:28 AM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. Error: (07/30/2013 11:20:27 AM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. Error: (07/30/2013 11:20:27 AM) (Source: Disk) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden. Error: (07/30/2013 10:15:37 AM) (Source: Application Popup) (User: ) Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\drivers\pfc.sys nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error: (07/30/2013 01:04:07 AM) (Source: Application Popup) (User: ) Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\drivers\pfc.sys nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error: (07/30/2013 00:25:57 AM) (Source: DCOM) (User: ) Description: {995C996E-D918-4A8C-A302-45719A6F4EA7} Microsoft Office Sessions: ========================= Error: (07/30/2013 01:29:03 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\DoppelAnton\Desktop\esetsmartinstaller_enu.exe Error: (07/30/2013 01:29:02 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\DoppelAnton\Desktop\esetsmartinstaller_enu.exe Error: (07/30/2013 01:26:11 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe Error: (07/30/2013 11:25:22 AM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\DoppelAnton\Desktop\esetsmartinstaller_enu.exe Error: (07/30/2013 11:25:20 AM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\DoppelAnton\Desktop\esetsmartinstaller_enu.exe Error: (07/30/2013 11:25:20 AM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\DoppelAnton\Desktop\esetsmartinstaller_enu.exe Error: (07/30/2013 11:23:38 AM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\DoppelAnton\Desktop\esetsmartinstaller_enu.exe Error: (07/30/2013 10:16:33 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/30/2013 01:05:20 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 ==================== Memory info =========================== Percentage of memory in use: 41% Total physical RAM: 6051.18 MB Available physical RAM: 3569.22 MB Total Pagefile: 12100.54 MB Available Pagefile: 9618.92 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: (System) (Fixed) (Total:100.1 GB) (Free:17.34 GB) NTFS (Disk=0 Partition=2) Drive d: (BACKUP files) (Fixed) (Total:249.02 GB) (Free:191.96 GB) NTFS (Disk=0 Partition=3) Drive e: (Data and PhD) (Fixed) (Total:249.02 GB) (Free:125.75 GB) NTFS (Disk=0 Partition=4) Drive g: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS (Disk=0 Partition=1) ==>[System with boot components (obtained from reading drive)] Drive h: (TRANSCEND) (Removable) (Total:14.95 GB) (Free:1 GB) FAT32 (Disk=1 Partition=1) ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 699 GB) (Disk ID: 3D500F99) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=100 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=249 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=249 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 15 GB) (Disk ID: 00000000) Partition 1: (Not Active) - (Size=15 GB) - (Type=0C) ==================== End Of Log ============================ Ob das Problem behoben wurde kann ich ehrlich gesagt leider nicht beurteilen. Aber ich bin sehr dankbar für die kompetente und rasche Hilfe!! Liebe Grüße, bma PS: das Problem mit den grün unterstrichenen Links auf den Internetseiten ist jedenfalls weg!! super!! :-) danke!! Betrachtest du damit auch das Problem als erledigt oder gibt es noch andere Probleme die man in den log files erkennen kann? Falls du es als erledigt betrachtest, kannst du mir evtl noch bitte eine Enpfehlung geben, welche Programme ich auf meinem PC installiert haben sollte um mich selbst besser zu schützen? Ist die Kombination aus Avast und CCleaner deiner Meinung nach gut oder zu wenig?? Vielen Dank und lieben Gruß!! bma |
30.07.2013, 14:00 | #8 |
/// the machine /// TB-Ausbilder | Avast häufige Meldung "bösartige Website gefunden" (nach voherigen PC Problemen) Hi, Downloade Dir bitte TFC ( von Oldtimer ) und speichere die Datei auf dem Desktop. Schließe nun alle offenen Programme und trenne Dich von dem Internet. Doppelklick auf die TFC.exe und drücke auf Start. Sollte TFC nicht alle Dateien löschen können wird es einen Neustart verlangen. Dies bitte zulassen. Fertig Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
30.07.2013, 17:22 | #9 |
| Avast häufige Meldung "bösartige Website gefunden" (nach voherigen PC Problemen) hi schrauber!! tausen dank für deine hilfe. Ich hab alles in dieser Reihenfolge befolgt und es sieht gut aus... die links sind auf jeden fall weg und auch die warnungen von avast. Deine Tipps werde ich mir auch zu herzen nehmen. Danke und schönen Abend noch!! bma |
31.07.2013, 08:00 | #10 |
/// the machine /// TB-Ausbilder | Avast häufige Meldung "bösartige Website gefunden" (nach voherigen PC Problemen) gern geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Avast häufige Meldung "bösartige Website gefunden" (nach voherigen PC Problemen) |
adblock, avast, bösartige website, converter, firewall, forum, gelöscht, homepage, internet, jpg-dateien, links, log, lösung, nerven, neu, neue, notebook, ordner, pc probleme, problem, problem gelöst, programm, seite, software, system, treiber, unseriöse seiten, virus, virus verdacht, werbefenster, windows, wlan, wörter |