|
Plagegeister aller Art und deren Bekämpfung: Wartungscenter und Windows Explorer funktionieren nicht mehr!Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
23.02.2014, 10:46 | #1 |
| Wartungscenter und Windows Explorer funktionieren nicht mehr! Hallo zusammen, seit heute Mittag habe ich folgendes Problem, in regelmäßigen Abstand kommt folgende Fehlermeldung "Windows Explorer funktioniert nicht mehr" etc. Schuld daran soll folgendes sein: werconcpl.dll , nun habe ich schon alle Virenprogramme durchlaufen lassen, jedoch nichts gefunden (Malwarebytes, Adware, Avira etc) Allgemein bootet der Pc im Vergleich zu vorher auch langsamer als sonst. Gehe ich in die Systemsteuerung und möchte auf das Wartungscenter zugreifen kommt sofort die Meldung mit "Windows Explorer funktioniert nicht mehr" und ich muss den Dienst neu starten. Ich hoffe ihr habt eine Idee. Mfg. Dazu noch, diese Fehlermeldung "Windows Explorer funktioniert nicht mehr" trat erst dann auf nachdem ich aus dem Wartungscenter 2 Meldungen ausgeblendet habe: Sicherung einrichten und dass kein Antivirenprogramm erkannt wurde (Obwohl Avira etc drauf ist) Seitdem ist das Fähnchen weg, aber dafür die Probleme da. |
23.02.2014, 10:51 | #2 |
/// the machine /// TB-Ausbilder | Wartungscenter und Windows Explorer funktionieren nicht mehr! hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
23.02.2014, 21:15 | #3 |
| Wartungscenter und Windows Explorer funktionieren nicht mehr! FRST Logfile:
__________________FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 22-02-2014 01 Ran by Mario (administrator) on MARIO-PC on 23-02-2014 11:40:59 Running from C:\Users\Mario\Desktop Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (SurfRight B.V.) C:\Program Files\HitmanPro\hmpsched.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (APN LLC.) C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Windows\system32\PnkBstrA.exe (VIA Technologies, Inc.) C:\Windows\system32\viakaraokesrv.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (AVM Berlin GmbH) C:\Program Files\avmwlanstick\FRITZWLanMini.exe (VIA) C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (APN) C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Logitech Inc.) C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe (Palit Microsystems Ltd.) C:\Program Files\Thunder Master\THPanel.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Spotify Ltd) C:\Users\Mario\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Curse) C:\Users\Mario\AppData\Local\Apps\2.0\BOAV3H5H.VNM\BJ4V8M56.TLY\curs..tion_9e9e83ddf3ed3ead_0005.0001_181b5e0542e9eb6c\CurseClient.exe (OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.bin (Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_12_0_0_70.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_12_0_0_70.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [AVMWlanClient] - C:\Program Files\avmwlanstick\FRITZWLANMini.exe [343552 2006-06-23] (AVM Berlin GmbH) HKLM\...\Run: [] - [X] HKLM\...\Run: [HDAudDeck] - C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe [4017296 2012-08-09] (VIA) HKLM\...\Run: [USB3MON] - C:\Program Files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-20] (Intel Corporation) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [ApnTBMon] - C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1758160 2014-02-13] (APN) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Run: [LWS] - C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-13] (Logitech Inc.) HKLM\...\Run: [NvBackend] - C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-02-05] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\nvspcap.dll [1048152 2014-02-05] (NVIDIA Corporation) HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [948440 2013-10-23] (Microsoft Corporation) HKLM\...\Policies\Explorer: [AllowLegacyWebView] 1 HKLM\...\Policies\Explorer: [AllowUnhashedWebView] 1 HKU\S-1-5-21-1334393099-4186190667-1764432719-1000\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [18678376 2013-04-19] (Skype Technologies S.A.) HKU\S-1-5-21-1334393099-4186190667-1764432719-1000\...\Run: [THPanel] - C:\Program Files\Thunder Master\THPanel.exe [2157352 2013-05-09] (Palit Microsystems Ltd.) HKU\S-1-5-21-1334393099-4186190667-1764432719-1000\...\Run: [Spotify] - C:\Users\Mario\AppData\Roaming\Spotify\Spotify.exe [6118400 2014-01-15] (Spotify Ltd) HKU\S-1-5-21-1334393099-4186190667-1764432719-1000\...\Run: [Spotify Web Helper] - C:\Users\Mario\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171968 2014-01-15] (Spotify Ltd) HKU\S-1-5-21-1334393099-4186190667-1764432719-1000\...\Run: [Steam] - F:\Program Files\Steam\steam.exe [1822400 2014-02-20] (Valve Corporation) HKU\S-1-5-21-1334393099-4186190667-1764432719-1000\...\MountPoints2: {a109cb81-9013-11e2-b0d3-806e6f6e6963} - D:\SETUP.EXE HKU\S-1-5-21-1334393099-4186190667-1764432719-1000\...\MountPoints2: {b3f86d19-ee55-11df-b522-0021851ca989} - I:\pushinst.exe Startup: C:\Users\Mario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip () Startup: C:\Users\Mario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Produktregistrierung.lnk ShortcutTarget: Logitech . Produktregistrierung.lnk -> C:\Program Files\Logitech\Ereg\eReg.exe (Leader Technologies/Logitech) Startup: C:\Users\Mario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe () Startup: C:\Users\Mario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Samsung SSD Magician.lnk ShortcutTarget: Samsung SSD Magician.lnk -> C:\Program Files\Samsung SSD Magician\Samsung SSD Magician.exe (Samsung Electronics.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x03AD0D2598DACB01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.t-online.de/cpm-redir/ie-9.html SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {12182C2A-D9B9-40EC-A130-D84D6BEE9414} URL = hxxp://suche.t-online.de/fastcgi/tsc?mandant=toi&device=html&portallanguage=de&userlanguage=de&d ia=suche&context=wiki-tab&tpc=internet&ptl=std&classification=wikitab_internet_std&q={searchTerms}&br=ie7-toi SearchScopes: HKCU - {654EE9FA-CAE7-4F63-92D6-FB0D2D4FA75D} URL = hxxp://www.amazon.de/gp/search?ie=UTF8&keywords={searchTerms}&tag= interactivemesuche21&index=blended&linkCode=ur2&camp=1638&creative=6742 SearchScopes: HKCU - {B4D60619-3805-4691-BCD5-6866B6C0BA24} URL = hxxp://suche.t-online.de/fast-cgi/tsc?mandant=toi&device=html&portallanguage=de&userlanguage=de&dia=suche&context=internet-tab&tpc=internet&ptl=std&classification=internet-tab_internet_std&q={searchTerms}&br=ie7-toi SearchScopes: HKCU - {DBF9EC0B-2111-4A4E-8FD5-7FA70C2D8EDC} URL = hxxp://rover.ebay.com/rover/1/707-1403-276402/4?mpre=hxxp://search.ebay.de/search/search.dll?shortcut=4&query={sear chTerms} BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) Toolbar: HKCU - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG) Tcpip\..\Interfaces\{917C2AEA-81EC-42D0-B60E-F157BACF5E2D}: [NameServer]192.168.178.1,192.168.178.17 FireFox: ======== FF ProfilePath: C:\Users\Mario\AppData\Roaming\Mozilla\Firefox\Profiles\4bbvqsh4.default FF DefaultSearchEngine: ICQ Search FF SearchEngineOrder.user_pref("browser.search.order.1", "");: user_pref("browser.search.order.1", ""); FF SelectedSearchEngine: ICQ Search FF Homepage: hxxp://www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_70.dll () FF Plugin: @esn.me/esnsonar,version=0.70.4 - C:\Program Files\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll No File FF Plugin: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll No File FF SearchPlugin: C:\Users\Mario\AppData\Roaming\Mozilla\Firefox\Profiles\4bbvqsh4.default\searchplugins\icq-search.xml FF SearchPlugin: C:\Users\Mario\AppData\Roaming\Mozilla\Firefox\Profiles\4bbvqsh4.default\searchplugins\searchplugins-backup FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: ProxTube - Unblock YouTube - C:\Users\Mario\AppData\Roaming\Mozilla\Firefox\Profiles\4bbvqsh4.default\Extensions\ich@maltegoetz.de [2013-12-12] FF Extension: Avira SearchFree Toolbar plus Web Protection - C:\Users\Mario\AppData\Roaming\Mozilla\Firefox\Profiles\4bbvqsh4.default\Extensions\toolbar_AVIRA-V7@apn.ask.com.xpi [2013-07-26] Chrome: ======= CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\24.0.1312.57\PepperFlash\pepflashplayer.dll No File CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\24.0.1312.57\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\24.0.1312.57\pdf.dll No File CHR Plugin: (Injovo Extension Plugin) - C:\Users\Mario\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.478_0\npbrowserext.dll No File CHR Plugin: (Java Deployment Toolkit 6.0.290.11) - C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll No File CHR Plugin: (Java(TM) Platform SE 6 U29) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files\Battlelog Web Plugins\2.1.2\npesnlaunch.dll No File CHR Plugin: (ESN Sonar API) - C:\Program Files\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll No File CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll No File CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.0.50401.0\npctrl.dll No File CHR Extension: (Google Docs) - C:\Users\Mario\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-02-08] CHR Extension: (Google Drive) - C:\Users\Mario\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-02-08] CHR Extension: (YouTube) - C:\Users\Mario\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-02-08] CHR Extension: (Google-Suche) - C:\Users\Mario\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-02-08] CHR Extension: (Google Mail) - C:\Users\Mario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-02-08] CHR HKLM\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx [2014-02-20] ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1017424 2014-02-20] (Avira Operations GmbH & Co. KG) R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2014-02-13] (APN LLC.) S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] () R2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [106248 2014-01-31] (SurfRight B.V.) S3 ICCS; C:\Program Files\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [160256 2011-08-30] (Intel Corporation) R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [462048 2012-04-20] (Intel(R) Corporation) R2 jhi_service; C:\Program Files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation) R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-10-23] (Microsoft Corporation) R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [280288 2013-10-23] (Microsoft Corporation) U2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-02-05] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15904544 2014-02-05] (NVIDIA Corporation) R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76888 2013-03-19] () R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27792 2012-08-03] (VIA Technologies, Inc.) ==================== Drivers (Whitelisted) ==================== R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [19056 2011-11-02] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-12-01] (Avira Operations GmbH & Co. KG) R3 FWLANUSB; C:\Windows\System32\DRIVERS\fwlanusb.sys [264704 2006-04-06] (AVM GmbH) R0 iusb3hcs; C:\Windows\System32\DRIVERS\iusb3hcs.sys [15680 2012-05-20] (Intel Corporation) R3 iusb3hub; C:\Windows\System32\DRIVERS\iusb3hub.sys [350016 2012-05-20] (Intel Corporation) R3 iusb3xhc; C:\Windows\System32\DRIVERS\iusb3xhc.sys [793920 2012-05-20] (Intel Corporation) R3 L1C; C:\Windows\System32\DRIVERS\L1C62x86.sys [99992 2012-07-19] (Qualcomm Atheros Co., Ltd.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) R3 MEI; C:\Windows\System32\DRIVERS\HECI.sys [55104 2012-07-02] (Intel Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [214696 2013-09-27] (Microsoft Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [34080 2013-12-27] (NVIDIA Corporation) S3 SCREAMINGBDRIVER; C:\Windows\System32\drivers\ScreamingBAudio.sys [34896 2010-07-01] (Screaming Bee LLC) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-08-05] (Avira GmbH) S3 TIEHDUSB; C:\Windows\System32\drivers\tiehdusb.sys [49536 2004-02-04] (Texas Instruments Incorporated) R3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [1840272 2012-08-03] (VIA Technologies, Inc.) S3 amdiox86; system32\DRIVERS\amdiox86.sys [X] S3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [X] S3 gdrv; \??\C:\Windows\gdrv.sys [X] S1 SBRE; \??\C:\Windows\system32\drivers\SBREdrv.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-23 11:40 - 2014-02-23 11:41 - 00020945 _____ () C:\Users\Mario\Desktop\FRST.txt 2014-02-23 11:40 - 2014-02-23 11:40 - 01142784 _____ (Farbar) C:\Users\Mario\Desktop\FRST.exe 2014-02-23 11:40 - 2014-02-23 11:40 - 00000000 ____D () C:\FRST 2014-02-23 10:55 - 2014-02-23 11:35 - 00000000 ____D () C:\Users\Mario\Desktop\vw 2014-02-22 23:20 - 2014-02-22 23:21 - 00005384 _____ () C:\Windows\system32\jupdate-1.7.0_51-b13.log 2014-02-22 19:33 - 2014-02-22 19:39 - 00000000 ____D () C:\AdwCleaner 2014-02-22 19:26 - 2014-02-23 10:40 - 00000840 _____ () C:\Windows\setupact.log 2014-02-22 19:26 - 2014-02-22 19:26 - 00000510 _____ () C:\Windows\PFRO.log 2014-02-22 19:26 - 2014-02-22 19:26 - 00000000 _____ () C:\Windows\setuperr.log 2014-02-22 17:43 - 2014-02-22 17:43 - 00017338 _____ () C:\Users\Mario\Documents\cc_20140222_174319.reg 2014-02-22 14:24 - 2014-02-22 14:24 - 00000000 ____D () C:\Program Files\Microsoft CAPICOM 2.1.0.2 2014-02-22 14:05 - 2014-02-22 14:05 - 00001912 _____ () C:\Windows\epplauncher.mif 2014-02-22 14:05 - 2014-02-22 14:05 - 00000000 ____D () C:\Program Files\Microsoft Security Client 2014-02-22 14:04 - 2014-02-22 14:04 - 11157328 _____ (Microsoft Corporation) C:\Users\Mario\Downloads\mseinstall.exe 2014-02-22 13:41 - 2014-02-22 13:41 - 01241834 _____ () C:\Users\Mario\Downloads\adwcleaner.exe 2014-02-22 13:40 - 2014-02-22 13:40 - 00001071 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-22 13:40 - 2014-02-22 13:40 - 00000000 ____D () C:\Users\Mario\AppData\Roaming\Malwarebytes 2014-02-22 13:40 - 2014-02-22 13:40 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware 2014-02-22 13:40 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-02-22 13:39 - 2014-02-22 13:39 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Mario\Downloads\mbam-setup-1.75.0.1300.exe 2014-02-22 13:27 - 2014-02-22 13:27 - 00001309 _____ () C:\Users\Public\Desktop\GeForce Experience.lnk 2014-02-22 13:26 - 2014-02-22 13:27 - 00000000 ____D () C:\Users\Mario\AppData\Local\NVIDIA 2014-02-22 13:26 - 2014-02-22 13:26 - 00000000 ____D () C:\Program Files\AGEIA Technologies 2014-02-22 13:26 - 2014-02-05 10:31 - 01048152 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap.dll 2014-02-22 13:25 - 2014-02-08 17:18 - 00599840 _____ (NVIDIA Corporation) C:\Windows\system32\nvStreaming.exe 2014-02-22 13:24 - 2014-02-08 19:27 - 23683360 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv32.dll 2014-02-22 13:24 - 2014-02-08 19:27 - 17560352 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2014-02-22 13:24 - 2014-02-08 19:27 - 10180896 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2014-02-22 13:24 - 2014-02-08 19:27 - 09728064 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2014-02-22 13:24 - 2014-02-08 19:27 - 09690424 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2014-02-22 13:24 - 2014-02-08 19:27 - 02956576 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2014-02-22 13:24 - 2014-02-08 19:27 - 02410784 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2014-02-22 13:24 - 2014-02-08 19:27 - 01049888 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco3233489.dll 2014-02-22 13:24 - 2014-02-08 19:27 - 00895264 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco3233489.dll 2014-02-22 13:24 - 2014-02-08 19:27 - 00863520 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR.dll 2014-02-22 13:24 - 2014-02-08 19:27 - 00844576 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC.dll 2014-02-22 13:24 - 2014-02-08 19:27 - 00408352 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI.dll 2014-02-22 13:24 - 2014-02-08 19:27 - 00333600 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2014-02-22 13:24 - 2014-02-08 19:27 - 00305600 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim32.dll 2014-02-22 13:24 - 2014-02-08 19:27 - 00148528 _____ (NVIDIA Corporation) C:\Windows\system32\nvinit.dll 2014-02-22 13:24 - 2013-12-27 19:42 - 00034080 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad32v.sys 2014-02-22 13:24 - 2013-12-27 19:42 - 00033056 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap32v.dll 2014-02-22 13:23 - 2014-02-22 13:23 - 00000000 ____D () C:\NVIDIA 2014-02-22 13:19 - 2014-02-22 13:23 - 219694912 _____ (NVIDIA Corporation) C:\Users\Mario\Downloads\334.89-desktop-win8-win7-winvista-32bit-international-whql.exe 2014-02-22 13:05 - 2014-02-22 13:05 - 00086860 _____ () C:\Users\Mario\Documents\cc_20140222_130519.reg 2014-02-22 13:05 - 2014-02-22 13:05 - 00000422 _____ () C:\Users\Mario\Documents\cc_20140222_130544.reg 2014-02-22 13:03 - 2014-02-22 13:03 - 03645064 _____ (Piriform Ltd) C:\Users\Mario\Downloads\ccsetup410_slim.exe 2014-02-22 13:03 - 2014-02-22 13:03 - 00000969 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-02-22 13:03 - 2014-02-22 13:03 - 00000000 ____D () C:\Program Files\CCleaner 2014-02-22 12:30 - 2014-02-22 12:30 - 10255080 _____ (Lavalys, Inc. ) C:\Users\Mario\Downloads\everestultimate550.exe 2014-02-17 00:23 - 2014-02-17 00:25 - 90396104 _____ (The GIMP Team ) C:\Users\Mario\Downloads\gimp-2.8.10-setup.exe 2014-02-14 16:24 - 2014-02-14 16:24 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-02-07 15:10 - 2013-12-19 21:26 - 01049888 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco3233221.dll 2014-02-07 15:10 - 2013-12-19 21:26 - 00893728 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco3233221.dll 2014-02-07 15:10 - 2013-11-28 14:38 - 00162592 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda32v.sys 2014-02-07 15:10 - 2013-11-28 14:38 - 00028448 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap32.dll 2014-02-07 15:04 - 2014-02-08 12:07 - 00000000 ____D () C:\Users\Mario\AppData\Local\NVIDIA Corporation 2014-02-06 23:59 - 2014-02-07 00:00 - 31475128 _____ (NVIDIA Corporation) C:\Users\Mario\Downloads\GeForce_Experience_v1.8.2.0.exe 2014-02-02 16:19 - 2014-02-02 16:19 - 00000000 ____D () C:\Users\Mario\AppData\Local\Blizzard 2014-02-02 15:52 - 2014-02-22 12:36 - 00000000 ____D () C:\Users\Mario\AppData\Local\Battle.net 2014-02-02 15:52 - 2014-02-07 00:24 - 00000000 ____D () C:\Users\Mario\AppData\Roaming\Battle.net 2014-02-02 15:52 - 2014-02-02 15:52 - 00000795 _____ () C:\Users\Public\Desktop\Battle.net.lnk 2014-02-02 15:49 - 2014-02-02 15:49 - 05971128 _____ (Blizzard Entertainment) C:\Users\Mario\Downloads\Hearthstone-Beta-Setup-deDE.exe 2014-02-01 00:11 - 2014-02-01 00:17 - 70803920 _____ () C:\Users\Mario\ts3_recording_14_02_01_0_11_21.wav ==================== One Month Modified Files and Folders ======= 2014-02-23 11:41 - 2014-02-23 11:40 - 00020945 _____ () C:\Users\Mario\Desktop\FRST.txt 2014-02-23 11:40 - 2014-02-23 11:40 - 01142784 _____ (Farbar) C:\Users\Mario\Desktop\FRST.exe 2014-02-23 11:40 - 2014-02-23 11:40 - 00000000 ____D () C:\FRST 2014-02-23 11:35 - 2014-02-23 10:55 - 00000000 ____D () C:\Users\Mario\Desktop\vw 2014-02-23 11:00 - 2013-05-29 15:15 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-02-23 10:48 - 2009-07-14 05:34 - 00014800 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-02-23 10:48 - 2009-07-14 05:34 - 00014800 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-02-23 10:47 - 2010-11-12 13:16 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-23 10:45 - 2013-01-20 19:26 - 00290255 _____ () C:\Windows\WindowsUpdate.log 2014-02-23 10:41 - 2013-06-11 18:28 - 00000000 ____D () C:\Users\Mario\AppData\Roaming\Spotify 2014-02-23 10:41 - 2010-11-12 16:45 - 00000000 ____D () C:\Users\Mario\AppData\Local\Deployment 2014-02-23 10:40 - 2014-02-22 19:26 - 00000840 _____ () C:\Windows\setupact.log 2014-02-23 10:40 - 2013-03-18 16:29 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-02-23 10:40 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-22 23:21 - 2014-02-22 23:20 - 00005384 _____ () C:\Windows\system32\jupdate-1.7.0_51-b13.log 2014-02-22 23:21 - 2013-10-17 19:27 - 00000000 ____D () C:\ProgramData\Oracle 2014-02-22 23:21 - 2011-11-23 15:02 - 00000000 ____D () C:\Program Files\Java 2014-02-22 23:05 - 2012-12-10 16:38 - 00000000 ____D () C:\Users\Mario\AppData\Roaming\Skype 2014-02-22 22:56 - 2010-11-14 17:02 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information 2014-02-22 22:40 - 2010-11-12 13:12 - 00000000 ____D () C:\Users\Mario 2014-02-22 19:39 - 2014-02-22 19:33 - 00000000 ____D () C:\AdwCleaner 2014-02-22 19:26 - 2014-02-22 19:26 - 00000510 _____ () C:\Windows\PFRO.log 2014-02-22 19:26 - 2014-02-22 19:26 - 00000000 _____ () C:\Windows\setuperr.log 2014-02-22 19:25 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Help 2014-02-22 17:43 - 2014-02-22 17:43 - 00017338 _____ () C:\Users\Mario\Documents\cc_20140222_174319.reg 2014-02-22 17:22 - 2011-12-14 13:45 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-02-22 14:24 - 2014-02-22 14:24 - 00000000 ____D () C:\Program Files\Microsoft CAPICOM 2.1.0.2 2014-02-22 14:05 - 2014-02-22 14:05 - 00001912 _____ () C:\Windows\epplauncher.mif 2014-02-22 14:05 - 2014-02-22 14:05 - 00000000 ____D () C:\Program Files\Microsoft Security Client 2014-02-22 14:04 - 2014-02-22 14:04 - 11157328 _____ (Microsoft Corporation) C:\Users\Mario\Downloads\mseinstall.exe 2014-02-22 14:01 - 2013-12-24 21:57 - 00000000 ____D () C:\Users\Mario\Desktop\Fix it 2014-02-22 13:54 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system 2014-02-22 13:41 - 2014-02-22 13:41 - 01241834 _____ () C:\Users\Mario\Downloads\adwcleaner.exe 2014-02-22 13:40 - 2014-02-22 13:40 - 00001071 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-02-22 13:40 - 2014-02-22 13:40 - 00000000 ____D () C:\Users\Mario\AppData\Roaming\Malwarebytes 2014-02-22 13:40 - 2014-02-22 13:40 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware 2014-02-22 13:39 - 2014-02-22 13:39 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Mario\Downloads\mbam-setup-1.75.0.1300.exe 2014-02-22 13:27 - 2014-02-22 13:27 - 00001309 _____ () C:\Users\Public\Desktop\GeForce Experience.lnk 2014-02-22 13:27 - 2014-02-22 13:26 - 00000000 ____D () C:\Users\Mario\AppData\Local\NVIDIA 2014-02-22 13:27 - 2013-03-18 16:29 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2014-02-22 13:26 - 2014-02-22 13:26 - 00000000 ____D () C:\Program Files\AGEIA Technologies 2014-02-22 13:26 - 2013-03-18 16:29 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-02-22 13:26 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-02-22 13:23 - 2014-02-22 13:23 - 00000000 ____D () C:\NVIDIA 2014-02-22 13:23 - 2014-02-22 13:19 - 219694912 _____ (NVIDIA Corporation) C:\Users\Mario\Downloads\334.89-desktop-win8-win7-winvista-32bit-international-whql.exe 2014-02-22 13:05 - 2014-02-22 13:05 - 00086860 _____ () C:\Users\Mario\Documents\cc_20140222_130519.reg 2014-02-22 13:05 - 2014-02-22 13:05 - 00000422 _____ () C:\Users\Mario\Documents\cc_20140222_130544.reg 2014-02-22 13:04 - 2011-10-13 18:02 - 00000000 ____D () C:\Windows\Minidump 2014-02-22 13:04 - 2010-11-19 13:38 - 00000000 ____D () C:\Users\Mario\AppData\Roaming\TS3Client 2014-02-22 13:03 - 2014-02-22 13:03 - 03645064 _____ (Piriform Ltd) C:\Users\Mario\Downloads\ccsetup410_slim.exe 2014-02-22 13:03 - 2014-02-22 13:03 - 00000969 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-02-22 13:03 - 2014-02-22 13:03 - 00000000 ____D () C:\Program Files\CCleaner 2014-02-22 12:38 - 2010-11-17 14:02 - 00000000 ____D () C:\Program Files\Common Files\Blizzard Entertainment 2014-02-22 12:36 - 2014-02-02 15:52 - 00000000 ____D () C:\Users\Mario\AppData\Local\Battle.net 2014-02-22 12:30 - 2014-02-22 12:30 - 10255080 _____ (Lavalys, Inc. ) C:\Users\Mario\Downloads\everestultimate550.exe 2014-02-22 00:54 - 2012-08-27 23:27 - 00000000 ____D () C:\World of Warcraft 2014-02-21 22:59 - 2011-11-09 17:09 - 00000000 ____D () C:\Program Files\Common Files\Steam 2014-02-20 21:00 - 2012-10-11 19:05 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-02-20 21:00 - 2012-02-05 12:44 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-02-17 00:25 - 2014-02-17 00:23 - 90396104 _____ (The GIMP Team ) C:\Users\Mario\Downloads\gimp-2.8.10-setup.exe 2014-02-15 19:34 - 2012-05-02 14:39 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-02-14 16:24 - 2014-02-14 16:24 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-02-14 01:04 - 2013-08-15 22:09 - 00000000 ____D () C:\Windows\system32\MRT 2014-02-14 01:04 - 2010-11-16 20:41 - 85946576 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-02-08 19:27 - 2014-02-22 13:24 - 23683360 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv32.dll 2014-02-08 19:27 - 2014-02-22 13:24 - 17560352 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2014-02-08 19:27 - 2014-02-22 13:24 - 10180896 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2014-02-08 19:27 - 2014-02-22 13:24 - 09728064 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2014-02-08 19:27 - 2014-02-22 13:24 - 09690424 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2014-02-08 19:27 - 2014-02-22 13:24 - 02956576 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2014-02-08 19:27 - 2014-02-22 13:24 - 02410784 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2014-02-08 19:27 - 2014-02-22 13:24 - 01049888 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco3233489.dll 2014-02-08 19:27 - 2014-02-22 13:24 - 00895264 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco3233489.dll 2014-02-08 19:27 - 2014-02-22 13:24 - 00863520 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR.dll 2014-02-08 19:27 - 2014-02-22 13:24 - 00844576 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC.dll 2014-02-08 19:27 - 2014-02-22 13:24 - 00408352 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI.dll 2014-02-08 19:27 - 2014-02-22 13:24 - 00333600 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2014-02-08 19:27 - 2014-02-22 13:24 - 00305600 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim32.dll 2014-02-08 19:27 - 2014-02-22 13:24 - 00148528 _____ (NVIDIA Corporation) C:\Windows\system32\nvinit.dll 2014-02-08 19:27 - 2013-03-18 17:48 - 14669032 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dum.dll 2014-02-08 19:27 - 2013-03-18 16:29 - 15740232 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2um.dll 2014-02-08 19:27 - 2013-03-18 16:29 - 02713728 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi.dll 2014-02-08 19:27 - 2013-03-18 16:29 - 00832424 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshim.dll 2014-02-08 19:27 - 2013-03-18 16:29 - 00019204 _____ () C:\Windows\system32\nvinfo.pb 2014-02-08 19:27 - 2012-07-04 02:30 - 00053024 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2014-02-08 18:11 - 2013-03-18 16:29 - 04348704 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2014-02-08 18:11 - 2013-03-18 16:29 - 03045664 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc.dll 2014-02-08 18:11 - 2013-03-18 16:29 - 02555168 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2014-02-08 18:11 - 2013-03-18 16:29 - 00664864 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2014-02-08 18:11 - 2013-03-18 16:29 - 00376096 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2014-02-08 18:11 - 2013-03-18 16:29 - 00062752 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2014-02-08 17:18 - 2014-02-22 13:25 - 00599840 _____ (NVIDIA Corporation) C:\Windows\system32\nvStreaming.exe 2014-02-08 12:07 - 2014-02-07 15:04 - 00000000 ____D () C:\Users\Mario\AppData\Local\NVIDIA Corporation 2014-02-07 00:24 - 2014-02-02 15:52 - 00000000 ____D () C:\Users\Mario\AppData\Roaming\Battle.net 2014-02-07 00:00 - 2014-02-06 23:59 - 31475128 _____ (NVIDIA Corporation) C:\Users\Mario\Downloads\GeForce_Experience_v1.8.2.0.exe 2014-02-05 10:31 - 2014-02-22 13:26 - 01048152 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap.dll 2014-02-04 15:49 - 2013-03-18 16:29 - 03573739 _____ () C:\Windows\system32\nvcoproc.bin 2014-02-02 16:19 - 2014-02-02 16:19 - 00000000 ____D () C:\Users\Mario\AppData\Local\Blizzard 2014-02-02 15:52 - 2014-02-02 15:52 - 00000795 _____ () C:\Users\Public\Desktop\Battle.net.lnk 2014-02-02 15:49 - 2014-02-02 15:49 - 05971128 _____ (Blizzard Entertainment) C:\Users\Mario\Downloads\Hearthstone-Beta-Setup-deDE.exe 2014-02-01 00:17 - 2014-02-01 00:11 - 70803920 _____ () C:\Users\Mario\ts3_recording_14_02_01_0_11_21.wav 2014-01-26 20:42 - 2013-06-11 18:33 - 00000000 ____D () C:\Users\Mario\AppData\Local\Spotify Some content of TEMP: ==================== C:\Users\Mario\AppData\Local\Temp\avgnt.exe C:\Users\Mario\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\Mario\AppData\Local\Temp\nvStInst.exe C:\Users\Mario\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\system32\winlogon.exe => MD5 is legit C:\Windows\system32\wininit.exe => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\services.exe => MD5 is legit C:\Windows\system32\User32.dll => MD5 is legit C:\Windows\system32\userinit.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-18 16:00 ==================== End Of Log ============================ --- --- --- --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 22-02-2014 01 Ran by Mario at 2014-02-23 11:41:12 Running from C:\Users\Mario\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} ==================== Installed Programs ====================== @BIOS (HKLM\...\{B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83}) (Version: 2.28 - GIGABYTE) 7-Zip 9.20 (HKLM\...\7-Zip) (Version: - ) Adobe Flash Player 12 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 12.0.0.70 - Adobe Systems Incorporated) Adobe Flash Player 12 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 12.0.0.70 - Adobe Systems Incorporated) AION Free-To-Play (Version: 2.70.0000 - Gameforge) Hidden Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.7 - Atheros Communications Inc.) AutoGreen B12.0206.1 (HKLM\...\InstallShield_{C75FAD21-EC08-42F3-92D6-C9C0AB355345}) (Version: 1.00.0000 - GIGABYTE) AutoGreen B12.0206.1 (Version: 1.00.0000 - GIGABYTE) Hidden Avira Free Antivirus (HKLM\...\Avira AntiVir Desktop) (Version: 14.0.3.338 - Avira) Avira SearchFree Toolbar (HKLM\...\{41564952-412D-5637-00A7-A758B70C0A03}) (Version: 12.10.3.4487 - APN, LLC) Battle.net (HKLM\...\Battle.net) (Version: - Blizzard Entertainment) Call of Duty: Modern Warfare 3 - Multiplayer (HKLM\...\Steam App 42690) (Version: - Infinity Ward) CameraHelperMsi (Version: 13.51.815.0 - Logitech) Hidden CCleaner (HKLM\...\CCleaner) (Version: 4.10 - Piriform) Curse Client (HKCU\...\101a9f93b8f0bb6f) (Version: 5.1.1.792 - Curse) erLT (Version: 1.20.138.34 - Logitech, Inc.) Hidden Foxit Reader (HKLM\...\Foxit Reader_is1) (Version: 5.4.4.1023 - Foxit Corporation) GeForce Experience NvStream Client Components (Version: 1.6.28 - NVIDIA Corporation) Hidden HitmanPro 3.7 (HKLM\...\HitmanPro37) (Version: 3.7.9.212 - SurfRight B.V.) HP Officejet 6500 E710a-f - Grundlegende Software für das Gerät (HKLM\...\{FBBA35E1-9449-4902-8A0F-89252C0C1407}) (Version: 22.50.231.0 - Hewlett-Packard Co.) HP Officejet 6500 E710a-f Hilfe (HKLM\...\{037CD593-D760-4A00-B030-7BBAFA1123FE}) (Version: 140.0.2.2 - Hewlett Packard) HP Update (HKLM\...\{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}) (Version: 5.002.006.003 - Hewlett-Packard) I.R.I.S. OCR (HKLM\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP) Intel(R) Management Engine Components (HKLM\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.5.235 - Intel Corporation) Intel® Trusted Connect Service Client (Version: 1.24.388.1 - Intel Corporation) Hidden Internet Explorer (Version: 9 - Microsoft Corporation) Hidden Java 7 Update 51 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.510 - Oracle) Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Java(TM) 6 Update 29 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83216029FF}) (Version: 6.0.290 - Oracle) Kies Air Discovery Service (HKCU\...\Kies Air Discovery Service) (Version: - Samsung) Logitech Webcam-Software (HKLM\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.51 - Logitech Inc.) LWS Facebook (Version: 13.50.854.0 - Logitech) Hidden LWS Gallery (Version: 13.51.827.0 - Logitech) Hidden LWS Help_main (Version: 13.51.828.0 - Logitech) Hidden LWS Launcher (Version: 13.51.828.0 - Logitech) Hidden LWS Motion Detection (Version: 13.51.815.0 - Logitech) Hidden LWS Pictures And Video (Version: 13.51.815.0 - Logitech) Hidden LWS Twitter (Version: 13.30.1346.0 - Logitech) Hidden LWS Webcam Software (Version: 13.51.815.0 - Logitech) Hidden LWS WLM Plugin (Version: 1.30.1201.0 - Logitech) Hidden LWS YouTube Plugin (Version: 13.31.1038.0 - Logitech) Hidden Malwarebytes Anti-Malware Version 1.75.0.1300 (HKLM\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation) Marketsplash Schnellzugriffe (HKLM\...\{7A108EBC-C9DF-4E14-93A8-42CF316F1ECF}) (Version: 1.0.1.7 - Hewlett-Packard) Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Extended DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Extended DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Office Word Viewer 2003 (HKLM\...\{90850407-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation) Microsoft Security Client (Version: 4.4.0304.0 - Microsoft Corporation) Hidden Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.4.304.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Mozilla Firefox 27.0.1 (x86 de) (HKLM\...\Mozilla Firefox 27.0.1 (x86 de)) (Version: 27.0.1 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 27.0.1 - Mozilla) Need For Speed™ World (HKLM\...\{7B2CC3DF-64FA-44AE-8F57-B0F915147E4F}_is1) (Version: 1.0.0.1599 - Electronic Arts) NVIDIA 3D Vision Controller-Treiber 334.89 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 334.89 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 334.89 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 334.89 - NVIDIA Corporation) NVIDIA GeForce Experience 1.8.2.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 1.8.2.1 - NVIDIA Corporation) NVIDIA Grafiktreiber 334.89 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 334.89 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.30.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.147.1067 - NVIDIA Corporation) Hidden NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA PhysX (Version: 9.13.1220 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation) NVIDIA ShadowPlay 11.10.13 (Version: 11.10.13 - NVIDIA Corporation) Hidden NVIDIA Stereoscopic 3D Driver (Version: 7.17.13.3489 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 334.89 (Version: 334.89 - NVIDIA Corporation) Hidden NVIDIA Update 11.10.13 (Version: 11.10.13 - NVIDIA Corporation) Hidden NVIDIA Update Core (Version: 11.10.13 - NVIDIA Corporation) Hidden NVIDIA Virtual Audio 1.2.20 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver) (Version: 1.2.20 - NVIDIA Corporation) ON_OFF Charge B11.1102.1 (HKLM\...\{3DECD372-76A1-4483-BF10-B547790A3261}) (Version: 1.00.0001 - GIGABYTE) OpenOffice.org 3.4.1 (HKLM\...\{2303AEEA-0FA8-4AFD-80A9-8F86BA4B44D2}) (Version: 3.41.9593 - Apache Software Foundation) Platform (Version: 1.39 - VIA Technologies, Inc.) Hidden Samsung SSD Magician (HKLM\...\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 3.2 - Samsung Electronics) SHIELD Streaming (Version: 1.7.321 - NVIDIA Corporation) Hidden Skype™ 6.3 (HKLM\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.3.107 - Skype Technologies S.A.) Speccy (HKLM\...\Speccy) (Version: 1.21 - Piriform) Spotify (HKCU\...\Spotify) (Version: 0.9.7.16.g4b197456 - Spotify AB) Steam (HKLM\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) Studie zur Verbesserung von HP Officejet 6500 E710a-f Produkten (HKLM\...\{01E6B88D-32B1-4848-9AC7-7E2CB093EF04}) (Version: 22.50.231.0 - Hewlett-Packard Co.) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.12 - TeamSpeak Systems GmbH) Thunder Master v1.9 (HKLM\...\{EE04522C-0814-4B63-AE57-0B63E5A355BB}_is1) (Version: 1.9.3.2 - Palit Microsystems Ltd.) VIA Plattform-Geräte-Manager (HKLM\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.39 - VIA Technologies, Inc.) WinRAR 4.11 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 4.11.0 - win.rar GmbH) World of Warcraft (HKLM\...\World of Warcraft) (Version: - Blizzard Entertainment) ==================== Restore Points ========================= ==================== Hosts content: ========================== 2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {0CBC0CF7-1CB2-406C-9E60-6E7F67ABC90B} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-01-21] (Piriform Ltd) Task: {1C58669A-B812-4672-978D-CB6ADD9B573C} - System32\Tasks\{A6C07F54-5CB9-451F-9AB4-8AAE1B719613} => C:\Program Files\EA GAMES\Die Sims 2\TSBin\Sims2.exe Task: {34096CB3-EFFE-4D0B-AB9B-332CB9306FB3} - System32\Tasks\{FD1EA96D-7B60-4D2B-B33E-68B97241E253} => C:\Program Files\Skype\\Phone\Skype.exe [2013-04-19] (Skype Technologies S.A.) Task: {45285473-60FC-4FD2-94E7-DDD322627447} - System32\Tasks\Java Update Scheduler => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation) Task: {50A57AF3-09DF-4FE6-B87E-44D240B54862} - System32\Tasks\{1D86914E-4CD6-43AE-8A75-1A7184771723} => C:\Program Files\EA GAMES\Die Sims 2\TSBin\Sims2.exe Task: {58507185-2C2B-4662-90A6-B965B8A06532} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-02-20] (Adobe Systems Incorporated) Task: {6481328E-6EF1-4BF6-9D9A-8D3ED813A84F} - System32\Tasks\{3EF631C1-295D-438F-A8E9-BABE090E2EF6} => C:\Program Files\EA GAMES\Die Sims 2\TSBin\Sims2.exe Task: {9C768F5A-89B0-40A0-AD9E-D1FCC49AC932} - System32\Tasks\{F563DFC5-F7B1-4E52-83D3-34525A355BDA} => C:\Program Files\EA GAMES\Die Sims 2\TSBin\Sims2.exe Task: {A02AC012-D6E9-402B-B032-C44B79FC4761} - System32\Tasks\Ad-Aware Antivirus Scheduled Scan => C:\PROGRA~1\AD-AWA~1\AdAwareLauncher.exe Task: {B341B572-8968-4AA5-8028-729D7190DACA} - System32\Tasks\HP-Online-Aktualisierungsprogramm => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2010-06-09] (Hewlett-Packard) Task: {C3118BC1-2E91-460D-A062-FA7C77F94096} - System32\Tasks\{0658F451-3B4C-4D77-B685-C6F6BD4BC56E} => C:\Program Files\EA GAMES\Die Sims 2\TSBin\Sims2.exe Task: {D9E6BC88-C24D-41CC-9068-1DD133839247} - System32\Tasks\{C7A4D741-02B5-4B53-9876-D805AC59ED38} => C:\Program Files\EA GAMES\Die Sims 2\TSBin\Sims2.exe Task: {EFB863A4-144C-4E2C-80C4-F529B579BDCD} - System32\Tasks\HPCustParticipation HP Officejet 6500 E710a-f => C:\Program Files\HP\HP Officejet 6500 E710a-f\Bin\HPCustPartic.exe [2010-11-16] (Hewlett-Packard Co.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2013-03-18 16:29 - 2014-02-08 18:11 - 00107808 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll 2013-08-05 21:18 - 2013-08-05 21:14 - 00394824 _____ () C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll 2012-12-27 19:34 - 2013-03-19 19:40 - 00076888 _____ () C:\Windows\system32\PnkBstrA.exe 2013-03-18 16:17 - 2012-08-09 11:53 - 00080528 ____R () C:\Program Files\VIA\VIAudioi\VDeck\QsApoApi.dll 2013-03-18 16:17 - 2012-08-09 11:53 - 00113296 ____R () C:\Program Files\VIA\VIAudioi\VDeck\Dts2ApoApi.dll 2012-09-13 00:38 - 2012-09-13 00:38 - 02144104 _____ () C:\Program Files\Logitech\LWS\Webcam Software\QtCore4.dll 2012-09-13 00:38 - 2012-09-13 00:38 - 07955304 _____ () C:\Program Files\Logitech\LWS\Webcam Software\QtGui4.dll 2012-09-13 00:38 - 2012-09-13 00:38 - 00341352 _____ () C:\Program Files\Logitech\LWS\Webcam Software\QtXml4.dll 2012-09-13 00:38 - 2012-09-13 00:38 - 00028008 _____ () C:\Program Files\Logitech\LWS\Webcam Software\imageformats\QGif4.dll 2012-09-13 00:38 - 2012-09-13 00:38 - 00127336 _____ () C:\Program Files\Logitech\LWS\Webcam Software\imageformats\QJpeg4.dll 2013-05-20 18:32 - 2013-05-20 18:32 - 00035840 ____N () C:\Users\Mario\AppData\Local\Apps\2.0\BOAV3H5H.VNM\BJ4V8M56.TLY\curs..tion_9e9e83ddf3ed3ead_0005.0001_181b5e0542e9eb6c\Curse.Advertising.dll 2013-05-20 18:32 - 2013-05-20 18:32 - 00014848 ____N () C:\Users\Mario\AppData\Local\Apps\2.0\BOAV3H5H.VNM\BJ4V8M56.TLY\curs..tion_9e9e83ddf3ed3ead_0005.0001_181b5e0542e9eb6c\Curse.CurseClient.WowDb.dll 2013-05-20 18:32 - 2013-05-20 18:31 - 00099840 ____N () C:\Users\Mario\AppData\Local\Apps\2.0\BOAV3H5H.VNM\BJ4V8M56.TLY\curs..tion_9e9e83ddf3ed3ead_0005.0001_181b5e0542e9eb6c\Curse.CurseClient.CMOD2.dll 2012-08-10 15:51 - 2012-08-10 15:51 - 00985088 _____ () C:\Program Files\OpenOffice.org 3\program\libxml2.dll 2012-08-10 15:50 - 2012-08-10 15:50 - 00170496 _____ () C:\Program Files\OpenOffice.org 3\program\libxslt.dll 2013-03-18 16:17 - 2012-06-25 10:41 - 01198912 _____ () C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\ACE.dll 2014-02-14 16:24 - 2014-02-14 16:24 - 03578992 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll 2014-02-20 21:00 - 2014-02-20 21:00 - 16265096 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_70.dll 2012-05-02 13:20 - 2012-02-17 19:55 - 00166912 _____ () C:\Program Files\WinRAR\rarext.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\45708424.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\45708424.sys => ""="Driver" ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= Name: SBRE Description: SBRE Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: SBRE Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Event log errors: ========================= Application errors: ================== Error: (02/23/2014 11:39:22 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17514, Zeitstempel: 0x4ce796f3 Name des fehlerhaften Moduls: werconcpl.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7ba2a Ausnahmecode: 0xc0000409 Fehleroffset: 0x00021f76 ID des fehlerhaften Prozesses: 0x99c Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Error: (02/23/2014 11:37:10 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17514, Zeitstempel: 0x4ce796f3 Name des fehlerhaften Moduls: werconcpl.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7ba2a Ausnahmecode: 0xc0000409 Fehleroffset: 0x00021f76 ID des fehlerhaften Prozesses: 0xda8 Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Error: (02/23/2014 11:34:56 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17514, Zeitstempel: 0x4ce796f3 Name des fehlerhaften Moduls: werconcpl.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7ba2a Ausnahmecode: 0xc0000409 Fehleroffset: 0x00021f76 ID des fehlerhaften Prozesses: 0x1404 Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Error: (02/23/2014 11:32:36 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17514, Zeitstempel: 0x4ce796f3 Name des fehlerhaften Moduls: werconcpl.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7ba2a Ausnahmecode: 0xc0000409 Fehleroffset: 0x00021f76 ID des fehlerhaften Prozesses: 0x1554 Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Error: (02/23/2014 10:59:33 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17514, Zeitstempel: 0x4ce796f3 Name des fehlerhaften Moduls: werconcpl.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7ba2a Ausnahmecode: 0xc0000409 Fehleroffset: 0x00021f76 ID des fehlerhaften Prozesses: 0xd4c Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Error: (02/23/2014 10:57:21 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17514, Zeitstempel: 0x4ce796f3 Name des fehlerhaften Moduls: werconcpl.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7ba2a Ausnahmecode: 0xc0000409 Fehleroffset: 0x00021f76 ID des fehlerhaften Prozesses: 0x16a4 Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Error: (02/23/2014 10:55:09 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17514, Zeitstempel: 0x4ce796f3 Name des fehlerhaften Moduls: werconcpl.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7ba2a Ausnahmecode: 0xc0000409 Fehleroffset: 0x00021f76 ID des fehlerhaften Prozesses: 0x404 Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Error: (02/23/2014 10:52:55 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17514, Zeitstempel: 0x4ce796f3 Name des fehlerhaften Moduls: werconcpl.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7ba2a Ausnahmecode: 0xc0000409 Fehleroffset: 0x00021f76 ID des fehlerhaften Prozesses: 0x174c Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Error: (02/23/2014 10:50:37 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17514, Zeitstempel: 0x4ce796f3 Name des fehlerhaften Moduls: werconcpl.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7ba2a Ausnahmecode: 0xc0000409 Fehleroffset: 0x00021f76 ID des fehlerhaften Prozesses: 0x11dc Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Error: (02/23/2014 10:48:23 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17514, Zeitstempel: 0x4ce796f3 Name des fehlerhaften Moduls: werconcpl.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7ba2a Ausnahmecode: 0xc0000409 Fehleroffset: 0x00021f76 ID des fehlerhaften Prozesses: 0x1460 Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 System errors: ============= Error: (02/23/2014 10:41:44 AM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: SBRE Error: (02/22/2014 11:22:41 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Microsoft Visual C++ 2008 Service Pack 1 Redistributable Package (KB2538243) Error: (02/22/2014 08:07:19 PM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: SBRE Error: (02/22/2014 07:53:33 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Microsoft Visual C++ 2008 Service Pack 1 Redistributable Package (KB2538243) Error: (02/22/2014 07:40:49 PM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: SBRE Error: (02/22/2014 07:36:19 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Microsoft-Netzwerkinspektion" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (02/22/2014 07:36:19 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NisSrv" konnte sich nicht als "NT AUTHORITY\LocalService" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%50 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (02/22/2014 07:36:19 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Error: (02/22/2014 07:36:19 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "netprofm" konnte sich nicht als "NT AUTHORITY\LocalService" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: %%50 Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC). Error: (02/22/2014 07:36:19 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Diagnosediensthost" wurde aufgrund folgenden Fehlers nicht gestartet: %%1069 Microsoft Office Sessions: ========================= Error: (02/23/2014 11:39:22 AM) (Source: Application Error)(User: ) Description: Explorer.EXE6.1.7601.175144ce796f3werconcpl.dll6.1.7601.175144ce7ba2ac000040900021f7699c01cf3083380a125eC:\Windows\Explorer.EXEC:\Windows\System32\werconcpl.dllc188300e-9c76-11e3-babe-00040efeb603 Error: (02/23/2014 11:37:10 AM) (Source: Application Error)(User: ) Description: Explorer.EXE6.1.7601.175144ce796f3werconcpl.dll6.1.7601.175144ce7ba2ac000040900021f76da801cf3082e894249cC:\Windows\Explorer.EXEC:\Windows\System32\werconcpl.dll72d5d3c9-9c76-11e3-babe-00040efeb603 Error: (02/23/2014 11:34:56 AM) (Source: Application Error)(User: ) Description: Explorer.EXE6.1.7601.175144ce796f3werconcpl.dll6.1.7601.175144ce7ba2ac000040900021f76140401cf308298c52948C:\Windows\Explorer.EXEC:\Windows\System32\werconcpl.dll22fd2c7c-9c76-11e3-babe-00040efeb603 Error: (02/23/2014 11:32:36 AM) (Source: Application Error)(User: ) Description: Explorer.EXE6.1.7601.175144ce796f3werconcpl.dll6.1.7601.175144ce7ba2ac000040900021f76155401cf308245bd1bf6C:\Windows\Explorer.EXEC:\Windows\System32\werconcpl.dllcf85b1e5-9c75-11e3-babe-00040efeb603 Error: (02/23/2014 10:59:33 AM) (Source: Application Error)(User: ) Description: Explorer.EXE6.1.7601.175144ce796f3werconcpl.dll6.1.7601.175144ce7ba2ac000040900021f76d4c01cf307da7ea47feC:\Windows\Explorer.EXEC:\Windows\System32\werconcpl.dll318ecb7e-9c71-11e3-babe-00040efeb603 Error: (02/23/2014 10:57:21 AM) (Source: Application Error)(User: ) Description: Explorer.EXE6.1.7601.175144ce796f3werconcpl.dll6.1.7601.175144ce7ba2ac000040900021f7616a401cf307d593c08e7C:\Windows\Explorer.EXEC:\Windows\System32\werconcpl.dlle2dfc10e-9c70-11e3-babe-00040efeb603 Error: (02/23/2014 10:55:09 AM) (Source: Application Error)(User: ) Description: Explorer.EXE6.1.7601.175144ce796f3werconcpl.dll6.1.7601.175144ce7ba2ac000040900021f7640401cf307d09c460beC:\Windows\Explorer.EXEC:\Windows\System32\werconcpl.dll943765d7-9c70-11e3-babe-00040efeb603 Error: (02/23/2014 10:52:55 AM) (Source: Application Error)(User: ) Description: Explorer.EXE6.1.7601.175144ce796f3werconcpl.dll6.1.7601.175144ce7ba2ac000040900021f76174c01cf307cba209427C:\Windows\Explorer.EXEC:\Windows\System32\werconcpl.dll445aba44-9c70-11e3-babe-00040efeb603 Error: (02/23/2014 10:50:37 AM) (Source: Application Error)(User: ) Description: Explorer.EXE6.1.7601.175144ce796f3werconcpl.dll6.1.7601.175144ce7ba2ac000040900021f7611dc01cf307c689b6723C:\Windows\Explorer.EXEC:\Windows\System32\werconcpl.dllf213e03f-9c6f-11e3-babe-00040efeb603 Error: (02/23/2014 10:48:23 AM) (Source: Application Error)(User: ) Description: Explorer.EXE6.1.7601.175144ce796f3werconcpl.dll6.1.7601.175144ce7ba2ac000040900021f76146001cf307c17dd528aC:\Windows\Explorer.EXEC:\Windows\System32\werconcpl.dlla23c545b-9c6f-11e3-babe-00040efeb603 ==================== Memory info =========================== Percentage of memory in use: 49% Total physical RAM: 3561.11 MB Available physical RAM: 1791.97 MB Total Pagefile: 7120.5 MB Available Pagefile: 4927.68 MB Total Virtual: 2047.88 MB Available Virtual: 1869.91 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:111.79 GB) (Free:58.49 GB) NTFS Drive e: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive f: () (Fixed) (Total:148.94 GB) (Free:131.13 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 112 GB) (Disk ID: 32FC8ABD) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=112 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 149 GB) (Disk ID: 28B227B6) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=149 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=10 MB) - (Type=17) ATTENTION ===> Suspicious partition bootkit on partition 3 ==================== End Of Log ============================ Mfg. |
24.02.2014, 18:35 | #4 |
/// the machine /// TB-Ausbilder | Wartungscenter und Windows Explorer funktionieren nicht mehr! melde dich wenn nicht
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
25.02.2014, 15:40 | #5 |
| Wartungscenter und Windows Explorer funktionieren nicht mehr! Würde nur gerne wissen ob man was in den Logfiles erkennt, ob da etwas nicht stimmt, oder alles in Ordnung ist. Mfg |
26.02.2014, 14:19 | #6 |
/// the machine /// TB-Ausbilder | Wartungscenter und Windows Explorer funktionieren nicht mehr! Logs sehen gut aus.
__________________ --> Wartungscenter und Windows Explorer funktionieren nicht mehr! |
Themen zu Wartungscenter und Windows Explorer funktionieren nicht mehr! |
adware, allgemein, avira, dienst, explorer, explorer funktioniert nicht, fehlermeldung, folge, folgendes, funktionieren, funktioniert, funktioniert nicht, funktioniert nicht mehr, hallo zusammen, heute, langsamer, malwarebytes, neu, nicht mehr, nichts, problem, programme, schuld, systemsteuerung, werconcpl.dll, windows, windows explorer, zusammen |