|
Plagegeister aller Art und deren Bekämpfung: Windows 7: Mozilla stürzt ab und es erscheint ein BluescreenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
12.04.2014, 08:49 | #1 |
| Windows 7: Mozilla stürzt ab und es erscheint ein Bluescreen Hallo, ich habe folgendes Problem: Mozilla Firefox bleibt oft stecken, nach einer gewissen Zeit stürzt der PC vollkommen ab und es erscheint ein Bluescreen. Ich wollte alles in der Anweisung für Hilfesuchende befolgen, jedoch bekam ich mehrere Fehlermeldungen als ich mein System mit FRST scannen wollte und es erschien wieder ein Bluescreen. Ich habe mein System mit Microsoft Security Essentials und Malwarebytes gescannt. MSE hat keine Viren entdeckt, bei Malwarebytes ist es zum Absturz gekommen. |
12.04.2014, 13:57 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows 7: Mozilla stürzt ab und es erscheint ein Bluescreen Hi,
__________________Scan mit Farbar's Recovery Scan Tool (FRST) Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit. Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
12.04.2014, 16:37 | #3 |
| Windows 7: Mozilla stürzt ab und es erscheint ein Bluescreen Ich bekomme eine Fehlermeldung nachdem ich FRST gestartet habe.
__________________Ich habe sie mittels eines Screenshots eingefangen und als Anhang gespeichert. Ich habe bei dieser Fehlermedlung auf "Nein" geklickt und dann auf "Scan". Wenn ich auf "Ja" bei dieser Fehlermeldung klicke, stürzt mein Computer ab und es kommt ein Bluescreen. FRST.txt FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-04-2014 01 Ran by Octavio (ATTENTION: The logged in user is not administrator) on OCTAVIONOTEBOOK on 12-04-2014 17:35:05 Running from C:\Users\Octavio\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Intel Corporation) C:\Windows\system32\igfxsrvc.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe () C:\Program Files\Acer\Acer Theft Shield\USecuAppClient.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe (Intel Corporation) C:\Windows\system32\igfxext.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Dolby Laboratories Inc.) C:\Dolby PCEE4\pcee4.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe (Apple Inc.) D:\Program Files (x86)\iTunes\iTunesHelper.exe () C:\Program Files (x86)\T-Mobile\InternetManager_H\Internet Manager.exe (CyberLink) C:\Program Files (x86)\Cyberlink\MediaEspresso\DeviceDetector\DeviceDetector.exe () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12459112 2012-03-16] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1158248 2012-03-10] (Realtek Semiconductor) HKLM\...\Run: [AtherosBtStack] - C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [1021056 2012-03-08] (Atheros Communications) HKLM\...\Run: [AthBtTray] - C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [800896 2012-03-08] (Atheros Commnucations) HKLM\...\Run: [Power Management] - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1829768 2012-02-07] (Acer Incorporated) HKLM\...\Run: [InstantUpdate] - C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuDaemon.exe [124520 2012-02-20] () HKLM\...\Run: [Secure Applicayion] - c:\Program Files\Acer\Acer Theft Shield\USecuAppClient.exe [257640 2012-03-06] () HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation) HKLM-x32\...\Run: [OOTag] - C:\Program Files (x86)\Acer\OOBEOffer\OOTag.exe [13856 2010-02-23] (Microsoft) HKLM-x32\...\Run: [Dolby Home Theater v4] - C:\Dolby PCEE4\pcee4.exe [506712 2011-06-01] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-27] (Intel Corporation) HKLM-x32\...\Run: [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe [1105488 2012-03-24] (Dritek System Inc.) HKLM-x32\...\Run: [SuiteTray] - C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [341360 2011-09-20] (Egis Technology Inc.) HKLM-x32\...\Run: [NBAgent] - C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [1406248 2011-03-22] (Nero AG) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-06] (Apple Inc.) HKLM-x32\...\Run: [WinampAgent] - "D:\Program Files (x86)\Winamp\winampa.exe" HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard) HKLM-x32\...\Run: [] - [X] HKLM-x32\...\Run: [iTunesHelper] - D:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-06] (Apple Inc.) HKLM\...\RunOnce: [*WerKernelReporting] - %SYSTEMROOT%\SYSTEM32\WerFault.exe -k -rq [415232 2009-07-14] (Microsoft Corporation) HKLM-x32\...\RunOnce: [ Malwarebytes Anti-Malware ] - D:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation) HKLM-x32\...\RunOnce: [ Malwarebytes Anti-Malware (cleanup)] - rundll32.exe "C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript [1127496 2013-04-04] (Malwarebytes Corporation) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\.DEFAULT\...\RunOnce: [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid} HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {2e18814b-7337-11e3-a8ef-08edb9585f2c} - E:\AutoRun.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {2e188308-7337-11e3-a8ef-08edb9585f2c} - E:\AutoRun.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {59892f1e-5b2f-11e3-9349-08edb9585f2c} - E:\AutoRun.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {666866b3-3cd7-11e3-9a3d-08edb9585f2c} - E:\AutoRun.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {666866cd-3cd7-11e3-9a3d-08edb9585f2c} - E:\AutoRun.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {666866fb-3cd7-11e3-9a3d-08edb9585f2c} - E:\AutoRun.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {77bc75cb-6754-11e3-96cd-08edb9585f2c} - E:\AutoRun.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {77bc75e9-6754-11e3-96cd-08edb9585f2c} - E:\AutoRun.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {8380457c-5c44-11e3-ac4a-08edb9585f2b} - E:\AutoRun.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {ccc626fe-5768-11e3-bdc9-08edb9585f2c} - E:\AutoRun.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {dde15604-c0c1-11e3-9bdb-08edb9585f2b} - E:\AutoRun.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {f76fa12d-9634-11e3-8c0b-08edb9585f2c} - E:\AutoRun.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x67A17B65DA95CD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll No File BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\..\Interfaces\{037375DD-C61C-486A-B7FE-711E0C51FC62}: [NameServer]10.74.210.210 10.74.210.211 Tcpip\..\Interfaces\{35EAF2DC-C901-4A0C-9489-49D7158F8B2D}: [NameServer] Tcpip\..\Interfaces\{53EC8EE9-7859-47ED-A79E-3AF6A6359BBC}: [NameServer] Tcpip\..\Interfaces\{5829B6C7-F318-45C7-B99F-B4D8422C08EB}: [NameServer] Tcpip\..\Interfaces\{83F27B3B-D9A3-4CAF-98C8-D7A3118F45A9}: [NameServer]10.74.210.210 10.74.210.211 Tcpip\..\Interfaces\{872BB3BC-EC5F-474D-8978-6F554EF57D5D}: [NameServer] Tcpip\..\Interfaces\{97F66A92-7A05-42A2-8322-D3B90C230090}: [NameServer] Tcpip\..\Interfaces\{B915B0D8-04B3-4654-B399-88076163BB00}: [NameServer]10.74.210.210 10.74.210.211 Tcpip\..\Interfaces\{C149951C-15B2-4109-BCFF-6E6DADCB903F}: [NameServer] Tcpip\..\Interfaces\{C9058999-0CD6-430C-9A4F-A7862710E46D}: [NameServer] Tcpip\..\Interfaces\{D097112A-8F24-4906-A4C8-050547F7324E}: [NameServer] Tcpip\..\Interfaces\{DC9110D3-37D9-45BE-9C42-CFD9E8C749A8}: [NameServer] FireFox: ======== FF ProfilePath: C:\Users\Octavio\AppData\Roaming\Mozilla\Firefox\Profiles\1wck7teo.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - D:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: WOT - C:\Users\Octavio\AppData\Roaming\Mozilla\Firefox\Profiles\1wck7teo.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-11-26] FF Extension: NoScript - C:\Users\Octavio\AppData\Roaming\Mozilla\Firefox\Profiles\1wck7teo.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2012-09-19] FF Extension: Adblock Plus - C:\Users\Octavio\AppData\Roaming\Mozilla\Firefox\Profiles\1wck7teo.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-09-19] ==================== Services (Whitelisted) ================= R2 FFSOpzSvc; C:\Program Files\Sleep Memory Optimizer\FFSService.exe [141192 2011-09-17] (Acer Incorporated) R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] () R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [127320 2012-03-16] () S2 Internet Manager. RunOuc; C:\Program Files (x86)\T-Mobile\InternetManager_H\UpdateDog\ouc.exe [224096 2011-06-17] () S3 irstrtsv; C:\Windows\SysWOW64\irstrtsv.exe [192856 2012-02-24] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [162648 2012-03-16] (Intel Corporation) R2 lmhosts; C:\Windows\system32\svchost.exe [27648 2011-03-01] (Microsoft Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation) R2 NlaSvc; C:\Windows\System32\svchost.exe [27648 2011-03-01] (Microsoft Corporation) R2 nsi; C:\Windows\system32\svchost.exe [27648 2011-03-01] (Microsoft Corporation) R2 RS_Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [260640 2010-01-29] (Acer Incorporated) R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia) R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [660184 2013-07-03] (Secunia) R2 USecuAppSvc; c:\Program Files\Acer\Acer Theft Shield\USecuAppSvc.exe [236648 2012-03-06] () R2 ZAtheros Wlan Agent; C:\Program Files (x86)\Atheros\Ath_WlanAgent.exe [72864 2012-02-19] (Atheros) ==================== Drivers (Whitelisted) ==================== S3 AX88772B; C:\Windows\System32\DRIVERS\ax88772b.sys [98816 2011-01-01] (ASIX Electronics Corp.) R3 huawei_wwanecm; C:\Windows\System32\DRIVERS\ew_juwwanecm.sys [238080 2012-04-23] (Huawei Technologies Co., Ltd.) S3 irstrtdv; C:\Windows\System32\DRIVERS\irstrtdv.sys [26504 2012-02-23] (Intel Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation) R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-07-03] (Secunia) S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-12 17:27 - 2014-04-12 17:35 - 00014340 _____ () C:\Users\Octavio\Desktop\FRST.txt 2014-04-12 15:15 - 2014-04-12 15:15 - 00000000 ___RD () C:\Users\Octavio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2014-04-12 09:39 - 2014-04-12 17:24 - 02157568 _____ (Farbar) C:\Users\Octavio\Desktop\FRST64.exe 2014-04-12 09:37 - 2014-04-12 09:37 - 00000472 _____ () C:\Users\Octavio\Desktop\defogger_disable.log 2014-04-12 09:37 - 2014-04-12 09:37 - 00000000 _____ () C:\Users\Admin\defogger_reenable 2014-04-12 09:36 - 2014-04-12 09:36 - 00050477 _____ () C:\Users\Octavio\Desktop\Defogger.exe 2014-04-09 15:19 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-09 15:19 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-09 15:19 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-09 15:19 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-09 15:17 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-09 15:17 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-09 15:17 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-09 15:17 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-09 15:17 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-09 15:17 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-09 15:17 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-09 15:17 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-09 15:17 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-09 15:17 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-09 15:17 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-09 15:17 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-09 15:17 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-09 15:17 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-09 15:17 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-09 15:17 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-09 15:17 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-03-29 12:12 - 2014-03-29 12:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-19 18:25 - 2014-03-19 18:25 - 00000729 _____ () C:\Users\Octavio\Desktop\FLV Player.lnk 2014-03-19 18:25 - 2014-03-19 18:25 - 00000000 ____D () C:\Users\Octavio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FLV Player 2014-03-19 18:23 - 2014-03-19 18:23 - 00000000 ____D () C:\Users\Octavio\AppData\Roaming\WinRAR 2014-03-14 11:09 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-14 11:09 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-14 11:09 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-14 11:09 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-14 11:09 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-14 11:09 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-14 11:09 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-14 11:09 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-14 11:09 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-14 11:09 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-14 11:09 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-14 11:09 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-14 11:09 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-14 11:09 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-14 11:09 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-14 11:09 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-14 11:09 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-14 11:09 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-14 11:09 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-14 11:09 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-14 11:09 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-14 11:09 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-14 11:09 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-14 11:09 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-14 11:09 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-14 11:09 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-14 11:09 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-14 11:09 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-14 11:09 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-14 11:09 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-14 11:09 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-14 11:09 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-14 11:09 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-14 11:09 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-14 11:09 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-14 11:09 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-03-14 11:08 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-14 11:08 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-03-14 11:08 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2014-03-14 11:08 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-03-14 11:03 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-03-14 11:03 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-14 11:03 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-03-14 11:03 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll ==================== One Month Modified Files and Folders ======= 2014-04-12 17:35 - 2014-04-12 17:27 - 00014340 _____ () C:\Users\Octavio\Desktop\FRST.txt 2014-04-12 17:35 - 2014-01-20 11:42 - 00000000 ____D () C:\FRST 2014-04-12 17:34 - 2014-01-29 10:08 - 00071680 ___SH () C:\Users\Octavio\Desktop\Thumbs.db 2014-04-12 17:26 - 2012-05-15 12:41 - 00699682 _____ () C:\Windows\system32\perfh007.dat 2014-04-12 17:26 - 2012-05-15 12:41 - 00149790 _____ () C:\Windows\system32\perfc007.dat 2014-04-12 17:26 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-12 17:24 - 2014-04-12 09:39 - 02157568 _____ (Farbar) C:\Users\Octavio\Desktop\FRST64.exe 2014-04-12 17:23 - 2012-05-15 02:48 - 01201959 _____ () C:\Windows\WindowsUpdate.log 2014-04-12 17:22 - 2012-03-27 20:45 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-12 15:22 - 2009-07-14 06:45 - 00024416 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-12 15:22 - 2009-07-14 06:45 - 00024416 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-12 15:15 - 2014-04-12 15:15 - 00000000 ___RD () C:\Users\Octavio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2014-04-12 15:15 - 2012-05-15 02:47 - 00000828 _____ () C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job 2014-04-12 15:14 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-12 15:14 - 2009-07-14 06:51 - 00115388 _____ () C:\Windows\setupact.log 2014-04-12 11:41 - 2012-05-15 02:47 - 00000830 _____ () C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job 2014-04-12 09:41 - 2012-06-14 19:36 - 502918635 _____ () C:\Windows\MEMORY.DMP 2014-04-12 09:41 - 2012-06-14 19:36 - 00000000 ____D () C:\Windows\Minidump 2014-04-12 09:37 - 2014-04-12 09:37 - 00000472 _____ () C:\Users\Octavio\Desktop\defogger_disable.log 2014-04-12 09:37 - 2014-04-12 09:37 - 00000000 _____ () C:\Users\Admin\defogger_reenable 2014-04-12 09:37 - 2012-09-18 19:48 - 00000000 ____D () C:\Users\Admin 2014-04-12 09:36 - 2014-04-12 09:36 - 00050477 _____ () C:\Users\Octavio\Desktop\Defogger.exe 2014-04-11 13:05 - 2010-11-21 05:47 - 00145016 _____ () C:\Windows\PFRO.log 2014-04-10 17:07 - 2013-12-11 21:44 - 00000000 ____D () C:\ProgramData\OnlineUpdate 2014-04-10 09:36 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-04-09 20:19 - 2013-07-25 20:45 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-09 20:18 - 2012-09-19 15:43 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-09 01:21 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\LiveKernelReports 2014-04-06 12:51 - 2012-09-18 22:13 - 00000000 ____D () C:\Users\Octavio 2014-03-31 03:16 - 2014-04-09 15:19 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-09 15:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-09 15:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-09 15:19 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-29 13:46 - 2012-09-19 16:28 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-29 12:12 - 2014-03-29 12:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-28 19:49 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-03-26 13:00 - 2012-09-19 15:36 - 00001912 _____ () C:\Windows\epplauncher.mif 2014-03-26 13:00 - 2012-09-19 15:36 - 00000000 ____D () C:\Program Files\Microsoft Security Client 2014-03-26 13:00 - 2012-09-19 15:36 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client 2014-03-19 18:25 - 2014-03-19 18:25 - 00000729 _____ () C:\Users\Octavio\Desktop\FLV Player.lnk 2014-03-19 18:25 - 2014-03-19 18:25 - 00000000 ____D () C:\Users\Octavio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FLV Player 2014-03-19 18:25 - 2012-12-25 23:28 - 00000238 _____ () C:\Windows\wininit.ini 2014-03-19 18:23 - 2014-03-19 18:23 - 00000000 ____D () C:\Users\Octavio\AppData\Roaming\WinRAR 2014-03-14 13:17 - 2013-03-15 14:18 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-03-14 13:17 - 2013-03-15 14:18 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-03-14 13:17 - 2009-07-14 06:45 - 00334552 _____ () C:\Windows\system32\FNTCACHE.DAT Files to move or delete: ==================== C:\Users\Admin\AppData\Roaming\EasyToolz.ini Some content of TEMP: ==================== C:\Users\Octavio\AppData\Local\Temp\install_flashplayer11x32au_mssd_aih.exe C:\Users\Octavio\AppData\Local\Temp\install_reader10_de_gtbd_chrd_dn_aih.exe C:\Users\Octavio\AppData\Local\Temp\npp.6.2.2.Installer.exe C:\Users\Octavio\AppData\Local\Temp\npp.6.2.Installer.exe C:\Users\Octavio\AppData\Local\Temp\npp.6.3.2.Installer.exe C:\Users\Octavio\AppData\Local\Temp\npp.6.3.Installer.exe C:\Users\Octavio\AppData\Local\Temp\npp.6.5.2.Installer.exe C:\Users\Octavio\AppData\Local\Temp\SkypeSetup.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== End Of Log ============================ --- --- --- --- --- --- Addition.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-04-2014 01 Ran by Octavio at 2014-04-12 17:35:50 Running from C:\Users\Octavio\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} ==================== Installed Programs ====================== 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Acer Crystal Eye Webcam (HKLM-x32\...\InstallShield_{A0382E3C-7384-429A-9BFA-AF5888E5A193}) (Version: 1.5.2624.00 - CyberLink Corp.) Acer Crystal Eye Webcam (x32 Version: 1.5.2624.00 - CyberLink Corp.) Hidden Acer ePower Management (HKLM-x32\...\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 6.00.3010 - Acer Incorporated) Acer eRecovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3507 - Acer Incorporated) Acer Instant Update Service (HKLM\...\{86B80582-A4F2-4F12-B29F-49D3309C7024}) (Version: 1.00.3001 - Acer Incorporated) Acer Theft Shield (HKLM\...\{8ADB0CD2-4E5A-452F-BB3B-3A2984CAC749}) (Version: 1.00.3001 - Acer Incorporated) Acer Updater (HKLM-x32\...\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3501 - Acer Incorporated) Acer VCM (HKLM-x32\...\{047F790A-7A2A-4B6A-AD02-38092BA63DAC}) (Version: 4.05.3501 - Acer Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.8.0.870 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.8.0.870 - Adobe Systems Incorporated) Hidden Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated) Apple Application Support (HKLM-x32\...\{21FC2093-6E43-460B-B9B0-5F5AA35BBB0F}) (Version: 3.0 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{FE86CB0C-FCB3-4358-B4B0-B0A41E33B3DD}) (Version: 7.1.0.32 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Atheros Bluetooth Suite (64) (HKLM\...\{230D1595-57DA-4933-8C4E-375797EBB7E1}) (Version: 7.4.0.126 - Atheros) AX88772B Windows 7 Drivers (HKLM-x32\...\InstallShield_{54A168C9-2250-4058-80EB-1F4A4192548A}) (Version: 1.0.1.1 - ASIX Electronics Corporation) AX88772B Windows 7 Drivers (x32 Version: 1.0.1.1 - ASIX Electronics Corporation) Hidden Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) calibre (HKLM-x32\...\{5FD4B351-1567-426F-AEB4-08F41E3FA6C5}) (Version: 0.9.31 - Kovid Goyal) CATBox 1.1 (HKLM-x32\...\{5140A79F-17C4-4B33-91D6-330D9B7C2D4C}_is1) (Version: - Schliep & Hochstaettler) CyberLink MediaEspresso (HKLM-x32\...\InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}) (Version: 6.5.1720_38230 - CyberLink Corp.) CyberLink MediaEspresso (x32 Version: 6.5.1720_38230 - CyberLink Corp.) Hidden Dolby Home Theater v4 (HKLM-x32\...\{B26438B4-BF51-49C3-9567-7F14A5E40CB9}) (Version: 7.2.7000.7 - Dolby Laboratories Inc) GPL Ghostscript (HKLM-x32\...\GPL Ghostscript 9.05) (Version: 9.05 - Artifex Software Inc.) High-Definition Video Playback (x32 Version: 7.1.13900.47.0 - Nero AG) Hidden HP Deskjet 3520 series - Grundlegende Software für das Gerät (HKLM\...\{15B2F0E3-3FAC-4495-B0FD-398EECFA4100}) (Version: 28.0.1315.0 - Hewlett-Packard Co.) HP Deskjet 3520 series Hilfe (HKLM-x32\...\{6B953497-169C-4929-9AA9-A9F510347468}) (Version: 27.0.0 - Hewlett Packard) HP Deskjet 3520 series Setup Guide (HKLM-x32\...\{AEEDCEB7-00B8-4BE1-B492-AB04803D5F1E}) (Version: 27.0.0 - Hewlett Packard) HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard) Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3501 - Acer Incorporated) Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.35342 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.4.1441 - Intel Corporation) Intel(R) OpenCL CPU Runtime (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2653 - Intel Corporation) Intel(R) Rapid Start Technology (HKLM-x32\...\3D073343-CEEB-4ce7-85AC-A69A7631B5D6) (Version: 1.0.0.1022 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.0.0.1032 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.4.220 - Intel Corporation) Intel® Trusted Connect Service Client (HKLM\...\{09536BA1-E498-4CC3-B834-D884A67D7E34}) (Version: 1.23.605.1 - Intel Corporation) Internet Manager (HKLM-x32\...\Internet Manager) (Version: 22.001.18.68.55 - Huawei Technologies Co.,Ltd) iTunes (HKLM\...\{96B53CA8-5ABB-49D8-96F1-F6C0D73A76C6}) (Version: 11.1.4.62 - Apple Inc.) Java SE Development Kit 7 Update 51 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0170510}) (Version: 1.7.0.510 - Oracle) Launch Manager (HKLM-x32\...\LManager) (Version: 5.1.15 - Acer Inc.) LibreOffice 3.6 (HKLM-x32\...\{CBCF6C86-4738-4A84-9C2C-331804DCEB9B}) (Version: 3.6.3.2 - The Document Foundation) LMMS 0.4.15 (HKLM-x32\...\LMMS) (Version: 0.4.15 - LMMS Developers) Malwarebytes Anti-Malware Version 1.75.0.1300 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation) Marketsplash Schnellzugriffe (HKLM-x32\...\{7A108EBC-C9DF-4E14-93A8-42CF316F1ECF}) (Version: 1.0.1.7 - Hewlett-Packard) MATLAB R2011a (HKLM\...\MatlabR2011a) (Version: 7.12 - The MathWorks, Inc.) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Security Client (Version: 4.5.0216.0 - Microsoft Corporation) Hidden Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) MiKTeX 2.9 (HKLM\...\MiKTeX 2.9) (Version: 2.9 - MiKTeX.org) Mozilla Firefox 28.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla) Mozilla Thunderbird 17.0.7 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 17.0.7 (x86 de)) (Version: 17.0.7 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) MyWinLocker (Version: 4.0.14.27 - Egis Technology Inc.) Hidden MyWinLocker 4 (x32 Version: 4.0.14.27 - Egis Technology Inc.) Hidden MyWinLocker Suite (HKLM-x32\...\InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}) (Version: 4.0.14.19 - Egis Technology Inc.) MyWinLocker Suite (x32 Version: 4.0.14.19 - Egis Technology Inc.) Hidden Nero BackItUp 10 (HKLM-x32\...\{68AB6930-5BFF-4FF6-923B-516A91984FE6}) (Version: 5.6.11700.17.100 - Nero AG) Nero BackItUp 10 Help (CHM) (x32 Version: 10.5.10700 - Nero AG) Hidden Nero BurnRights 10 (HKLM-x32\...\{943CFD7D-5336-47AF-9418-E02473A5A517}) (Version: 4.2.10500.1.102 - Nero AG) Nero BurnRights 10 Help (CHM) (x32 Version: 10.5.10000 - Nero AG) Hidden Nero Control Center 10 (x32 Version: 10.2.11100.1.1 - Nero AG) Hidden Nero ControlCenter 10 Help (CHM) (x32 Version: 10.5.10000 - Nero AG) Hidden Nero Core Components 10 (x32 Version: 2.0.19800.9.10 - Nero AG) Hidden Nero CoverDesigner 10 (HKLM-x32\...\{FCF00A6E-FB58-477A-ABE9-232907105521}) (Version: 5.2.11400.11.100 - Nero AG) Nero CoverDesigner 10 Help (CHM) (x32 Version: 10.5.10000 - Nero AG) Hidden Nero DiscSpeed 10 (HKLM-x32\...\{34490F4E-48D0-492E-8249-B48BECF0537C}) (Version: 6.2.10500.2.100 - Nero AG) Nero DiscSpeed 10 Help (CHM) (x32 Version: 10.5.10000 - Nero AG) Hidden Nero Express 10 (HKLM-x32\...\{70550193-1C22-445C-8FA4-564E155DB1A7}) (Version: 10.2.12400.25.100 - Nero AG) Nero Express 10 Help (CHM) (x32 Version: 10.5.10200 - Nero AG) Hidden Nero InfoTool 10 (HKLM-x32\...\{F412B4AF-388C-4FF5-9B2F-33DB1C536953}) (Version: 7.2.10400.5.100 - Nero AG) Nero InfoTool 10 Help (CHM) (x32 Version: 10.5.10000 - Nero AG) Hidden Nero Multimedia Suite 10 Essentials (HKLM-x32\...\{89590A73-9AC3-48ED-B83E-6489900DED5A}) (Version: 10.5.10000 - Nero AG) Nero StartSmart 10 (HKLM-x32\...\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}) (Version: 10.2.11300.12.100 - Nero AG) Nero StartSmart 10 Help (CHM) (x32 Version: 10.5.10000 - Nero AG) Hidden Nero Update (x32 Version: 11.0.11500.28.0 - Nero AG) Hidden Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.5.2 - Notepad++ Team) PDF Split And Merge Basic (HKLM\...\{C91B24F6-1629-11E2-B696-21676188709B}) (Version: 2.2.2 - Andrea Vacondio) Python 2.7.6 (64-bit) (HKLM\...\{C3CC4DF5-39A5-4027-B136-2B3E1F5AB6E3}) (Version: 2.7.6150 - Python Software Foundation) Qualcomm Atheros WiFi Driver Installation (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 3.1 - Qualcomm Atheros) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6597 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7601.39025 - Realtek Semiconductor Corp.) Secunia PSI (3.0.0.7011) (HKLM-x32\...\Secunia PSI) (Version: 3.0.0.7011 - Secunia) Shredder (Version: 2.0.8.9 - Egis Technology Inc.) Hidden Shredder (x32 Version: 2.0.8.9 - Egis Technology Inc.) Hidden Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) Sleep Memory Optimizer (HKLM-x32\...\{34BE2594-1D20-4A2E-97A0-B9E2837520AE}) (Version: 1.00.3004 - Acer Incorporated) Smart Timer (HKLM-x32\...\{89DB52FC-EA72-468F-A0C7-150AF8B7AB74}) (Version: 1.00.3004 - Acer Incorporated) SpywareBlaster 5.0 (HKLM-x32\...\SpywareBlaster_is1) (Version: 5.0.0 - BrightFort LLC) TeXnicCenter Version 2.0 Beta 1 (HKLM\...\TeXnicCenter_is1) (Version: 2.0 Beta 1 - The TeXnicCenter Team) TSST OEM Content (HKLM-x32\...\{885AFEC2-0809-47CE-8B3F-00AEC19DDD5F}) (Version: 10.0.10300.0.0 - Nero AG) Überwachungstool für die Intel® Turbo-Boost-Technik 2.5 (HKLM\...\{6C9365EB-1F9E-4893-9196-3EC77C88D0C5}) (Version: 2.5.1.0 - Intel) Welcome Center (HKLM-x32\...\Acer Welcome Center) (Version: 1.02.3507 - Acer Incorporated) WinPatrol (HKLM\...\{4BB7A109-FDB5-45E3-9DB9-ECB2EA7B80EE}) (Version: 28.5.2013.0 - BillP Studios) WinRAR 5.10 beta 1 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.10.1 - win.rar GmbH) WinSCP 5.1.6 (HKLM-x32\...\winscp3_is1) (Version: 5.1.6 - Martin Prikryl) ==================== Restore Points ========================= Could not list Restore Points. Check "winmgmt" service or repair WMI. ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => ? Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => ? Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => ? ==================== Loaded Modules (whitelisted) ============= 2009-01-21 16:45 - 2009-01-21 16:45 - 01401856 _____ () C:\Program Files (x86)\EgisTec MyWinLocker\x64\LIBEAY32.dll 2012-06-18 17:24 - 2012-06-18 17:24 - 00222720 _____ () D:\Program Files (x86)\Notepad++\NppShell_05.dll 2012-05-15 12:33 - 2012-02-14 19:53 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2012-03-06 21:49 - 2012-03-06 21:49 - 00257640 _____ () C:\Program Files\Acer\Acer Theft Shield\USecuAppClient.exe 2012-03-06 21:49 - 2012-03-06 21:49 - 00213608 _____ () C:\Program Files\Acer\Acer Theft Shield\CommPtl.dll 2012-03-06 21:49 - 2012-03-06 21:49 - 00197736 _____ () C:\Program Files\Acer\Acer Theft Shield\LogMgr2.dll 2012-03-06 21:49 - 2012-03-06 21:49 - 00114280 _____ () C:\Program Files\Acer\Acer Theft Shield\SysCtrl.dll 2012-03-06 21:49 - 2012-03-06 21:49 - 00140904 _____ () C:\Program Files\Acer\Acer Theft Shield\WHNCtrl.dll 2013-10-25 18:09 - 2011-06-17 13:00 - 00324448 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\Internet Manager.exe 2012-02-20 15:34 - 2012-02-20 15:34 - 00040552 _____ () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe 2012-02-20 15:34 - 2012-02-20 15:34 - 00022632 _____ () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe 2014-02-06 01:52 - 2014-02-06 01:52 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2014-02-06 01:52 - 2014-02-06 01:52 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2013-10-25 18:09 - 2012-10-16 05:42 - 00434568 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\core.dll 2013-10-25 18:09 - 2012-09-24 13:51 - 00281992 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\sdk.dll 2013-10-25 18:09 - 2009-01-10 12:32 - 00011362 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\mingwm10.dll 2013-10-25 18:09 - 2009-06-22 20:42 - 00043008 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\libgcc_s_dw2-1.dll 2013-10-25 18:09 - 2010-05-05 10:47 - 02415104 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\QtCore4.dll 2013-10-25 18:09 - 2010-02-10 16:43 - 09515520 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\QtGui4.dll 2013-10-25 18:09 - 2012-09-24 13:51 - 00396168 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\Proxy.DLL 2013-10-25 18:09 - 2012-09-24 13:50 - 00228232 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\Common.dll 2013-10-25 18:09 - 2012-09-24 13:51 - 00141704 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\Trace.dll 2013-10-25 18:09 - 2012-09-24 13:51 - 00551304 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\PluginContainer.dll 2013-10-25 18:09 - 2012-09-24 13:50 - 00245128 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\AtCodec.dll 2013-10-25 18:09 - 2012-09-24 13:50 - 00306568 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\DeviceSrvPlugin.dll 2013-10-25 18:09 - 2012-09-24 13:51 - 00242568 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\NetSrvPlugin.dll 2013-10-25 18:09 - 2012-09-24 13:51 - 00139656 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\OSDialup.dll 2013-10-25 18:09 - 2012-09-24 13:51 - 00174984 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\XCodec.dll 2013-10-25 18:09 - 2012-09-24 13:50 - 00163208 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\DataServicePlugin.dll 2013-10-25 18:09 - 2012-09-24 13:50 - 00268680 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\AddrBookSrvPlugin.dll 2013-10-25 18:09 - 2012-09-24 13:51 - 00225160 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\SmsSrvPlugin.dll 2013-10-25 18:09 - 2012-09-24 13:51 - 00148360 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\USSDSrvPlugin.dll 2013-10-25 18:09 - 2012-09-24 13:50 - 00343432 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\DeviceAppPlugin.dll 2013-10-25 18:09 - 2012-09-24 13:51 - 00071560 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\OSPowerMgr.dll 2013-10-25 18:09 - 2012-05-18 02:40 - 00120192 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\Win7Support.dll 2013-10-25 18:09 - 2012-09-24 13:50 - 00129928 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\ATR2SMgr.dll 2013-10-25 18:09 - 2012-09-24 13:50 - 01093000 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\AddrBookPlugin.dll 2013-10-25 18:09 - 2012-09-24 13:51 - 00692104 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\SmsAppPlugin.dll 2013-10-25 18:09 - 2012-09-24 13:50 - 00164744 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\NetConnectSrvPlugin.dll 2013-10-25 18:09 - 2012-09-24 13:50 - 00217992 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\DialUpPlugin.dll 2013-10-25 18:09 - 2012-09-24 13:51 - 00107912 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\OSAdapt.dll 2013-10-25 18:09 - 2012-09-24 13:50 - 00185224 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\NDISPlugin.dll 2013-10-25 18:09 - 2012-09-24 13:51 - 00137608 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\OSNDIS.dll 2013-10-25 18:09 - 2012-05-18 02:39 - 01107328 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\NDISAPI.dll 2013-10-25 18:09 - 2012-09-24 13:50 - 00301960 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\NetInfoSrvPlugin.dll 2013-10-25 18:09 - 2012-09-24 13:50 - 00565640 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\DeviceMgrUIPlugin.dll 2013-10-25 18:09 - 2012-09-24 13:51 - 00309128 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\XFramePlugin.dll 2013-10-25 18:09 - 2012-09-25 03:05 - 00820104 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\MiniFramePlugin.dll 2013-10-25 18:09 - 2010-02-10 16:06 - 00398336 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\QtXml4.dll 2013-10-25 18:09 - 2012-09-24 13:51 - 00103304 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\NotifyServicePlugin.dll 2013-10-25 18:09 - 2012-09-24 13:50 - 00336264 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\NetConnectPlugin.dll 2013-10-25 18:09 - 2012-09-24 13:50 - 00424840 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\DialupUIPlugin.dll 2013-10-25 18:09 - 2012-09-24 13:51 - 00325000 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\StatusBarMgrPlugin.dll 2013-10-25 18:09 - 2012-09-24 13:50 - 00277384 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\MenuMgrPlugin.dll 2013-10-25 18:09 - 2012-09-24 13:50 - 00123272 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\LayoutPlugin.dll 2013-10-25 18:09 - 2012-09-24 13:51 - 00313224 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\SettingUIPlugin.dll 2013-10-25 18:09 - 2012-10-16 05:42 - 00506760 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\NetSettingPlugin.dll 2013-10-25 18:09 - 2012-09-24 13:50 - 00314760 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\NetInfoRecordUIPlugin.dll 2013-10-25 18:09 - 2012-09-24 13:50 - 00106376 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\CompressRatePlugin.dll 2013-10-25 18:09 - 2012-09-24 13:50 - 00523656 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\NetInfoUIExPlugin.dll 2013-10-25 18:09 - 2012-09-24 13:51 - 00845704 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\SMSUIPlugin.dll 2013-10-25 18:09 - 2012-09-24 13:51 - 00116104 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\ServiceUIPlugin.dll 2013-10-25 18:09 - 2012-09-24 13:50 - 00418184 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\DiagnosisPlugin.dll 2013-10-25 18:09 - 2010-02-10 16:10 - 01148416 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\QtNetwork4.dll 2013-10-25 18:09 - 2012-10-16 05:42 - 00145800 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\HelpUIPlugin.dll 2013-10-25 18:09 - 2012-10-11 05:30 - 00440712 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\USSDUIPlugin.dll 2013-10-25 18:09 - 2012-09-24 13:50 - 00811912 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\AddrBookUIPlugin.dll 2013-10-25 18:09 - 2012-10-08 03:41 - 00082944 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\plugins\imageformats\qgif4.dll 2013-10-25 18:09 - 2012-10-08 03:41 - 00081920 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\plugins\imageformats\qico4.dll 2013-10-25 18:09 - 2012-05-18 02:38 - 00250752 _____ () C:\Program Files (x86)\T-Mobile\InternetManager_H\LiveUpdateInterface.dll 2014-03-29 12:12 - 2014-03-29 12:12 - 03642480 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:5C321E34 ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (04/12/2014 03:15:10 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: BtvStack.exe, Version: 7.4.0.126, Zeitstempel: 0x4f587ad6 Name des fehlerhaften Moduls: BtvStack.exe, Version: 7.4.0.126, Zeitstempel: 0x4f587ad6 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000007da38 ID des fehlerhaften Prozesses: 0xec4 Startzeit der fehlerhaften Anwendung: 0xBtvStack.exe0 Pfad der fehlerhaften Anwendung: BtvStack.exe1 Pfad des fehlerhaften Moduls: BtvStack.exe2 Berichtskennung: BtvStack.exe3 Error: (04/12/2014 09:42:08 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: BtvStack.exe, Version: 7.4.0.126, Zeitstempel: 0x4f587ad6 Name des fehlerhaften Moduls: BtvStack.exe, Version: 7.4.0.126, Zeitstempel: 0x4f587ad6 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000007da38 ID des fehlerhaften Prozesses: 0xf08 Startzeit der fehlerhaften Anwendung: 0xBtvStack.exe0 Pfad der fehlerhaften Anwendung: BtvStack.exe1 Pfad des fehlerhaften Moduls: BtvStack.exe2 Berichtskennung: BtvStack.exe3 Error: (04/12/2014 09:32:20 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: BtvStack.exe, Version: 7.4.0.126, Zeitstempel: 0x4f587ad6 Name des fehlerhaften Moduls: BtvStack.exe, Version: 7.4.0.126, Zeitstempel: 0x4f587ad6 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000007da38 ID des fehlerhaften Prozesses: 0xe9c Startzeit der fehlerhaften Anwendung: 0xBtvStack.exe0 Pfad der fehlerhaften Anwendung: BtvStack.exe1 Pfad des fehlerhaften Moduls: BtvStack.exe2 Berichtskennung: BtvStack.exe3 Error: (04/12/2014 00:10:39 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: BtvStack.exe, Version: 7.4.0.126, Zeitstempel: 0x4f587ad6 Name des fehlerhaften Moduls: BtvStack.exe, Version: 7.4.0.126, Zeitstempel: 0x4f587ad6 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000007da38 ID des fehlerhaften Prozesses: 0xeb4 Startzeit der fehlerhaften Anwendung: 0xBtvStack.exe0 Pfad der fehlerhaften Anwendung: BtvStack.exe1 Pfad des fehlerhaften Moduls: BtvStack.exe2 Berichtskennung: BtvStack.exe3 Error: (04/11/2014 10:53:53 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: BtvStack.exe, Version: 7.4.0.126, Zeitstempel: 0x4f587ad6 Name des fehlerhaften Moduls: BtvStack.exe, Version: 7.4.0.126, Zeitstempel: 0x4f587ad6 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000007da38 ID des fehlerhaften Prozesses: 0xeac Startzeit der fehlerhaften Anwendung: 0xBtvStack.exe0 Pfad der fehlerhaften Anwendung: BtvStack.exe1 Pfad des fehlerhaften Moduls: BtvStack.exe2 Berichtskennung: BtvStack.exe3 Error: (04/11/2014 10:51:56 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: BtvStack.exe, Version: 7.4.0.126, Zeitstempel: 0x4f587ad6 Name des fehlerhaften Moduls: BtvStack.exe, Version: 7.4.0.126, Zeitstempel: 0x4f587ad6 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000007da38 ID des fehlerhaften Prozesses: 0xcc4 Startzeit der fehlerhaften Anwendung: 0xBtvStack.exe0 Pfad der fehlerhaften Anwendung: BtvStack.exe1 Pfad des fehlerhaften Moduls: BtvStack.exe2 Berichtskennung: BtvStack.exe3 Error: (04/11/2014 10:03:37 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 1014 Error: (04/11/2014 10:03:37 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 1014 Error: (04/11/2014 10:03:37 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/11/2014 06:31:25 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: BtvStack.exe, Version: 7.4.0.126, Zeitstempel: 0x4f587ad6 Name des fehlerhaften Moduls: BtvStack.exe, Version: 7.4.0.126, Zeitstempel: 0x4f587ad6 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000007da38 ID des fehlerhaften Prozesses: 0xd9c Startzeit der fehlerhaften Anwendung: 0xBtvStack.exe0 Pfad der fehlerhaften Anwendung: BtvStack.exe1 Pfad des fehlerhaften Moduls: BtvStack.exe2 Berichtskennung: BtvStack.exe3 System errors: ============= Error: (04/12/2014 05:35:04 PM) (Source: iaStor) (User: ) Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet. Error: (04/12/2014 05:35:03 PM) (Source: iaStor) (User: ) Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet. Error: (04/12/2014 05:35:02 PM) (Source: iaStor) (User: ) Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet. Error: (04/12/2014 05:35:01 PM) (Source: iaStor) (User: ) Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet. Error: (04/12/2014 05:35:00 PM) (Source: iaStor) (User: ) Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet. Error: (04/12/2014 05:34:59 PM) (Source: iaStor) (User: ) Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet. Error: (04/12/2014 05:34:58 PM) (Source: iaStor) (User: ) Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet. Error: (04/12/2014 05:34:01 PM) (Source: iaStor) (User: ) Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet. Error: (04/12/2014 05:34:00 PM) (Source: iaStor) (User: ) Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet. Error: (04/12/2014 05:33:59 PM) (Source: iaStor) (User: ) Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet. Microsoft Office Sessions: ========================= Error: (04/12/2014 03:15:10 PM) (Source: Application Error)(User: ) Description: BtvStack.exe7.4.0.1264f587ad6BtvStack.exe7.4.0.1264f587ad6c0000005000000000007da38ec401cf565136673a7aC:\Program Files (x86)\Bluetooth Suite\BtvStack.exeC:\Program Files (x86)\Bluetooth Suite\BtvStack.exe790f97b9-c244-11e3-9184-08edb9585f2c Error: (04/12/2014 09:42:08 AM) (Source: Application Error)(User: ) Description: BtvStack.exe7.4.0.1264f587ad6BtvStack.exe7.4.0.1264f587ad6c0000005000000000007da38f0801cf5622acec0fcdC:\Program Files (x86)\Bluetooth Suite\BtvStack.exeC:\Program Files (x86)\Bluetooth Suite\BtvStack.exef2d9a563-c215-11e3-8013-08edb9585f2c Error: (04/12/2014 09:32:20 AM) (Source: Application Error)(User: ) Description: BtvStack.exe7.4.0.1264f587ad6BtvStack.exe7.4.0.1264f587ad6c0000005000000000007da38e9c01cf56214f2d7478C:\Program Files (x86)\Bluetooth Suite\BtvStack.exeC:\Program Files (x86)\Bluetooth Suite\BtvStack.exe945fa956-c214-11e3-8088-08edb9585f2c Error: (04/12/2014 00:10:39 AM) (Source: Application Error)(User: ) Description: BtvStack.exe7.4.0.1264f587ad6BtvStack.exe7.4.0.1264f587ad6c0000005000000000007da38eb401cf55d2d737b16eC:\Program Files (x86)\Bluetooth Suite\BtvStack.exeC:\Program Files (x86)\Bluetooth Suite\BtvStack.exe1d0a4d19-c1c6-11e3-80e6-08edb9585f2c Error: (04/11/2014 10:53:53 PM) (Source: Application Error)(User: ) Description: BtvStack.exe7.4.0.1264f587ad6BtvStack.exe7.4.0.1264f587ad6c0000005000000000007da38eac01cf55c81dfb4474C:\Program Files (x86)\Bluetooth Suite\BtvStack.exeC:\Program Files (x86)\Bluetooth Suite\BtvStack.exe63a1e5cc-c1bb-11e3-8150-08edb9585f2c Error: (04/11/2014 10:51:56 PM) (Source: Application Error)(User: ) Description: BtvStack.exe7.4.0.1264f587ad6BtvStack.exe7.4.0.1264f587ad6c0000005000000000007da38cc401cf55c7d87fb328C:\Program Files (x86)\Bluetooth Suite\BtvStack.exeC:\Program Files (x86)\Bluetooth Suite\BtvStack.exe1de3580e-c1bb-11e3-80b4-08edb9585f2c Error: (04/11/2014 10:03:37 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 1014 Error: (04/11/2014 10:03:37 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 1014 Error: (04/11/2014 10:03:37 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/11/2014 06:31:25 PM) (Source: Application Error)(User: ) Description: BtvStack.exe7.4.0.1264f587ad6BtvStack.exe7.4.0.1264f587ad6c0000005000000000007da38d9c01cf55a3771c8ec5C:\Program Files (x86)\Bluetooth Suite\BtvStack.exeC:\Program Files (x86)\Bluetooth Suite\BtvStack.exeb919043c-c196-11e3-89b1-08edb9585f2c ==================== Memory info =========================== Percentage of memory in use: 44% Total physical RAM: 3934.36 MB Available physical RAM: 2186.32 MB Total Pagefile: 7866.89 MB Available Pagefile: 5998.75 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: (ACER) (Fixed) (Total:81.35 GB) (Free:32.57 GB) NTFS Drive d: (Data) (Fixed) (Total:22.65 GB) (Free:3.62 GB) NTFS Drive e: (Internet Manager) (CDROM) (Total:0.05 GB) (Free:0 GB) CDFS Drive g: (Elements) (Fixed) (Total:931.51 GB) (Free:748.81 GB) NTFS ==================== MBR & Partition Table ================== ==================== End Of Log ============================ Geändert von Homomorphism (12.04.2014 um 16:44 Uhr) |
13.04.2014, 11:55 | #4 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows 7: Mozilla stürzt ab und es erscheint ein BluescreenZitat:
__________________ Logfiles bitte immer in CODE-Tags posten |
13.04.2014, 12:24 | #5 |
| Windows 7: Mozilla stürzt ab und es erscheint ein Bluescreen Sorry, das war natürlich sehr dumm von mir. FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-04-2014 01 Ran by Admin (administrator) on OCTAVIONOTEBOOK on 13-04-2014 13:22:39 Running from C:\Users\Octavio\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe (Acer Incorporated) C:\Program Files\Sleep Memory Optimizer\FFSService.exe () C:\ProgramData\DatacardService\HWDeviceService64.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe () C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\PSIA.exe () c:\Program Files\Acer\Acer Theft Shield\USecuAppSvc.exe (Atheros) C:\Program Files (x86)\Atheros\Ath_WlanAgent.exe (Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Intel Corporation) C:\Windows\system32\igfxsrvc.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe () C:\Program Files\Acer\Acer Theft Shield\USecuAppClient.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Dolby Laboratories Inc.) C:\Dolby PCEE4\pcee4.exe (Intel Corporation) C:\Windows\system32\igfxext.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Apple Inc.) D:\Program Files (x86)\iTunes\iTunesHelper.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (CyberLink) C:\Program Files (x86)\Cyberlink\MediaEspresso\DeviceDetector\DeviceDetector.exe () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\ismagent.exe () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\updateui.exe (Microsoft Corporation) C:\Windows\splwow64.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12459112 2012-03-16] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1158248 2012-03-10] (Realtek Semiconductor) HKLM\...\Run: [AtherosBtStack] - C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [1021056 2012-03-08] (Atheros Communications) HKLM\...\Run: [AthBtTray] - C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [800896 2012-03-08] (Atheros Commnucations) HKLM\...\Run: [Power Management] - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1829768 2012-02-07] (Acer Incorporated) HKLM\...\Run: [InstantUpdate] - C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuDaemon.exe [124520 2012-02-20] () HKLM\...\Run: [Secure Applicayion] - c:\Program Files\Acer\Acer Theft Shield\USecuAppClient.exe [257640 2012-03-06] () HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation) HKLM-x32\...\Run: [OOTag] - C:\Program Files (x86)\Acer\OOBEOffer\OOTag.exe [13856 2010-02-23] (Microsoft) HKLM-x32\...\Run: [Dolby Home Theater v4] - C:\Dolby PCEE4\pcee4.exe [506712 2011-06-01] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-27] (Intel Corporation) HKLM-x32\...\Run: [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe [1105488 2012-03-24] (Dritek System Inc.) HKLM-x32\...\Run: [SuiteTray] - C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [341360 2011-09-20] (Egis Technology Inc.) HKLM-x32\...\Run: [NBAgent] - C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [1406248 2011-03-22] (Nero AG) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-06] (Apple Inc.) HKLM-x32\...\Run: [WinampAgent] - "D:\Program Files (x86)\Winamp\winampa.exe" HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard) HKLM-x32\...\Run: [] - [X] HKLM-x32\...\Run: [iTunesHelper] - D:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-06] (Apple Inc.) HKLM\...\RunOnce: [*WerKernelReporting] - %SYSTEMROOT%\SYSTEM32\WerFault.exe -k -rq [415232 2009-07-14] (Microsoft Corporation) HKLM-x32\...\RunOnce: [ Malwarebytes Anti-Malware ] - D:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation) HKLM-x32\...\RunOnce: [ Malwarebytes Anti-Malware (cleanup)] - rundll32.exe "C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript [1127496 2013-04-04] (Malwarebytes Corporation) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\.DEFAULT\...\RunOnce: [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid} HKU\S-1-5-19\...\RunOnce: [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid} HKU\S-1-5-20\...\RunOnce: [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid} HKU\S-1-5-21-2527760400-2436397135-2658251733-1001\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.) HKU\S-1-5-21-2527760400-2436397135-2658251733-1001\...\Run: [WinPatrol] - D:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe [436800 2013-07-15] (BillP Studios) HKU\S-1-5-21-2527760400-2436397135-2658251733-1001\...\MountPoints2: {a99067eb-1acc-11e2-8601-9680beddddac} - E:\Setup.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {2e18814b-7337-11e3-a8ef-08edb9585f2c} - E:\AutoRun.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {2e188308-7337-11e3-a8ef-08edb9585f2c} - E:\AutoRun.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {59892f1e-5b2f-11e3-9349-08edb9585f2c} - E:\AutoRun.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {666866b3-3cd7-11e3-9a3d-08edb9585f2c} - E:\AutoRun.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {666866cd-3cd7-11e3-9a3d-08edb9585f2c} - E:\AutoRun.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {666866fb-3cd7-11e3-9a3d-08edb9585f2c} - E:\AutoRun.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {77bc75cb-6754-11e3-96cd-08edb9585f2c} - E:\AutoRun.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {77bc75e9-6754-11e3-96cd-08edb9585f2c} - E:\AutoRun.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {8380457c-5c44-11e3-ac4a-08edb9585f2b} - E:\AutoRun.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {ccc626fe-5768-11e3-bdc9-08edb9585f2c} - E:\AutoRun.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {dde15604-c0c1-11e3-9bdb-08edb9585f2b} - E:\AutoRun.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {f76fa12d-9634-11e3-8c0b-08edb9585f2c} - E:\AutoRun.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x713FC8D17096CD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll No File BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{037375DD-C61C-486A-B7FE-711E0C51FC62}: [NameServer]10.74.210.210 10.74.210.211 Tcpip\..\Interfaces\{35EAF2DC-C901-4A0C-9489-49D7158F8B2D}: [NameServer] Tcpip\..\Interfaces\{53EC8EE9-7859-47ED-A79E-3AF6A6359BBC}: [NameServer] Tcpip\..\Interfaces\{5829B6C7-F318-45C7-B99F-B4D8422C08EB}: [NameServer] Tcpip\..\Interfaces\{83F27B3B-D9A3-4CAF-98C8-D7A3118F45A9}: [NameServer]10.74.210.210 10.74.210.211 Tcpip\..\Interfaces\{872BB3BC-EC5F-474D-8978-6F554EF57D5D}: [NameServer] Tcpip\..\Interfaces\{97F66A92-7A05-42A2-8322-D3B90C230090}: [NameServer] Tcpip\..\Interfaces\{B915B0D8-04B3-4654-B399-88076163BB00}: [NameServer]10.74.210.210 10.74.210.211 Tcpip\..\Interfaces\{C149951C-15B2-4109-BCFF-6E6DADCB903F}: [NameServer] Tcpip\..\Interfaces\{C9058999-0CD6-430C-9A4F-A7862710E46D}: [NameServer] Tcpip\..\Interfaces\{D097112A-8F24-4906-A4C8-050547F7324E}: [NameServer] Tcpip\..\Interfaces\{DC9110D3-37D9-45BE-9C42-CFD9E8C749A8}: [NameServer] FireFox: ======== FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\i21tf6d9.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - D:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: SaveByclick - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\i21tf6d9.default\Extensions\50e9ac90d7550@50e9ac90d758a.com [2013-07-13] FF Extension: WOT - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\i21tf6d9.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2014-01-16] FF Extension: NoScript - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\i21tf6d9.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2012-09-19] FF Extension: Adblock Plus - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\i21tf6d9.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-09-19] Chrome: ======= CHR Extension: (SaveByclick) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mibcnakgfemboeekpgkkojofbeakhhha [2013-01-06] ==================== Services (Whitelisted) ================= R2 FFSOpzSvc; C:\Program Files\Sleep Memory Optimizer\FFSService.exe [141192 2011-09-17] (Acer Incorporated) R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] () R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [127320 2012-03-16] () S2 Internet Manager. RunOuc; C:\Program Files (x86)\T-Mobile\InternetManager_H\UpdateDog\ouc.exe [224096 2011-06-17] () S3 irstrtsv; C:\Windows\SysWOW64\irstrtsv.exe [192856 2012-02-24] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [162648 2012-03-16] (Intel Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation) R2 RS_Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [260640 2010-01-29] (Acer Incorporated) R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia) R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [660184 2013-07-03] (Secunia) R2 USecuAppSvc; c:\Program Files\Acer\Acer Theft Shield\USecuAppSvc.exe [236648 2012-03-06] () R2 ZAtheros Wlan Agent; C:\Program Files (x86)\Atheros\Ath_WlanAgent.exe [72864 2012-02-19] (Atheros) ==================== Drivers (Whitelisted) ==================== S3 AX88772B; C:\Windows\System32\DRIVERS\ax88772b.sys [98816 2011-01-01] (ASIX Electronics Corp.) S3 huawei_wwanecm; C:\Windows\System32\DRIVERS\ew_juwwanecm.sys [238080 2012-04-23] (Huawei Technologies Co., Ltd.) S3 irstrtdv; C:\Windows\System32\DRIVERS\irstrtdv.sys [26504 2012-02-23] (Intel Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation) R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-07-03] (Secunia) S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-12 23:38 - 2014-04-12 23:38 - 00000000 ___RD () C:\Users\Octavio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2014-04-12 17:27 - 2014-04-13 13:22 - 00017448 _____ () C:\Users\Octavio\Desktop\FRST.txt 2014-04-12 09:41 - 2014-04-12 09:41 - 00280368 _____ () C:\Windows\Minidump\041214-5553-01.dmp 2014-04-12 09:39 - 2014-04-12 17:24 - 02157568 _____ (Farbar) C:\Users\Octavio\Desktop\FRST64.exe 2014-04-12 09:37 - 2014-04-12 09:37 - 00000472 _____ () C:\Users\Octavio\Desktop\defogger_disable.log 2014-04-12 09:37 - 2014-04-12 09:37 - 00000000 _____ () C:\Users\Admin\defogger_reenable 2014-04-12 09:36 - 2014-04-12 09:36 - 00050477 _____ () C:\Users\Octavio\Desktop\Defogger.exe 2014-04-12 09:32 - 2014-04-12 09:32 - 00280368 _____ () C:\Windows\Minidump\041214-5647-01.dmp 2014-04-11 18:25 - 2014-04-11 18:25 - 00280368 _____ () C:\Windows\Minidump\041114-6396-02.dmp 2014-04-11 18:24 - 2014-04-11 18:24 - 00280368 _____ () C:\Windows\Minidump\041114-6552-01.dmp 2014-04-11 13:05 - 2014-04-11 13:05 - 00280368 _____ () C:\Windows\Minidump\041114-6396-01.dmp 2014-04-09 15:19 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-09 15:19 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-09 15:19 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-09 15:19 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-09 15:17 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-09 15:17 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-09 15:17 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-09 15:17 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-09 15:17 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-09 15:17 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-09 15:17 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-09 15:17 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-09 15:17 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-09 15:17 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-09 15:17 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-09 15:17 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-09 15:17 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-09 15:17 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-09 15:17 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-09 15:17 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-09 15:17 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-07 18:27 - 2014-04-07 18:27 - 00280368 _____ () C:\Windows\Minidump\040714-5538-01.dmp 2014-04-06 12:25 - 2014-04-06 12:25 - 00269376 _____ () C:\Windows\Minidump\040614-5787-01.dmp 2014-03-29 12:12 - 2014-03-29 12:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-19 18:25 - 2014-03-19 18:25 - 00000729 _____ () C:\Users\Octavio\Desktop\FLV Player.lnk 2014-03-19 18:25 - 2014-03-19 18:25 - 00000000 ____D () C:\Users\Octavio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FLV Player 2014-03-19 18:23 - 2014-03-19 18:23 - 00000000 ____D () C:\Users\Octavio\AppData\Roaming\WinRAR 2014-03-19 18:23 - 2014-03-19 18:23 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2014-03-14 11:09 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-14 11:09 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-14 11:09 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-14 11:09 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-14 11:09 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-14 11:09 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-14 11:09 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-14 11:09 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-14 11:09 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-14 11:09 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-14 11:09 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-14 11:09 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-14 11:09 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-14 11:09 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-14 11:09 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-14 11:09 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-14 11:09 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-14 11:09 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-14 11:09 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-14 11:09 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-14 11:09 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-14 11:09 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-14 11:09 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-14 11:09 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-14 11:09 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-14 11:09 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-14 11:09 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-14 11:09 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-14 11:09 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-14 11:09 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-14 11:09 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-14 11:09 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-14 11:09 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-14 11:09 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-14 11:09 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-14 11:09 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-03-14 11:08 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-14 11:08 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-03-14 11:08 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2014-03-14 11:08 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-03-14 11:03 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-03-14 11:03 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-14 11:03 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-03-14 11:03 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll ==================== One Month Modified Files and Folders ======= 2014-04-13 13:22 - 2014-04-12 17:27 - 00017448 _____ () C:\Users\Octavio\Desktop\FRST.txt 2014-04-13 13:22 - 2014-01-20 11:42 - 00000000 ____D () C:\FRST 2014-04-13 13:21 - 2012-05-15 02:48 - 01261749 _____ () C:\Windows\WindowsUpdate.log 2014-04-13 13:20 - 2012-05-15 12:41 - 00699682 _____ () C:\Windows\system32\perfh007.dat 2014-04-13 13:20 - 2012-05-15 12:41 - 00149790 _____ () C:\Windows\system32\perfc007.dat 2014-04-13 13:20 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-13 13:19 - 2012-03-27 20:45 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-13 12:33 - 2009-07-14 06:45 - 00024416 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-13 12:33 - 2009-07-14 06:45 - 00024416 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-13 11:41 - 2012-05-15 02:47 - 00000830 _____ () C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job 2014-04-12 23:54 - 2009-07-14 06:51 - 00115668 _____ () C:\Windows\setupact.log 2014-04-12 23:38 - 2014-04-12 23:38 - 00000000 ___RD () C:\Users\Octavio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2014-04-12 23:38 - 2012-05-15 02:47 - 00000828 _____ () C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job 2014-04-12 23:16 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-12 20:17 - 2014-01-29 10:08 - 00071680 ___SH () C:\Users\Octavio\Desktop\Thumbs.db 2014-04-12 17:24 - 2014-04-12 09:39 - 02157568 _____ (Farbar) C:\Users\Octavio\Desktop\FRST64.exe 2014-04-12 09:41 - 2014-04-12 09:41 - 00280368 _____ () C:\Windows\Minidump\041214-5553-01.dmp 2014-04-12 09:41 - 2012-06-14 19:36 - 502918635 _____ () C:\Windows\MEMORY.DMP 2014-04-12 09:41 - 2012-06-14 19:36 - 00000000 ____D () C:\Windows\Minidump 2014-04-12 09:37 - 2014-04-12 09:37 - 00000472 _____ () C:\Users\Octavio\Desktop\defogger_disable.log 2014-04-12 09:37 - 2014-04-12 09:37 - 00000000 _____ () C:\Users\Admin\defogger_reenable 2014-04-12 09:37 - 2012-09-18 19:48 - 00000000 ____D () C:\Users\Admin 2014-04-12 09:36 - 2014-04-12 09:36 - 00050477 _____ () C:\Users\Octavio\Desktop\Defogger.exe 2014-04-12 09:32 - 2014-04-12 09:32 - 00280368 _____ () C:\Windows\Minidump\041214-5647-01.dmp 2014-04-11 18:25 - 2014-04-11 18:25 - 00280368 _____ () C:\Windows\Minidump\041114-6396-02.dmp 2014-04-11 18:24 - 2014-04-11 18:24 - 00280368 _____ () C:\Windows\Minidump\041114-6552-01.dmp 2014-04-11 13:05 - 2014-04-11 13:05 - 00280368 _____ () C:\Windows\Minidump\041114-6396-01.dmp 2014-04-11 13:05 - 2010-11-21 05:47 - 00145016 _____ () C:\Windows\PFRO.log 2014-04-10 17:07 - 2013-12-11 21:44 - 00000000 ____D () C:\ProgramData\OnlineUpdate 2014-04-10 09:36 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-04-09 20:19 - 2013-07-25 20:45 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-09 20:18 - 2012-09-19 15:43 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-09 01:21 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\LiveKernelReports 2014-04-07 18:27 - 2014-04-07 18:27 - 00280368 _____ () C:\Windows\Minidump\040714-5538-01.dmp 2014-04-06 12:51 - 2012-09-18 22:13 - 00000000 ____D () C:\Users\Octavio 2014-04-06 12:25 - 2014-04-06 12:25 - 00269376 _____ () C:\Windows\Minidump\040614-5787-01.dmp 2014-03-31 03:16 - 2014-04-09 15:19 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-09 15:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-09 15:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-09 15:19 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-29 13:46 - 2012-09-19 16:28 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-29 12:12 - 2014-03-29 12:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-28 19:49 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-03-26 13:00 - 2012-09-19 15:36 - 00001912 _____ () C:\Windows\epplauncher.mif 2014-03-26 13:00 - 2012-09-19 15:36 - 00000000 ____D () C:\Program Files\Microsoft Security Client 2014-03-26 13:00 - 2012-09-19 15:36 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client 2014-03-19 18:25 - 2014-03-19 18:25 - 00000729 _____ () C:\Users\Octavio\Desktop\FLV Player.lnk 2014-03-19 18:25 - 2014-03-19 18:25 - 00000000 ____D () C:\Users\Octavio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FLV Player 2014-03-19 18:25 - 2012-12-25 23:28 - 00000238 _____ () C:\Windows\wininit.ini 2014-03-19 18:23 - 2014-03-19 18:23 - 00000000 ____D () C:\Users\Octavio\AppData\Roaming\WinRAR 2014-03-19 18:23 - 2014-03-19 18:23 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2014-03-14 13:17 - 2013-03-15 14:18 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-03-14 13:17 - 2013-03-15 14:18 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-03-14 13:17 - 2009-07-14 06:45 - 00334552 _____ () C:\Windows\system32\FNTCACHE.DAT Files to move or delete: ==================== C:\Users\Admin\AppData\Roaming\EasyToolz.ini Some content of TEMP: ==================== C:\Users\Admin\AppData\Local\Temp\AskSLib.dll C:\Users\Admin\AppData\Local\Temp\clearfiSetup.exe C:\Users\Admin\AppData\Local\Temp\Core.dll C:\Users\Admin\AppData\Local\Temp\dbghelp.dll C:\Users\Admin\AppData\Local\Temp\Engine.dll C:\Users\Admin\AppData\Local\Temp\IFC23.dll C:\Users\Admin\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe C:\Users\Admin\AppData\Local\Temp\jre-7u40-windows-i586-iftw.exe C:\Users\Admin\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\Admin\AppData\Local\Temp\MSNEB98.exe C:\Users\Admin\AppData\Local\Temp\MSVCR71.dll C:\Users\Admin\AppData\Local\Temp\npp.6.2.Installer.exe C:\Users\Admin\AppData\Local\Temp\ogg.dll C:\Users\Admin\AppData\Local\Temp\Setup.exe C:\Users\Admin\AppData\Local\Temp\vorbis.dll C:\Users\Admin\AppData\Local\Temp\vorbisfile.dll C:\Users\Admin\AppData\Local\Temp\Window.dll C:\Users\Admin\AppData\Local\Temp\xmlUpdater.exe C:\Users\Octavio\AppData\Local\Temp\install_flashplayer11x32au_mssd_aih.exe C:\Users\Octavio\AppData\Local\Temp\install_reader10_de_gtbd_chrd_dn_aih.exe C:\Users\Octavio\AppData\Local\Temp\npp.6.2.2.Installer.exe C:\Users\Octavio\AppData\Local\Temp\npp.6.2.Installer.exe C:\Users\Octavio\AppData\Local\Temp\npp.6.3.2.Installer.exe C:\Users\Octavio\AppData\Local\Temp\npp.6.3.Installer.exe C:\Users\Octavio\AppData\Local\Temp\npp.6.5.2.Installer.exe C:\Users\Octavio\AppData\Local\Temp\SkypeSetup.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-09 02:18 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-04-2014 01 Ran by Admin at 2014-04-13 13:22:55 Running from C:\Users\Octavio\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} ==================== Installed Programs ====================== 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Acer Crystal Eye Webcam (HKLM-x32\...\InstallShield_{A0382E3C-7384-429A-9BFA-AF5888E5A193}) (Version: 1.5.2624.00 - CyberLink Corp.) Acer Crystal Eye Webcam (x32 Version: 1.5.2624.00 - CyberLink Corp.) Hidden Acer ePower Management (HKLM-x32\...\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 6.00.3010 - Acer Incorporated) Acer eRecovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3507 - Acer Incorporated) Acer Instant Update Service (HKLM\...\{86B80582-A4F2-4F12-B29F-49D3309C7024}) (Version: 1.00.3001 - Acer Incorporated) Acer Theft Shield (HKLM\...\{8ADB0CD2-4E5A-452F-BB3B-3A2984CAC749}) (Version: 1.00.3001 - Acer Incorporated) Acer Updater (HKLM-x32\...\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3501 - Acer Incorporated) Acer VCM (HKLM-x32\...\{047F790A-7A2A-4B6A-AD02-38092BA63DAC}) (Version: 4.05.3501 - Acer Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.8.0.870 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.8.0.870 - Adobe Systems Incorporated) Hidden Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated) Apple Application Support (HKLM-x32\...\{21FC2093-6E43-460B-B9B0-5F5AA35BBB0F}) (Version: 3.0 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{FE86CB0C-FCB3-4358-B4B0-B0A41E33B3DD}) (Version: 7.1.0.32 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Atheros Bluetooth Suite (64) (HKLM\...\{230D1595-57DA-4933-8C4E-375797EBB7E1}) (Version: 7.4.0.126 - Atheros) AX88772B Windows 7 Drivers (HKLM-x32\...\InstallShield_{54A168C9-2250-4058-80EB-1F4A4192548A}) (Version: 1.0.1.1 - ASIX Electronics Corporation) AX88772B Windows 7 Drivers (x32 Version: 1.0.1.1 - ASIX Electronics Corporation) Hidden Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) calibre (HKLM-x32\...\{5FD4B351-1567-426F-AEB4-08F41E3FA6C5}) (Version: 0.9.31 - Kovid Goyal) CATBox 1.1 (HKLM-x32\...\{5140A79F-17C4-4B33-91D6-330D9B7C2D4C}_is1) (Version: - Schliep & Hochstaettler) CyberLink MediaEspresso (HKLM-x32\...\InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}) (Version: 6.5.1720_38230 - CyberLink Corp.) CyberLink MediaEspresso (x32 Version: 6.5.1720_38230 - CyberLink Corp.) Hidden Dolby Home Theater v4 (HKLM-x32\...\{B26438B4-BF51-49C3-9567-7F14A5E40CB9}) (Version: 7.2.7000.7 - Dolby Laboratories Inc) GPL Ghostscript (HKLM-x32\...\GPL Ghostscript 9.05) (Version: 9.05 - Artifex Software Inc.) High-Definition Video Playback (x32 Version: 7.1.13900.47.0 - Nero AG) Hidden HP Deskjet 3520 series - Grundlegende Software für das Gerät (HKLM\...\{15B2F0E3-3FAC-4495-B0FD-398EECFA4100}) (Version: 28.0.1315.0 - Hewlett-Packard Co.) HP Deskjet 3520 series Hilfe (HKLM-x32\...\{6B953497-169C-4929-9AA9-A9F510347468}) (Version: 27.0.0 - Hewlett Packard) HP Deskjet 3520 series Setup Guide (HKLM-x32\...\{AEEDCEB7-00B8-4BE1-B492-AB04803D5F1E}) (Version: 27.0.0 - Hewlett Packard) HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard) Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3501 - Acer Incorporated) Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.35342 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.4.1441 - Intel Corporation) Intel(R) OpenCL CPU Runtime (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2653 - Intel Corporation) Intel(R) Rapid Start Technology (HKLM-x32\...\3D073343-CEEB-4ce7-85AC-A69A7631B5D6) (Version: 1.0.0.1022 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.0.0.1032 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.4.220 - Intel Corporation) Intel® Trusted Connect Service Client (HKLM\...\{09536BA1-E498-4CC3-B834-D884A67D7E34}) (Version: 1.23.605.1 - Intel Corporation) Internet Manager (HKLM-x32\...\Internet Manager) (Version: 22.001.18.68.55 - Huawei Technologies Co.,Ltd) iTunes (HKLM\...\{96B53CA8-5ABB-49D8-96F1-F6C0D73A76C6}) (Version: 11.1.4.62 - Apple Inc.) Java SE Development Kit 7 Update 51 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0170510}) (Version: 1.7.0.510 - Oracle) Launch Manager (HKLM-x32\...\LManager) (Version: 5.1.15 - Acer Inc.) LibreOffice 3.6 (HKLM-x32\...\{CBCF6C86-4738-4A84-9C2C-331804DCEB9B}) (Version: 3.6.3.2 - The Document Foundation) LMMS 0.4.15 (HKLM-x32\...\LMMS) (Version: 0.4.15 - LMMS Developers) Malwarebytes Anti-Malware Version 1.75.0.1300 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation) Marketsplash Schnellzugriffe (HKLM-x32\...\{7A108EBC-C9DF-4E14-93A8-42CF316F1ECF}) (Version: 1.0.1.7 - Hewlett-Packard) MATLAB R2011a (HKLM\...\MatlabR2011a) (Version: 7.12 - The MathWorks, Inc.) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Security Client (Version: 4.5.0216.0 - Microsoft Corporation) Hidden Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) MiKTeX 2.9 (HKLM\...\MiKTeX 2.9) (Version: 2.9 - MiKTeX.org) Mozilla Firefox 28.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla) Mozilla Thunderbird 17.0.7 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 17.0.7 (x86 de)) (Version: 17.0.7 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) MyWinLocker (Version: 4.0.14.27 - Egis Technology Inc.) Hidden MyWinLocker 4 (x32 Version: 4.0.14.27 - Egis Technology Inc.) Hidden MyWinLocker Suite (HKLM-x32\...\InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}) (Version: 4.0.14.19 - Egis Technology Inc.) MyWinLocker Suite (x32 Version: 4.0.14.19 - Egis Technology Inc.) Hidden Nero BackItUp 10 (HKLM-x32\...\{68AB6930-5BFF-4FF6-923B-516A91984FE6}) (Version: 5.6.11700.17.100 - Nero AG) Nero BackItUp 10 Help (CHM) (x32 Version: 10.5.10700 - Nero AG) Hidden Nero BurnRights 10 (HKLM-x32\...\{943CFD7D-5336-47AF-9418-E02473A5A517}) (Version: 4.2.10500.1.102 - Nero AG) Nero BurnRights 10 Help (CHM) (x32 Version: 10.5.10000 - Nero AG) Hidden Nero Control Center 10 (x32 Version: 10.2.11100.1.1 - Nero AG) Hidden Nero ControlCenter 10 Help (CHM) (x32 Version: 10.5.10000 - Nero AG) Hidden Nero Core Components 10 (x32 Version: 2.0.19800.9.10 - Nero AG) Hidden Nero CoverDesigner 10 (HKLM-x32\...\{FCF00A6E-FB58-477A-ABE9-232907105521}) (Version: 5.2.11400.11.100 - Nero AG) Nero CoverDesigner 10 Help (CHM) (x32 Version: 10.5.10000 - Nero AG) Hidden Nero DiscSpeed 10 (HKLM-x32\...\{34490F4E-48D0-492E-8249-B48BECF0537C}) (Version: 6.2.10500.2.100 - Nero AG) Nero DiscSpeed 10 Help (CHM) (x32 Version: 10.5.10000 - Nero AG) Hidden Nero Express 10 (HKLM-x32\...\{70550193-1C22-445C-8FA4-564E155DB1A7}) (Version: 10.2.12400.25.100 - Nero AG) Nero Express 10 Help (CHM) (x32 Version: 10.5.10200 - Nero AG) Hidden Nero InfoTool 10 (HKLM-x32\...\{F412B4AF-388C-4FF5-9B2F-33DB1C536953}) (Version: 7.2.10400.5.100 - Nero AG) Nero InfoTool 10 Help (CHM) (x32 Version: 10.5.10000 - Nero AG) Hidden Nero Multimedia Suite 10 Essentials (HKLM-x32\...\{89590A73-9AC3-48ED-B83E-6489900DED5A}) (Version: 10.5.10000 - Nero AG) Nero StartSmart 10 (HKLM-x32\...\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}) (Version: 10.2.11300.12.100 - Nero AG) Nero StartSmart 10 Help (CHM) (x32 Version: 10.5.10000 - Nero AG) Hidden Nero Update (x32 Version: 11.0.11500.28.0 - Nero AG) Hidden Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.5.2 - Notepad++ Team) PDF Split And Merge Basic (HKLM\...\{C91B24F6-1629-11E2-B696-21676188709B}) (Version: 2.2.2 - Andrea Vacondio) Python 2.7.6 (64-bit) (HKLM\...\{C3CC4DF5-39A5-4027-B136-2B3E1F5AB6E3}) (Version: 2.7.6150 - Python Software Foundation) Qualcomm Atheros WiFi Driver Installation (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 3.1 - Qualcomm Atheros) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6597 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7601.39025 - Realtek Semiconductor Corp.) Secunia PSI (3.0.0.7011) (HKLM-x32\...\Secunia PSI) (Version: 3.0.0.7011 - Secunia) Shredder (Version: 2.0.8.9 - Egis Technology Inc.) Hidden Shredder (x32 Version: 2.0.8.9 - Egis Technology Inc.) Hidden Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) Sleep Memory Optimizer (HKLM-x32\...\{34BE2594-1D20-4A2E-97A0-B9E2837520AE}) (Version: 1.00.3004 - Acer Incorporated) Smart Timer (HKLM-x32\...\{89DB52FC-EA72-468F-A0C7-150AF8B7AB74}) (Version: 1.00.3004 - Acer Incorporated) SpywareBlaster 5.0 (HKLM-x32\...\SpywareBlaster_is1) (Version: 5.0.0 - BrightFort LLC) TeXnicCenter Version 2.0 Beta 1 (HKLM\...\TeXnicCenter_is1) (Version: 2.0 Beta 1 - The TeXnicCenter Team) TSST OEM Content (HKLM-x32\...\{885AFEC2-0809-47CE-8B3F-00AEC19DDD5F}) (Version: 10.0.10300.0.0 - Nero AG) Überwachungstool für die Intel® Turbo-Boost-Technik 2.5 (HKLM\...\{6C9365EB-1F9E-4893-9196-3EC77C88D0C5}) (Version: 2.5.1.0 - Intel) Welcome Center (HKLM-x32\...\Acer Welcome Center) (Version: 1.02.3507 - Acer Incorporated) WinPatrol (HKLM\...\{4BB7A109-FDB5-45E3-9DB9-ECB2EA7B80EE}) (Version: 28.5.2013.0 - BillP Studios) WinRAR 5.10 beta 1 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.10.1 - win.rar GmbH) WinSCP 5.1.6 (HKLM-x32\...\winscp3_is1) (Version: 5.1.6 - Martin Prikryl) ==================== Restore Points ========================= 11-04-2014 08:48:54 Geplanter Prüfpunkt 13-04-2014 10:00:11 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {1AB333BC-9380-4B0F-9AFC-ECE472FDF735} - System32\Tasks\hpUtility.exe_{06E9ED4A-8202-492F-B83C-D7FD23AADE98} => C:\Program Files\HP\HP Deskjet 3520 series\Bin\utils\hpUtility.exe [2012-10-17] (Hewlett-Packard Co.) Task: {3EBE6547-6EC8-45A8-AEBF-D0C6B3A18A05} - System32\Tasks\hpUtility.exe => C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\utils\hpUtility.exe Task: {4A77AFC5-DEDB-4052-8CD7-FC1815775C96} - System32\Tasks\DeviceDetector => C:\Program Files (x86)\Cyberlink\MediaEspresso\DeviceDetector\DeviceDetector.exe [2011-05-20] (CyberLink) Task: {56F06DD2-E015-43AD-B2FD-69C6114A441C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-12] (Adobe Systems Incorporated) Task: {7CA41C93-7F9A-447D-A080-1A8AA78ACE99} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {8530F25C-6E85-4071-B4A8-5D79BB1F6E1C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {ABFF5843-CD09-4706-A95D-D09EE9B96991} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {B10A38B2-91C0-4CD4-9D82-55EF5FDAE7D9} - System32\Tasks\Smart Timer Task Scheduler => Smart_Timer.exe Task: {CF4FFBCE-786A-47A9-AC5D-0A5A48958081} - System32\Tasks\Intel® Rapid Start Technology Manager => C:\Program Files (x86)\Intel\irstrt\RapidStartConfig.exe [2012-02-24] (Intel) Task: {E433214B-8740-428A-A491-22F90E4BE505} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {EA1E36F0-DD88-423F-A651-B4D9F2D504EF} - System32\Tasks\UALU notificatin => C:\Program Files\Acer\Acer Updater\UALU.exe [2012-02-07] (Acer Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe ==================== Loaded Modules (whitelisted) ============= 2011-03-14 17:27 - 2011-03-14 17:27 - 00346976 _____ () C:\ProgramData\DatacardService\HWDeviceService64.exe 2012-05-15 02:46 - 2012-03-16 13:48 - 00127320 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe 2013-10-25 18:10 - 2011-06-17 13:04 - 00224096 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe 2012-03-06 21:49 - 2012-03-06 21:49 - 00236648 _____ () c:\Program Files\Acer\Acer Theft Shield\USecuAppSvc.exe 2012-03-06 21:49 - 2012-03-06 21:49 - 00114280 _____ () c:\Program Files\Acer\Acer Theft Shield\SysCtrl.dll 2012-03-06 21:49 - 2012-03-06 21:49 - 00197736 _____ () c:\Program Files\Acer\Acer Theft Shield\LogMgr2.dll 2012-03-06 21:49 - 2012-03-06 21:49 - 00140904 _____ () c:\Program Files\Acer\Acer Theft Shield\WHNCtrl.dll 2009-01-21 16:45 - 2009-01-21 16:45 - 01401856 _____ () C:\Program Files (x86)\EgisTec MyWinLocker\x64\LIBEAY32.dll 2012-06-18 17:24 - 2012-06-18 17:24 - 00222720 _____ () D:\Program Files (x86)\Notepad++\NppShell_05.dll 2012-05-15 12:33 - 2012-02-14 19:53 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2012-03-06 21:49 - 2012-03-06 21:49 - 00257640 _____ () C:\Program Files\Acer\Acer Theft Shield\USecuAppClient.exe 2012-03-06 21:49 - 2012-03-06 21:49 - 00213608 _____ () C:\Program Files\Acer\Acer Theft Shield\CommPtl.dll 2012-03-06 21:49 - 2012-03-06 21:49 - 00197736 _____ () C:\Program Files\Acer\Acer Theft Shield\LogMgr2.dll 2012-03-06 21:49 - 2012-03-06 21:49 - 00114280 _____ () C:\Program Files\Acer\Acer Theft Shield\SysCtrl.dll 2012-03-06 21:49 - 2012-03-06 21:49 - 00140904 _____ () C:\Program Files\Acer\Acer Theft Shield\WHNCtrl.dll 2012-02-20 15:34 - 2012-02-20 15:34 - 00040552 _____ () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe 2012-02-20 15:34 - 2012-02-20 15:34 - 00022632 _____ () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe 2011-12-23 10:24 - 2011-12-23 10:24 - 00119808 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\updateui.exe 2014-02-06 01:52 - 2014-02-06 01:52 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2014-02-06 01:52 - 2014-02-06 01:52 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2013-10-25 18:10 - 2009-01-10 12:32 - 00011362 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\mingwm10.dll 2013-10-25 18:10 - 2009-06-22 20:42 - 00043008 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\libgcc_s_dw2-1.dll 2013-10-25 18:10 - 2010-05-05 10:47 - 02415104 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\QtCore4.dll 2013-10-25 18:10 - 2010-02-10 16:10 - 01148416 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\QtNetwork4.dll 2012-05-15 02:46 - 2012-03-07 16:27 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll 2014-03-29 12:12 - 2014-03-29 12:12 - 03642480 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2011-08-15 20:12 - 2011-08-15 20:12 - 02603520 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtCore4.dll 2011-08-15 20:15 - 2011-08-15 20:15 - 00382464 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtXml4.dll 2011-08-17 16:41 - 2011-08-17 16:41 - 00400384 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\sqlite3.dll 2011-08-17 16:48 - 2011-08-17 16:48 - 00322048 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\log4cplus.dll 2011-11-25 13:29 - 2011-11-25 13:29 - 00015872 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\featureController.dll 2011-08-15 20:12 - 2011-08-15 20:12 - 01006592 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtNetwork4.dll 2011-08-17 16:48 - 2011-08-17 16:48 - 00195584 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\libgsoap.dll 2011-08-15 19:23 - 2011-08-15 19:23 - 00062464 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\zlib1.dll 2011-11-25 13:28 - 2011-11-25 13:28 - 00484352 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\DeviceProfile.dll 2011-11-25 13:42 - 2011-11-25 13:42 - 00499976 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\plugin\PServerPlugin.dll 2011-11-25 13:26 - 2011-11-25 13:26 - 00013824 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\eventsSender.dll 2011-07-19 16:05 - 2011-07-19 16:05 - 14978048 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtWebKit4.dll 2011-07-19 16:04 - 2011-07-19 16:04 - 00317952 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\phonon4.dll 2011-08-15 20:17 - 2011-08-15 20:17 - 09224704 _____ () C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtGui4.dll 2014-03-12 12:19 - 2014-03-12 12:19 - 16276872 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:5C321E34 ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (04/13/2014 01:18:47 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 609059 Error: (04/13/2014 01:18:47 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 609059 Error: (04/13/2014 01:18:47 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/13/2014 01:08:39 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 1061 Error: (04/13/2014 01:08:39 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 1061 Error: (04/13/2014 01:08:39 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/13/2014 10:14:24 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 34288910 Error: (04/13/2014 10:14:24 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 34288910 Error: (04/13/2014 10:14:24 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/13/2014 00:42:57 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 1294 System errors: ============= Error: (04/13/2014 01:21:25 PM) (Source: iaStor) (User: ) Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet. Error: (04/13/2014 01:21:24 PM) (Source: iaStor) (User: ) Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet. Error: (04/13/2014 01:21:23 PM) (Source: iaStor) (User: ) Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet. Error: (04/13/2014 01:21:23 PM) (Source: iaStor) (User: ) Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet. Error: (04/13/2014 01:21:22 PM) (Source: iaStor) (User: ) Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet. Error: (04/13/2014 01:21:21 PM) (Source: iaStor) (User: ) Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet. Error: (04/13/2014 01:21:21 PM) (Source: iaStor) (User: ) Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet. Error: (04/13/2014 01:21:20 PM) (Source: iaStor) (User: ) Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet. Error: (04/13/2014 01:21:19 PM) (Source: iaStor) (User: ) Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet. Error: (04/13/2014 01:21:19 PM) (Source: iaStor) (User: ) Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet. Microsoft Office Sessions: ========================= Error: (04/13/2014 01:18:47 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 609059 Error: (04/13/2014 01:18:47 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 609059 Error: (04/13/2014 01:18:47 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/13/2014 01:08:39 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 1061 Error: (04/13/2014 01:08:39 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 1061 Error: (04/13/2014 01:08:39 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/13/2014 10:14:24 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 34288910 Error: (04/13/2014 10:14:24 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 34288910 Error: (04/13/2014 10:14:24 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/13/2014 00:42:57 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 1294 ==================== Memory info =========================== Percentage of memory in use: 62% Total physical RAM: 3934.36 MB Available physical RAM: 1478.1 MB Total Pagefile: 7866.89 MB Available Pagefile: 5276.15 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: (ACER) (Fixed) (Total:81.35 GB) (Free:31.62 GB) NTFS Drive d: (Data) (Fixed) (Total:22.65 GB) (Free:3.62 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 119 GB) (Disk ID: 5833D626) Partition 1: (Not Active) - (Size=15 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=104 GB) - (Type=OF Extended) ==================== End Of Log ============================ |
13.04.2014, 12:39 | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows 7: Mozilla stürzt ab und es erscheint ein Bluescreen Adware/Junkware/Toolbars entfernen 1. Schritt: adwCleaner Downloade Dir bitte AdwCleaner auf deinen Desktop.
2. Schritt: JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
3. Schritt: Frisches Log mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ --> Windows 7: Mozilla stürzt ab und es erscheint ein Bluescreen |
13.04.2014, 13:44 | #7 |
| Windows 7: Mozilla stürzt ab und es erscheint ein BluescreenCode:
ATTFilter # AdwCleaner v3.023 - Bericht erstellt am 13/04/2014 um 14:07:34 # Aktualisiert 01/04/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Admin - OCTAVIONOTEBOOK # Gestartet von : C:\Users\Octavio\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SaveByclick Ordner Gelöscht : C:\Users\Octavio\AppData\Local\DownloadGuide Ordner Gelöscht : C:\Users\Octavio\AppData\Roaming\pdfforge ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16521 -\\ Mozilla Firefox v28.0 (de) [ Datei : C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\i21tf6d9.default\prefs.js ] Zeile gelöscht : user_pref("extensions.50e9ac90d75fd.scode", "(function(){try{if(window.self.location.hostname.indexOf(\"acebook.co\")>-1){return};}catch(e){};(function(){if(window.self==window.top&&!document.getEleme[...] [ Datei : C:\Users\Octavio\AppData\Roaming\Mozilla\Firefox\Profiles\1wck7teo.default\prefs.js ] -\\ Google Chrome v [ Datei : C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [1666 octets] - [13/04/2014 14:06:08] AdwCleaner[S0].txt - [1595 octets] - [13/04/2014 14:07:34] ########## EOF - \AdwCleaner\AdwCleaner[S0].txt - [1655 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Home Premium x64 Ran by Admin on 13.04.2014 at 14:25:43,71 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\Admin\AppData\Roaming\mozilla\firefox\profiles\i21tf6d9.default\minidumps [3 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 13.04.2014 at 14:30:01,01 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-04-2014 01 Ran by Admin (administrator) on OCTAVIONOTEBOOK on 13-04-2014 14:40:20 Running from D:\Users\Octavio\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe (Acer Incorporated) C:\Program Files\Sleep Memory Optimizer\FFSService.exe () C:\ProgramData\DatacardService\HWDeviceService64.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe () C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\PSIA.exe () c:\Program Files\Acer\Acer Theft Shield\USecuAppSvc.exe (Atheros) C:\Program Files (x86)\Atheros\Ath_WlanAgent.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Intel Corporation) C:\Windows\system32\igfxsrvc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe () C:\Program Files\Acer\Acer Theft Shield\USecuAppClient.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe (Intel Corporation) C:\Windows\system32\igfxext.exe (Dolby Laboratories Inc.) C:\Dolby PCEE4\pcee4.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Apple Inc.) D:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe (CyberLink) C:\Program Files (x86)\Cyberlink\MediaEspresso\DeviceDetector\DeviceDetector.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe (Thisisu) D:\Users\Octavio\Downloads\JRT.exe (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12459112 2012-03-16] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1158248 2012-03-10] (Realtek Semiconductor) HKLM\...\Run: [AtherosBtStack] - C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [1021056 2012-03-08] (Atheros Communications) HKLM\...\Run: [AthBtTray] - C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [800896 2012-03-08] (Atheros Commnucations) HKLM\...\Run: [Power Management] - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1829768 2012-02-07] (Acer Incorporated) HKLM\...\Run: [InstantUpdate] - C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuDaemon.exe [124520 2012-02-20] () HKLM\...\Run: [Secure Applicayion] - c:\Program Files\Acer\Acer Theft Shield\USecuAppClient.exe [257640 2012-03-06] () HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation) HKLM-x32\...\Run: [OOTag] - C:\Program Files (x86)\Acer\OOBEOffer\OOTag.exe [13856 2010-02-23] (Microsoft) HKLM-x32\...\Run: [Dolby Home Theater v4] - C:\Dolby PCEE4\pcee4.exe [506712 2011-06-01] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-27] (Intel Corporation) HKLM-x32\...\Run: [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe [1105488 2012-03-24] (Dritek System Inc.) HKLM-x32\...\Run: [SuiteTray] - C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [341360 2011-09-20] (Egis Technology Inc.) HKLM-x32\...\Run: [NBAgent] - C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [1406248 2011-03-22] (Nero AG) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-06] (Apple Inc.) HKLM-x32\...\Run: [WinampAgent] - "D:\Program Files (x86)\Winamp\winampa.exe" HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard) HKLM-x32\...\Run: [] - [X] HKLM-x32\...\Run: [iTunesHelper] - D:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-06] (Apple Inc.) HKLM\...\RunOnce: [*WerKernelReporting] - %SYSTEMROOT%\SYSTEM32\WerFault.exe -k -rq [415232 2009-07-14] (Microsoft Corporation) HKLM-x32\...\RunOnce: [ Malwarebytes Anti-Malware ] - D:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation) HKLM-x32\...\RunOnce: [ Malwarebytes Anti-Malware (cleanup)] - rundll32.exe "C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript [1127496 2013-04-04] (Malwarebytes Corporation) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\.DEFAULT\...\RunOnce: [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid} HKU\S-1-5-19\...\RunOnce: [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid} HKU\S-1-5-20\...\RunOnce: [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid} HKU\S-1-5-21-2527760400-2436397135-2658251733-1001\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.) HKU\S-1-5-21-2527760400-2436397135-2658251733-1001\...\Run: [WinPatrol] - D:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe [436800 2013-07-15] (BillP Studios) HKU\S-1-5-21-2527760400-2436397135-2658251733-1001\...\MountPoints2: {a99067eb-1acc-11e2-8601-9680beddddac} - E:\Setup.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {2e18814b-7337-11e3-a8ef-08edb9585f2c} - E:\AutoRun.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {2e188308-7337-11e3-a8ef-08edb9585f2c} - E:\AutoRun.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {59892f1e-5b2f-11e3-9349-08edb9585f2c} - E:\AutoRun.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {666866b3-3cd7-11e3-9a3d-08edb9585f2c} - E:\AutoRun.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {666866cd-3cd7-11e3-9a3d-08edb9585f2c} - E:\AutoRun.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {666866fb-3cd7-11e3-9a3d-08edb9585f2c} - E:\AutoRun.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {77bc75cb-6754-11e3-96cd-08edb9585f2c} - E:\AutoRun.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {77bc75e9-6754-11e3-96cd-08edb9585f2c} - E:\AutoRun.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {8380457c-5c44-11e3-ac4a-08edb9585f2b} - E:\AutoRun.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {ccc626fe-5768-11e3-bdc9-08edb9585f2c} - E:\AutoRun.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {dde15604-c0c1-11e3-9bdb-08edb9585f2b} - E:\AutoRun.exe HKU\S-1-5-21-2527760400-2436397135-2658251733-1003\...\MountPoints2: {f76fa12d-9634-11e3-8c0b-08edb9585f2c} - E:\AutoRun.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x713FC8D17096CD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll No File BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{037375DD-C61C-486A-B7FE-711E0C51FC62}: [NameServer]10.74.210.210 10.74.210.211 Tcpip\..\Interfaces\{35EAF2DC-C901-4A0C-9489-49D7158F8B2D}: [NameServer] Tcpip\..\Interfaces\{53EC8EE9-7859-47ED-A79E-3AF6A6359BBC}: [NameServer] Tcpip\..\Interfaces\{5829B6C7-F318-45C7-B99F-B4D8422C08EB}: [NameServer] Tcpip\..\Interfaces\{83F27B3B-D9A3-4CAF-98C8-D7A3118F45A9}: [NameServer]10.74.210.210 10.74.210.211 Tcpip\..\Interfaces\{872BB3BC-EC5F-474D-8978-6F554EF57D5D}: [NameServer] Tcpip\..\Interfaces\{97F66A92-7A05-42A2-8322-D3B90C230090}: [NameServer] Tcpip\..\Interfaces\{B915B0D8-04B3-4654-B399-88076163BB00}: [NameServer]10.74.210.210 10.74.210.211 Tcpip\..\Interfaces\{C149951C-15B2-4109-BCFF-6E6DADCB903F}: [NameServer] Tcpip\..\Interfaces\{C9058999-0CD6-430C-9A4F-A7862710E46D}: [NameServer] Tcpip\..\Interfaces\{D097112A-8F24-4906-A4C8-050547F7324E}: [NameServer] Tcpip\..\Interfaces\{DC9110D3-37D9-45BE-9C42-CFD9E8C749A8}: [NameServer] FireFox: ======== FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\i21tf6d9.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - D:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: SaveByclick - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\i21tf6d9.default\Extensions\50e9ac90d7550@50e9ac90d758a.com [2013-07-13] FF Extension: No Name - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\i21tf6d9.default\Extensions\staged [2014-04-13] FF Extension: WOT - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\i21tf6d9.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2014-01-16] FF Extension: NoScript - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\i21tf6d9.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2012-09-19] FF Extension: Adblock Plus - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\i21tf6d9.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-09-19] Chrome: ======= CHR Extension: (SaveByclick) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mibcnakgfemboeekpgkkojofbeakhhha [2013-01-06] ==================== Services (Whitelisted) ================= R2 FFSOpzSvc; C:\Program Files\Sleep Memory Optimizer\FFSService.exe [141192 2011-09-17] (Acer Incorporated) R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] () R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [127320 2012-03-16] () S2 Internet Manager. RunOuc; C:\Program Files (x86)\T-Mobile\InternetManager_H\UpdateDog\ouc.exe [224096 2011-06-17] () S3 irstrtsv; C:\Windows\SysWOW64\irstrtsv.exe [192856 2012-02-24] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [162648 2012-03-16] (Intel Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation) R2 RS_Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [260640 2010-01-29] (Acer Incorporated) R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia) R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [660184 2013-07-03] (Secunia) R2 USecuAppSvc; c:\Program Files\Acer\Acer Theft Shield\USecuAppSvc.exe [236648 2012-03-06] () R2 ZAtheros Wlan Agent; C:\Program Files (x86)\Atheros\Ath_WlanAgent.exe [72864 2012-02-19] (Atheros) ==================== Drivers (Whitelisted) ==================== S3 AX88772B; C:\Windows\System32\DRIVERS\ax88772b.sys [98816 2011-01-01] (ASIX Electronics Corp.) S3 huawei_wwanecm; C:\Windows\System32\DRIVERS\ew_juwwanecm.sys [238080 2012-04-23] (Huawei Technologies Co., Ltd.) S3 irstrtdv; C:\Windows\System32\DRIVERS\irstrtdv.sys [26504 2012-02-23] (Intel Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation) R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-07-03] (Secunia) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-13 14:34 - 2014-04-13 14:34 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Thunderbird 2014-04-13 14:34 - 2014-04-13 14:34 - 00000000 ____D () C:\Users\Admin\AppData\Local\Thunderbird 2014-04-13 14:30 - 2014-04-13 14:30 - 00000756 _____ () C:\Users\Admin\Desktop\JRT.txt 2014-04-13 14:25 - 2014-04-13 14:25 - 00000000 ____D () C:\Windows\ERUNT 2014-04-13 14:08 - 2014-04-13 14:08 - 00000000 ___RD () C:\Users\Octavio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2014-04-13 14:06 - 2014-04-13 14:07 - 00000000 ____D () C:\AdwCleaner 2014-04-13 14:04 - 2014-04-13 14:04 - 01426178 _____ () C:\Users\Octavio\Desktop\adwcleaner.exe 2014-04-13 13:22 - 2014-04-13 13:23 - 00027539 _____ () C:\Users\Octavio\Desktop\Addition.txt 2014-04-13 12:00 - 2014-03-06 12:21 - 23549440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-13 12:00 - 2014-03-06 11:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-13 12:00 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-04-13 12:00 - 2014-03-06 11:19 - 17387008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-13 12:00 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-04-13 12:00 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-04-13 12:00 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-04-13 12:00 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-04-13 12:00 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-04-13 12:00 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-04-13 12:00 - 2014-03-06 10:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-13 12:00 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-04-13 12:00 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-04-13 12:00 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-04-13 12:00 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-04-13 12:00 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-04-13 12:00 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-04-13 12:00 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-04-13 12:00 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-04-13 12:00 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-04-13 12:00 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-04-13 12:00 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-04-13 12:00 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-04-13 12:00 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-04-13 12:00 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-04-13 12:00 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-04-13 12:00 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-04-13 12:00 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-04-13 12:00 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-04-13 12:00 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-04-13 12:00 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-04-13 12:00 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-04-13 12:00 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-04-13 12:00 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-04-13 12:00 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-04-13 12:00 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-04-13 12:00 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-04-13 12:00 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-04-13 12:00 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-04-13 12:00 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-04-13 12:00 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-04-13 12:00 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-04-13 12:00 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-04-13 12:00 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-04-13 12:00 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-04-13 12:00 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-04-13 12:00 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-04-13 12:00 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-04-12 17:27 - 2014-04-13 13:23 - 00034413 _____ () C:\Users\Octavio\Desktop\FRST.txt 2014-04-12 09:41 - 2014-04-12 09:41 - 00280368 _____ () C:\Windows\Minidump\041214-5553-01.dmp 2014-04-12 09:39 - 2014-04-12 17:24 - 02157568 _____ (Farbar) C:\Users\Octavio\Desktop\FRST64.exe 2014-04-12 09:37 - 2014-04-12 09:37 - 00000472 _____ () C:\Users\Octavio\Desktop\defogger_disable.log 2014-04-12 09:37 - 2014-04-12 09:37 - 00000000 _____ () C:\Users\Admin\defogger_reenable 2014-04-12 09:36 - 2014-04-12 09:36 - 00050477 _____ () C:\Users\Octavio\Desktop\Defogger.exe 2014-04-12 09:32 - 2014-04-12 09:32 - 00280368 _____ () C:\Windows\Minidump\041214-5647-01.dmp 2014-04-11 18:25 - 2014-04-11 18:25 - 00280368 _____ () C:\Windows\Minidump\041114-6396-02.dmp 2014-04-11 18:24 - 2014-04-11 18:24 - 00280368 _____ () C:\Windows\Minidump\041114-6552-01.dmp 2014-04-11 13:05 - 2014-04-11 13:05 - 00280368 _____ () C:\Windows\Minidump\041114-6396-01.dmp 2014-04-09 15:17 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-09 15:17 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-09 15:17 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-09 15:17 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-09 15:17 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-09 15:17 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-09 15:17 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-09 15:17 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-09 15:17 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-09 15:17 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-09 15:17 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-09 15:17 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-09 15:17 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-09 15:17 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-09 15:17 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-09 15:17 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-09 15:17 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-07 18:27 - 2014-04-07 18:27 - 00280368 _____ () C:\Windows\Minidump\040714-5538-01.dmp 2014-04-06 12:25 - 2014-04-06 12:25 - 00269376 _____ () C:\Windows\Minidump\040614-5787-01.dmp 2014-03-29 12:12 - 2014-03-29 12:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-19 18:25 - 2014-03-19 18:25 - 00000729 _____ () C:\Users\Octavio\Desktop\FLV Player.lnk 2014-03-19 18:25 - 2014-03-19 18:25 - 00000000 ____D () C:\Users\Octavio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FLV Player 2014-03-19 18:23 - 2014-03-19 18:23 - 00000000 ____D () C:\Users\Octavio\AppData\Roaming\WinRAR 2014-03-19 18:23 - 2014-03-19 18:23 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2014-03-14 11:08 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-14 11:08 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-03-14 11:08 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2014-03-14 11:08 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-03-14 11:03 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-03-14 11:03 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-14 11:03 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-03-14 11:03 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll ==================== One Month Modified Files and Folders ======= 2014-04-13 14:40 - 2014-01-20 11:42 - 00000000 ____D () C:\FRST 2014-04-13 14:34 - 2014-04-13 14:34 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Thunderbird 2014-04-13 14:34 - 2014-04-13 14:34 - 00000000 ____D () C:\Users\Admin\AppData\Local\Thunderbird 2014-04-13 14:30 - 2014-04-13 14:30 - 00000756 _____ () C:\Users\Admin\Desktop\JRT.txt 2014-04-13 14:25 - 2014-04-13 14:25 - 00000000 ____D () C:\Windows\ERUNT 2014-04-13 14:19 - 2012-03-27 20:45 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-13 14:13 - 2009-07-14 06:45 - 00024416 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-13 14:13 - 2009-07-14 06:45 - 00024416 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-13 14:12 - 2012-05-15 12:41 - 00699682 _____ () C:\Windows\system32\perfh007.dat 2014-04-13 14:12 - 2012-05-15 12:41 - 00149790 _____ () C:\Windows\system32\perfc007.dat 2014-04-13 14:12 - 2012-05-15 02:48 - 01269701 _____ () C:\Windows\WindowsUpdate.log 2014-04-13 14:12 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-13 14:08 - 2014-04-13 14:08 - 00000000 ___RD () C:\Users\Octavio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2014-04-13 14:08 - 2012-05-15 02:47 - 00000828 _____ () C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job 2014-04-13 14:08 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-13 14:08 - 2009-07-14 06:51 - 00115724 _____ () C:\Windows\setupact.log 2014-04-13 14:08 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-04-13 14:07 - 2014-04-13 14:06 - 00000000 ____D () C:\AdwCleaner 2014-04-13 14:04 - 2014-04-13 14:04 - 01426178 _____ () C:\Users\Octavio\Desktop\adwcleaner.exe 2014-04-13 13:23 - 2014-04-13 13:22 - 00027539 _____ () C:\Users\Octavio\Desktop\Addition.txt 2014-04-13 13:23 - 2014-04-12 17:27 - 00034413 _____ () C:\Users\Octavio\Desktop\FRST.txt 2014-04-13 11:41 - 2012-05-15 02:47 - 00000830 _____ () C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job 2014-04-12 20:17 - 2014-01-29 10:08 - 00071680 ___SH () C:\Users\Octavio\Desktop\Thumbs.db 2014-04-12 17:24 - 2014-04-12 09:39 - 02157568 _____ (Farbar) C:\Users\Octavio\Desktop\FRST64.exe 2014-04-12 09:41 - 2014-04-12 09:41 - 00280368 _____ () C:\Windows\Minidump\041214-5553-01.dmp 2014-04-12 09:41 - 2012-06-14 19:36 - 502918635 _____ () C:\Windows\MEMORY.DMP 2014-04-12 09:41 - 2012-06-14 19:36 - 00000000 ____D () C:\Windows\Minidump 2014-04-12 09:37 - 2014-04-12 09:37 - 00000472 _____ () C:\Users\Octavio\Desktop\defogger_disable.log 2014-04-12 09:37 - 2014-04-12 09:37 - 00000000 _____ () C:\Users\Admin\defogger_reenable 2014-04-12 09:37 - 2012-09-18 19:48 - 00000000 ____D () C:\Users\Admin 2014-04-12 09:36 - 2014-04-12 09:36 - 00050477 _____ () C:\Users\Octavio\Desktop\Defogger.exe 2014-04-12 09:32 - 2014-04-12 09:32 - 00280368 _____ () C:\Windows\Minidump\041214-5647-01.dmp 2014-04-11 18:25 - 2014-04-11 18:25 - 00280368 _____ () C:\Windows\Minidump\041114-6396-02.dmp 2014-04-11 18:24 - 2014-04-11 18:24 - 00280368 _____ () C:\Windows\Minidump\041114-6552-01.dmp 2014-04-11 13:05 - 2014-04-11 13:05 - 00280368 _____ () C:\Windows\Minidump\041114-6396-01.dmp 2014-04-11 13:05 - 2010-11-21 05:47 - 00145016 _____ () C:\Windows\PFRO.log 2014-04-10 17:07 - 2013-12-11 21:44 - 00000000 ____D () C:\ProgramData\OnlineUpdate 2014-04-10 09:36 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-04-09 20:19 - 2013-07-25 20:45 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-09 20:18 - 2012-09-19 15:43 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-09 01:21 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\LiveKernelReports 2014-04-07 18:27 - 2014-04-07 18:27 - 00280368 _____ () C:\Windows\Minidump\040714-5538-01.dmp 2014-04-06 12:51 - 2012-09-18 22:13 - 00000000 ____D () C:\Users\Octavio 2014-04-06 12:25 - 2014-04-06 12:25 - 00269376 _____ () C:\Windows\Minidump\040614-5787-01.dmp 2014-03-29 13:46 - 2012-09-19 16:28 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-29 12:12 - 2014-03-29 12:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-28 19:49 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-03-26 13:00 - 2012-09-19 15:36 - 00001912 _____ () C:\Windows\epplauncher.mif 2014-03-26 13:00 - 2012-09-19 15:36 - 00000000 ____D () C:\Program Files\Microsoft Security Client 2014-03-26 13:00 - 2012-09-19 15:36 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client 2014-03-19 18:25 - 2014-03-19 18:25 - 00000729 _____ () C:\Users\Octavio\Desktop\FLV Player.lnk 2014-03-19 18:25 - 2014-03-19 18:25 - 00000000 ____D () C:\Users\Octavio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FLV Player 2014-03-19 18:25 - 2012-12-25 23:28 - 00000238 _____ () C:\Windows\wininit.ini 2014-03-19 18:23 - 2014-03-19 18:23 - 00000000 ____D () C:\Users\Octavio\AppData\Roaming\WinRAR 2014-03-19 18:23 - 2014-03-19 18:23 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2014-03-14 13:17 - 2013-03-15 14:18 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-03-14 13:17 - 2013-03-15 14:18 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-03-14 13:17 - 2009-07-14 06:45 - 00334552 _____ () C:\Windows\system32\FNTCACHE.DAT Files to move or delete: ==================== C:\Users\Admin\AppData\Roaming\EasyToolz.ini Some content of TEMP: ==================== C:\Users\Admin\AppData\Local\Temp\AskSLib.dll C:\Users\Admin\AppData\Local\Temp\clearfiSetup.exe C:\Users\Admin\AppData\Local\Temp\Core.dll C:\Users\Admin\AppData\Local\Temp\dbghelp.dll C:\Users\Admin\AppData\Local\Temp\Engine.dll C:\Users\Admin\AppData\Local\Temp\IFC23.dll C:\Users\Admin\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe C:\Users\Admin\AppData\Local\Temp\jre-7u40-windows-i586-iftw.exe C:\Users\Admin\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\Admin\AppData\Local\Temp\MSNEB98.exe C:\Users\Admin\AppData\Local\Temp\MSVCR71.dll C:\Users\Admin\AppData\Local\Temp\npp.6.2.Installer.exe C:\Users\Admin\AppData\Local\Temp\ogg.dll C:\Users\Admin\AppData\Local\Temp\Quarantine.exe C:\Users\Admin\AppData\Local\Temp\Setup.exe C:\Users\Admin\AppData\Local\Temp\vorbis.dll C:\Users\Admin\AppData\Local\Temp\vorbisfile.dll C:\Users\Admin\AppData\Local\Temp\Window.dll C:\Users\Admin\AppData\Local\Temp\xmlUpdater.exe C:\Users\Octavio\AppData\Local\Temp\install_flashplayer11x32au_mssd_aih.exe C:\Users\Octavio\AppData\Local\Temp\install_reader10_de_gtbd_chrd_dn_aih.exe C:\Users\Octavio\AppData\Local\Temp\npp.6.2.2.Installer.exe C:\Users\Octavio\AppData\Local\Temp\npp.6.2.Installer.exe C:\Users\Octavio\AppData\Local\Temp\npp.6.3.2.Installer.exe C:\Users\Octavio\AppData\Local\Temp\npp.6.3.Installer.exe C:\Users\Octavio\AppData\Local\Temp\npp.6.5.2.Installer.exe C:\Users\Octavio\AppData\Local\Temp\SkypeSetup.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-09 02:18 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-04-2014 01 Ran by Admin at 2014-04-13 14:41:41 Running from D:\Users\Octavio\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} ==================== Installed Programs ====================== 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Acer Crystal Eye Webcam (HKLM-x32\...\InstallShield_{A0382E3C-7384-429A-9BFA-AF5888E5A193}) (Version: 1.5.2624.00 - CyberLink Corp.) Acer Crystal Eye Webcam (x32 Version: 1.5.2624.00 - CyberLink Corp.) Hidden Acer ePower Management (HKLM-x32\...\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 6.00.3010 - Acer Incorporated) Acer eRecovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3507 - Acer Incorporated) Acer Instant Update Service (HKLM\...\{86B80582-A4F2-4F12-B29F-49D3309C7024}) (Version: 1.00.3001 - Acer Incorporated) Acer Theft Shield (HKLM\...\{8ADB0CD2-4E5A-452F-BB3B-3A2984CAC749}) (Version: 1.00.3001 - Acer Incorporated) Acer Updater (HKLM-x32\...\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3501 - Acer Incorporated) Acer VCM (HKLM-x32\...\{047F790A-7A2A-4B6A-AD02-38092BA63DAC}) (Version: 4.05.3501 - Acer Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.8.0.870 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.8.0.870 - Adobe Systems Incorporated) Hidden Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated) Apple Application Support (HKLM-x32\...\{21FC2093-6E43-460B-B9B0-5F5AA35BBB0F}) (Version: 3.0 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{FE86CB0C-FCB3-4358-B4B0-B0A41E33B3DD}) (Version: 7.1.0.32 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Atheros Bluetooth Suite (64) (HKLM\...\{230D1595-57DA-4933-8C4E-375797EBB7E1}) (Version: 7.4.0.126 - Atheros) AX88772B Windows 7 Drivers (HKLM-x32\...\InstallShield_{54A168C9-2250-4058-80EB-1F4A4192548A}) (Version: 1.0.1.1 - ASIX Electronics Corporation) AX88772B Windows 7 Drivers (x32 Version: 1.0.1.1 - ASIX Electronics Corporation) Hidden Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) calibre (HKLM-x32\...\{5FD4B351-1567-426F-AEB4-08F41E3FA6C5}) (Version: 0.9.31 - Kovid Goyal) CATBox 1.1 (HKLM-x32\...\{5140A79F-17C4-4B33-91D6-330D9B7C2D4C}_is1) (Version: - Schliep & Hochstaettler) CyberLink MediaEspresso (HKLM-x32\...\InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}) (Version: 6.5.1720_38230 - CyberLink Corp.) CyberLink MediaEspresso (x32 Version: 6.5.1720_38230 - CyberLink Corp.) Hidden Dolby Home Theater v4 (HKLM-x32\...\{B26438B4-BF51-49C3-9567-7F14A5E40CB9}) (Version: 7.2.7000.7 - Dolby Laboratories Inc) GPL Ghostscript (HKLM-x32\...\GPL Ghostscript 9.05) (Version: 9.05 - Artifex Software Inc.) High-Definition Video Playback (x32 Version: 7.1.13900.47.0 - Nero AG) Hidden HP Deskjet 3520 series - Grundlegende Software für das Gerät (HKLM\...\{15B2F0E3-3FAC-4495-B0FD-398EECFA4100}) (Version: 28.0.1315.0 - Hewlett-Packard Co.) HP Deskjet 3520 series Hilfe (HKLM-x32\...\{6B953497-169C-4929-9AA9-A9F510347468}) (Version: 27.0.0 - Hewlett Packard) HP Deskjet 3520 series Setup Guide (HKLM-x32\...\{AEEDCEB7-00B8-4BE1-B492-AB04803D5F1E}) (Version: 27.0.0 - Hewlett Packard) HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard) Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3501 - Acer Incorporated) Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.35342 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.4.1441 - Intel Corporation) Intel(R) OpenCL CPU Runtime (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2653 - Intel Corporation) Intel(R) Rapid Start Technology (HKLM-x32\...\3D073343-CEEB-4ce7-85AC-A69A7631B5D6) (Version: 1.0.0.1022 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.0.0.1032 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.4.220 - Intel Corporation) Intel® Trusted Connect Service Client (HKLM\...\{09536BA1-E498-4CC3-B834-D884A67D7E34}) (Version: 1.23.605.1 - Intel Corporation) Internet Manager (HKLM-x32\...\Internet Manager) (Version: 22.001.18.68.55 - Huawei Technologies Co.,Ltd) iTunes (HKLM\...\{96B53CA8-5ABB-49D8-96F1-F6C0D73A76C6}) (Version: 11.1.4.62 - Apple Inc.) Java SE Development Kit 7 Update 51 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0170510}) (Version: 1.7.0.510 - Oracle) Launch Manager (HKLM-x32\...\LManager) (Version: 5.1.15 - Acer Inc.) LibreOffice 3.6 (HKLM-x32\...\{CBCF6C86-4738-4A84-9C2C-331804DCEB9B}) (Version: 3.6.3.2 - The Document Foundation) LMMS 0.4.15 (HKLM-x32\...\LMMS) (Version: 0.4.15 - LMMS Developers) Malwarebytes Anti-Malware Version 1.75.0.1300 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation) Marketsplash Schnellzugriffe (HKLM-x32\...\{7A108EBC-C9DF-4E14-93A8-42CF316F1ECF}) (Version: 1.0.1.7 - Hewlett-Packard) MATLAB R2011a (HKLM\...\MatlabR2011a) (Version: 7.12 - The MathWorks, Inc.) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Security Client (Version: 4.5.0216.0 - Microsoft Corporation) Hidden Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) MiKTeX 2.9 (HKLM\...\MiKTeX 2.9) (Version: 2.9 - MiKTeX.org) Mozilla Firefox 28.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla) Mozilla Thunderbird 17.0.7 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 17.0.7 (x86 de)) (Version: 17.0.7 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) MyWinLocker (Version: 4.0.14.27 - Egis Technology Inc.) Hidden MyWinLocker 4 (x32 Version: 4.0.14.27 - Egis Technology Inc.) Hidden MyWinLocker Suite (HKLM-x32\...\InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}) (Version: 4.0.14.19 - Egis Technology Inc.) MyWinLocker Suite (x32 Version: 4.0.14.19 - Egis Technology Inc.) Hidden Nero BackItUp 10 (HKLM-x32\...\{68AB6930-5BFF-4FF6-923B-516A91984FE6}) (Version: 5.6.11700.17.100 - Nero AG) Nero BackItUp 10 Help (CHM) (x32 Version: 10.5.10700 - Nero AG) Hidden Nero BurnRights 10 (HKLM-x32\...\{943CFD7D-5336-47AF-9418-E02473A5A517}) (Version: 4.2.10500.1.102 - Nero AG) Nero BurnRights 10 Help (CHM) (x32 Version: 10.5.10000 - Nero AG) Hidden Nero Control Center 10 (x32 Version: 10.2.11100.1.1 - Nero AG) Hidden Nero ControlCenter 10 Help (CHM) (x32 Version: 10.5.10000 - Nero AG) Hidden Nero Core Components 10 (x32 Version: 2.0.19800.9.10 - Nero AG) Hidden Nero CoverDesigner 10 (HKLM-x32\...\{FCF00A6E-FB58-477A-ABE9-232907105521}) (Version: 5.2.11400.11.100 - Nero AG) Nero CoverDesigner 10 Help (CHM) (x32 Version: 10.5.10000 - Nero AG) Hidden Nero DiscSpeed 10 (HKLM-x32\...\{34490F4E-48D0-492E-8249-B48BECF0537C}) (Version: 6.2.10500.2.100 - Nero AG) Nero DiscSpeed 10 Help (CHM) (x32 Version: 10.5.10000 - Nero AG) Hidden Nero Express 10 (HKLM-x32\...\{70550193-1C22-445C-8FA4-564E155DB1A7}) (Version: 10.2.12400.25.100 - Nero AG) Nero Express 10 Help (CHM) (x32 Version: 10.5.10200 - Nero AG) Hidden Nero InfoTool 10 (HKLM-x32\...\{F412B4AF-388C-4FF5-9B2F-33DB1C536953}) (Version: 7.2.10400.5.100 - Nero AG) Nero InfoTool 10 Help (CHM) (x32 Version: 10.5.10000 - Nero AG) Hidden Nero Multimedia Suite 10 Essentials (HKLM-x32\...\{89590A73-9AC3-48ED-B83E-6489900DED5A}) (Version: 10.5.10000 - Nero AG) Nero StartSmart 10 (HKLM-x32\...\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}) (Version: 10.2.11300.12.100 - Nero AG) Nero StartSmart 10 Help (CHM) (x32 Version: 10.5.10000 - Nero AG) Hidden Nero Update (x32 Version: 11.0.11500.28.0 - Nero AG) Hidden Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.5.2 - Notepad++ Team) PDF Split And Merge Basic (HKLM\...\{C91B24F6-1629-11E2-B696-21676188709B}) (Version: 2.2.2 - Andrea Vacondio) Python 2.7.6 (64-bit) (HKLM\...\{C3CC4DF5-39A5-4027-B136-2B3E1F5AB6E3}) (Version: 2.7.6150 - Python Software Foundation) Qualcomm Atheros WiFi Driver Installation (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 3.1 - Qualcomm Atheros) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6597 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7601.39025 - Realtek Semiconductor Corp.) Secunia PSI (3.0.0.7011) (HKLM-x32\...\Secunia PSI) (Version: 3.0.0.7011 - Secunia) Shredder (Version: 2.0.8.9 - Egis Technology Inc.) Hidden Shredder (x32 Version: 2.0.8.9 - Egis Technology Inc.) Hidden Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) Sleep Memory Optimizer (HKLM-x32\...\{34BE2594-1D20-4A2E-97A0-B9E2837520AE}) (Version: 1.00.3004 - Acer Incorporated) Smart Timer (HKLM-x32\...\{89DB52FC-EA72-468F-A0C7-150AF8B7AB74}) (Version: 1.00.3004 - Acer Incorporated) SpywareBlaster 5.0 (HKLM-x32\...\SpywareBlaster_is1) (Version: 5.0.0 - BrightFort LLC) TeXnicCenter Version 2.0 Beta 1 (HKLM\...\TeXnicCenter_is1) (Version: 2.0 Beta 1 - The TeXnicCenter Team) TSST OEM Content (HKLM-x32\...\{885AFEC2-0809-47CE-8B3F-00AEC19DDD5F}) (Version: 10.0.10300.0.0 - Nero AG) Überwachungstool für die Intel® Turbo-Boost-Technik 2.5 (HKLM\...\{6C9365EB-1F9E-4893-9196-3EC77C88D0C5}) (Version: 2.5.1.0 - Intel) Welcome Center (HKLM-x32\...\Acer Welcome Center) (Version: 1.02.3507 - Acer Incorporated) WinPatrol (HKLM\...\{4BB7A109-FDB5-45E3-9DB9-ECB2EA7B80EE}) (Version: 28.5.2013.0 - BillP Studios) WinRAR 5.10 beta 1 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.10.1 - win.rar GmbH) WinSCP 5.1.6 (HKLM-x32\...\winscp3_is1) (Version: 5.1.6 - Martin Prikryl) ==================== Restore Points ========================= 11-04-2014 08:48:54 Geplanter Prüfpunkt 13-04-2014 10:00:11 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {1AB333BC-9380-4B0F-9AFC-ECE472FDF735} - System32\Tasks\hpUtility.exe_{06E9ED4A-8202-492F-B83C-D7FD23AADE98} => C:\Program Files\HP\HP Deskjet 3520 series\Bin\utils\hpUtility.exe [2012-10-17] (Hewlett-Packard Co.) Task: {3EBE6547-6EC8-45A8-AEBF-D0C6B3A18A05} - System32\Tasks\hpUtility.exe => C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\utils\hpUtility.exe Task: {4A77AFC5-DEDB-4052-8CD7-FC1815775C96} - System32\Tasks\DeviceDetector => C:\Program Files (x86)\Cyberlink\MediaEspresso\DeviceDetector\DeviceDetector.exe [2011-05-20] (CyberLink) Task: {56F06DD2-E015-43AD-B2FD-69C6114A441C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-12] (Adobe Systems Incorporated) Task: {7CA41C93-7F9A-447D-A080-1A8AA78ACE99} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {8530F25C-6E85-4071-B4A8-5D79BB1F6E1C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {ABFF5843-CD09-4706-A95D-D09EE9B96991} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {B10A38B2-91C0-4CD4-9D82-55EF5FDAE7D9} - System32\Tasks\Smart Timer Task Scheduler => Smart_Timer.exe Task: {CF4FFBCE-786A-47A9-AC5D-0A5A48958081} - System32\Tasks\Intel® Rapid Start Technology Manager => C:\Program Files (x86)\Intel\irstrt\RapidStartConfig.exe [2012-02-24] (Intel) Task: {E433214B-8740-428A-A491-22F90E4BE505} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {EA1E36F0-DD88-423F-A651-B4D9F2D504EF} - System32\Tasks\UALU notificatin => C:\Program Files\Acer\Acer Updater\UALU.exe [2012-02-07] (Acer Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe ==================== Loaded Modules (whitelisted) ============= 2011-03-14 17:27 - 2011-03-14 17:27 - 00346976 _____ () C:\ProgramData\DatacardService\HWDeviceService64.exe 2012-05-15 02:46 - 2012-03-16 13:48 - 00127320 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe 2013-10-25 18:10 - 2011-06-17 13:04 - 00224096 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe 2012-03-06 21:49 - 2012-03-06 21:49 - 00236648 _____ () c:\Program Files\Acer\Acer Theft Shield\USecuAppSvc.exe 2012-03-06 21:49 - 2012-03-06 21:49 - 00114280 _____ () c:\Program Files\Acer\Acer Theft Shield\SysCtrl.dll 2012-03-06 21:49 - 2012-03-06 21:49 - 00197736 _____ () c:\Program Files\Acer\Acer Theft Shield\LogMgr2.dll 2012-03-06 21:49 - 2012-03-06 21:49 - 00140904 _____ () c:\Program Files\Acer\Acer Theft Shield\WHNCtrl.dll 2012-05-15 12:33 - 2012-02-14 19:53 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2012-03-06 21:49 - 2012-03-06 21:49 - 00257640 _____ () C:\Program Files\Acer\Acer Theft Shield\USecuAppClient.exe 2012-03-06 21:49 - 2012-03-06 21:49 - 00213608 _____ () C:\Program Files\Acer\Acer Theft Shield\CommPtl.dll 2012-03-06 21:49 - 2012-03-06 21:49 - 00197736 _____ () C:\Program Files\Acer\Acer Theft Shield\LogMgr2.dll 2012-03-06 21:49 - 2012-03-06 21:49 - 00114280 _____ () C:\Program Files\Acer\Acer Theft Shield\SysCtrl.dll 2012-03-06 21:49 - 2012-03-06 21:49 - 00140904 _____ () C:\Program Files\Acer\Acer Theft Shield\WHNCtrl.dll 2012-02-20 15:34 - 2012-02-20 15:34 - 00040552 _____ () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe 2012-02-20 15:34 - 2012-02-20 15:34 - 00022632 _____ () C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe 2014-02-06 01:52 - 2014-02-06 01:52 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2014-02-06 01:52 - 2014-02-06 01:52 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2013-10-25 18:10 - 2009-01-10 12:32 - 00011362 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\mingwm10.dll 2013-10-25 18:10 - 2009-06-22 20:42 - 00043008 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\libgcc_s_dw2-1.dll 2013-10-25 18:10 - 2010-05-05 10:47 - 02415104 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\QtCore4.dll 2013-10-25 18:10 - 2010-02-10 16:10 - 01148416 _____ () C:\ProgramData\Internet Manager\OnlineUpdate\QtNetwork4.dll 2012-05-15 02:46 - 2012-03-07 16:27 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll 2014-03-29 12:12 - 2014-03-29 12:12 - 03642480 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2012-09-22 11:47 - 2013-06-20 19:24 - 02244504 _____ () C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll 2012-09-22 11:47 - 2013-06-20 19:24 - 00158104 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll 2012-09-22 11:47 - 2013-06-20 19:24 - 00022424 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:5C321E34 ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Error: (04/13/2014 02:40:55 PM) (Source: DCOM) (User: ) Description: {3EEF301F-B596-4C0B-BD92-013BEAFCE793} Microsoft Office Sessions: ========================= ==================== Memory info =========================== Percentage of memory in use: 46% Total physical RAM: 3934.36 MB Available physical RAM: 2086.77 MB Total Pagefile: 7866.89 MB Available Pagefile: 5875.88 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: (ACER) (Fixed) (Total:81.35 GB) (Free:31.09 GB) NTFS Drive d: (Data) (Fixed) (Total:22.65 GB) (Free:3.62 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 119 GB) (Disk ID: 5833D626) Partition 1: (Not Active) - (Size=15 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=104 GB) - (Type=OF Extended) ==================== End Of Log ============================ |
13.04.2014, 13:55 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows 7: Mozilla stürzt ab und es erscheint ein Bluescreen Ok, probier nochmal Malwarebytes aus: Downloade Dir bitte Malwarebytes Anti-Malware
__________________ Logfiles bitte immer in CODE-Tags posten |
13.04.2014, 14:34 | #9 |
| Windows 7: Mozilla stürzt ab und es erscheint ein BluescreenCode:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 13.04.2014 Suchlauf-Zeit: 15:32:03 Logdatei: mbam.txt Administrator: Ja Version: 2.00.1.1004 Malware Datenbank: v2014.04.13.03 Rootkit Datenbank: v2014.03.27.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Chameleon: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Admin Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 291336 Verstrichene Zeit: 10 Min, 54 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Aktiviert Shuriken: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 0 (No malicious items detected) Physische Sektoren: 0 (No malicious items detected) (end) |
13.04.2014, 22:30 | #10 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows 7: Mozilla stürzt ab und es erscheint ein Bluescreen Ok, lief anscheinend ja durch. Sind die Abstürze/Bluescreens nun auch weg?
__________________ Logfiles bitte immer in CODE-Tags posten |
14.04.2014, 11:35 | #11 |
| Windows 7: Mozilla stürzt ab und es erscheint ein Bluescreen Sie waren nach dem Scan von JRT weg und Firefox lief richtig schnell ohne abzustürzen, aber tauchten dann wieder auf. Folgendes ist nachdem Scan von JRT passiert: ich konnte nicht mehr auf viele Dateien zugreifen (Doppelklick und es passierte nichts) und von meinem Desktop verschwanden sämtliche Verknüpfungen. Nachdem ich mein Computer neustartete, sind die Verknüpfungen wieder aufgetaucht und die Dateien waren wieder zu öffnen, aber mit einher kamen auch die Abstürze. Kann man mir vielleicht erklären was JRT genau macht/gemacht hat und was diese Analysen herausgefunden haben ? |
14.04.2014, 13:12 | #12 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows 7: Mozilla stürzt ab und es erscheint ein Bluescreen JRT hat lt Log garnix gemacht außer einen Ordner zu leeren. Ich würde mal den Firefox komplett deinstallieren, keine Daten behalten, Setup von Home of the Mozilla Project ? Mozilla neu runterladen und den FF wieder installieren. Falls du wichtige Lesezeichen im jetzigen Browserprofil hast solltest du diese VORHER sichern.
__________________ Logfiles bitte immer in CODE-Tags posten |
15.04.2014, 11:35 | #13 |
| Windows 7: Mozilla stürzt ab und es erscheint ein Bluescreen So habe Firefox deinstalliert und wieder neu drauf installiert ohne meine Dateien zu sichern. Es hat sich aber nichts getan. Firefox stürzt immernoch ab. Kann man sagen, dass man PC virenfrei ist und das Problem woanders liegt ? Der IE dagegen funktioniert ohne Probleme. |
15.04.2014, 13:27 | #14 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Windows 7: Mozilla stürzt ab und es erscheint ein Bluescreen Hast du auch bei der Deinstallation gesagt "keine Daten behalten"?
__________________ Logfiles bitte immer in CODE-Tags posten |
15.04.2014, 13:34 | #15 |
| Windows 7: Mozilla stürzt ab und es erscheint ein Bluescreen ja, wie gesagt ohne meine Dateien zu sichern. |
Themen zu Windows 7: Mozilla stürzt ab und es erscheint ein Bluescreen |
absturz, anweisung, bluescreen, entdeck, entdeckt, erscheint, essen, fehlermeldungen, firefox, folge, folgendes, keine viren, malwarebytes, microsoft, mozilla, problem, scan, scanne, scannen, security, stürzt, stürzt ab, system, viren, windows, windows 7 |