|
Log-Analyse und Auswertung: Windows 8 Fehler in REGSVR32 .dllWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
02.06.2014, 05:57 | #1 |
| Windows 8 Fehler in REGSVR32 .dllHallo an alle ! Also ich bin durch Zufall auf dieses Forum gestoßen und da es hier ähnliche Frage gibt ich aber leider Windows 8 . Dachte ich mir schreib doch einfach ein Thema und hoffe das dir einer hilft. Beim Starten des Rechners kommt eine Meldung . " Fehler beim Laden der SVRREG32 " Kann mir mal einer von euch sagen was das für ein Ding ist ? Der Rechner läuft sonst ohne Probleme nur es nervt tierisch wenn bei jedem start diese meldung kommt. Habe Avira als Antivir und sonst benutze ich den Rechner eigentlich nur für Musik Videos und 1 Spiel . Also wie kann ich diese Meldung beheben? Gruß Frank |
02.06.2014, 07:17 | #2 |
/// the machine /// TB-Ausbilder | Windows 8 Fehler in REGSVR32 .dll hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
02.06.2014, 07:54 | #3 |
| Windows 8 Fehler in REGSVR32 .dll FRST Additions Logfile:
__________________Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-06-2014 01 Ran by Frank at 2014-06-02 08:49:16 Running from C:\Users\Frank\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Adobe Reader XI (11.0.07) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated) Amazon Cloud Drive (HKCU\...\23ab716f18849b6f) (Version: 2.1.2013.1340 - Amazon) Amazon MP3-Downloader 1.0.18 (HKCU\...\Amazon MP3-Downloader) (Version: 1.0.18 - Amazon Services LLC) Ask Toolbar (HKLM-x32\...\{86D4B82A-ABED-442A-BE86-96357B70F4FE}) (Version: 1.6.9.0 - Ask.com) <==== ATTENTION aTube Catcher (HKLM-x32\...\aTube Catcher) (Version: 3.8.5187 - DsNET Corp) Audio Edit Pro 4.0 (HKLM-x32\...\Audio Edit Pro_is1) (Version: 4.0 - Softfeld KG) AutoUpdate (HKLM-x32\...\{18D10072035C4515918F7E37EAFAACFC}) (Version: 1.1 - ) Avira Antivirus Suite (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.4.642 - Avira) Avira Savings Advisor (HKLM-x32\...\{A18A516C-AA41-46A9-92DB-60208917E442}) (Version: 1.5.14 - Avira) <==== ATTENTION Beyond Compare 3.3.10 (HKLM-x32\...\BeyondCompare3_is1) (Version: 3.3.10.17762 - Scooter Software) BlueStacks App Player (HKLM-x32\...\BlueStacks App Player) (Version: 0.8.4.3036 - BlueStack Systems, Inc.) BlueStacks Notification Center (HKLM-x32\...\{44181DF6-2751-48C7-B918-72F14508F127}) (Version: 0.8.4.3036 - BlueStack Systems, Inc.) Bonjour (HKLM\...\{B91110FB-33B4-468B-90C2-4D5E8AE3FAE1}) (Version: 2.0.2.0 - Apple Inc.) Bonjour-Druckdienste (HKLM\...\{0DA20600-6130-443B-9D4B-F30520315FA6}) (Version: 2.0.2.0 - Apple Inc.) CCleaner (HKLM\...\CCleaner) (Version: 4.14 - Piriform) Chicony USB 2.0 Camera (HKLM-x32\...\{FC9B811E-39BC-4813-9E29-B83CCF700010}) (Version: 2.22.25.4 - Alcor) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DivX (HKLM-x32\...\{7B63B2922B174135AFC0E1377DD81EC2}) (Version: 6.0 - DivXNetworks, Inc.) DVD Shrink 3.2 deutsch (DeCSS-frei) (HKLM-x32\...\DVD Shrink DE_is1) (Version: - DVD Shrink) Facebook Video Calling 2.0.0.447 (HKLM-x32\...\{8DF41A9F-FE13-43E8-A003-5F9B55A011EE}) (Version: 2.0.447 - Skype Limited) FileZilla Client 3.7.3 (HKLM-x32\...\FileZilla Client) (Version: 3.7.3 - Tim Kosse) Fotogalerie (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden FreeFileSync 6.4 (HKLM-x32\...\FreeFileSync) (Version: 6.4 - Zenju) Galería de fotos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Galerie de photos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 35.0.1916.114 - Google Inc.) Google Drive (HKLM-x32\...\{418BAAD1-754D-48B4-B078-46EF4F25AF42}) (Version: 1.15.6556.8063 - Google, Inc.) Google Update Helper (x32 Version: 1.3.24.7 - Google Inc.) Hidden Google+ Auto Backup (HKCU\...\Google+ Auto Backup) (Version: 1.0.25.133 - Google, Inc.) High-Definition Video Playback (x32 Version: 7.1.12500.33.0 - Nero AG) Hidden homepageMAKER 8 Ultimate (HKLM-x32\...\homepageMAKER 8 Ultimate_is1) (Version: 7 - bhv Software GmbH) Hotkey 8.0082 (HKLM-x32\...\InstallShield_{164714B6-46BC-4649-9A30-A6ED32F03B5A}) (Version: 8.0082 - NoteBook) Hotkey 8.0082 (x32 Version: 8.0082 - NoteBook) Hidden Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3316 - Intel Corporation) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{DA2600C1-6BDF-4FD1-8F3D-148929CC1385}) (Version: 2.6.1210.0278 - Intel Corporation) Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation) Intel® Trusted Connect Service Client (Version: 1.24.388.1 - Intel Corporation) Hidden Iperius Backup Version 3.5.4.0 (HKLM-x32\...\Iperius Backup_is1) (Version: 3.5.4.0 - Enter Srl) Java 7 Update 55 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.550 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden kwiksupport.me (HKLM-x32\...\kwiksupport.me) (Version: 12.0.33.7173 - pcvisit Software AG) Microsoft .NET Framework 1.1 (HKLM-x32\...\Microsoft .NET Framework 1.1 (1033)) (Version: - ) Microsoft .NET Framework 1.1 (x32 Version: 1.1.4322 - Microsoft) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.6120.5004 - Microsoft Corporation) Microsoft OneDrive (HKCU\...\OneDriveSetup.exe) (Version: 17.0.4041.0512 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\...\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation) Microsoft SQL Server Compact 3.5 SP2 x64 ENU (HKLM\...\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}) (Version: 3.5.8080.0 - Microsoft Corporation) Microsoft Sync Framework 2.0 Core Components (x64) ENU (HKLM\...\{8CCBEC22-D2DB-4DC9-A58A-E1A1F3A38C8A}) (Version: 2.0.1578.0 - Microsoft Corporation) Microsoft Sync Framework 2.0 Provider Services (x64) ENU (HKLM\...\{03AC245F-4C64-425C-89CF-7783C1D3AB2C}) (Version: 2.0.1578.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 24.5.0 - Mozilla) Mozilla Thunderbird 24.5.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.5.0 (x86 de)) (Version: 24.5.0 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden MSXML 4.0 SP2 Parser and SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation) Music Manager (HKCU\...\MusicManager) (Version: - Google, Inc.) Nero 10 ClipartPack (HKLM-x32\...\{96ED4B78-300E-4033-AE6C-C115CEB4DF07}) (Version: 10.2.10000.11.0 - Nero AG) Nero 10 Menu TemplatePack 1 (HKLM-x32\...\{42C8B7DF-FEB0-4D51-B169-506B6BEC5797}) (Version: 10.2.10000.0.0 - Nero AG) Nero 10 Menu TemplatePack 2 (HKLM-x32\...\{E712C273-7564-4C8E-AA59-0FA19BC35117}) (Version: 10.2.10000.0.0 - Nero AG) Nero 10 Menu TemplatePack 3 (HKLM-x32\...\{92146419-AE44-4C8B-A48B-0ABB1B5EC026}) (Version: 10.2.10000.0.0 - Nero AG) Nero 10 Menu TemplatePack Basic (x32 Version: 10.2.10000.0.0 - Nero AG) Hidden Nero 10 Movie ThemePack 1 (HKLM-x32\...\{43FBAB46-5969-4200-9958-1FF81FEE506F}) (Version: 10.2.10000.11.0 - Nero AG) Nero 10 Movie ThemePack 2 (HKLM-x32\...\{70F19404-B96C-4EBB-AD2B-3574F8736197}) (Version: 10.2.10000.12.0 - Nero AG) Nero 10 Movie ThemePack 3 (HKLM-x32\...\{DD238642-14C7-4D54-8BD7-FAD6DEA9999B}) (Version: 10.2.10000.0.0 - Nero AG) Nero 10 Movie ThemePack 4 (HKLM-x32\...\{A70B0C7B-3527-4D53-A694-E9492ECE9EE1}) (Version: 10.2.10000.11.0 - Nero AG) Nero 10 Movie ThemePack Basic (x32 Version: 10.2.10000.0.0 - Nero AG) Hidden Nero 10 PiP EffectPack 1 (HKLM-x32\...\{EF3A4DAE-F16F-4AC1-87BB-FE00A784084F}) (Version: 10.2.10000.0.0 - Nero AG) Nero 10 Sample ImagePack (HKLM-x32\...\{ACD15FDF-FC42-4175-B477-576F92FF2256}) (Version: 10.2.10000.11.0 - Nero AG) Nero 10 Sample Videos (HKLM-x32\...\{92A10E9D-EA00-4A46-8F22-EEA660992D61}) (Version: 10.2.10000.11.0 - Nero AG) Nero 10 Video TransitionPack 1 (HKLM-x32\...\{85BEC8F6-9AA3-43FF-B56B-8276277137B3}) (Version: 10.2.10000.0.0 - Nero AG) Nero Control Center 10 (x32 Version: 10.2.0.0.0 - Nero AG) Hidden Nero ControlCenter 10 Help (CHM) (x32 Version: 10.2.10600 - Nero AG) Hidden Nero Core Components 10 (x32 Version: 2.0.17200.8.0 - Nero AG) Hidden Nero Dolby Files 10 (x32 Version: 2.0.12001.0.10 - Nero AG) Hidden Nero MediaHub 10 (HKLM-x32\...\{1F7FB68F-52F6-46A3-B42F-38CE46295AE5}) (Version: 1.2.10800.14.100 - Nero AG) Nero MediaHub 10 Help (CHM) (x32 Version: 10.2.10500 - Nero AG) Hidden Nero Update (HKLM-x32\...\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}) (Version: 1.0.0018 - Nero AG) Nero Video HD Premium (HKLM-x32\...\{7AA92D13-8B7A-48B9-B18D-645564FAD258}) (Version: 10.5.10000 - Nero AG) Nero Vision 10 (HKLM-x32\...\{9A4297F3-2A51-4ED9-92CA-4BCB8380947E}) (Version: 7.2.14000.4.100 - Nero AG) Nero Vision 10 Help (CHM) (x32 Version: 10.2.10800 - Nero AG) Hidden OpenOffice 4.0.1 (HKLM-x32\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation) Photo Common (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Photo Gallery (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden PHOTOfunSTUDIO 5.0 HD Edition (HKLM-x32\...\{959282E3-55A9-49D8-B885-D27CF8A2FD82}) (Version: 5.00.316 - Panasonic Corporation) Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.) Pinnacle MediaCenter (HKLM-x32\...\{F38ADCA4-AF7C-4C73-9021-6F1EA15D15EA}) (Version: - ) Platform (x32 Version: 1.39 - VIA Technologies, Inc.) Hidden Print Artist Platinum (HKLM-x32\...\{4BC2BE31-3DCF-4CF5-AD52-66DB68638EC0}) (Version: 23.0.0.31 - Avanquest) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.3.730.2012 - Realtek) Realtek PCIE Card Reader (HKLM-x32\...\{0D61A55C-3ADC-409F-BF5B-A1766D1F5944}) (Version: 6.2.9200.27035 - Realtek Semiconductor Corp.) Riva FLV Encoder 2.0 (HKLM-x32\...\Riva FLV Encoder 2.0_is1) (Version: 2.00.0004 - Rothenberger & Partner) Seagate Dashboard (HKLM-x32\...\{67445E65-3D93-428F-83A5-446F7D02689A}) (Version: 3.1.3.0 - Seagate) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.3.4.0 - Synaptics Incorporated) SyncToy 2.1 (x64) (HKLM\...\{88DAAF05-5A72-46D2-A7C5-C3759697E943}) (Version: 2.1.0 - Microsoft) TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.28223 - TeamViewer) Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.01 - Ghisler Software GmbH) VIA Plattform-Geräte-Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.39 - VIA Technologies, Inc.) WD My Cloud (HKLM\...\{8F19C800-80A5-4636-B560-39A58112D45B}) (Version: 1.0.4.37 - Western Digital Technologies, Inc.) WD SmartWare (HKLM\...\{FA72BBFB-C42C-44C1-8555-75B629252DD6}) (Version: 1.4.2.5 - Western Digital) Windows Live (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Communications Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation) Windows Live Essentials (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Mobile Device Updater Component (Version: 04.08.2345.00 - Microsoft Corporation) Hidden WinSCP 5.1.7 (HKLM-x32\...\winscp3_is1) (Version: 5.1.7 - Martin Prikryl) Wondershare Video Converter Ultimate(Build 6.7.0.10) (HKLM-x32\...\Wondershare Video Converter Ultimate_is1) (Version: 6.7.0.10 - Wondershare Software) Zune (HKLM\...\Zune) (Version: 04.08.2345.00 - Microsoft Corporation) Zune (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (CHS) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (CHT) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (CSY) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (DAN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (DEU) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (ELL) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (ESP) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (FIN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (FRA) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (HUN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (IND) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (ITA) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (JPN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (KOR) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (MSL) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (NLD) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (NOR) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (PLK) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (PTB) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (PTG) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (RUS) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden Zune Language Pack (SVE) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden ==================== Restore Points ========================= 30-05-2014 04:38:59 Geplanter Prüfpunkt ==================== Hosts content: ========================== 2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____N C:\WINDOWS\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList Task: {13CDD0EC-5768-4FBD-8205-EF50345378FE} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2014-05-14] (Microsoft Corporation) Task: {1B5B169B-CCD3-4A51-8EC4-DA63303CA9B6} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-12812500-3875771965-374869435-1001Core => C:\Users\Frank\AppData\Local\Google\Update\GoogleUpdate.exe [2013-11-14] (Google Inc.) Task: {1D5701B8-B769-4109-B2DF-68545BAEA655} - System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup => C:\Windows\system32\cleanmgr.exe [2014-02-22] (Microsoft Corporation) Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask Task: {2B42D7D8-0110-4D4C-9837-ABB59698518B} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-05-20] (Piriform Ltd) Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation) Task: {36F9BD5A-C6CC-4494-9A48-288061550E8B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-18] (Google Inc.) Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation) Task: {3CAD076B-DF32-4486-A1D8-D775D57FA87E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-18] (Google Inc.) Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance Task: {5E4EA0E1-D6B5-410E-BC9D-4A3F92FFE4C1} - System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-12812500-3875771965-374869435-1001 => %localappdata%\Microsoft\SkyDrive\SkyDrive.exe Task: {60968F12-5F96-4CFB-AC80-AA8B80A03E80} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-12812500-3875771965-374869435-1001UA => C:\Users\Frank\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-11-19] (Facebook Inc.) Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState Task: {7AABF784-8F5B-46E3-A84D-2B44A10D94DE} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics Task: {8673364A-D09A-4B79-B544-657FFA4B8D93} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files (x86)\Ask.com\UpdateTask.exe [2010-05-21] () <==== ATTENTION Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task Task: {8C5C6F18-BFC4-4996-B772-D5A746724E16} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Validation Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask Task: {926C27CF-5EEA-46C1-A827-B92DC6CF0EB3} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-12812500-3875771965-374869435-1001Core => C:\Users\Frank\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-11-19] (Facebook Inc.) Task: {9A96B808-1E43-4A8B-8413-77F6506E1EC7} - System32\Tasks\Frank DBAgent 2 0 => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe [2014-04-30] (Seagate Technology LLC) Task: {9F140607-D384-4E0A-B253-91A6A4DDC84E} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network => Sc.exe start wuauserv Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work Task: {A1E8BDD2-B1BC-42C2-AFFD-F9932D106B8E} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-12812500-3875771965-374869435-1001UA => C:\Users\Frank\AppData\Local\Google\Update\GoogleUpdate.exe [2013-11-14] (Google Inc.) Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE Task: {F0879C9B-0879-4CD3-8A10-537473EED8DC} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Management Task: {F76C8080-B4ED-4551-8ADC-188AF17095D8} - System32\Tasks\aviraSWU => Cscript.exe "C:\Program Files (x86)\avira\Internet Explorer\swu.vbs" Task: {F8F13B95-887D-4ABA-A4DB-E43A0E6FC958} - System32\Tasks\Seagate_Install_Launch => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Dashboard.exe [2014-04-30] (Seagate Technology LLC) Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-12812500-3875771965-374869435-1001Core.job => C:\Users\Frank\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-12812500-3875771965-374869435-1001UA.job => C:\Users\Frank\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-12812500-3875771965-374869435-1001Core.job => C:\Users\Frank\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-12812500-3875771965-374869435-1001UA.job => C:\Users\Frank\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe ==================== Loaded Modules (whitelisted) ============= 2012-11-05 14:02 - 2012-11-05 14:02 - 00046080 _____ () C:\Program Files (x86)\Hotkey\PowerBiosServer.exe 2010-10-05 16:28 - 2010-10-05 16:28 - 01060352 _____ () C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe 2010-10-05 16:27 - 2010-10-05 16:27 - 00485376 _____ () C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSC.exe 2010-01-02 16:42 - 2010-01-02 16:42 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll 2013-10-04 00:42 - 2013-10-04 00:42 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2012-11-16 13:20 - 2012-11-16 13:20 - 04749312 _____ () C:\Program Files (x86)\Hotkey\Hotkey.exe 2013-02-19 14:52 - 2012-09-13 00:55 - 00078480 _____ () C:\Program Files (x86)\VIA\VIAudioi\VDeck\QsApoApi64.dll 2013-02-19 14:52 - 2012-09-13 00:55 - 00386192 _____ () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Dts2ApoApi64.dll 2009-10-22 18:47 - 2009-10-22 18:47 - 00144664 _____ () C:\Program Files (x86)\Avanquest\Print Artist Platinum\ReminderApp.exe 2010-03-05 11:24 - 2010-03-05 11:24 - 00886272 _____ () C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDFME\System.Data.SQLite.dll 2013-02-19 14:48 - 2012-06-24 19:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll 2013-12-10 23:06 - 2013-12-10 23:06 - 10683392 _____ () C:\Users\Frank\AppData\Local\Programs\Google\MusicManager\QtWebKit4.dll 2013-12-10 23:06 - 2013-12-10 23:06 - 07741952 _____ () C:\Users\Frank\AppData\Local\Programs\Google\MusicManager\QtGui4.dll 2013-12-10 23:06 - 2013-12-10 23:06 - 01681408 _____ () C:\Users\Frank\AppData\Local\Programs\Google\MusicManager\QtNetwork4.dll 2013-12-10 23:06 - 2013-12-10 23:06 - 02248192 _____ () C:\Users\Frank\AppData\Local\Programs\Google\MusicManager\QtCore4.dll 2014-05-15 23:20 - 2014-05-15 23:20 - 00117248 _____ () C:\Users\Frank\AppData\Local\Programs\Google\MusicManager\libaacdec.dll 2014-05-15 23:20 - 2014-05-15 23:20 - 00231936 _____ () C:\Users\Frank\AppData\Local\Programs\Google\MusicManager\libmpgdec.dll 2014-05-15 23:21 - 2014-05-15 23:21 - 00253440 _____ () C:\Users\Frank\AppData\Local\Programs\Google\MusicManager\libid3tag.dll 2014-05-15 23:24 - 2014-05-15 23:24 - 00344064 _____ () C:\Users\Frank\AppData\Local\Programs\Google\MusicManager\libaudioenc.dll 2013-12-10 23:06 - 2013-12-10 23:06 - 00026624 _____ () C:\Users\Frank\AppData\Local\Programs\Google\MusicManager\imageformats\qgif4.dll 2014-06-02 06:29 - 2014-06-02 06:29 - 00098816 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\win32api.pyd 2014-06-02 06:29 - 2014-06-02 06:29 - 00110080 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\pywintypes27.dll 2014-06-02 06:29 - 2014-06-02 06:29 - 00364544 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\pythoncom27.dll 2014-06-02 06:29 - 2014-06-02 06:29 - 00045568 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\_socket.pyd 2014-06-02 06:29 - 2014-06-02 06:29 - 01159680 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\_ssl.pyd 2014-06-02 06:29 - 2014-06-02 06:29 - 00320512 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\win32com.shell.shell.pyd 2014-06-02 06:29 - 2014-06-02 06:29 - 00713216 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\_hashlib.pyd 2014-06-02 06:29 - 2014-06-02 06:29 - 01175040 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\wx._core_.pyd 2014-06-02 06:29 - 2014-06-02 06:29 - 00805888 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\wx._gdi_.pyd 2014-06-02 06:29 - 2014-06-02 06:29 - 00811008 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\wx._windows_.pyd 2014-06-02 06:29 - 2014-06-02 06:29 - 01062400 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\wx._controls_.pyd 2014-06-02 06:29 - 2014-06-02 06:29 - 00735232 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\wx._misc_.pyd 2014-06-02 06:29 - 2014-06-02 06:29 - 00128512 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\_elementtree.pyd 2014-06-02 06:29 - 2014-06-02 06:29 - 00127488 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\pyexpat.pyd 2014-06-02 06:29 - 2014-06-02 06:29 - 00557056 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\pysqlite2._sqlite.pyd 2014-06-02 06:29 - 2014-06-02 06:29 - 00087552 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\_ctypes.pyd 2014-06-02 06:29 - 2014-06-02 06:29 - 00119808 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\win32file.pyd 2014-06-02 06:29 - 2014-06-02 06:29 - 00108544 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\win32security.pyd 2014-06-02 06:29 - 2014-06-02 06:29 - 00018432 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\win32event.pyd 2014-06-02 06:29 - 2014-06-02 06:29 - 00038912 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\win32inet.pyd 2014-06-02 06:29 - 2014-06-02 06:29 - 00070656 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\wx._html2.pyd 2014-06-02 06:29 - 2014-06-02 06:29 - 00167936 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\win32gui.pyd 2014-06-02 06:29 - 2014-06-02 06:29 - 00011264 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\win32crypt.pyd 2014-06-02 06:29 - 2014-06-02 06:29 - 00027136 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\_multiprocessing.pyd 2014-06-02 06:29 - 2014-06-02 06:29 - 00122368 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\wx._wizard.pyd 2014-06-02 06:29 - 2014-06-02 06:29 - 00010240 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\select.pyd 2014-06-02 06:29 - 2014-06-02 06:29 - 00024064 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\win32pipe.pyd 2014-06-02 06:29 - 2014-06-02 06:29 - 00686080 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\unicodedata.pyd 2014-06-02 06:29 - 2014-06-02 06:29 - 00025600 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\win32pdh.pyd 2014-06-02 06:29 - 2014-06-02 06:29 - 00525640 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\windows._lib_cacheinvalidation.pyd 2014-06-02 06:29 - 2014-06-02 06:29 - 00035840 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\win32process.pyd 2014-06-02 06:29 - 2014-06-02 06:29 - 00017408 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\win32profile.pyd 2014-06-02 06:29 - 2014-06-02 06:29 - 00022528 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\win32ts.pyd 2014-06-02 06:29 - 2014-06-02 06:29 - 00078336 _____ () C:\Users\Frank\AppData\Local\Temp\_MEI54202\wx._animate.pyd 2014-03-26 18:02 - 2014-03-26 18:02 - 03305472 _____ () C:\Users\Frank\AppData\Local\Programs\Google\Google+ Auto Backup\gpuploader_i18n.dll 2009-10-22 18:47 - 2009-10-22 18:47 - 00087320 _____ () C:\Program Files (x86)\Avanquest\Print Artist Platinum\AddressBookCore.dll 2009-10-22 18:47 - 2009-10-22 18:47 - 00148760 _____ () C:\Program Files (x86)\Avanquest\Print Artist Platinum\de-DE\ReminderApp.resources.dll 2014-05-02 06:06 - 2014-05-02 06:07 - 03019888 _____ () C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll 2014-05-02 06:06 - 2014-05-02 06:07 - 00158832 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll 2014-05-02 06:06 - 2014-05-02 06:07 - 00023152 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll 2013-08-07 21:25 - 2013-08-07 21:25 - 00093696 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll 2014-05-28 07:03 - 2014-05-14 01:40 - 00716616 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\libglesv2.dll 2014-05-28 07:03 - 2014-05-14 01:40 - 00126280 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\libegl.dll 2014-05-28 07:03 - 2014-05-14 01:40 - 04217672 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\pdf.dll 2014-05-28 07:03 - 2014-05-14 01:40 - 00414536 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\ppGoogleNaClPluginChrome.dll 2014-05-28 07:03 - 2014-05-14 01:40 - 01732424 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\ffmpegsumo.dll 2014-05-28 07:03 - 2014-05-14 01:40 - 13695816 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\WINDOWS\system32\Drivers\btmhsf.sys:Microsoft_Appcompat_ReinstallUpgrade AlternateDataStreams: C:\Users\Frank\SkyDrive:ms-properties ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRkrn => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRSVC => ""="Service" ==================== EXE Association (whitelisted) ============= HKU\.DEFAULT\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION! HKU\.DEFAULT\Software\Classes\exefile: "%1" %* <===== ATTENTION! HKU\S-1-5-19\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION! HKU\S-1-5-19\Software\Classes\exefile: "%1" %* <===== ATTENTION! HKU\S-1-5-20\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION! HKU\S-1-5-20\Software\Classes\exefile: "%1" %* <===== ATTENTION! HKU\S-1-5-21-12812500-3875771965-374869435-1001\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION! HKU\S-1-5-21-12812500-3875771965-374869435-1001\Software\Classes\exefile: "%1" %* <===== ATTENTION! ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (06/02/2014 07:32:59 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm wwahost.exe, Version 6.3.9600.17031 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 2cc Startzeit: 01cf7e2360d6ad87 Endzeit: 4294967295 Anwendungspfad: C:\WINDOWS\syswow64\wwahost.exe Berichts-ID: 580843b2-ea17-11e3-bea1-0cd2924658fb Vollständiger Name des fehlerhaften Pakets: Microsoft.SkypeApp_2.8.0.1001_x86__kzf8qxf38zg5c Anwendungs-ID, die relativ zum fehlerhaften Paket ist: App Error: (06/02/2014 07:32:57 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm wwahost.exe, Version 6.3.9600.17031 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1b18 Startzeit: 01cf7e2366d167bd Endzeit: 4294967295 Anwendungspfad: C:\WINDOWS\system32\wwahost.exe Berichts-ID: 56f61054-ea17-11e3-bea1-0cd2924658fb Vollständiger Name des fehlerhaften Pakets: 68D6D712.WebrootBackupandSync_1.0.0.31_neutral__3n9w82bea0x6e Anwendungs-ID, die relativ zum fehlerhaften Paket ist: App Error: (06/01/2014 07:38:38 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 14984 Error: (06/01/2014 07:38:38 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 14984 Error: (06/01/2014 07:38:38 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (06/01/2014 02:32:33 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: delegate_execute.exe, Version: 35.0.1916.114, Zeitstempel: 0x53725c7e Name des fehlerhaften Moduls: delegate_execute.exe, Version: 35.0.1916.114, Zeitstempel: 0x53725c7e Ausnahmecode: 0xc0000005 Fehleroffset: 0x000461e9 ID des fehlerhaften Prozesses: 0x7f4 Startzeit der fehlerhaften Anwendung: 0xdelegate_execute.exe0 Pfad der fehlerhaften Anwendung: delegate_execute.exe1 Pfad des fehlerhaften Moduls: delegate_execute.exe2 Berichtskennung: delegate_execute.exe3 Vollständiger Name des fehlerhaften Pakets: delegate_execute.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: delegate_execute.exe5 Error: (06/01/2014 02:08:35 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: ) Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (06/01/2014 00:13:56 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm LiveComm.exe, Version 17.5.9600.20498 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 21f0 Startzeit: 01cf7d817bb2b64c Endzeit: 4294967295 Anwendungspfad: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbwe\LiveComm.exe Berichts-ID: 6f4cfcf3-e975-11e3-bea0-0cd2924658fb Vollständiger Name des fehlerhaften Pakets: microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbwe Anwendungs-ID, die relativ zum fehlerhaften Paket ist: ppleae38af2e007f4358a809ac99a64a67c1 Error: (06/01/2014 00:13:53 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm wwahost.exe, Version 6.3.9600.17031 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 22c0 Startzeit: 01cf7d8178e043b2 Endzeit: 4294967295 Anwendungspfad: C:\WINDOWS\syswow64\wwahost.exe Berichts-ID: 6d1773c1-e975-11e3-bea0-0cd2924658fb Vollständiger Name des fehlerhaften Pakets: Microsoft.SkypeApp_2.8.0.1001_x86__kzf8qxf38zg5c Anwendungs-ID, die relativ zum fehlerhaften Paket ist: App Error: (06/01/2014 00:13:51 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm wwahost.exe, Version 6.3.9600.17031 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 2240 Startzeit: 01cf7d817ee4864f Endzeit: 4294967295 Anwendungspfad: C:\WINDOWS\system32\wwahost.exe Berichts-ID: 6c85dad8-e975-11e3-bea0-0cd2924658fb Vollständiger Name des fehlerhaften Pakets: 68D6D712.WebrootBackupandSync_1.0.0.31_neutral__3n9w82bea0x6e Anwendungs-ID, die relativ zum fehlerhaften Paket ist: App System errors: ============= Error: (06/01/2014 02:08:49 PM) (Source: DCOM) (EventID: 10016) (User: FRANK-PC) Description: AnwendungsspezifischLokalStart{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}Frank-PCFrankS-1-5-21-12812500-3875771965-374869435-1001LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar Error: (06/01/2014 02:08:35 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler beendet: %%1064 Error: (06/01/2014 00:14:28 PM) (Source: Schannel) (EventID: 4101) (User: NT-AUTORITÄT) Description: Das Zertifikat der Referenz Server für SSL hat keine angehängte Eigenschaft für Privatschlüsselinformationen. Dies kommt häufig vor, wenn ein Zertifikat nicht ordnungsgemäß gesichert wird und anschließend wiederhergestellt wird. Diese Nachricht wird auch bei einem Fehler bei der Zertifikatregistrierung angezeigt. Error: (06/01/2014 00:12:19 PM) (Source: Schannel) (EventID: 4101) (User: NT-AUTORITÄT) Description: Das Zertifikat der Referenz Server für SSL hat keine angehängte Eigenschaft für Privatschlüsselinformationen. Dies kommt häufig vor, wenn ein Zertifikat nicht ordnungsgemäß gesichert wird und anschließend wiederhergestellt wird. Diese Nachricht wird auch bei einem Fehler bei der Zertifikatregistrierung angezeigt. Error: (06/01/2014 11:42:43 AM) (Source: Schannel) (EventID: 4101) (User: NT-AUTORITÄT) Description: Das Zertifikat der Referenz Server für SSL hat keine angehängte Eigenschaft für Privatschlüsselinformationen. Dies kommt häufig vor, wenn ein Zertifikat nicht ordnungsgemäß gesichert wird und anschließend wiederhergestellt wird. Diese Nachricht wird auch bei einem Fehler bei der Zertifikatregistrierung angezeigt. Error: (05/27/2014 04:26:40 PM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: Der Dienst "Avira Email-Schutz" wurde mit dem folgenden dienstspezifischen Fehler beendet: %%1 Error: (05/27/2014 04:20:27 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler beendet: %%1064 Error: (05/27/2014 04:20:27 PM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: Der Dienst "Avira Browser-Schutz" wurde mit dem folgenden dienstspezifischen Fehler beendet: %%1 Error: (05/27/2014 04:20:26 PM) (Source: Service Control Manager) (EventID: 7024) (User: ) Description: Der Dienst "Avira Email-Schutz" wurde mit dem folgenden dienstspezifischen Fehler beendet: %%1 Error: (05/27/2014 02:23:45 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler beendet: %%1064 Microsoft Office Sessions: ========================= Error: (06/02/2014 07:32:59 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: wwahost.exe6.3.9600.170312cc01cf7e2360d6ad874294967295C:\WINDOWS\syswow64\wwahost.exe580843b2-ea17-11e3-bea1-0cd2924658fbMicrosoft.SkypeApp_2.8.0.1001_x86__kzf8qxf38zg5cApp Error: (06/02/2014 07:32:57 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: wwahost.exe6.3.9600.170311b1801cf7e2366d167bd4294967295C:\WINDOWS\system32\wwahost.exe56f61054-ea17-11e3-bea1-0cd2924658fb68D6D712.WebrootBackupandSync_1.0.0.31_neutral__3n9w82bea0x6eApp Error: (06/01/2014 07:38:38 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 14984 Error: (06/01/2014 07:38:38 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 14984 Error: (06/01/2014 07:38:38 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (06/01/2014 02:32:33 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: delegate_execute.exe35.0.1916.11453725c7edelegate_execute.exe35.0.1916.11453725c7ec0000005000461e97f401cf7d956801489bC:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\delegate_execute.exeC:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\delegate_execute.execd49d09e-e988-11e3-bea1-0cd2924658fb Error: (06/01/2014 02:08:35 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: ) Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run. bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args) bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state) Error: (06/01/2014 00:13:56 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: LiveComm.exe17.5.9600.2049821f001cf7d817bb2b64c4294967295C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbwe\LiveComm.exe6f4cfcf3-e975-11e3-bea0-0cd2924658fbmicrosoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbweppleae38af2e007f4358a809ac99a64a67c1 Error: (06/01/2014 00:13:53 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: wwahost.exe6.3.9600.1703122c001cf7d8178e043b24294967295C:\WINDOWS\syswow64\wwahost.exe6d1773c1-e975-11e3-bea0-0cd2924658fbMicrosoft.SkypeApp_2.8.0.1001_x86__kzf8qxf38zg5cApp Error: (06/01/2014 00:13:51 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: wwahost.exe6.3.9600.17031224001cf7d817ee4864f4294967295C:\WINDOWS\system32\wwahost.exe6c85dad8-e975-11e3-bea0-0cd2924658fb68D6D712.WebrootBackupandSync_1.0.0.31_neutral__3n9w82bea0x6eApp CodeIntegrity Errors: =================================== Date: 2014-05-27 19:34:37.115 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2014-05-27 19:34:36.959 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2014-05-27 19:19:11.740 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2014-05-27 19:18:27.003 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2014-05-27 19:18:26.878 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2014-05-27 19:18:26.785 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2014-05-27 19:18:26.581 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2014-05-27 19:18:26.488 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2014-05-27 19:18:26.316 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2014-05-27 19:18:26.222 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== Percentage of memory in use: 49% Total physical RAM: 3795.47 MB Available physical RAM: 1898.47 MB Total Pagefile: 6611.47 MB Available Pagefile: 4161.14 MB Total Virtual: 131072 MB Available Virtual: 131071.81 MB ==================== Drives ================================ Drive c: (Windows) (Fixed) (Total:911.5 GB) (Free:384.56 GB) NTFS Drive e: (Public) (Network) (Total:3663.13 GB) (Free:11.11 GB) NTFS Drive z: (Public) (Network) (Total:1850.68 GB) (Free:0 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 932 GB) (Disk ID: B42D7263) Partition: GPT Partition Type. ==================== End Of Log ============================ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-06-2014 01 Ran by Frank (administrator) on FRANK-PC on 02-06-2014 08:48:28 Running from C:\Users\Frank\Downloads Platform: Windows 8.1 (Update 1) (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials ==================== Processes (Whitelisted) ================= (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (B.H.A Corporation) C:\Windows\SysWOW64\bgsvcgen.exe (Apple Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe () C:\Program Files (x86)\Hotkey\PowerBiosServer.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe (WDC) C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe () C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe () C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSC.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler64.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.DASWindowsService.exe (Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\MobileService.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Microsoft Corporation) C:\Program Files\Zune\ZuneLauncher.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Google Inc.) C:\Users\Frank\AppData\Local\Programs\Google\MusicManager\MusicManager.exe (Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Enter Srl) C:\Program Files (x86)\Iperius Backup\Iperius.exe (Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe (Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Google Inc.) C:\Users\Frank\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe () C:\Program Files (x86)\Hotkey\Hotkey.exe (Western Digital Technologies, Inc.) C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (STRATO) C:\Program Files (x86)\STRATO AG\STRATO HiDrive\STRATO HiDrive.exe () C:\Program Files (x86)\Avanquest\Print Artist Platinum\ReminderApp.exe (Alcor) C:\Windows\WebCam\S6000\S6000Mnt.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe (BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-Agent.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe (Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DeviceAgent.exe (Microsoft Corporation) C:\Windows\System32\WWAHost.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbwe\livecomm.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [BTMTrayAgent] => C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll [11582848 2012-09-30] (Motorola Solutions, Inc.) HKLM\...\Run: [Zune Launcher] => C:\Program Files\Zune\ZuneLauncher.exe [163552 2011-08-05] (Microsoft Corporation) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3008824 2012-11-30] (Synaptics Incorporated) HKLM\...\Run: [etMonitor] => C:\WINDOWS\etMon.exe [88576 2007-04-04] (EMPIA Technology Corporation) HKLM-x32\...\Run: [S6000Mnt] => C:\WINDOWS\SysWOW64\Rundll32.exe S6000Rmv.dll,WinMainRmv /StartStillMnt HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5263504 2012-09-13] (VIA) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [PrintArtist] => C:\Program Files (x86)\Avanquest\Print Artist Platinum\ReminderApp.exe [144664 2009-10-22] () HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [1743648 2013-06-13] (Wondershare) HKLM-x32\...\Run: [BrowserPlugInHelper] => C:\Program Files (x86)\Wondershare\Video Converter Ultimate\BrowserPlugInHelper.exe [1962896 2013-12-09] () HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [807696 2013-12-20] (BlueStack Systems, Inc.) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-05-15] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [DBAgent] => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe [1519176 2014-04-30] (Seagate Technology LLC) Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer: [NoFolderOptions] 0 HKLM\...\Policies\Explorer: [NoViewOnDrive] 0 HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKLM\...\Policies\Explorer: [DisableLocalMachineRun] 0 HKLM\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0 HKLM\...\Policies\Explorer: [DisableCurrentUserRun] 0 HKLM\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0 HKLM\...\Policies\Explorer: [NoViewContextMenu] 0 HKLM\...\Policies\Explorer: [NoShellSearchButton] 0 HKLM\...\Policies\Explorer: [NoFind] 0 HKLM\...\Policies\Explorer: [NoFile] 0 HKLM\...\Policies\Explorer: [HideClock] 0 HKLM\...\Policies\Explorer: [NoTrayContextMenu] 0 HKLM\...\Policies\Explorer: [NoTrayItemsDisplay] 0 HKLM\...\Policies\Explorer: [NoSetFolders] 0 HKLM\...\Policies\Explorer: [NoDevMgrUpdate] 0 HKLM\...\Policies\Explorer: [NoSetTaskbar] 0 HKLM\...\Policies\Explorer: [NoDeletePrinter] 0 HKLM\...\Policies\Explorer: [NoDFSTab] 0 HKLM\...\Policies\Explorer: [NoChangeStartMenu] 0 HKLM\...\Policies\Explorer: [NoLogoff] 0 HKLM\...\Policies\Explorer: [NoWindowsUpdate] 0 HKLM\...\Policies\Explorer: [NoEncryptOnMove] 0 HKLM\...\Policies\Explorer: [NoRunasInstallPrompt] 0 HKLM\...\Policies\Explorer: [NoResolveSearch] 0 HKLM\...\Policies\Explorer: [NoSaveSettings] 0 HKLM\...\Policies\Explorer: [NoHardwareTab] 0 HKLM\...\Policies\Explorer: [NoStartMenuSubFolders] 0 HKLM\...\Policies\Explorer: [NoDesktop] 0 HKU\.DEFAULT\...\Policies\system: [DisableCMD] 0 HKU\.DEFAULT\...\Policies\system: [NoDispAppearancePage] 0 HKU\.DEFAULT\...\Policies\system: [NoDispBackgroundPage] 0 HKU\.DEFAULT\...\Policies\system: [NoDispSettingsPage] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoFolderOptions] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoViewOnDrive] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoControlPanel] 0 HKU\.DEFAULT\...\Policies\Explorer: [DisableLocalMachineRun] 0 HKU\.DEFAULT\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0 HKU\.DEFAULT\...\Policies\Explorer: [DisableCurrentUserRun] 0 HKU\.DEFAULT\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoViewContextMenu] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoShellSearchButton] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoFind] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoFile] 0 HKU\.DEFAULT\...\Policies\Explorer: [HideClock] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoTrayContextMenu] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoTrayItemsDisplay] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoSetFolders] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoDevMgrUpdate] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoSetTaskbar] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoDeletePrinter] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoDFSTab] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoChangeStartMenu] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoLogoff] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoWindowsUpdate] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoEncryptOnMove] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoRunasInstallPrompt] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoResolveSearch] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoSaveSettings] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoHardwareTab] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoStartMenuSubFolders] 0 HKU\S-1-5-19\...\Policies\system: [DisableCMD] 0 HKU\S-1-5-19\...\Policies\system: [NoDispAppearancePage] 0 HKU\S-1-5-19\...\Policies\system: [NoDispBackgroundPage] 0 HKU\S-1-5-19\...\Policies\system: [NoDispSettingsPage] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoFolderOptions] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoViewOnDrive] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-19\...\Policies\Explorer: [DisableLocalMachineRun] 0 HKU\S-1-5-19\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0 HKU\S-1-5-19\...\Policies\Explorer: [DisableCurrentUserRun] 0 HKU\S-1-5-19\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoViewContextMenu] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoShellSearchButton] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoFind] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoFile] 0 HKU\S-1-5-19\...\Policies\Explorer: [HideClock] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoTrayContextMenu] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoTrayItemsDisplay] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoSetFolders] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoDevMgrUpdate] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoSetTaskbar] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoDeletePrinter] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoDFSTab] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoChangeStartMenu] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoLogoff] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoWindowsUpdate] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoEncryptOnMove] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoRunasInstallPrompt] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoResolveSearch] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoSaveSettings] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoHardwareTab] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoStartMenuSubFolders] 0 HKU\S-1-5-20\...\Policies\system: [DisableCMD] 0 HKU\S-1-5-20\...\Policies\system: [NoDispAppearancePage] 0 HKU\S-1-5-20\...\Policies\system: [NoDispBackgroundPage] 0 HKU\S-1-5-20\...\Policies\system: [NoDispSettingsPage] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoFolderOptions] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoViewOnDrive] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-20\...\Policies\Explorer: [DisableLocalMachineRun] 0 HKU\S-1-5-20\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0 HKU\S-1-5-20\...\Policies\Explorer: [DisableCurrentUserRun] 0 HKU\S-1-5-20\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoViewContextMenu] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoShellSearchButton] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoFind] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoFile] 0 HKU\S-1-5-20\...\Policies\Explorer: [HideClock] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoTrayContextMenu] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoTrayItemsDisplay] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoSetFolders] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoDevMgrUpdate] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoSetTaskbar] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoDeletePrinter] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoDFSTab] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoChangeStartMenu] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoLogoff] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoWindowsUpdate] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoEncryptOnMove] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoRunasInstallPrompt] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoResolveSearch] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoSaveSettings] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoHardwareTab] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoStartMenuSubFolders] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Run: [Google Update] => C:\Users\Frank\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-11-14] (Google Inc.) HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Run: [MusicManager] => C:\Users\Frank\AppData\Local\Programs\Google\MusicManager\MusicManager.exe [7631872 2014-05-15] (Google Inc.) HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Run: [AmazonMP3DownloaderHelper] => C:\Users\Frank\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-22] () HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [22415552 2014-04-25] (Google) HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Run: [SkyDrive] => C:\Users\Frank\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [257224 2014-05-15] (Microsoft Corporation) HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Run: [Facebook Update] => C:\Users\Frank\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-11-19] (Facebook Inc.) HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Run: [Iperius Backup] => C:\Program Files (x86)\Iperius Backup\Iperius.exe [15267664 2013-12-04] (Enter Srl) HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Run: [Uploader] => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe [126056 2014-04-30] (Seagate Technology LLC) HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Run: [Google+ Auto Backup] => C:\Users\Frank\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe [3701064 2014-03-26] (Google Inc.) HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Run: [tpdbxm] => regsvr32.exe " HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\system: [DisableCMD] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\system: [NoDispAppearancePage] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\system: [NoDispBackgroundPage] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\system: [NoDispSettingsPage] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoFolderOptions] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoViewOnDrive] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [DisableLocalMachineRun] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [DisableCurrentUserRun] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoViewContextMenu] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoShellSearchButton] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoFind] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoFile] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [HideClock] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoTrayContextMenu] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoTrayItemsDisplay] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoSetFolders] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoDevMgrUpdate] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoSetTaskbar] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoDeletePrinter] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoDFSTab] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoChangeStartMenu] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoLogoff] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoWindowsUpdate] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoEncryptOnMove] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoRunasInstallPrompt] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoResolveSearch] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoSaveSettings] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoHardwareTab] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoStartMenuSubFolders] 0 Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Hotkey.lnk ShortcutTarget: Hotkey.lnk -> C:\Program Files (x86)\Hotkey\Hotkey.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\PHOTOfunSTUDIO 5.0 HD Edition.lnk ShortcutTarget: PHOTOfunSTUDIO 5.0 HD Edition.lnk -> C:\Program Files (x86)\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe (Panasonic Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WDDMStatus.lnk ShortcutTarget: WDDMStatus.lnk -> C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe (Western Digital Technologies, Inc.) Startup: C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Amazon Cloud Drive.lnk ShortcutTarget: Amazon Cloud Drive.lnk -> C:\Users\Frank\AppData\Local\Apps\2.0\APCJ5E1P.MQK\Y50GAJHD.KY9\amaz..tion_f2fa081ea2183235_0002.0001_cb34a912a946f839\AmazonCloudDrive.exe (Amazon Digital Services, LLC.) Startup: C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\STRATO HiDrive.lnk ShortcutTarget: STRATO HiDrive.lnk -> C:\Program Files (x86)\STRATO AG\STRATO HiDrive\STRATO HiDrive.exe (STRATO) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login. HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login. HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Upgrade to Google Chrome HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Upgrade to Google Chrome SearchScopes: HKLM - DefaultScope {B904397E-4149-42A6-A059-5282FFB3919B} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASBJS SearchScopes: HKLM - {B904397E-4149-42A6-A059-5282FFB3919B} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASBJS SearchScopes: HKLM-x32 - DefaultScope {B904397E-4149-42A6-A059-5282FFB3919B} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASBJS SearchScopes: HKLM-x32 - {B904397E-4149-42A6-A059-5282FFB3919B} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASBJS SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear BHO: No Name - {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} - No File BHO-x32: Wondershare Video Converter Ultimate - {65DEE40A-3E93-4cae-9F98-B8E06DCEE2BF} - C:\Program Files (x86)\Wondershare\Video Converter Ultimate\SVRIEPlugin.dll (Wondershare Software Co., Ltd.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Avira Savings Advisor BHO - {A18A516C-AA41-46A9-92DB-60208917E442} - C:\Program Files (x86)\avira\Internet Explorer\avira32.dll () BHO-x32: No Name - {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} - No File BHO-x32: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask.com) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - No Name - {97ab88ef-346b-4179-a0b1-7445896547a5} - No File Toolbar: HKLM-x32 - Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask.com) Toolbar: HKLM-x32 - No Name - {97ab88ef-346b-4179-a0b1-7445896547a5} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Frank\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Frank\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Frank\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Users\Frank\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.) FF HKLM-x32\...\Firefox\Extensions: [{8D150B8F-EFE8-45a3-A4A3-053020F48FAC}] - C:\Program Files (x86)\Wondershare\Video Converter Ultimate\SVRFirefoxExt\ FF Extension: Wondershare Video Converter Ultimate - C:\Program Files (x86)\Wondershare\Video Converter Ultimate\SVRFirefoxExt\ [] FF HKCU\...\Firefox\Extensions: [{8D150B8F-EFE8-45a3-A4A3-053020F48FAC}] - C:\Program Files (x86)\Wondershare\Video Converter Ultimate\SVRFirefoxExt\ FF Extension: Wondershare Video Converter Ultimate - C:\Program Files (x86)\Wondershare\Video Converter Ultimate\SVRFirefoxExt\ [] Chrome: ======= CHR Extension: (Google Docs) - C:\Users\Frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-18] CHR Extension: (Google Drive) - C:\Users\Frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-18] CHR Extension: (YouTube) - C:\Users\Frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-18] CHR Extension: (Wondershare Video Converter Ultimate) - C:\Users\Frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\chgdeabpmphfhkoemjjglmilajldekbp [2013-12-17] CHR Extension: (Avira Sparberater) - C:\Users\Frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\cojnmaaohncijldefpkpkkakjonfmgeb [2014-02-12] CHR Extension: (Google-Suche) - C:\Users\Frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-18] CHR Extension: (Easy Video Downloader Express) - C:\Users\Frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbcpmdpjjlhppmhfkcgbeanaanipdjbk [2014-01-22] CHR Extension: (Google Wallet) - C:\Users\Frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-18] CHR Extension: (Personal Blocklist (by Google)) - C:\Users\Frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\nolijncfnkgaikbjbdaogikpmpbdcdef [2014-01-22] CHR Extension: (Google Mail) - C:\Users\Frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-18] CHR HKLM-x32\...\Chrome\Extension: [chgdeabpmphfhkoemjjglmilajldekbp] - C:\Program Files (x86)\Wondershare\Video Converter Ultimate\SVRChromePlugin.crx [2013-12-16] CHR HKLM-x32\...\Chrome\Extension: [cojnmaaohncijldefpkpkkakjonfmgeb] - C:\Program Files (x86)\avira\Chrome\avira-1.5.14.crx [2013-12-11] ==================== Services (Whitelisted) ================= R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [811088 2014-05-15] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-05-15] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-05-15] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1039952 2014-05-15] (Avira Operations GmbH & Co. KG) S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [402192 2013-12-20] (BlueStack Systems, Inc.) R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [385808 2013-12-20] (BlueStack Systems, Inc.) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-07-17] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation) R2 PowerBiosServer; C:\Program Files (x86)\Hotkey\PowerBiosServer.exe [46080 2012-11-05] () R2 Seagate Dashboard Services; C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.DASWindowsService.exe [16000 2014-04-30] (Seagate Technology LLC) R2 Seagate MobileBackup Service; C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\MobileService.exe [157264 2014-04-30] (Seagate Technology LLC) R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27792 2012-09-10] (VIA Technologies, Inc.) R2 WDFME; C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe [1060352 2010-10-05] () S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation) R2 WDSC; C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSC.exe [485376 2010-10-05] () S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-05-15] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [130584 2014-05-15] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-12-18] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [84720 2013-12-18] (Avira Operations GmbH & Co. KG) S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider) R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [114448 2013-12-20] (BlueStack Systems) R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation) R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1337216 2012-10-01] (Motorola Solutions, Inc.) S3 DCamUSBET; C:\Windows\system32\DRIVERS\etDevice64.sys [187776 2008-03-01] (eMPIA Technology, Inc.) S3 FiltUSBET; C:\Windows\system32\DRIVERS\etFilter64.sys [259968 2007-09-13] (eMPIA Technology Inc.) S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation) S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation) S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation) R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-11] (Microsoft Corporation) S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation) R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation) S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation) R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [3344352 2013-07-08] (Intel Corporation) S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924504 2014-02-22] (Microsoft Corporation) R3 S6000KNT; C:\Windows\System32\Drivers\S6000KNT.sys [3555456 2012-07-12] (Windows (R) Win 7 DDK provider) S3 ScanUSBET; C:\Windows\system32\DRIVERS\etScan64.sys [9216 2007-09-07] (eMPIA Technology, Inc.) S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-10-26] (Microsoft Corporation) S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [26424 2012-11-30] (Synaptics Incorporated) R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [31032 2012-11-30] (Synaptics Incorporated) S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-11-30] (Microsoft Corporation) S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation) R0 Wof; C:\Windows\System32\Drivers\Wof.sys [157016 2014-03-13] (Microsoft Corporation) U0 SR; U2 srservice; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-02 08:48 - 2014-06-02 08:48 - 00033266 _____ () C:\Users\Frank\Downloads\FRST.txt 2014-06-02 08:48 - 2014-06-02 08:48 - 00000000 ____D () C:\FRST 2014-06-02 08:47 - 2014-06-02 08:47 - 02067456 _____ (Farbar) C:\Users\Frank\Downloads\FRST64.exe 2014-06-01 14:22 - 2014-06-01 14:22 - 00002741 _____ () C:\Users\Public\Desktop\Seagate Dashboard 2.0.lnk 2014-06-01 14:12 - 2014-06-01 14:25 - 00002238 _____ () C:\Users\Frank\Desktop\Server2014.lnk 2014-06-01 14:07 - 2014-06-01 14:07 - 00000566 _____ () C:\WINDOWS\PFRO.log 2014-06-01 11:44 - 2014-06-01 14:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bluetooth Devices 2014-06-01 11:36 - 2014-06-01 11:42 - 00005207 _____ () C:\WINDOWS\setupact.log 2014-06-01 11:36 - 2014-06-01 11:36 - 00000000 _____ () C:\WINDOWS\setuperr.log 2014-05-29 19:32 - 2014-06-02 06:57 - 00202267 _____ () C:\WINDOWS\WindowsUpdate.log 2014-05-29 19:21 - 2014-05-29 19:21 - 00002772 _____ () C:\WINDOWS\System32\Tasks\CCleanerSkipUAC 2014-05-29 19:21 - 2014-05-29 19:21 - 00000841 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-05-29 19:21 - 2014-05-29 19:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2014-05-29 19:21 - 2014-05-29 19:21 - 00000000 ____D () C:\Program Files\CCleaner 2014-05-28 07:02 - 2014-05-28 07:03 - 00000000 ____D () C:\Users\Frank\AppData\Local\Deployment 2014-05-21 06:26 - 2014-05-21 06:26 - 00000691 _____ () C:\Users\Frank\Downloads\vcard-Alexander-Rieg2.vcf 2014-05-14 06:13 - 2014-03-24 04:30 - 00257880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys 2014-05-14 06:12 - 2014-03-24 04:30 - 00123224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys 2014-05-14 06:12 - 2014-03-24 04:27 - 00035856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys 2014-05-14 06:11 - 2014-03-27 11:12 - 21225584 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2014-05-14 06:11 - 2014-03-27 09:48 - 18679728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2014-05-14 06:06 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2014-05-14 06:06 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2014-05-14 06:06 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2014-05-14 06:06 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll 2014-05-14 06:06 - 2014-04-11 12:03 - 00555736 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll 2014-05-14 06:06 - 2014-04-11 12:03 - 00054776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2014-05-14 06:06 - 2014-04-11 10:25 - 00419928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll 2014-05-14 06:06 - 2014-04-11 08:04 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll 2014-05-14 06:06 - 2014-04-11 07:53 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSReset.exe 2014-05-14 06:06 - 2014-04-11 07:22 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll 2014-05-14 06:06 - 2014-04-11 05:54 - 00201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll 2014-05-14 06:06 - 2014-04-11 05:36 - 11792384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2014-05-14 06:06 - 2014-04-11 05:24 - 13288960 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2014-05-14 06:06 - 2014-04-11 05:06 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe 2014-05-14 06:06 - 2014-04-11 05:05 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2014-05-14 06:06 - 2014-04-11 05:05 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll 2014-05-14 06:06 - 2014-04-11 05:02 - 00249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2014-05-14 06:06 - 2014-04-11 05:02 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe 2014-05-14 06:06 - 2014-04-11 05:01 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll 2014-05-14 06:06 - 2014-04-11 05:00 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll 2014-05-14 06:06 - 2014-04-11 04:59 - 00666624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll 2014-05-14 06:06 - 2014-04-11 04:57 - 00190976 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll 2014-05-14 06:06 - 2014-04-11 04:56 - 00381440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll 2014-05-14 06:06 - 2014-04-11 04:55 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll 2014-05-14 06:06 - 2014-04-11 04:53 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 2014-05-14 06:06 - 2014-04-11 04:52 - 03464192 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2014-05-14 06:06 - 2014-04-11 04:46 - 01705472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll 2014-05-14 06:06 - 2014-04-11 04:36 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll 2014-05-14 06:06 - 2014-04-11 04:34 - 00754688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll 2014-05-14 06:06 - 2014-04-11 04:29 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll 2014-05-14 06:06 - 2014-04-11 04:25 - 00921088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll 2014-05-14 05:48 - 2014-03-13 09:42 - 00308224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wusa.exe 2014-05-14 05:48 - 2014-03-13 08:51 - 00305152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wusa.exe 2014-05-14 05:22 - 2014-04-09 00:46 - 00086688 _____ (Microsoft Corporation) C:\WINDOWS\system32\mrt_map.dll 2014-05-14 05:22 - 2014-04-09 00:46 - 00028320 _____ (Microsoft Corporation) C:\WINDOWS\system32\mrt100.dll 2014-05-14 05:22 - 2014-04-08 20:54 - 00080032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mrt_map.dll 2014-05-14 05:22 - 2014-04-08 20:54 - 00026784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mrt100.dll 2014-05-11 13:52 - 2014-05-11 13:52 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf 2014-05-05 08:30 - 2014-05-05 08:30 - 00000000 __SHD () C:\Users\Frank\AppData\Local\EmieUserList 2014-05-05 08:30 - 2014-05-05 08:30 - 00000000 __SHD () C:\Users\Frank\AppData\Local\EmieSiteList 2014-05-05 08:25 - 2014-05-05 08:25 - 00000000 ____D () C:\wander2014 2014-05-03 05:34 - 2014-05-03 05:34 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb 2014-05-03 05:34 - 2014-05-03 05:34 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb ==================== One Month Modified Files and Folders ======= 2014-06-02 08:48 - 2014-06-02 08:48 - 00033266 _____ () C:\Users\Frank\Downloads\FRST.txt 2014-06-02 08:48 - 2014-06-02 08:48 - 00000000 ____D () C:\FRST 2014-06-02 08:48 - 2013-11-30 21:31 - 00000000 ____D () C:\Users\Frank\AppData\Local\Temp 2014-06-02 08:47 - 2014-06-02 08:47 - 02067456 _____ (Farbar) C:\Users\Frank\Downloads\FRST64.exe 2014-06-02 08:47 - 2013-11-14 08:17 - 00001138 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-12812500-3875771965-374869435-1001UA.job 2014-06-02 08:13 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru 2014-06-02 07:55 - 2013-11-18 12:24 - 00001126 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2014-06-02 07:12 - 2013-11-19 20:07 - 00000946 _____ () C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-12812500-3875771965-374869435-1001UA.job 2014-06-02 07:04 - 2013-11-14 00:06 - 00003594 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-12812500-3875771965-374869435-1001 2014-06-02 06:57 - 2014-05-29 19:32 - 00202267 _____ () C:\WINDOWS\WindowsUpdate.log 2014-06-02 06:32 - 2013-11-30 22:30 - 00003930 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{2841A1D3-8229-4440-86A2-403F02A60133} 2014-06-02 06:30 - 2013-11-18 17:01 - 00000000 ___RD () C:\Users\Frank\Google Drive 2014-06-02 06:29 - 2013-11-18 17:16 - 00000000 __RDO () C:\Users\Frank\SkyDrive 2014-06-02 06:29 - 2013-11-18 12:24 - 00001122 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2014-06-01 19:12 - 2013-11-19 20:07 - 00000924 _____ () C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-12812500-3875771965-374869435-1001Core.job 2014-06-01 14:35 - 2013-11-14 23:33 - 00000000 ____D () C:\Users\Frank\AppData\Local\CrashDumps 2014-06-01 14:25 - 2014-06-01 14:12 - 00002238 _____ () C:\Users\Frank\Desktop\Server2014.lnk 2014-06-01 14:25 - 2014-03-13 14:40 - 00003504 _____ () C:\WINDOWS\System32\Tasks\Seagate_Install_Launch 2014-06-01 14:25 - 2014-03-13 14:40 - 00003492 _____ () C:\WINDOWS\System32\Tasks\Frank DBAgent 2 0 2014-06-01 14:22 - 2014-06-01 14:22 - 00002741 _____ () C:\Users\Public\Desktop\Seagate Dashboard 2.0.lnk 2014-06-01 14:22 - 2014-03-13 14:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Seagate Dashboard 2.0 2014-06-01 14:08 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-06-01 14:07 - 2014-06-01 14:07 - 00000566 _____ () C:\WINDOWS\PFRO.log 2014-06-01 14:07 - 2013-08-22 15:25 - 00786432 ___SH () C:\WINDOWS\system32\config\BBI 2014-06-01 14:03 - 2014-06-01 11:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bluetooth Devices 2014-06-01 11:42 - 2014-06-01 11:36 - 00005207 _____ () C:\WINDOWS\setupact.log 2014-06-01 11:36 - 2014-06-01 11:36 - 00000000 _____ () C:\WINDOWS\setuperr.log 2014-05-31 20:47 - 2013-11-14 08:17 - 00001086 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-12812500-3875771965-374869435-1001Core.job 2014-05-31 12:06 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness 2014-05-29 19:23 - 2013-11-30 21:23 - 00000000 ___DC () C:\WINDOWS\Panther 2014-05-29 19:23 - 2013-11-28 20:31 - 00000000 ____D () C:\Users\Frank\AppData\Roaming\FileZilla 2014-05-29 19:21 - 2014-05-29 19:21 - 00002772 _____ () C:\WINDOWS\System32\Tasks\CCleanerSkipUAC 2014-05-29 19:21 - 2014-05-29 19:21 - 00000841 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-05-29 19:21 - 2014-05-29 19:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2014-05-29 19:21 - 2014-05-29 19:21 - 00000000 ____D () C:\Program Files\CCleaner 2014-05-28 07:03 - 2014-05-28 07:02 - 00000000 ____D () C:\Users\Frank\AppData\Local\Deployment 2014-05-27 19:10 - 2013-11-30 21:31 - 00000000 ____D () C:\Users\Frank 2014-05-27 18:05 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM 2014-05-27 16:18 - 2013-11-18 12:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-05-27 16:18 - 2013-11-14 08:18 - 00000000 ____D () C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Music Manager 2014-05-27 16:03 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\registration 2014-05-27 14:36 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\NDF 2014-05-27 11:42 - 2013-11-19 10:23 - 00000000 ____D () C:\Users\Frank\AppData\Local\Windows Live 2014-05-21 06:26 - 2014-05-21 06:26 - 00000691 _____ () C:\Users\Frank\Downloads\vcard-Alexander-Rieg2.vcf 2014-05-20 11:11 - 2013-11-13 23:58 - 00000000 ____D () C:\Users\Frank\AppData\Local\Packages 2014-05-18 06:31 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\rescache 2014-05-17 19:44 - 2013-02-19 04:22 - 00002457 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2014-05-17 19:41 - 2013-11-19 17:02 - 00000000 ___RD () C:\Users\Frank\Podcasts 2014-05-17 19:41 - 2013-11-13 23:58 - 00000000 ___RD () C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-05-17 19:41 - 2013-11-13 23:58 - 00000000 ___RD () C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-05-17 19:36 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ToastData 2014-05-17 19:36 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2014-05-17 19:36 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2014-05-17 19:36 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\WinStore 2014-05-17 19:36 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\SecureBootUpdates 2014-05-17 19:36 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Windows Defender 2014-05-17 19:36 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender 2014-05-15 13:39 - 2014-02-12 10:46 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys 2014-05-15 13:39 - 2014-02-12 10:46 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys 2014-05-14 09:02 - 2012-07-26 09:59 - 00000000 ____D () C:\WINDOWS\CbsTemp 2014-05-14 08:59 - 2013-11-15 09:39 - 00000000 ____D () C:\WINDOWS\system32\MRT 2014-05-14 08:55 - 2013-11-15 09:38 - 93223848 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2014-05-11 13:52 - 2014-05-11 13:52 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf 2014-05-07 20:42 - 2013-11-14 08:17 - 00004084 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-12812500-3875771965-374869435-1001UA 2014-05-07 20:42 - 2013-11-14 08:17 - 00003704 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-12812500-3875771965-374869435-1001Core 2014-05-07 19:50 - 2013-11-18 12:24 - 00004098 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2014-05-07 19:50 - 2013-11-18 12:24 - 00003862 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2014-05-06 06:40 - 2014-05-14 06:06 - 23544320 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2014-05-06 05:25 - 2014-05-14 06:06 - 17382912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2014-05-06 05:00 - 2014-05-14 06:06 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2014-05-06 04:10 - 2014-05-14 06:06 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll 2014-05-05 08:30 - 2014-05-05 08:30 - 00000000 __SHD () C:\Users\Frank\AppData\Local\EmieUserList 2014-05-05 08:30 - 2014-05-05 08:30 - 00000000 __SHD () C:\Users\Frank\AppData\Local\EmieSiteList 2014-05-05 08:25 - 2014-05-05 08:25 - 00000000 ____D () C:\wander2014 2014-05-05 02:51 - 2013-11-18 17:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive 2014-05-04 17:55 - 2013-09-30 06:14 - 01804156 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2014-05-04 17:55 - 2013-09-30 05:56 - 00775588 _____ () C:\WINDOWS\system32\perfh007.dat 2014-05-04 17:55 - 2013-09-30 05:56 - 00163774 _____ () C:\WINDOWS\system32\perfc007.dat 2014-05-03 20:44 - 2013-11-14 00:16 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-05-03 05:34 - 2014-05-03 05:34 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb 2014-05-03 05:34 - 2014-05-03 05:34 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb Some content of TEMP: ==================== C:\Users\Frank\AppData\Local\Temp\avgnt.exe C:\Users\Frank\AppData\Local\Temp\setup.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-06-02 07:57 ==================== End Of Log ============================ --- --- --- |
02.06.2014, 07:56 | #4 |
| Windows 8 Fehler in REGSVR32 .dll FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-06-2014 01 Ran by Frank (administrator) on FRANK-PC on 02-06-2014 08:48:28 Running from C:\Users\Frank\Downloads Platform: Windows 8.1 (Update 1) (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials ==================== Processes (Whitelisted) ================= (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (B.H.A Corporation) C:\Windows\SysWOW64\bgsvcgen.exe (Apple Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe () C:\Program Files (x86)\Hotkey\PowerBiosServer.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe (WDC) C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe () C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe () C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSC.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler64.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.DASWindowsService.exe (Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\MobileService.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Microsoft Corporation) C:\Program Files\Zune\ZuneLauncher.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Google Inc.) C:\Users\Frank\AppData\Local\Programs\Google\MusicManager\MusicManager.exe (Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Enter Srl) C:\Program Files (x86)\Iperius Backup\Iperius.exe (Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe (Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Google Inc.) C:\Users\Frank\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe () C:\Program Files (x86)\Hotkey\Hotkey.exe (Western Digital Technologies, Inc.) C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (STRATO) C:\Program Files (x86)\STRATO AG\STRATO HiDrive\STRATO HiDrive.exe () C:\Program Files (x86)\Avanquest\Print Artist Platinum\ReminderApp.exe (Alcor) C:\Windows\WebCam\S6000\S6000Mnt.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe (BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-Agent.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe (Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DeviceAgent.exe (Microsoft Corporation) C:\Windows\System32\WWAHost.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbwe\livecomm.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [BTMTrayAgent] => C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll [11582848 2012-09-30] (Motorola Solutions, Inc.) HKLM\...\Run: [Zune Launcher] => C:\Program Files\Zune\ZuneLauncher.exe [163552 2011-08-05] (Microsoft Corporation) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3008824 2012-11-30] (Synaptics Incorporated) HKLM\...\Run: [etMonitor] => C:\WINDOWS\etMon.exe [88576 2007-04-04] (EMPIA Technology Corporation) HKLM-x32\...\Run: [S6000Mnt] => C:\WINDOWS\SysWOW64\Rundll32.exe S6000Rmv.dll,WinMainRmv /StartStillMnt HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5263504 2012-09-13] (VIA) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [PrintArtist] => C:\Program Files (x86)\Avanquest\Print Artist Platinum\ReminderApp.exe [144664 2009-10-22] () HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [1743648 2013-06-13] (Wondershare) HKLM-x32\...\Run: [BrowserPlugInHelper] => C:\Program Files (x86)\Wondershare\Video Converter Ultimate\BrowserPlugInHelper.exe [1962896 2013-12-09] () HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [807696 2013-12-20] (BlueStack Systems, Inc.) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-05-15] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [DBAgent] => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe [1519176 2014-04-30] (Seagate Technology LLC) Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer: [NoFolderOptions] 0 HKLM\...\Policies\Explorer: [NoViewOnDrive] 0 HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKLM\...\Policies\Explorer: [DisableLocalMachineRun] 0 HKLM\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0 HKLM\...\Policies\Explorer: [DisableCurrentUserRun] 0 HKLM\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0 HKLM\...\Policies\Explorer: [NoViewContextMenu] 0 HKLM\...\Policies\Explorer: [NoShellSearchButton] 0 HKLM\...\Policies\Explorer: [NoFind] 0 HKLM\...\Policies\Explorer: [NoFile] 0 HKLM\...\Policies\Explorer: [HideClock] 0 HKLM\...\Policies\Explorer: [NoTrayContextMenu] 0 HKLM\...\Policies\Explorer: [NoTrayItemsDisplay] 0 HKLM\...\Policies\Explorer: [NoSetFolders] 0 HKLM\...\Policies\Explorer: [NoDevMgrUpdate] 0 HKLM\...\Policies\Explorer: [NoSetTaskbar] 0 HKLM\...\Policies\Explorer: [NoDeletePrinter] 0 HKLM\...\Policies\Explorer: [NoDFSTab] 0 HKLM\...\Policies\Explorer: [NoChangeStartMenu] 0 HKLM\...\Policies\Explorer: [NoLogoff] 0 HKLM\...\Policies\Explorer: [NoWindowsUpdate] 0 HKLM\...\Policies\Explorer: [NoEncryptOnMove] 0 HKLM\...\Policies\Explorer: [NoRunasInstallPrompt] 0 HKLM\...\Policies\Explorer: [NoResolveSearch] 0 HKLM\...\Policies\Explorer: [NoSaveSettings] 0 HKLM\...\Policies\Explorer: [NoHardwareTab] 0 HKLM\...\Policies\Explorer: [NoStartMenuSubFolders] 0 HKLM\...\Policies\Explorer: [NoDesktop] 0 HKU\.DEFAULT\...\Policies\system: [DisableCMD] 0 HKU\.DEFAULT\...\Policies\system: [NoDispAppearancePage] 0 HKU\.DEFAULT\...\Policies\system: [NoDispBackgroundPage] 0 HKU\.DEFAULT\...\Policies\system: [NoDispSettingsPage] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoFolderOptions] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoViewOnDrive] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoControlPanel] 0 HKU\.DEFAULT\...\Policies\Explorer: [DisableLocalMachineRun] 0 HKU\.DEFAULT\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0 HKU\.DEFAULT\...\Policies\Explorer: [DisableCurrentUserRun] 0 HKU\.DEFAULT\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoViewContextMenu] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoShellSearchButton] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoFind] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoFile] 0 HKU\.DEFAULT\...\Policies\Explorer: [HideClock] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoTrayContextMenu] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoTrayItemsDisplay] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoSetFolders] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoDevMgrUpdate] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoSetTaskbar] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoDeletePrinter] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoDFSTab] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoChangeStartMenu] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoLogoff] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoWindowsUpdate] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoEncryptOnMove] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoRunasInstallPrompt] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoResolveSearch] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoSaveSettings] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoHardwareTab] 0 HKU\.DEFAULT\...\Policies\Explorer: [NoStartMenuSubFolders] 0 HKU\S-1-5-19\...\Policies\system: [DisableCMD] 0 HKU\S-1-5-19\...\Policies\system: [NoDispAppearancePage] 0 HKU\S-1-5-19\...\Policies\system: [NoDispBackgroundPage] 0 HKU\S-1-5-19\...\Policies\system: [NoDispSettingsPage] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoFolderOptions] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoViewOnDrive] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-19\...\Policies\Explorer: [DisableLocalMachineRun] 0 HKU\S-1-5-19\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0 HKU\S-1-5-19\...\Policies\Explorer: [DisableCurrentUserRun] 0 HKU\S-1-5-19\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoViewContextMenu] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoShellSearchButton] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoFind] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoFile] 0 HKU\S-1-5-19\...\Policies\Explorer: [HideClock] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoTrayContextMenu] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoTrayItemsDisplay] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoSetFolders] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoDevMgrUpdate] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoSetTaskbar] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoDeletePrinter] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoDFSTab] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoChangeStartMenu] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoLogoff] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoWindowsUpdate] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoEncryptOnMove] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoRunasInstallPrompt] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoResolveSearch] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoSaveSettings] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoHardwareTab] 0 HKU\S-1-5-19\...\Policies\Explorer: [NoStartMenuSubFolders] 0 HKU\S-1-5-20\...\Policies\system: [DisableCMD] 0 HKU\S-1-5-20\...\Policies\system: [NoDispAppearancePage] 0 HKU\S-1-5-20\...\Policies\system: [NoDispBackgroundPage] 0 HKU\S-1-5-20\...\Policies\system: [NoDispSettingsPage] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoFolderOptions] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoViewOnDrive] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-20\...\Policies\Explorer: [DisableLocalMachineRun] 0 HKU\S-1-5-20\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0 HKU\S-1-5-20\...\Policies\Explorer: [DisableCurrentUserRun] 0 HKU\S-1-5-20\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoViewContextMenu] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoShellSearchButton] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoFind] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoFile] 0 HKU\S-1-5-20\...\Policies\Explorer: [HideClock] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoTrayContextMenu] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoTrayItemsDisplay] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoSetFolders] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoDevMgrUpdate] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoSetTaskbar] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoDeletePrinter] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoDFSTab] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoChangeStartMenu] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoLogoff] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoWindowsUpdate] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoEncryptOnMove] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoRunasInstallPrompt] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoResolveSearch] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoSaveSettings] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoHardwareTab] 0 HKU\S-1-5-20\...\Policies\Explorer: [NoStartMenuSubFolders] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Run: [Google Update] => C:\Users\Frank\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-11-14] (Google Inc.) HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Run: [MusicManager] => C:\Users\Frank\AppData\Local\Programs\Google\MusicManager\MusicManager.exe [7631872 2014-05-15] (Google Inc.) HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Run: [AmazonMP3DownloaderHelper] => C:\Users\Frank\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-22] () HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [22415552 2014-04-25] (Google) HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Run: [SkyDrive] => C:\Users\Frank\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [257224 2014-05-15] (Microsoft Corporation) HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Run: [Facebook Update] => C:\Users\Frank\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-11-19] (Facebook Inc.) HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Run: [Iperius Backup] => C:\Program Files (x86)\Iperius Backup\Iperius.exe [15267664 2013-12-04] (Enter Srl) HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Run: [Uploader] => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe [126056 2014-04-30] (Seagate Technology LLC) HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Run: [Google+ Auto Backup] => C:\Users\Frank\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe [3701064 2014-03-26] (Google Inc.) HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Run: [tpdbxm] => regsvr32.exe " HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\system: [DisableCMD] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\system: [NoDispAppearancePage] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\system: [NoDispBackgroundPage] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\system: [NoDispSettingsPage] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoFolderOptions] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoViewOnDrive] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [DisableLocalMachineRun] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [DisableCurrentUserRun] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoViewContextMenu] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoShellSearchButton] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoFind] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoFile] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [HideClock] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoTrayContextMenu] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoTrayItemsDisplay] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoSetFolders] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoDevMgrUpdate] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoSetTaskbar] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoDeletePrinter] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoDFSTab] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoChangeStartMenu] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoLogoff] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoWindowsUpdate] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoEncryptOnMove] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoRunasInstallPrompt] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoResolveSearch] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoSaveSettings] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoHardwareTab] 0 HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Policies\Explorer: [NoStartMenuSubFolders] 0 Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Hotkey.lnk ShortcutTarget: Hotkey.lnk -> C:\Program Files (x86)\Hotkey\Hotkey.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\PHOTOfunSTUDIO 5.0 HD Edition.lnk ShortcutTarget: PHOTOfunSTUDIO 5.0 HD Edition.lnk -> C:\Program Files (x86)\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe (Panasonic Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WDDMStatus.lnk ShortcutTarget: WDDMStatus.lnk -> C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe (Western Digital Technologies, Inc.) Startup: C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Amazon Cloud Drive.lnk ShortcutTarget: Amazon Cloud Drive.lnk -> C:\Users\Frank\AppData\Local\Apps\2.0\APCJ5E1P.MQK\Y50GAJHD.KY9\amaz..tion_f2fa081ea2183235_0002.0001_cb34a912a946f839\AmazonCloudDrive.exe (Amazon Digital Services, LLC.) Startup: C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\STRATO HiDrive.lnk ShortcutTarget: STRATO HiDrive.lnk -> C:\Program Files (x86)\STRATO AG\STRATO HiDrive\STRATO HiDrive.exe (STRATO) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login. HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN Deutschland: Aktuelle Nachrichten, Outlook.com Email und Skype Login. HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Upgrade to Google Chrome HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Upgrade to Google Chrome SearchScopes: HKLM - DefaultScope {B904397E-4149-42A6-A059-5282FFB3919B} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASBJS SearchScopes: HKLM - {B904397E-4149-42A6-A059-5282FFB3919B} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASBJS SearchScopes: HKLM-x32 - DefaultScope {B904397E-4149-42A6-A059-5282FFB3919B} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASBJS SearchScopes: HKLM-x32 - {B904397E-4149-42A6-A059-5282FFB3919B} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASBJS SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear BHO: No Name - {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} - No File BHO-x32: Wondershare Video Converter Ultimate - {65DEE40A-3E93-4cae-9F98-B8E06DCEE2BF} - C:\Program Files (x86)\Wondershare\Video Converter Ultimate\SVRIEPlugin.dll (Wondershare Software Co., Ltd.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Avira Savings Advisor BHO - {A18A516C-AA41-46A9-92DB-60208917E442} - C:\Program Files (x86)\avira\Internet Explorer\avira32.dll () BHO-x32: No Name - {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} - No File BHO-x32: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask.com) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - No Name - {97ab88ef-346b-4179-a0b1-7445896547a5} - No File Toolbar: HKLM-x32 - Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask.com) Toolbar: HKLM-x32 - No Name - {97ab88ef-346b-4179-a0b1-7445896547a5} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Frank\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Frank\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Frank\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Users\Frank\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.) FF HKLM-x32\...\Firefox\Extensions: [{8D150B8F-EFE8-45a3-A4A3-053020F48FAC}] - C:\Program Files (x86)\Wondershare\Video Converter Ultimate\SVRFirefoxExt\ FF Extension: Wondershare Video Converter Ultimate - C:\Program Files (x86)\Wondershare\Video Converter Ultimate\SVRFirefoxExt\ [] FF HKCU\...\Firefox\Extensions: [{8D150B8F-EFE8-45a3-A4A3-053020F48FAC}] - C:\Program Files (x86)\Wondershare\Video Converter Ultimate\SVRFirefoxExt\ FF Extension: Wondershare Video Converter Ultimate - C:\Program Files (x86)\Wondershare\Video Converter Ultimate\SVRFirefoxExt\ [] Chrome: ======= CHR Extension: (Google Docs) - C:\Users\Frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-18] CHR Extension: (Google Drive) - C:\Users\Frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-18] CHR Extension: (YouTube) - C:\Users\Frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-18] CHR Extension: (Wondershare Video Converter Ultimate) - C:\Users\Frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\chgdeabpmphfhkoemjjglmilajldekbp [2013-12-17] CHR Extension: (Avira Sparberater) - C:\Users\Frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\cojnmaaohncijldefpkpkkakjonfmgeb [2014-02-12] CHR Extension: (Google-Suche) - C:\Users\Frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-18] CHR Extension: (Easy Video Downloader Express) - C:\Users\Frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbcpmdpjjlhppmhfkcgbeanaanipdjbk [2014-01-22] CHR Extension: (Google Wallet) - C:\Users\Frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-18] CHR Extension: (Personal Blocklist (by Google)) - C:\Users\Frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\nolijncfnkgaikbjbdaogikpmpbdcdef [2014-01-22] CHR Extension: (Google Mail) - C:\Users\Frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-18] CHR HKLM-x32\...\Chrome\Extension: [chgdeabpmphfhkoemjjglmilajldekbp] - C:\Program Files (x86)\Wondershare\Video Converter Ultimate\SVRChromePlugin.crx [2013-12-16] CHR HKLM-x32\...\Chrome\Extension: [cojnmaaohncijldefpkpkkakjonfmgeb] - C:\Program Files (x86)\avira\Chrome\avira-1.5.14.crx [2013-12-11] ==================== Services (Whitelisted) ================= R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [811088 2014-05-15] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-05-15] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-05-15] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1039952 2014-05-15] (Avira Operations GmbH & Co. KG) S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [402192 2013-12-20] (BlueStack Systems, Inc.) R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [385808 2013-12-20] (BlueStack Systems, Inc.) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-07-17] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation) R2 PowerBiosServer; C:\Program Files (x86)\Hotkey\PowerBiosServer.exe [46080 2012-11-05] () R2 Seagate Dashboard Services; C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.DASWindowsService.exe [16000 2014-04-30] (Seagate Technology LLC) R2 Seagate MobileBackup Service; C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\MobileService.exe [157264 2014-04-30] (Seagate Technology LLC) R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27792 2012-09-10] (VIA Technologies, Inc.) R2 WDFME; C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe [1060352 2010-10-05] () S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation) R2 WDSC; C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSC.exe [485376 2010-10-05] () S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-05-15] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [130584 2014-05-15] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-12-18] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [84720 2013-12-18] (Avira Operations GmbH & Co. KG) S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider) R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [114448 2013-12-20] (BlueStack Systems) R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation) R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1337216 2012-10-01] (Motorola Solutions, Inc.) S3 DCamUSBET; C:\Windows\system32\DRIVERS\etDevice64.sys [187776 2008-03-01] (eMPIA Technology, Inc.) S3 FiltUSBET; C:\Windows\system32\DRIVERS\etFilter64.sys [259968 2007-09-13] (eMPIA Technology Inc.) S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation) S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation) S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation) R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-11] (Microsoft Corporation) S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation) R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation) S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation) R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [3344352 2013-07-08] (Intel Corporation) S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924504 2014-02-22] (Microsoft Corporation) R3 S6000KNT; C:\Windows\System32\Drivers\S6000KNT.sys [3555456 2012-07-12] (Windows (R) Win 7 DDK provider) S3 ScanUSBET; C:\Windows\system32\DRIVERS\etScan64.sys [9216 2007-09-07] (eMPIA Technology, Inc.) S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-10-26] (Microsoft Corporation) S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [26424 2012-11-30] (Synaptics Incorporated) R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [31032 2012-11-30] (Synaptics Incorporated) S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-11-30] (Microsoft Corporation) S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation) R0 Wof; C:\Windows\System32\Drivers\Wof.sys [157016 2014-03-13] (Microsoft Corporation) U0 SR; U2 srservice; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-02 08:48 - 2014-06-02 08:48 - 00033266 _____ () C:\Users\Frank\Downloads\FRST.txt 2014-06-02 08:48 - 2014-06-02 08:48 - 00000000 ____D () C:\FRST 2014-06-02 08:47 - 2014-06-02 08:47 - 02067456 _____ (Farbar) C:\Users\Frank\Downloads\FRST64.exe 2014-06-01 14:22 - 2014-06-01 14:22 - 00002741 _____ () C:\Users\Public\Desktop\Seagate Dashboard 2.0.lnk 2014-06-01 14:12 - 2014-06-01 14:25 - 00002238 _____ () C:\Users\Frank\Desktop\Server2014.lnk 2014-06-01 14:07 - 2014-06-01 14:07 - 00000566 _____ () C:\WINDOWS\PFRO.log 2014-06-01 11:44 - 2014-06-01 14:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bluetooth Devices 2014-06-01 11:36 - 2014-06-01 11:42 - 00005207 _____ () C:\WINDOWS\setupact.log 2014-06-01 11:36 - 2014-06-01 11:36 - 00000000 _____ () C:\WINDOWS\setuperr.log 2014-05-29 19:32 - 2014-06-02 06:57 - 00202267 _____ () C:\WINDOWS\WindowsUpdate.log 2014-05-29 19:21 - 2014-05-29 19:21 - 00002772 _____ () C:\WINDOWS\System32\Tasks\CCleanerSkipUAC 2014-05-29 19:21 - 2014-05-29 19:21 - 00000841 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-05-29 19:21 - 2014-05-29 19:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2014-05-29 19:21 - 2014-05-29 19:21 - 00000000 ____D () C:\Program Files\CCleaner 2014-05-28 07:02 - 2014-05-28 07:03 - 00000000 ____D () C:\Users\Frank\AppData\Local\Deployment 2014-05-21 06:26 - 2014-05-21 06:26 - 00000691 _____ () C:\Users\Frank\Downloads\vcard-Alexander-Rieg2.vcf 2014-05-14 06:13 - 2014-03-24 04:30 - 00257880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys 2014-05-14 06:12 - 2014-03-24 04:30 - 00123224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys 2014-05-14 06:12 - 2014-03-24 04:27 - 00035856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys 2014-05-14 06:11 - 2014-03-27 11:12 - 21225584 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2014-05-14 06:11 - 2014-03-27 09:48 - 18679728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2014-05-14 06:06 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2014-05-14 06:06 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2014-05-14 06:06 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2014-05-14 06:06 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll 2014-05-14 06:06 - 2014-04-11 12:03 - 00555736 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll 2014-05-14 06:06 - 2014-04-11 12:03 - 00054776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2014-05-14 06:06 - 2014-04-11 10:25 - 00419928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll 2014-05-14 06:06 - 2014-04-11 08:04 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll 2014-05-14 06:06 - 2014-04-11 07:53 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSReset.exe 2014-05-14 06:06 - 2014-04-11 07:22 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll 2014-05-14 06:06 - 2014-04-11 05:54 - 00201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll 2014-05-14 06:06 - 2014-04-11 05:36 - 11792384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2014-05-14 06:06 - 2014-04-11 05:24 - 13288960 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2014-05-14 06:06 - 2014-04-11 05:06 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe 2014-05-14 06:06 - 2014-04-11 05:05 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2014-05-14 06:06 - 2014-04-11 05:05 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll 2014-05-14 06:06 - 2014-04-11 05:02 - 00249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2014-05-14 06:06 - 2014-04-11 05:02 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe 2014-05-14 06:06 - 2014-04-11 05:01 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll 2014-05-14 06:06 - 2014-04-11 05:00 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll 2014-05-14 06:06 - 2014-04-11 04:59 - 00666624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll 2014-05-14 06:06 - 2014-04-11 04:57 - 00190976 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll 2014-05-14 06:06 - 2014-04-11 04:56 - 00381440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll 2014-05-14 06:06 - 2014-04-11 04:55 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll 2014-05-14 06:06 - 2014-04-11 04:53 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 2014-05-14 06:06 - 2014-04-11 04:52 - 03464192 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2014-05-14 06:06 - 2014-04-11 04:46 - 01705472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll 2014-05-14 06:06 - 2014-04-11 04:36 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll 2014-05-14 06:06 - 2014-04-11 04:34 - 00754688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll 2014-05-14 06:06 - 2014-04-11 04:29 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll 2014-05-14 06:06 - 2014-04-11 04:25 - 00921088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll 2014-05-14 05:48 - 2014-03-13 09:42 - 00308224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wusa.exe 2014-05-14 05:48 - 2014-03-13 08:51 - 00305152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wusa.exe 2014-05-14 05:22 - 2014-04-09 00:46 - 00086688 _____ (Microsoft Corporation) C:\WINDOWS\system32\mrt_map.dll 2014-05-14 05:22 - 2014-04-09 00:46 - 00028320 _____ (Microsoft Corporation) C:\WINDOWS\system32\mrt100.dll 2014-05-14 05:22 - 2014-04-08 20:54 - 00080032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mrt_map.dll 2014-05-14 05:22 - 2014-04-08 20:54 - 00026784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mrt100.dll 2014-05-11 13:52 - 2014-05-11 13:52 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf 2014-05-05 08:30 - 2014-05-05 08:30 - 00000000 __SHD () C:\Users\Frank\AppData\Local\EmieUserList 2014-05-05 08:30 - 2014-05-05 08:30 - 00000000 __SHD () C:\Users\Frank\AppData\Local\EmieSiteList 2014-05-05 08:25 - 2014-05-05 08:25 - 00000000 ____D () C:\wander2014 2014-05-03 05:34 - 2014-05-03 05:34 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb 2014-05-03 05:34 - 2014-05-03 05:34 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb ==================== One Month Modified Files and Folders ======= 2014-06-02 08:48 - 2014-06-02 08:48 - 00033266 _____ () C:\Users\Frank\Downloads\FRST.txt 2014-06-02 08:48 - 2014-06-02 08:48 - 00000000 ____D () C:\FRST 2014-06-02 08:48 - 2013-11-30 21:31 - 00000000 ____D () C:\Users\Frank\AppData\Local\Temp 2014-06-02 08:47 - 2014-06-02 08:47 - 02067456 _____ (Farbar) C:\Users\Frank\Downloads\FRST64.exe 2014-06-02 08:47 - 2013-11-14 08:17 - 00001138 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-12812500-3875771965-374869435-1001UA.job 2014-06-02 08:13 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru 2014-06-02 07:55 - 2013-11-18 12:24 - 00001126 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2014-06-02 07:12 - 2013-11-19 20:07 - 00000946 _____ () C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-12812500-3875771965-374869435-1001UA.job 2014-06-02 07:04 - 2013-11-14 00:06 - 00003594 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-12812500-3875771965-374869435-1001 2014-06-02 06:57 - 2014-05-29 19:32 - 00202267 _____ () C:\WINDOWS\WindowsUpdate.log 2014-06-02 06:32 - 2013-11-30 22:30 - 00003930 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{2841A1D3-8229-4440-86A2-403F02A60133} 2014-06-02 06:30 - 2013-11-18 17:01 - 00000000 ___RD () C:\Users\Frank\Google Drive 2014-06-02 06:29 - 2013-11-18 17:16 - 00000000 __RDO () C:\Users\Frank\SkyDrive 2014-06-02 06:29 - 2013-11-18 12:24 - 00001122 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2014-06-01 19:12 - 2013-11-19 20:07 - 00000924 _____ () C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-12812500-3875771965-374869435-1001Core.job 2014-06-01 14:35 - 2013-11-14 23:33 - 00000000 ____D () C:\Users\Frank\AppData\Local\CrashDumps 2014-06-01 14:25 - 2014-06-01 14:12 - 00002238 _____ () C:\Users\Frank\Desktop\Server2014.lnk 2014-06-01 14:25 - 2014-03-13 14:40 - 00003504 _____ () C:\WINDOWS\System32\Tasks\Seagate_Install_Launch 2014-06-01 14:25 - 2014-03-13 14:40 - 00003492 _____ () C:\WINDOWS\System32\Tasks\Frank DBAgent 2 0 2014-06-01 14:22 - 2014-06-01 14:22 - 00002741 _____ () C:\Users\Public\Desktop\Seagate Dashboard 2.0.lnk 2014-06-01 14:22 - 2014-03-13 14:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Seagate Dashboard 2.0 2014-06-01 14:08 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-06-01 14:07 - 2014-06-01 14:07 - 00000566 _____ () C:\WINDOWS\PFRO.log 2014-06-01 14:07 - 2013-08-22 15:25 - 00786432 ___SH () C:\WINDOWS\system32\config\BBI 2014-06-01 14:03 - 2014-06-01 11:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bluetooth Devices 2014-06-01 11:42 - 2014-06-01 11:36 - 00005207 _____ () C:\WINDOWS\setupact.log 2014-06-01 11:36 - 2014-06-01 11:36 - 00000000 _____ () C:\WINDOWS\setuperr.log 2014-05-31 20:47 - 2013-11-14 08:17 - 00001086 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-12812500-3875771965-374869435-1001Core.job 2014-05-31 12:06 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness 2014-05-29 19:23 - 2013-11-30 21:23 - 00000000 ___DC () C:\WINDOWS\Panther 2014-05-29 19:23 - 2013-11-28 20:31 - 00000000 ____D () C:\Users\Frank\AppData\Roaming\FileZilla 2014-05-29 19:21 - 2014-05-29 19:21 - 00002772 _____ () C:\WINDOWS\System32\Tasks\CCleanerSkipUAC 2014-05-29 19:21 - 2014-05-29 19:21 - 00000841 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-05-29 19:21 - 2014-05-29 19:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2014-05-29 19:21 - 2014-05-29 19:21 - 00000000 ____D () C:\Program Files\CCleaner 2014-05-28 07:03 - 2014-05-28 07:02 - 00000000 ____D () C:\Users\Frank\AppData\Local\Deployment 2014-05-27 19:10 - 2013-11-30 21:31 - 00000000 ____D () C:\Users\Frank 2014-05-27 18:05 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM 2014-05-27 16:18 - 2013-11-18 12:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-05-27 16:18 - 2013-11-14 08:18 - 00000000 ____D () C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Music Manager 2014-05-27 16:03 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\registration 2014-05-27 14:36 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\NDF 2014-05-27 11:42 - 2013-11-19 10:23 - 00000000 ____D () C:\Users\Frank\AppData\Local\Windows Live 2014-05-21 06:26 - 2014-05-21 06:26 - 00000691 _____ () C:\Users\Frank\Downloads\vcard-Alexander-Rieg2.vcf 2014-05-20 11:11 - 2013-11-13 23:58 - 00000000 ____D () C:\Users\Frank\AppData\Local\Packages 2014-05-18 06:31 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\rescache 2014-05-17 19:44 - 2013-02-19 04:22 - 00002457 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2014-05-17 19:41 - 2013-11-19 17:02 - 00000000 ___RD () C:\Users\Frank\Podcasts 2014-05-17 19:41 - 2013-11-13 23:58 - 00000000 ___RD () C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-05-17 19:41 - 2013-11-13 23:58 - 00000000 ___RD () C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-05-17 19:36 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ToastData 2014-05-17 19:36 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2014-05-17 19:36 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2014-05-17 19:36 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\WinStore 2014-05-17 19:36 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\SecureBootUpdates 2014-05-17 19:36 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Windows Defender 2014-05-17 19:36 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender 2014-05-15 13:39 - 2014-02-12 10:46 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys 2014-05-15 13:39 - 2014-02-12 10:46 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys 2014-05-14 09:02 - 2012-07-26 09:59 - 00000000 ____D () C:\WINDOWS\CbsTemp 2014-05-14 08:59 - 2013-11-15 09:39 - 00000000 ____D () C:\WINDOWS\system32\MRT 2014-05-14 08:55 - 2013-11-15 09:38 - 93223848 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2014-05-11 13:52 - 2014-05-11 13:52 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf 2014-05-07 20:42 - 2013-11-14 08:17 - 00004084 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-12812500-3875771965-374869435-1001UA 2014-05-07 20:42 - 2013-11-14 08:17 - 00003704 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-12812500-3875771965-374869435-1001Core 2014-05-07 19:50 - 2013-11-18 12:24 - 00004098 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2014-05-07 19:50 - 2013-11-18 12:24 - 00003862 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2014-05-06 06:40 - 2014-05-14 06:06 - 23544320 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2014-05-06 05:25 - 2014-05-14 06:06 - 17382912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2014-05-06 05:00 - 2014-05-14 06:06 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2014-05-06 04:10 - 2014-05-14 06:06 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll 2014-05-05 08:30 - 2014-05-05 08:30 - 00000000 __SHD () C:\Users\Frank\AppData\Local\EmieUserList 2014-05-05 08:30 - 2014-05-05 08:30 - 00000000 __SHD () C:\Users\Frank\AppData\Local\EmieSiteList 2014-05-05 08:25 - 2014-05-05 08:25 - 00000000 ____D () C:\wander2014 2014-05-05 02:51 - 2013-11-18 17:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive 2014-05-04 17:55 - 2013-09-30 06:14 - 01804156 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2014-05-04 17:55 - 2013-09-30 05:56 - 00775588 _____ () C:\WINDOWS\system32\perfh007.dat 2014-05-04 17:55 - 2013-09-30 05:56 - 00163774 _____ () C:\WINDOWS\system32\perfc007.dat 2014-05-03 20:44 - 2013-11-14 00:16 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-05-03 05:34 - 2014-05-03 05:34 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb 2014-05-03 05:34 - 2014-05-03 05:34 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb Some content of TEMP: ==================== C:\Users\Frank\AppData\Local\Temp\avgnt.exe C:\Users\Frank\AppData\Local\Temp\setup.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-06-02 07:57 ==================== End Of Log ============================ --- --- --- Hoffe du hast jetzt alle infos die du brauchst um mir zu helfen. Danke schon mal im Voraus. Gruß Frank |
02.06.2014, 19:07 | #5 |
/// the machine /// TB-Ausbilder | Windows 8 Fehler in REGSVR32 .dll Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKU\S-1-5-21-12812500-3875771965-374869435-1001\...\Run: [tpdbxm] => regsvr32.exe " Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Adware & Co. deinstallieren
Solltest Du ein Programm nicht finden oder nicht deinstallieren können, mache bitte mit dem nächsten Schritt weiter: Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
02.06.2014, 21:13 | #6 |
| Windows 8 Fehler in REGSVR32 .dll ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 8.1 x64 Ran by Frank on 02.06.2014 at 21:18:52,84 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\browserpluginhelper ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\genericasktoolbar.dll Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{02DD8284-A49F-43E5-9D84-CF19DC9AD21D} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{1663C10B-0D55-438D-8496-19A3DBAEC0E4} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{27DE7D30-BCCD-44D1-ADCB-A74A4259EBEF} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{3A0EFC4E-F167-4D0E-9C24-FC5519237993} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{65DEE40A-3E93-4CAE-9F98-B8E06DCEE2BF} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{A43DE495-3D00-47D4-9D2C-303115707939} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{6C434537-053E-486D-B62A-160059D9D456} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\genericasktoolbar.toolbarwnd Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\genericasktoolbar.toolbarwnd.1 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\features\a28b4d68debaa244eb686953b7074fef Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\products\a28b4d68debaa244eb686953b7074fef Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\upgradecodes\f928123a039649549966d4c29d35b1c9 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{86d4b82a-abed-442a-be86-96357b70f4fe} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{65DEE40A-3E93-4CAE-9F98-B8E06DCEE2BF} ~~~ Files Successfully deleted: [File] "C:\WINDOWS\syswow64\wscm32.dll" Successfully deleted: [File] "C:\WINDOWS\syswow64\wscm64.dll" ~~~ Folders ~~~ Chrome Successfully deleted: [Folder] C:\Users\Frank\appdata\local\Google\Chrome\User Data\Default\Extensions\chgdeabpmphfhkoemjjglmilajldekbp Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\chgdeabpmphfhkoemjjglmilajldekbp ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 02.06.2014 at 21:23:56,54 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ also auch nach allen tests ist die meldung noch da |
03.06.2014, 19:23 | #7 |
/// the machine /// TB-Ausbilder | Windows 8 Fehler in REGSVR32 .dll irgendwie stand in meinen anweisungen mehr als nur Junkware Removal Tool.....
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
03.06.2014, 20:53 | #8 |
| Windows 8 Fehler in REGSVR32 .dll jo hab alle die du rein geschrieben hast durchlaufen lassen. leider hat es nix verändert die Meldung regsvr32 kommt bei jedem systemstart wieder das noch irgend ein Fehler sei es wird aber nicht genannt welcher. Hast du noch ne idee? |
04.06.2014, 18:38 | #9 |
/// the machine /// TB-Ausbilder | Windows 8 Fehler in REGSVR32 .dll wo sind die ganzen LOgs inklusive dem frischen FRST log??
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
05.06.2014, 05:18 | #10 |
| Windows 8 Fehler in REGSVR32 .dll von welchem Programm es waren so viele. aber ich hätte da einen Vorschlag ich mach von der meldung mal ein foto und bau das hier wenn es geht mit ein . vielleicht kannst du damit was anfangen . [IMG]C:\Users\Frank\Pictures\2014-06-05\P1140143.jpg[/IMG] |
05.06.2014, 05:23 | #11 |
| Windows 8 Fehler in REGSVR32 .dll also nix gegen dich aber was ist das für ein schrott hier . man versucht ne Grafik ein zu fügen und raus kommt nur die Text zeile. hast du ne Email ich schick dir das Bild. |
05.06.2014, 19:27 | #12 |
/// the machine /// TB-Ausbilder | Windows 8 Fehler in REGSVR32 .dll http://www.trojaner-board.de/154650-...ml#post1309990 hast Du alles aus diesem Post gemacht? Wenn ja warum postest du nur das Log vom JRT?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
05.06.2014, 19:28 | #13 |
| Windows 8 Fehler in REGSVR32 .dll hab ich was vergessen . ups sorry . was fehlt den noch |
06.06.2014, 18:35 | #14 |
/// the machine /// TB-Ausbilder | Windows 8 Fehler in REGSVR32 .dll WIllst du mich ärgern? Wieviele Schritte, wieviele Tools, wieviele Anweisungen habe ich gepostet? Wie viele Logfiles hast Du gepostet? Wir verschwenden hier deine Zeit. Du sollst mit REvo Adware deinstallieren MBAM laufen lassen => Logfile fehlt AdwCLeaner laufen lassen => Logfile fehlt Junkware laufen lassen Frisches FRST log posten => Logfile fehlt
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
06.06.2014, 19:15 | #15 |
| Windows 8 Fehler in REGSVR32 .dll Malwarebytes Anti-Malware Malwarebytes | Free Anti-Malware & Internet Security Software Scan Date: 06.06.2014 Scan Time: 19:53:08 Logfile: Administrator: Yes Version: 2.00.2.1012 Malware Database: v2014.06.06.06 Rootkit Database: v2014.06.02.01 License: Trial Malware Protection: Enabled Malicious Website Protection: Enabled Self-protection: Disabled OS: Windows 8.1 CPU: x64 File System: NTFS User: Frank Scan Type: Threat Scan Result: Completed Objects Scanned: 298854 Time Elapsed: 20 min, 6 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 0 (No malicious items detected) Modules: 0 (No malicious items detected) Registry Keys: 0 (No malicious items detected) Registry Values: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Folders: 1 PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced System Protector, Quarantined, [51ed83f25c1f46f00417e0a34bb77f81], Files: 1 PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced System Protector\log.xslt, Quarantined, [51ed83f25c1f46f00417e0a34bb77f81], Physical Sectors: 0 (No malicious items detected) (end) |
Themen zu Windows 8 Fehler in REGSVR32 .dll |
.dll, antivir, arten, avira, beheben, einfach, fehler, forum, frage, hoffe, laden, meldung, musik, nervt, probleme, rechners, regsvr32, spiel, srvreg32, starte, starten, thema, videos, windows, windows 8, zufall |