![]() |
Plagegeister aller Art und deren Bekämpfung: Andauernd werden Werbebanner eingeblendetWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
![]() | #1 |
| ![]() Andauernd werden Werbebanner eingeblendet Habe Windows7 und seit einigen Tagen werden bei allen Browsern (Mozilla, Chrome, Opera) ständig Werbebanner eingeblendet (siehe Bild), wenn ich die schliesse, öffenen sich sofort neue, die Neuinstallation der Browser hat nichts gebracht |
![]() | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Andauernd werden Werbebanner eingeblendet Hallo und
__________________![]() Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die mal fündig geworden? Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520 Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs in CODE-Tags posten! Relevant sind nur Logs der letzten 7 Tage bzw. seitdem das Problem besteht! Zudem bitte auch ein Log mit Farbars Tool machen: Scan mit Farbar's Recovery Scan Tool (FRST) Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
![]() Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit. Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
![]() | #3 |
| ![]() Andauernd werden Werbebanner eingeblendet Hallo, Danke für das Hilfsangebot, hier die logfiles
__________________FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-06-2014 02 Ran by Siegfried (ATTENTION: The logged in user is not administrator) on SIEGFRIED-PC on 14-06-2014 09:41:02 Running from C:\Users\Siegfried.Siegfried-PC.001\Downloads Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (ASUS) C:\Windows\AsScrPro.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrl.exe () C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (SRS Labs, Inc.) C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel_64.exe (Dropbox, Inc.) C:\Users\SIEGFR~1.001\AppData\Roaming\Dropbox\bin\Dropbox.exe (Boingo Wireless, Inc.) C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo Wi-Fi.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office\WINWORD.EXE (Microsoft Corporation) C:\Windows\splwow64.exe (Microsoft Corporation) C:\Windows\Msagent\AGENTSVR.EXE ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ETDWare] => C:\Program Files\Elantech\ETDCtrl.exe [649608 2010-04-13] (ELAN Microelectronic Corp.) HKLM\...\Run: [ASUS WebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe [1754448 2010-03-16] () HKLM-x32\...\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [Boingo Wi-Fi] => C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk [2429 2010-09-03] () HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [6806144 2010-06-25] (ASUS) HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-05-03] (ASUS) HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1597440 2010-07-02] () HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-03] (Adobe Systems Incorporated) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-06-03] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard) HKLM-x32\...\Run: [hpqSRMon] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard) HKLM-x32\...\Runonce: [Del7717556] - cmd.exe /Q /D /c del "C:\Users\SIEGFR~2\AppData\Local\Temp\0.del" [X] HKLM-x32\...\Runonce: [Del7771704] - cmd.exe /Q /D /c del "C:\Users\SIEGFR~2\AppData\Local\Temp\0.del" [X] HKLM-x32\...\Runonce: [SpUninstallCleanUp] - REG delete HKEY_LOCAL_MACHINE\Software\SearchProtect /f [X] HKU\S-1-5-21-1647987812-3911492254-688806334-1007\...\Run: [BlazeServoTool] => "C:\Program Files (x86)\BlazeVideo\BlazeVideo HDTV Player Standard\MediaDetector.exe" AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~2.DLL => C:\PROGRA~2\SupTab\SEARCH~2.DLL File Not Found AppInit_DLLs-x32: C:\PROGRA~2\SupTab\SEARCH~1.DLL => "C:\PROGRA~2\SupTab\SEARCH~1.DLL" File Not Found Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FancyStart daemon.lnk ShortcutTarget: FancyStart daemon.lnk -> C:\Windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SRS Premium Sound.lnk ShortcutTarget: SRS Premium Sound.lnk -> C:\Windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe (Acresso Software Inc.) Startup: C:\Users\Siegfried.Siegfried-PC.001\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Siegfried.Siegfried-PC.001\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Siegfried.Siegfried-PC.001\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Siegfried.Siegfried-PC.001\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus.msn.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1400932709&from=cor&uid=WDCXWD3200BEVT-80A0RT0_WD-WXK1A50C9555C9555&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1400932709&from=cor&uid=WDCXWD3200BEVT-80A0RT0_WD-WXK1A50C9555C9555&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1400932709&from=cor&uid=WDCXWD3200BEVT-80A0RT0_WD-WXK1A50C9555C9555&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1400932709&from=cor&uid=WDCXWD3200BEVT-80A0RT0_WD-WXK1A50C9555C9555&q={searchTerms} URLSearchHook: HKLM-x32 - (No Name) - {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - No File SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT SearchScopes: HKLM-x32 - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.chatzum.com/?q={searchTerms} SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - bProtectorDefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = BHO-x32: No Name - {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - No File BHO-x32: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO-x32: No Name - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - No File BHO-x32: No Name - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - No File BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files (x86)\Delta\delta\\bh\delta.dll (Delta-search.com) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc) BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM-x32 - No Name - {98889811-442D-49dd-99D7-DC866BE87DBC} - No File Toolbar: HKLM-x32 - No Name - {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - No File Toolbar: HKLM-x32 - Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files (x86)\Delta\delta\\deltaTlbr.dll (Delta-search.com) Toolbar: HKLM-x32 - Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) Toolbar: HKCU - No Name - {0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF} - No File Handler: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - No File Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: http\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: https\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\Siegfried.Siegfried-PC.001\AppData\Roaming\Mozilla\Firefox\Profiles\jdj4l1md.default FF NewTab: hxxp://www.delta-search.com/?affID=121845&tt=gc_&babsrc=NT_ss&mntrId=DAF520CF305084D5 FF SearchEngineOrder.1: Delta Search FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", ""); FF Homepage: hxxp://www.google.de/ FF Keyword.URL: hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=ORJ&o=100000027&locale=de_DE&apn_uid=3F5B1296-3B5F-42B4-8FEA-27B016E7CB6F&apn_ptnrs=U3&apn_sauid=C43A27E2-6B8F-4A4E-BF79-075B7BC6E951&apn_dtid=YYYYYYYYDE&&q= FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.40.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @videolan.org/vlc,version=2.0.5 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2014-03-20] Chrome: ======= CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\PepperFlash\pepflashplayer.dll No File CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\pdf.dll No File CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll (Apple Inc.) CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll No File CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll No File CHR Plugin: (Java Deployment Toolkit - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll No File CHR Extension: (Google Wallet) - C:\Users\Siegfried.Siegfried-PC.001\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-08] ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-06-03] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-06-03] (Avira Operations GmbH & Co. KG) S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1039440 2014-06-03] (Avira Operations GmbH & Co. KG) R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [249344 2009-09-20] (Hewlett-Packard Co.) [File not signed] R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-09-20] (Hewlett-Packard Co.) [File not signed] R2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [704112 2014-05-08] (Cherished Technololgy LIMITED) R2 lmhosts; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed] R2 NlaSvc; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 nsi; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed] S2 Update webget; "C:\Program Files (x86)\webget\updatewebget.exe" [X] S2 Util webget; "C:\Program Files (x86)\webget\bin\utilwebget.exe" [X] ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-06-03] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-06-03] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-25] (Avira Operations GmbH & Co. KG) R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1800192 2009-08-20] () R1 {55685567-4840-4a91-962b-49a412e9485a}w64; C:\Windows\System32\drivers\{55685567-4840-4a91-962b-49a412e9485a}w64.sys [61112 2014-05-26] (StdLib) R1 {9edd0ea8-2819-47c2-8320-b007d5996f8a}w64; C:\Windows\System32\drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}w64.sys [61112 2014-05-22] (StdLib) S3 Bulk1528; System32\Drivers\Bulk1528.sys [X] S2 Ca1528av; System32\Drivers\Ca1528av.sys [X] U3 tmlwf; U3 tmwfp; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-14 09:38 - 2014-06-14 09:41 - 00018481 _____ () C:\Users\Siegfried.Siegfried-PC.001\Downloads\FRST.txt 2014-06-14 09:38 - 2014-06-14 09:41 - 00000000 ____D () C:\FRST 2014-06-14 09:36 - 2014-06-14 09:37 - 02081792 _____ (Farbar) C:\Users\Siegfried.Siegfried-PC.001\Downloads\FRST64.exe 2014-06-14 09:35 - 2014-06-14 09:36 - 01073152 _____ (Farbar) C:\Users\Siegfried.Siegfried-PC.001\Downloads\FRST.exe 2014-06-13 21:08 - 2014-06-13 21:08 - 00001161 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-06-13 21:08 - 2014-06-13 21:08 - 00001149 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-06-13 21:08 - 2014-06-13 21:08 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-06-13 19:32 - 2014-06-13 19:32 - 00000000 __SHD () C:\Users\Siegfried.Siegfried-PC.001\AppData\Local\EmieUserList 2014-06-13 19:32 - 2014-06-13 19:32 - 00000000 __SHD () C:\Users\Siegfried.Siegfried-PC.001\AppData\Local\EmieSiteList 2014-06-13 16:59 - 2014-06-13 17:00 - 40514640 _____ (Google Inc.) C:\Users\Siegfried.Siegfried-PC.001\Downloads\ChromeStandaloneSetup_35.0.1916.153.exe 2014-06-13 16:58 - 2014-06-13 16:59 - 29677544 _____ (Mozilla) C:\Users\Siegfried.Siegfried-PC.001\Downloads\Firefox_Setup_de30.0.exe 2014-06-12 20:22 - 2014-06-12 20:22 - 00004721 _____ () C:\Users\Siegfried.Siegfried-PC.001\AppData\Local\recently-used.xbel 2014-06-10 21:13 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-06-10 21:13 - 2014-05-30 12:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-06-10 21:13 - 2014-05-30 12:02 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-06-10 21:13 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-06-10 21:13 - 2014-05-30 11:39 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-06-10 21:13 - 2014-05-30 11:39 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-06-10 21:13 - 2014-05-30 11:38 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-06-10 21:13 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-06-10 21:13 - 2014-05-30 11:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-06-10 21:13 - 2014-05-30 11:24 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-06-10 21:13 - 2014-05-30 11:21 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-06-10 21:13 - 2014-05-30 11:21 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-06-10 21:13 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-06-10 21:13 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-06-10 21:13 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-06-10 21:13 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-06-10 21:13 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-06-10 21:13 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-06-10 21:13 - 2014-05-30 10:55 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-06-10 21:13 - 2014-05-30 10:49 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-06-10 21:13 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-06-10 21:13 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-06-10 21:13 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-06-10 21:13 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-06-10 21:13 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-06-10 21:13 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-06-10 21:13 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-06-10 21:13 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-06-10 21:13 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-06-10 21:13 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-06-10 21:13 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-06-10 21:13 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-06-10 21:13 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-06-10 21:13 - 2014-05-30 10:24 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-06-10 21:13 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-06-10 21:13 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-06-10 21:13 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-06-10 21:13 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-06-10 21:13 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-06-10 21:13 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-06-10 21:13 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-06-10 21:13 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-06-10 21:13 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-06-10 21:13 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-06-10 21:13 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-06-10 21:13 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-06-10 21:13 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-06-10 21:13 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-06-10 21:13 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-06-10 21:13 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-06-10 21:13 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-06-10 21:13 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-06-10 21:11 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2014-06-10 21:11 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2014-06-10 21:11 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-06-10 21:11 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS 2014-06-10 21:11 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2014-06-10 21:11 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-06-10 21:11 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2014-06-10 21:11 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-06-10 21:11 - 2013-11-26 13:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-06-10 21:10 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll 2014-06-10 21:10 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-06-10 21:10 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll 2014-06-10 21:10 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-06-08 22:03 - 2014-06-08 22:03 - 00000000 ____D () C:\Users\Siegfried.Siegfried-PC.001\AppData\Roaming\TuneUp Software 2014-06-08 22:03 - 2014-06-08 22:03 - 00000000 ____D () C:\Users\Siegfried.Siegfried-PC.001\AppData\Local\TuneUp Software 2014-06-08 21:51 - 2014-06-08 21:51 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} 2014-06-08 21:50 - 2014-06-08 21:50 - 00000000 ____D () C:\Users\Siegfried.Siegfried-PC.001\Documents\Any Video Converter 2014-06-08 21:50 - 2014-06-08 21:50 - 00000000 ____D () C:\Users\Siegfried.Siegfried-PC.001\AppData\Roaming\AnvSoft 2014-06-08 21:50 - 2014-06-08 21:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnvSoft 2014-06-08 21:49 - 2014-06-08 21:49 - 00000000 ____D () C:\Program Files (x86)\AnvSoft 2014-06-08 21:48 - 2014-06-08 21:48 - 31485368 _____ (Any-Video-Converter.com ) C:\Users\Siegfried.Siegfried-PC.001\Downloads\avc-free_5.6.2.exe 2014-06-08 21:45 - 2014-06-08 21:46 - 06738572 _____ (Avi to Mpeg ) C:\Users\Siegfried.Siegfried-PC.001\Downloads\avitompeg_setup.exe 2014-06-04 20:23 - 2014-06-04 20:23 - 00000000 ____D () C:\Users\Siegfried.Siegfried-PC.001\AppData\Roaming\CyberLink 2014-05-27 20:03 - 2014-05-26 20:57 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\{55685567-4840-4a91-962b-49a412e9485a}w64.sys 2014-05-25 19:11 - 2014-05-22 18:27 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}w64.sys 2014-05-24 21:31 - 2014-05-24 21:31 - 00000000 ____D () C:\Users\Siegfried.Siegfried-PC.001\AppData\Roaming\Opera Software 2014-05-24 21:31 - 2014-05-24 21:31 - 00000000 ____D () C:\Users\Siegfried.Siegfried-PC.001\AppData\Local\Opera Software 2014-05-24 19:08 - 2014-05-24 19:08 - 00000000 ____D () C:\Users\Siegfried1\AppData\Roaming\Opera Software 2014-05-24 19:08 - 2014-05-24 19:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Soft-Now bundle 2014-05-24 19:06 - 2014-05-24 19:06 - 00000000 ____D () C:\Program Files (x86)\sweetpacks bundle uninstaller_VirtualDub_1425784 2014-05-24 14:47 - 2014-05-24 14:48 - 00000000 ____D () C:\Users\Siegfried.Siegfried-PC.001\Documents\VideoPad Projekte 2014-05-24 14:17 - 2014-05-24 14:53 - 00000000 ____D () C:\Users\Siegfried.Siegfried-PC.001\AppData\Roaming\avidemux 2014-05-24 13:59 - 2014-06-14 09:31 - 00000000 ____D () C:\Program Files (x86)\webget 2014-05-24 13:58 - 2014-06-13 17:38 - 00000000 ____D () C:\ProgramData\WPM 2014-05-24 13:58 - 2014-06-13 17:37 - 00000000 ____D () C:\Users\Siegfried1\AppData\Roaming\Systweak 2014-05-24 13:58 - 2014-06-13 17:18 - 00000000 ____D () C:\Users\Siegfried1\AppData\Roaming\sweet-page 2014-05-24 13:58 - 2014-06-13 17:18 - 00000000 ____D () C:\Program Files (x86)\SupTab 2014-05-24 13:58 - 2014-05-25 12:52 - 00000000 ____D () C:\ProgramData\IePluginServices 2014-05-24 13:58 - 2014-05-24 13:58 - 00000000 ____D () C:\Users\Siegfried1\AppData\Roaming\DigitalSites 2014-05-24 13:58 - 2014-05-24 13:58 - 00000000 ____D () C:\Program Files (x86)\Image Converter 2014-05-23 20:41 - 2014-05-23 20:41 - 00000000 ____D () C:\Users\Siegfried.Siegfried-PC.001\AppData\Roaming\DVDVideoSoft 2014-05-23 20:38 - 2014-05-23 20:39 - 31464328 _____ (DVDVideoSoft Ltd. ) C:\Users\Siegfried.Siegfried-PC.001\Downloads\FreeVideoEditor- ==================== One Month Modified Files and Folders ======= 2014-06-14 09:41 - 2014-06-14 09:38 - 00018481 _____ () C:\Users\Siegfried.Siegfried-PC.001\Downloads\FRST.txt 2014-06-14 09:41 - 2014-06-14 09:38 - 00000000 ____D () C:\FRST 2014-06-14 09:41 - 2013-05-06 20:15 - 00000000 ____D () C:\Users\Siegfried.Siegfried-PC.001\AppData\Local\Temp 2014-06-14 09:40 - 2009-07-14 06:45 - 00010240 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-14 09:40 - 2009-07-14 06:45 - 00010240 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-14 09:38 - 2010-09-03 03:33 - 02031860 _____ () C:\Windows\WindowsUpdate.log 2014-06-14 09:37 - 2014-06-14 09:36 - 02081792 _____ (Farbar) C:\Users\Siegfried.Siegfried-PC.001\Downloads\FRST64.exe 2014-06-14 09:36 - 2014-06-14 09:35 - 01073152 _____ (Farbar) C:\Users\Siegfried.Siegfried-PC.001\Downloads\FRST.exe 2014-06-14 09:36 - 2009-08-04 11:51 - 00654166 _____ () C:\Windows\system32\perfh007.dat 2014-06-14 09:36 - 2009-08-04 11:51 - 00130006 _____ () C:\Windows\system32\perfc007.dat 2014-06-14 09:36 - 2009-07-14 07:13 - 01498506 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-06-14 09:33 - 2014-05-10 16:37 - 00000000 ____D () C:\Users\Siegfried.Siegfried-PC.001\AppData\Roaming\Dropbox 2014-06-14 09:33 - 2013-06-01 19:36 - 00000438 _____ () C:\Windows\system32\Drivers\etc\hosts.ics 2014-06-14 09:32 - 2014-05-10 16:41 - 00000000 ___RD () C:\Users\Siegfried.Siegfried-PC.001\Dropbox 2014-06-14 09:32 - 2014-05-10 16:40 - 00000000 ____D () C:\Users\Siegfried.Siegfried-PC.001\AppData\Roaming\DropboxMaster 2014-06-14 09:32 - 2013-05-09 20:01 - 00045340 _____ () C:\Windows\setupact.log 2014-06-14 09:31 - 2014-05-24 13:59 - 00000000 ____D () C:\Program Files (x86)\webget 2014-06-14 09:31 - 2013-05-09 20:01 - 00044598 _____ () C:\Windows\PFRO.log 2014-06-13 21:08 - 2014-06-13 21:08 - 00001161 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-06-13 21:08 - 2014-06-13 21:08 - 00001149 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-06-13 21:08 - 2014-06-13 21:08 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-06-13 21:08 - 2014-05-09 21:14 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-13 19:32 - 2014-06-13 19:32 - 00000000 __SHD () C:\Users\Siegfried.Siegfried-PC.001\AppData\Local\EmieUserList 2014-06-13 19:32 - 2014-06-13 19:32 - 00000000 __SHD () C:\Users\Siegfried.Siegfried-PC.001\AppData\Local\EmieSiteList 2014-06-13 19:25 - 2010-09-03 03:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-06-13 19:25 - 2010-09-03 03:54 - 00000000 ____D () C:\Program Files (x86)\Google 2014-06-13 18:58 - 2013-01-01 13:48 - 00000000 ____D () C:\Users\Siegfried1\AppData\Roaming\Mozilla 2014-06-13 17:39 - 2013-03-30 19:07 - 00000000 ____D () C:\Users\Siegfried1\AppData\Roaming\FBDownloader 2014-06-13 17:38 - 2014-05-24 13:58 - 00000000 ____D () C:\ProgramData\WPM 2014-06-13 17:37 - 2014-05-24 13:58 - 00000000 ____D () C:\Users\Siegfried1\AppData\Roaming\Systweak 2014-06-13 17:36 - 2013-01-01 13:47 - 00000000 ____D () C:\Users\Siegfried1\AppData\Roaming\DVDVideoSoft 2014-06-13 17:27 - 2009-07-14 04:34 - 00000540 _____ () C:\Windows\win.ini 2014-06-13 17:18 - 2014-05-24 13:58 - 00000000 ____D () C:\Users\Siegfried1\AppData\Roaming\sweet-page 2014-06-13 17:18 - 2014-05-24 13:58 - 00000000 ____D () C:\Program Files (x86)\SupTab 2014-06-13 17:14 - 2012-06-03 10:36 - 00000000 ____D () C:\Program Files (x86)\Opera 2014-06-13 17:00 - 2014-06-13 16:59 - 40514640 _____ (Google Inc.) C:\Users\Siegfried.Siegfried-PC.001\Downloads\ChromeStandaloneSetup_35.0.1916.153.exe 2014-06-13 16:59 - 2014-06-13 16:58 - 29677544 _____ (Mozilla) C:\Users\Siegfried.Siegfried-PC.001\Downloads\Firefox_Setup_de30.0.exe 2014-06-13 06:35 - 2012-06-03 11:15 - 00000000 ____D () C:\ProgramData\Zoom Player 2014-06-12 20:26 - 2014-04-05 18:17 - 00000000 ____D () C:\Users\Siegfried.Siegfried-PC.001\.gimp-2.8 2014-06-12 20:22 - 2014-06-12 20:22 - 00004721 _____ () C:\Users\Siegfried.Siegfried-PC.001\AppData\Local\recently-used.xbel 2014-06-12 19:37 - 2013-07-16 18:15 - 00000000 ____D () C:\Users\Siegfried.Siegfried-PC.001\AppData\Local\Google 2014-06-10 22:31 - 2013-07-20 14:32 - 00000000 ____D () C:\Windows\system32\MRT 2014-06-10 22:27 - 2012-07-08 19:39 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-06-09 13:37 - 2014-04-05 18:28 - 00000000 ____D () C:\Users\Siegfried.Siegfried-PC.001\AppData\Local\gtk-2.0 2014-06-09 11:39 - 2013-05-06 20:15 - 00000000 ____D () C:\Users\Siegfried.Siegfried-PC.001\AppData\Local\VirtualStore 2014-06-08 22:03 - 2014-06-08 22:03 - 00000000 ____D () C:\Users\Siegfried.Siegfried-PC.001\AppData\Roaming\TuneUp Software 2014-06-08 22:03 - 2014-06-08 22:03 - 00000000 ____D () C:\Users\Siegfried.Siegfried-PC.001\AppData\Local\TuneUp Software 2014-06-08 21:52 - 2013-01-01 13:48 - 00000000 ____D () C:\Users\Siegfried1\AppData\Roaming\TuneUp Software 2014-06-08 21:51 - 2014-06-08 21:51 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} 2014-06-08 21:51 - 2013-01-01 13:48 - 00000000 ____D () C:\ProgramData\TuneUp Software 2014-06-08 21:50 - 2014-06-08 21:50 - 00000000 ____D () C:\Users\Siegfried.Siegfried-PC.001\Documents\Any Video Converter 2014-06-08 21:50 - 2014-06-08 21:50 - 00000000 ____D () C:\Users\Siegfried.Siegfried-PC.001\AppData\Roaming\AnvSoft 2014-06-08 21:50 - 2014-06-08 21:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnvSoft 2014-06-08 21:49 - 2014-06-08 21:49 - 00000000 ____D () C:\Program Files (x86)\AnvSoft 2014-06-08 21:49 - 2013-01-01 13:47 - 00000000 ____D () C:\Users\Siegfried1\AppData\Roaming\OpenCandy 2014-06-08 21:48 - 2014-06-08 21:48 - 31485368 _____ (Any-Video-Converter.com ) C:\Users\Siegfried.Siegfried-PC.001\Downloads\avc-free_5.6.2.exe 2014-06-08 21:46 - 2014-06-08 21:45 - 06738572 _____ (Avi to Mpeg ) C:\Users\Siegfried.Siegfried-PC.001\Downloads\avitompeg_setup.exe 2014-06-04 20:23 - 2014-06-04 20:23 - 00000000 ____D () C:\Users\Siegfried.Siegfried-PC.001\AppData\Roaming\CyberLink 2014-06-03 18:49 - 2013-08-08 06:56 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-06-03 18:49 - 2013-08-08 06:56 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-05-31 13:42 - 2013-06-01 17:01 - 00000000 ____D () C:\Users\Siegfried.Siegfried-PC.001\AppData\Roaming\vlc 2014-05-30 12:21 - 2014-06-10 21:13 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-30 12:02 - 2014-06-10 21:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-30 12:02 - 2014-06-10 21:13 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-05-30 11:45 - 2014-06-10 21:13 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-05-30 11:39 - 2014-06-10 21:13 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-05-30 11:39 - 2014-06-10 21:13 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-05-30 11:38 - 2014-06-10 21:13 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-05-30 11:28 - 2014-06-10 21:13 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-05-30 11:27 - 2014-06-10 21:13 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-05-30 11:24 - 2014-06-10 21:13 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-05-30 11:21 - 2014-06-10 21:13 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-05-30 11:21 - 2014-06-10 21:13 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-05-30 11:20 - 2014-06-10 21:13 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-05-30 11:18 - 2014-06-10 21:13 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-30 11:11 - 2014-06-10 21:13 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-05-30 11:08 - 2014-06-10 21:13 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-05-30 11:06 - 2014-06-10 21:13 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-05-30 11:02 - 2014-06-10 21:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-30 10:55 - 2014-06-10 21:13 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-05-30 10:49 - 2014-06-10 21:13 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-05-30 10:46 - 2014-06-10 21:13 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-30 10:44 - 2014-06-10 21:13 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-05-30 10:44 - 2014-06-10 21:13 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-05-30 10:43 - 2014-06-10 21:13 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-05-30 10:42 - 2014-06-10 21:13 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-05-30 10:38 - 2014-06-10 21:13 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-05-30 10:35 - 2014-06-10 21:13 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-05-30 10:34 - 2014-06-10 21:13 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-05-30 10:33 - 2014-06-10 21:13 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-05-30 10:30 - 2014-06-10 21:13 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-05-30 10:29 - 2014-06-10 21:13 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-05-30 10:28 - 2014-06-10 21:13 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-05-30 10:27 - 2014-06-10 21:13 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-05-30 10:24 - 2014-06-10 21:13 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-05-30 10:23 - 2014-06-10 21:13 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-05-30 10:16 - 2014-06-10 21:13 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-05-30 10:10 - 2014-06-10 21:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-05-30 10:06 - 2014-06-10 21:13 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-05-30 10:04 - 2014-06-10 21:13 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-05-30 10:02 - 2014-06-10 21:13 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-05-30 09:56 - 2014-06-10 21:13 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-05-30 09:56 - 2014-06-10 21:13 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-05-30 09:54 - 2014-06-10 21:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-05-30 09:50 - 2014-06-10 21:13 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-05-30 09:49 - 2014-06-10 21:13 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-05-30 09:43 - 2014-06-10 21:13 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-05-30 09:40 - 2014-06-10 21:13 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-05-30 09:30 - 2014-06-10 21:13 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-05-30 09:21 - 2014-06-10 21:13 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-05-30 09:15 - 2014-06-10 21:13 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-05-30 09:13 - 2014-06-10 21:13 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-05-30 09:13 - 2014-06-10 21:13 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-05-28 16:33 - 2014-05-10 16:41 - 00001088 _____ () C:\Users\Siegfried.Siegfried-PC.001\Desktop\Dropbox.lnk 2014-05-28 16:33 - 2014-05-10 16:39 - 00000000 ____D () C:\Users\Siegfried.Siegfried-PC.001\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-05-28 16:33 - 2013-05-06 20:16 - 00000000 ___RD () C:\Users\Siegfried.Siegfried-PC.001\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-05-26 20:57 - 2014-05-27 20:03 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\{55685567-4840-4a91-962b-49a412e9485a}w64.sys 2014-05-25 12:52 - 2014-05-24 13:58 - 00000000 ____D () C:\ProgramData\IePluginServices 2014-05-25 12:51 - 2010-09-03 04:21 - 00002192 _____ () C:\Windows\system32\AutoRunFilter.ini 2014-05-25 12:51 - 2010-09-03 04:21 - 00001383 _____ () C:\Windows\system32\ServiceFilter.ini 2014-05-24 21:59 - 2013-05-07 20:29 - 00000000 ____D () C:\Users\Siegfried.Siegfried-PC.001\AppData\Roaming\NCH Software 2014-05-24 21:31 - 2014-05-24 21:31 - 00000000 ____D () C:\Users\Siegfried.Siegfried-PC.001\AppData\Roaming\Opera Software 2014-05-24 21:31 - 2014-05-24 21:31 - 00000000 ____D () C:\Users\Siegfried.Siegfried-PC.001\AppData\Local\Opera Software 2014-05-24 19:08 - 2014-05-24 19:08 - 00000000 ____D () C:\Users\Siegfried1\AppData\Roaming\Opera Software 2014-05-24 19:08 - 2014-05-24 19:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Soft-Now bundle 2014-05-24 19:06 - 2014-05-24 19:06 - 00000000 ____D () C:\Program Files (x86)\sweetpacks bundle uninstaller_VirtualDub_1425784 2014-05-24 14:53 - 2014-05-24 14:17 - 00000000 ____D () C:\Users\Siegfried.Siegfried-PC.001\AppData\Roaming\avidemux 2014-05-24 14:48 - 2014-05-24 14:47 - 00000000 ____D () C:\Users\Siegfried.Siegfried-PC.001\Documents\VideoPad Projekte 2014-05-24 13:59 - 2012-12-30 22:35 - 00000000 ____D () C:\Users\Siegfried1\AppData\Roaming\Opera 2014-05-24 13:58 - 2014-05-24 13:58 - 00000000 ____D () C:\Users\Siegfried1\AppData\Roaming\DigitalSites 2014-05-24 13:58 - 2014-05-24 13:58 - 00000000 ____D () C:\Program Files (x86)\Image Converter 2014-05-23 20:41 - 2014-05-23 20:41 - 00000000 ____D () C:\Users\Siegfried.Siegfried-PC.001\AppData\Roaming\DVDVideoSoft 2014-05-23 20:41 - 2013-05-25 15:10 - 00000000 ____D () C:\Users\Siegfried.Siegfried-PC.001\Documents\DVDVideoSoft 2014-05-23 20:39 - 2014-05-23 20:38 - 31464328 _____ (DVDVideoSoft Ltd. ) C:\Users\Siegfried.Siegfried-PC.001\Downloads\FreeVideoEditor- 2014-05-23 20:34 - 2012-06-03 10:08 - 00000000 ____D () C:\Program Files (x86)\Windows Live 2014-05-23 20:34 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared 2014-05-23 20:18 - 2014-04-25 09:24 - 00000000 ____D () C:\Users\Siegfried.Siegfried-PC.001\AppData\Local\Windows Live 2014-05-23 20:17 - 2012-12-30 22:25 - 00000000 ____D () C:\Users\Siegfried1 2014-05-22 18:27 - 2014-05-25 19:11 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}w64.sys 2014-05-17 22:56 - 2014-05-14 20:56 - 00000408 _____ () C:\Users\Siegfried.Siegfried-PC.001\AppData\Roaming\CamShapes.ini 2014-05-17 22:56 - 2014-05-14 20:56 - 00000408 _____ () C:\Users\Siegfried.Siegfried-PC.001\AppData\Roaming\CamLayout.ini 2014-05-17 22:56 - 2014-05-14 20:56 - 00000146 _____ () C:\Users\Siegfried.Siegfried-PC.001\AppData\Roaming\Camdata.ini 2014-05-17 22:56 - 2014-05-14 20:55 - 00004535 _____ () C:\Users\Siegfried.Siegfried-PC.001\AppData\Roaming\CamStudio.cfg 2014-05-17 22:55 - 2014-05-14 20:54 - 00000000 ____D () C:\Users\Siegfried.Siegfried-PC.001\Documents\My CamStudio Temp Files 2014-05-17 22:54 - 2014-05-14 20:53 - 00000096 _____ () C:\Users\Siegfried.Siegfried-PC.001\AppData\Roaming\version2.xml 2014-05-15 20:54 - 2013-05-06 20:16 - 00000000 ___RD () C:\Users\Siegfried.Siegfried-PC.001\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools Files to move or delete: ==================== C:\Users\Siegfried.Siegfried-PC.001\AppData\Roaming\CamLayout.ini C:\Users\Siegfried.Siegfried-PC.001\AppData\Roaming\CamShapes.ini C:\ProgramData\dsgsdgdsgdsgw.pad C:\ProgramData\jzdjr.exe C:\ProgramData\lrodej.pad C:\ProgramData\o8iwv.bat C:\ProgramData\o8iwv.pad C:\ProgramData\o8iwv.reg C:\ProgramData\rjw4raw.ctrl C:\ProgramData\rjw4raw.pff C:\ProgramData\rundll32.exe C:\Users\Siegfried.Siegfried-PC.001\7933989.dll Some content of TEMP: ==================== C:\Users\Siegfried.Siegfried-PC.001\AppData\Local\Temp\AskSLib.dll C:\Users\Siegfried.Siegfried-PC.001\AppData\Local\Temp\avgnt.exe C:\Users\Siegfried.Siegfried-PC.001\AppData\Local\Temp\drm_dialogs.dll C:\Users\Siegfried.Siegfried-PC.001\AppData\Local\Temp\drm_dyndata_7380012.dll C:\Users\Siegfried.Siegfried-PC.001\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp1sqbhe.dll C:\Users\Siegfried.Siegfried-PC.001\AppData\Local\Temp\mp3el2.exe C:\Users\Siegfried.Siegfried-PC.001\AppData\Local\Temp\Second_Life_3_7_7_289461_i686_Setup.exe C:\Users\Siegfried.Siegfried-PC.001\AppData\Local\Temp\wpsetup.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-06-2014 02 Ran by Siegfried at 2014-06-14 09:42:47 Running from C:\Users\Siegfried.Siegfried-PC.001\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== 64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden 7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - ) Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated) Adobe Reader X (10.1.5) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.5 - Adobe Systems Incorporated) AGEIA PhysX v7.11.13 (HKLM-x32\...\{95FC26FB-19FD-4A96-BBB1-B1062E8648F5}) (Version: 7.11.13 - AGEIA Technologies, Inc.) AMD USB Filter Driver (HKLM-x32\...\{987B04C4-B5AC-4AD6-A7E9-8D681085B850}) (Version: - Advanced Micro Devices, Inc.) Any Video Converter 5.6.2 (HKLM-x32\...\Any Video Converter_is1) (Version: - Any-Video-Converter.com) ASUS AI Recovery (HKLM-x32\...\{06585B02-F20D-4AB2-9A64-86EF2AE0F8F0}) (Version: 1.0.10 - ASUS) ASUS AP Bank (HKLM-x32\...\ASUS AP Bank_is1) (Version: - ASUSTEK) ASUS CopyProtect (HKLM-x32\...\{6B77A7F6-DD63-4F13-A6FF-83137A5AC354}) (Version: 1.0.0015 - ASUS) ASUS FancyStart (HKLM-x32\...\{2B81872B-A054-48DA-BE3B-FA5C164C303A}) (Version: 1.0.8 - ASUSTeK Computer Inc.) ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.0.20 - ASUS) ASUS Live Update (HKLM-x32\...\{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}) (Version: 2.5.9 - ASUS) ASUS MultiFrame (HKLM-x32\...\{9D48531D-2135-49FC-BC29-ACCDA5396A76}) (Version: 1.0.0021 - ASUS) ASUS Power4Gear Hybrid (HKLM\...\{91EFE3A1-585E-4F66-B5F6-F118F56C4C47}) (Version: 1.1.37 - ASUS) ASUS SmartLogon (HKLM-x32\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0008 - ASUS) ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.02.0028 - ASUS) ASUS Virtual Camera (HKLM-x32\...\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}) (Version: 1.0.20 - asus) ASUS WebStorage (HKLM-x32\...\ASUS WebStorage) (Version: - eCareme Technologies, Inc.) ATI Catalyst Install Manager (HKLM\...\{401D3422-5349-F819-D294-01CA297CB9E0}) (Version: 3.0.769.0 - ATI Technologies, Inc.) ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0005 - ASUS) Avi to Mpeg 3.5 (HKLM-x32\...\{14BF164E-80A4-422E-BE43-39FB759666C2}_is1) (Version: 3.5 - Avi to Mpeg) Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: - Avira) Bass Audio Decoder (remove only) (HKLM-x32\...\Bass Audio Decoder) (Version: - ) Boingo Wi-Fi (HKLM-x32\...\{B653A2EC-D816-4498-A4FD-651047AB9DC9}) (Version: 1.7.0048 - Boingo Wireless, Inc.) BufferChm (x32 Version: 130.0.331.000 - Hewlett-Packard) Hidden CamStudio 2.7.2 (HKLM\...\{04B83666-3A62-452B-85D3-70F8117F2329}_is1) (Version: 2.7.2 - CamStudio Open Source) Catalyst Control Center Core Implementation (x32 Version: 2010.0406.2133.36843 - ATI) Hidden Catalyst Control Center Graphics Full Existing (x32 Version: 2010.0406.2133.36843 - ATI) Hidden Catalyst Control Center Graphics Full New (x32 Version: 2010.0406.2133.36843 - ATI) Hidden Catalyst Control Center Graphics Light (x32 Version: 2010.0406.2133.36843 - ATI) Hidden Catalyst Control Center Graphics Previews Vista (x32 Version: 2010.0406.2133.36843 - ATI) Hidden Catalyst Control Center InstallProxy (x32 Version: 2010.0406.2133.36843 - ATI Technologies, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2010.0406.2133.36843 - ATI) Hidden CCC Help Chinese Standard (x32 Version: 2010.0406.2132.36843 - ATI) Hidden CCC Help Chinese Traditional (x32 Version: 2010.0406.2132.36843 - ATI) Hidden CCC Help Czech (x32 Version: 2010.0406.2132.36843 - ATI) Hidden CCC Help Danish (x32 Version: 2010.0406.2132.36843 - ATI) Hidden CCC Help Dutch (x32 Version: 2010.0406.2132.36843 - ATI) Hidden CCC Help English (x32 Version: 2010.0406.2132.36843 - ATI) Hidden CCC Help Finnish (x32 Version: 2010.0406.2132.36843 - ATI) Hidden CCC Help French (x32 Version: 2010.0406.2132.36843 - ATI) Hidden CCC Help German (x32 Version: 2010.0406.2132.36843 - ATI) Hidden CCC Help Greek (x32 Version: 2010.0406.2132.36843 - ATI) Hidden CCC Help Hungarian (x32 Version: 2010.0406.2132.36843 - ATI) Hidden CCC Help Italian (x32 Version: 2010.0406.2132.36843 - ATI) Hidden CCC Help Japanese (x32 Version: 2010.0406.2132.36843 - ATI) Hidden CCC Help Korean (x32 Version: 2010.0406.2132.36843 - ATI) Hidden CCC Help Norwegian (x32 Version: 2010.0406.2132.36843 - ATI) Hidden CCC Help Polish (x32 Version: 2010.0406.2132.36843 - ATI) Hidden CCC Help Portuguese (x32 Version: 2010.0406.2132.36843 - ATI) Hidden CCC Help Russian (x32 Version: 2010.0406.2132.36843 - ATI) Hidden CCC Help Spanish (x32 Version: 2010.0406.2132.36843 - ATI) Hidden CCC Help Swedish (x32 Version: 2010.0406.2132.36843 - ATI) Hidden CCC Help Thai (x32 Version: 2010.0406.2132.36843 - ATI) Hidden CCC Help Turkish (x32 Version: 2010.0406.2132.36843 - ATI) Hidden ccc-core-static (x32 Version: 2010.0406.2133.36843 - ATI) Hidden ccc-utility64 (Version: 2010.0406.2133.36843 - ATI) Hidden CCleaner (HKLM\...\CCleaner) (Version: 4.00 - Piriform) CD Audio Reader Filter (remove only) (HKLM-x32\...\CD Audio Reader Filter) (Version: - ) concept/design Video Jukebox (HKLM-x32\...\{37569A10-CB38-4615-8B32-0BF9FF5D887D}_is1) (Version: - concept/design GmbH) ControlDeck (HKLM-x32\...\{5B65EF64-1DFA-414A-8C94-7BB726158E21}) (Version: 1.0.8 - ASUS) Copy (x32 Version: 130.0.428.000 - Hewlett-Packard) Hidden CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.1908 - CyberLink Corp.) CyberLink LabelPrint (x32 Version: 2.5.1908 - CyberLink Corp.) Hidden CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.3602c - CyberLink Corp.) CyberLink Power2Go (x32 Version: 6.1.3602c - CyberLink Corp.) Hidden DCoder Image Source (remove only) (HKLM-x32\...\DCoder Image Source) (Version: - ) Delta toolbar (HKLM-x32\...\delta) (Version: - Delta) <==== ATTENTION Destinations (x32 Version: - Hewlett-Packard) Hidden DeviceDiscovery (x32 Version: 130.0.465.000 - Hewlett-Packard) Hidden Digital Video Repair 1.0 (HKLM-x32\...\Digital Video Repair) (Version: - ) DirectVobSub (remove only) (HKLM-x32\...\DirectVobSub) (Version: - ) DJ_AIO_03_F4200_Software_Min (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden Dropbox (HKCU\...\Dropbox) (Version: 2.8.2 - Dropbox, Inc.) DScaler 5 Mpeg Decoders (HKLM-x32\...\DScaler 5 Mpeg Decoders_is1) (Version: - ) ElsterFormular (HKLM-x32\...\ElsterFormular) (Version: 15.0.20140117 - Landesfinanzdirektion Thüringen) ETDWare PS/2-x64 (HKLM\...\Elantech) (Version: - ELAN Microelectronics Corp.) F4200 (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden Fast Boot (HKLM\...\{13F4A7F3-EABC-4261-AF6B-1317777F0755}) (Version: 1.0.6 - ASUS) ffdshow v1.2.4453 [2012-05-21] (HKLM-x32\...\ffdshow_is1) (Version: 1.2.4453.0 - ) FFMPEG Core Files (remove only) (HKLM-x32\...\FFMPEG Core Files) (Version: - ) FormatFactory 3.0.1 (HKLM-x32\...\FormatFactory) (Version: 3.0.1 - Free Time) Gabest MPEG Splitter (remove only) (HKLM-x32\...\Gabest MPEG Splitter) (Version: - ) GIMP 2.8.10 (HKLM\...\GIMP-2_is1) (Version: 2.8.10 - The GIMP Team) GPBaseService2 (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden HP Customer Participation Program 13.0 (HKLM\...\HPExtendedCapabilities) (Version: 13.0 - HP) HP Deskjet F4200 All-In-One Driver Software 13.0 Rel. 3 (HKLM\...\{A00C9114-40E6-4C70-A619-7DF264B23485}) (Version: 13.0 - HP) HP Imaging Device Functions 13.0 (HKLM\...\HP Imaging Device Functions) (Version: 13.0 - HP) HP Photosmart Essential 3.5 (HKLM\...\HP Photosmart Essential) (Version: 3.5 - HP) HP Smart Web Printing 4.51 (HKLM\...\HP Smart Web Printing) (Version: 4.51 - HP) HP Solution Center 13.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP) HP Update (HKLM-x32\...\{7059BDA7-E1DB-442C-B7A1-6144596720A4}) (Version: - Hewlett-Packard) HPPhotoGadget (x32 Version: - Hewlett-Packard) Hidden HPPhotoSmartDiscLabelContent1 (x32 Version: 2.04.0000 - Hewlett-Packard) Hidden HPPhotosmartEssential (x32 Version: 2.04.0000 - Hewlett-Packard) Hidden HPProductAssistant (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden HPSSupply (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.32 - Irfan Skiljan) Java 7 Update 40 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217040FF}) (Version: 7.0.400 - Oracle) Java Auto Updater (x32 Version: - Sun Microsystems, Inc.) Hidden JavaFX 2.1.1 (HKLM-x32\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation) JMicron Ethernet Adapter NDIS Driver (HKLM-x32\...\{96DCEE2F-98EE-4F80-8C0F-7C04D1FB9D7F}) (Version: - JMicron Technology Corp.) JMicron Flash Media Controller Driver (HKLM-x32\...\{26604C7E-A313-4D12-867F-7C6E7820BE4C}) (Version: - JMicron Technology Corp.) K_Series_ScreenSaver_EN (HKLM-x32\...\K_Series_ScreenSaver_EN) (Version: - ) LAV Filters 0.55.3 (HKLM-x32\...\lavfilters_is1) (Version: 0.55.3 - Hendrik Leppkes) MadVR (remove only) (HKLM-x32\...\MadVR) (Version: - ) MarketResearch (x32 Version: 130.0.374.000 - Hewlett-Packard) Hidden Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft Office 2000 Professional (HKLM-x32\...\{00010407-78E1-11D2-B60F-006097C998E7}) (Version: 9.00.2816 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SkyDrive (HKCU\...\SkyDriveSetup.exe) (Version: 16.4.6013.0910 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Mozilla Firefox 30.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 30.0 (x86 de)) (Version: 30.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 30.0 - Mozilla) MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB973685) (HKLM-x32\...\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation) QuickTime (HKLM-x32\...\{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}) (Version: - Apple Inc.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: - Realtek Semiconductor Corp.) Recuva (HKLM\...\Recuva) (Version: 1.42 - Piriform) Scan (x32 Version: - Hewlett-Packard) Hidden Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 13.0 - HP) Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) SmartWebPrinting (x32 Version: 130.0.457.000 - Hewlett-Packard) Hidden Soft-Now bundle (HKLM-x32\...\Soft-Now bundle) (Version: - Soft-Now) SolutionCenter (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden SolveigMM AVI Trimmer (HKLM-x32\...\SolveigMM AVI Trimmer 2.0.1210.11) (Version: 2.0.1210.11 - Solveig Multimedia) SPCA1528 PC Driver (HKLM-x32\...\{570C2A84-A145-4DF0-AE9D-012584DF09DC}) (Version: - ) SRS Premium Sound Control Panel (HKLM\...\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}) (Version: 1.8.5900 - SRS Labs, Inc.) Status (x32 Version: 130.0.469.000 - Hewlett-Packard) Hidden syncables desktop SE (HKLM-x32\...\{BBED4F90-7AE5-40BF-AFB7-1B495692F4AB}) (Version: 5.5.615.9518 - syncables) Tomb Raider: Underworld 1.0 (HKLM-x32\...\Tomb Raider: Underworld) (Version: - ) Toolbox (x32 Version: 130.0.648.000 - Hewlett-Packard) Hidden TrayApp (x32 Version: 130.0.422.000 - Hewlett-Packard) Hidden UnloadSupport (x32 Version: 11.0.0 - Hewlett-Packard) Hidden USB2.0 UVC VGA WebCam (HKLM\...\USB2.0 UVC VGA WebCam) (Version: 5.8.54000.207 - Sonix) VideoPad Videobearbeitungs-Software (HKLM-x32\...\VideoPad) (Version: - NCH Software) VLC media player 2.0.5 (HKLM-x32\...\VLC media player) (Version: 2.0.5 - VideoLAN) WavePad Audio-Editor (HKCU\...\WavePad) (Version: 5.49 - NCH Software) WebReg (x32 Version: - Hewlett-Packard) Hidden Windows Live Sync (HKLM-x32\...\{8C1E2925-14F8-45AA-B999-1E2A74BF5607}) (Version: 14.0.8050.1202 - Microsoft Corporation) WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.30.3 - ASUS) WinRAR 4.11 (32-Bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.11.0 - win.rar GmbH) Wireless Console 3 (HKLM-x32\...\{20FDF948-C8ED-4543-A539-F7F4AEF5AFA2}) (Version: 3.0.17 - ASUS) Wise Registry Cleaner 7.66 (HKLM-x32\...\Wise Registry Cleaner_is1) (Version: - WiseCleaner.com, Inc.) WM Capture 6 (HKLM-x32\...\WM Capture 6) (Version: - AllAlex, Inc.) xHamster Video Downloader 3.26 (HKLM-x32\...\xHamster Video Downloader_is1) (Version: - DownloadToolz, Inc.) Yahoo! Toolbar (HKLM-x32\...\Yahoo! Companion) (Version: - ) Zoom Player (remove only) (HKLM-x32\...\ZoomPlayer) (Version: - ) ==================== Restore Points ========================= Could not list Restore Points. Check "winmgmt" service or repair WMI. ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= ==================== Loaded Modules (whitelisted) ============= 2010-03-16 03:48 - 2010-03-16 03:48 - 01754448 _____ () C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe 2010-07-02 22:36 - 2010-07-02 22:36 - 01597440 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= ==================== MSCONFIG/TASK MANAGER disabled items ========= MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" MSCONFIG\startupreg: ASUS Screen Saver Protector => C:\Windows\AsScrPro.exe MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s ==================== Faulty Device Manager Devices ============= Name: Teredo Tunneling Pseudo-Interface Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (06/14/2014 09:40:31 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm FRST64.exe, Version 12.6.2014.2 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: d08 Startzeit: 01cf87a380955d9f Endzeit: 0 Anwendungspfad: C:\Users\Siegfried.Siegfried-PC.001\Downloads\FRST64.exe Berichts-ID: 24d26f55-f397-11e3-b72f-4e5d6000c7d3 Error: (06/13/2014 05:41:03 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm uninstaller.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1014 Startzeit: 01cf871da08b001f Endzeit: 15 Anwendungspfad: C:\Program Files (x86)\sweetpacks bundle uninstaller_VirtualDub_1425784\uninstaller.exe Berichts-ID: 1a96f93b-f311-11e3-a547-20cf305084d5 Error: (06/13/2014 05:16:37 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm Opera.exe, Version 12.17.1863.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: c30 Startzeit: 01cf871a4291e312 Endzeit: 16 Anwendungspfad: C:\Users\Siegfried.Siegfried-PC.001\AppData\Local\Programs\Opera\Opera.exe Berichts-ID: b30b07b7-f30d-11e3-a470-20cf305084d5 Error: (06/13/2014 04:50:09 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: RSHP.exe, Version:, Zeitstempel: 0x535f59f7 Name des fehlerhaften Moduls: DpInterface32.dll, Version:, Zeitstempel: 0x535f638f Ausnahmecode: 0xc0000005 Fehleroffset: 0x0001e2cc ID des fehlerhaften Prozesses: 0xe38 Startzeit der fehlerhaften Anwendung: 0xRSHP.exe0 Pfad der fehlerhaften Anwendung: RSHP.exe1 Pfad des fehlerhaften Moduls: RSHP.exe2 Berichtskennung: RSHP.exe3 Error: (06/12/2014 07:22:50 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: RSHP.exe, Version:, Zeitstempel: 0x535f59f7 Name des fehlerhaften Moduls: DpInterface32.dll, Version:, Zeitstempel: 0x535f638f Ausnahmecode: 0xc0000005 Fehleroffset: 0x0001e2cc ID des fehlerhaften Prozesses: 0xe34 Startzeit der fehlerhaften Anwendung: 0xRSHP.exe0 Pfad der fehlerhaften Anwendung: RSHP.exe1 Pfad des fehlerhaften Moduls: RSHP.exe2 Berichtskennung: RSHP.exe3 Error: (06/12/2014 05:48:03 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: RSHP.exe, Version:, Zeitstempel: 0x535f59f7 Name des fehlerhaften Moduls: DpInterface32.dll, Version:, Zeitstempel: 0x535f638f Ausnahmecode: 0xc0000005 Fehleroffset: 0x0001e2cc ID des fehlerhaften Prozesses: 0xdc4 Startzeit der fehlerhaften Anwendung: 0xRSHP.exe0 Pfad der fehlerhaften Anwendung: RSHP.exe1 Pfad des fehlerhaften Moduls: RSHP.exe2 Berichtskennung: RSHP.exe3 Error: (06/11/2014 08:58:46 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: DllHost.exe, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc6b7 Name des fehlerhaften Moduls: quartz.dll, Version: 6.6.7601.17713, Zeitstempel: 0x4ea78b37 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00011b6e ID des fehlerhaften Prozesses: 0x2470 Startzeit der fehlerhaften Anwendung: 0xDllHost.exe0 Pfad der fehlerhaften Anwendung: DllHost.exe1 Pfad des fehlerhaften Moduls: DllHost.exe2 Berichtskennung: DllHost.exe3 Error: (06/11/2014 07:31:51 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: PluginService.exe, Version:, Zeitstempel: 0x536b5640 Name des fehlerhaften Moduls: DpInterface32.dll, Version:, Zeitstempel: 0x535f638f Ausnahmecode: 0xc0000005 Fehleroffset: 0x0009b48e ID des fehlerhaften Prozesses: 0x580 Startzeit der fehlerhaften Anwendung: 0xPluginService.exe0 Pfad der fehlerhaften Anwendung: PluginService.exe1 Pfad des fehlerhaften Moduls: PluginService.exe2 Berichtskennung: PluginService.exe3 Error: (06/11/2014 07:31:41 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: RSHP.exe, Version:, Zeitstempel: 0x535f59f7 Name des fehlerhaften Moduls: DpInterface32.dll, Version:, Zeitstempel: 0x535f638f Ausnahmecode: 0xc0000005 Fehleroffset: 0x0001e2cc ID des fehlerhaften Prozesses: 0xaf8 Startzeit der fehlerhaften Anwendung: 0xRSHP.exe0 Pfad der fehlerhaften Anwendung: RSHP.exe1 Pfad des fehlerhaften Moduls: RSHP.exe2 Berichtskennung: RSHP.exe3 Error: (06/10/2014 09:56:59 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: DllHost.exe, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc6b7 Name des fehlerhaften Moduls: quartz.dll, Version: 6.6.7601.17713, Zeitstempel: 0x4ea78b37 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00011b6e ID des fehlerhaften Prozesses: 0x1b60 Startzeit der fehlerhaften Anwendung: 0xDllHost.exe0 Pfad der fehlerhaften Anwendung: DllHost.exe1 Pfad des fehlerhaften Moduls: DllHost.exe2 Berichtskennung: DllHost.exe3 System errors: ============= Error: (06/14/2014 09:32:14 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Util webget" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (06/14/2014 09:32:14 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Update webget" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (06/14/2014 09:32:13 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "SPCA1528 Video Camera Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (06/13/2014 05:35:23 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Update webget" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (06/13/2014 05:35:23 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Util webget" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (06/13/2014 05:35:18 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Update webget" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 5000 Millisekunden durchgeführt: Neustart des Diensts. Error: (06/13/2014 05:35:18 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Util webget" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 5000 Millisekunden durchgeführt: Neustart des Diensts. Error: (06/13/2014 05:32:29 PM) (Source: DCOM) (EventID: 10016) (User: Siegfried-PC) Description: AnwendungsspezifischLokalAktivierung{8BC3F05E-D86B-11D0-A075-00C04FB68820}{8BC3F05E-D86B-11D0-A075-00C04FB68820}Siegfried-PCGastS-1-5-21-1647987812-3911492254-688806334-501LocalHost (unter Verwendung von LRPC) Error: (06/13/2014 05:29:38 PM) (Source: DCOM) (EventID: 10016) (User: Siegfried-PC) Description: AnwendungsspezifischLokalAktivierung{8BC3F05E-D86B-11D0-A075-00C04FB68820}{8BC3F05E-D86B-11D0-A075-00C04FB68820}Siegfried-PCGastS-1-5-21-1647987812-3911492254-688806334-501LocalHost (unter Verwendung von LRPC) Error: (06/13/2014 05:29:38 PM) (Source: DCOM) (EventID: 10016) (User: Siegfried-PC) Description: AnwendungsspezifischLokalAktivierung{8BC3F05E-D86B-11D0-A075-00C04FB68820}{8BC3F05E-D86B-11D0-A075-00C04FB68820}Siegfried-PCGastS-1-5-21-1647987812-3911492254-688806334-501LocalHost (unter Verwendung von LRPC) Microsoft Office Sessions: ========================= Error: (06/14/2014 09:40:31 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: FRST64.exe12.6.2014.2d0801cf87a380955d9f0C:\Users\Siegfried.Siegfried-PC.001\Downloads\FRST64.exe24d26f55-f397-11e3-b72f-4e5d6000c7d3 Error: (06/13/2014 05:41:03 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: uninstaller.exe2.0.0.6101401cf871da08b001f15C:\Program Files (x86)\sweetpacks bundle uninstaller_VirtualDub_1425784\uninstaller.exe1a96f93b-f311-11e3-a547-20cf305084d5 Error: (06/13/2014 05:16:37 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Opera.exe12.17.1863.0c3001cf871a4291e31216C:\Users\Siegfried.Siegfried-PC.001\AppData\Local\Programs\Opera\Opera.exeb30b07b7-f30d-11e3-a470-20cf305084d5 Error: (06/13/2014 04:50:09 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: RSHP.exe2.0.3.263535f59f7DpInterface32.dll3.0.2.3482535f638fc00000050001e2cce3801cf8716b2bfab11C:\Program Files (x86)\SupTab\RSHP.exeC:\Program Files (x86)\SupTab\DpInterface32.dll038596a0-f30a-11e3-a470-20cf305084d5 Error: (06/12/2014 07:22:50 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: RSHP.exe2.0.3.263535f59f7DpInterface32.dll3.0.2.3482535f638fc00000050001e2cce3401cf8662e09ec1e4C:\Program Files (x86)\SupTab\RSHP.exeC:\Program Files (x86)\SupTab\DpInterface32.dll2d4cbb7f-f256-11e3-ac95-20cf305084d5 Error: (06/12/2014 05:48:03 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: RSHP.exe2.0.3.263535f59f7DpInterface32.dll3.0.2.3482535f638fc00000050001e2ccdc401cf85f1093b5c18C:\Program Files (x86)\SupTab\RSHP.exeC:\Program Files (x86)\SupTab\DpInterface32.dll5a7cc114-f1e4-11e3-afb4-20cf305084d5 Error: (06/11/2014 08:58:46 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: DllHost.exe6.1.7600.163854a5bc6b7quartz.dll6.6.7601.177134ea78b37c000000500011b6e247001cf85a7277d42ddC:\Windows\SysWOW64\DllHost.exeC:\Windows\SysWOW64\quartz.dll6a20143f-f19a-11e3-8f2e-4e5d6000c7d3 Error: (06/11/2014 07:31:51 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: PluginService.exe13.27.0.301536b5640DpInterface32.dll3.0.2.3482535f638fc00000050009b48e58001cf8535d30615fcC:\ProgramData\IePluginServices\PluginService.exeC:\Program Files (x86)\SupTab\DpInterface32.dllb03fea19-f129-11e3-8f2e-4e5d6000c7d3 Error: (06/11/2014 07:31:41 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: RSHP.exe2.0.3.263535f59f7DpInterface32.dll3.0.2.3482535f638fc00000050001e2ccaf801cf85365a176aabC:\Program Files (x86)\SupTab\RSHP.exeC:\Program Files (x86)\SupTab\DpInterface32.dllaa28c4c7-f129-11e3-8f2e-4e5d6000c7d3 Error: (06/10/2014 09:56:59 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: DllHost.exe6.1.7600.163854a5bc6b7quartz.dll6.6.7601.177134ea78b37c000000500011b6e1b6001cf84e62185be94C:\Windows\SysWOW64\DllHost.exeC:\Windows\SysWOW64\quartz.dll6132c47e-f0d9-11e3-b98a-4e5d6000c7d3 ==================== Memory info =========================== Percentage of memory in use: 39% Total physical RAM: 4093.82 MB Available physical RAM: 2464.28 MB Total Pagefile: 8185.83 MB Available Pagefile: 6362.67 MB Total Virtual: 8192 MB Available Virtual: 8191.85 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:74.52 GB) (Free:20.3 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (DATA) (Fixed) (Total:204.03 GB) (Free:17.61 GB) NTFS ==================== MBR & Partition Table ================== ==================== End Of Log ============================ |
![]() | #4 | |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Andauernd werden Werbebanner eingeblendet Was ist mit meiner Frage nach bisherigen Funden und den Logs dazu? Zitat:
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | #5 |
| ![]() Andauernd werden Werbebanner eingeblendet Hallo Cosinus, vielen Dank für deinen Hilfeversuch, komischerweise ist seit gesrtern wieder alles in Ordnung, als ich nach dem letzten Virusscan mit Avira wieder hochgefahren habe, waren die Einblendungen erst mal weg. Bitte entschuldige auch, wenn ich dir nicht alles richtig mitgeteilt habe, bin leider kein PC-Profi, hab aber aich keine anderen Logfiles gehabt. Vielen Dank! |
![]() |
Themen zu Andauernd werden Werbebanner eingeblendet |
andauernd, bild, browser, browsern, chrome, dauernd, eingeblendet, mozilla, neue, neuinstallation, nichts, opera, sofort, tagen, werbebanner, windows, windows7 |