Nach der Deinstallation von ESET und dem anschließenden Versuch den Rechner neunte starten.
reparieren war das Erste was ich probiert hatte, aber auch ohne Ergebnis.
vielleicht macht es das Ganze einfacher, wenn ich den Rechner platt mache.
Allerdings würde ich gerne die Daten, wenn möglich noch auf einer externen Festplatte sichern. In DOS komme ich ja rein, bin allerdings da nicht wirklich fit was die Befehle anbelangt - irgendwie an xCopy erinnere ich mich noch vage.
Ich habe mich nun in die DOS Umgebung begeben.
Ich kann so woe es aussieht alle Dateien sehen und auch einzelne Dateien aufrufen.
Wenn ich bspw eine Textdatei öffne und über das Menü Datei>öffnen den Explorer öffnen möchte geht das nicht.
Das war auch der Fall nachdem ich den ESET Scan durch hatte. Da könnte ich den Dateimanager auch nicht mehr öffnen.
Was mir beim Booten noch auffällt: kurz bevor der Login Screen kommt ist der Bildschirm woe gewohnt erstmal schwarz, zeigt dann kurz den Login, wird dann wieder schwarz und zeigt dann den Login an.
Mehr kann ich glaube ich erstmal nicht sagen.
Hoffe Du kannst mir helfen...
13.02.2014
Neuer Tag, neues Glück. Musste Partition C nun doch formatieren und Windows7 Ultimate neu aufspielen da ich meinen Notebook dringend gebraucht habe.
So bin ich vorgegangen:
1. Habe wichtige Ordner und Dateien von mir von Partition C auf D per xcopy /kr/e/i/s/c/h kopiert.
2. Habe Partition C formatiert und Windows 7 neu installiert.
--> Rechner läuft wieder und kann auf Partition D zugreifen, nur die per xcopy verschobenen Ordner werden nicht angezeigt. Unter DOS sind sie aber da und einzelne Files auch aufrufbar. Ich weiß noch nicht woran das liegt.
3. Der Rechner bläst nur leider ständig.
Hier nun die neuen logs zu den Scans wie du sie mir zuanfangs angeraten hast:
FRST
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-02-2014 01
Ran by oh (administrator) on XMP on 13-02-2014 12:26:39
Running from C:\Users\oh\Downloads
Microsoft Windows 7 Ultimate (X86) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(Vodafone) C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Intel Corporation) C:\Windows\system32\igfxext.exe
(Microsoft Corporation) C:\Windows\system32\wbem\unsecapp.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Vodafone) C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Dropbox, Inc.) C:\Users\oh\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Flexera Software LLC.) C:\ProgramData\FLEXnet\Connect\11\agent.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Acer ePower Management] - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [714120 2011-01-05] (Acer Incorporated)
HKLM\...\Run: [NvCplDaemon] - C:\Windows\system32\NvCpl.dll [13834856 2010-05-20] (NVIDIA Corporation)
HKLM\...\Run: [cAudioFilterAgent] - C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent.exe [496184 2012-11-18] (Conexant Systems, Inc.)
HKLM\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3767096 2014-02-12] (AVAST Software)
HKLM\...\Run: [MobileBroadband] - C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe [76288 2013-02-05] (Vodafone)
Startup: C:\Users\oh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\oh\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Tcpip\Parameters: [DhcpNameServer] 192.168.250.40
FireFox:
========
FF ProfilePath: C:\Users\oh\AppData\Roaming\Mozilla\Firefox\Profiles\ep2r4gcc.default
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] - C:\Program Files\Vodafone\Vodafone Mobile Broadband\Optimization Client\addon\
FF Extension: Bytemobile Optimization Client - C:\Program Files\Vodafone\Vodafone Mobile Broadband\Optimization Client\addon\ []
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-02-12]
========================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-02-12] (AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [113704 2014-02-12] (AVAST Software)
R2 ePowerSvc; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [734592 2011-01-05] (Acer Incorporated)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 VmbService; C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [8704 2013-02-05] (Vodafone)
==================== Drivers (Whitelisted) ====================
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [26136 2014-02-12] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2014-02-12] (AVAST Software)
R1 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [265072 2014-02-12] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [79720 2014-02-12] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2014-02-12] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [775952 2014-02-12] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [410784 2014-02-12] (AVAST Software)
R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [64168 2014-02-12] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [180248 2014-02-12] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [14808 2009-11-02] ()
R3 vodafone_K3805-z_dc_enum; C:\Windows\System32\DRIVERS\vodafone_K3805-z_dc_enum.sys [61952 2010-09-01] (Vodafone)
U5 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [204800 2010-04-07] (Huawei Technologies Co., Ltd.)
U5 ew_hwusbdev; C:\Windows\System32\Drivers\ew_hwusbdev.sys [101504 2010-03-20] (Huawei Technologies Co., Ltd.)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-13 12:26 - 2014-02-13 12:27 - 00007505 _____ () C:\Users\oh\Downloads\FRST.txt
2014-02-13 12:26 - 2014-02-13 12:26 - 01141248 _____ (Farbar) C:\Users\oh\Downloads\FRST.exe
2014-02-13 12:26 - 2014-02-13 12:26 - 00000000 ____D () C:\FRST
2014-02-13 09:20 - 2014-02-13 09:20 - 00000000 ____D () C:\Users\oh\AppData\Roaming\FLEXnet
2014-02-13 07:51 - 2014-02-13 07:51 - 00000000 ____D () C:\Windows\PCHEALTH
2014-02-13 07:51 - 2014-02-13 07:51 - 00000000 ____D () C:\Program Files\Microsoft.NET
2014-02-13 07:51 - 2014-02-13 07:51 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER
2014-02-13 07:49 - 2014-02-13 07:49 - 00000000 ____D () C:\Program Files\Microsoft Analysis Services
2014-02-13 07:48 - 2014-02-13 07:53 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-02-13 07:48 - 2014-02-13 07:51 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-02-13 07:48 - 2014-02-13 07:48 - 00000000 __RHD () C:\MSOCache
2014-02-13 07:48 - 2014-02-13 07:48 - 00000000 ____D () C:\Users\oh\AppData\Local\Microsoft Help
2014-02-13 07:42 - 2014-02-13 07:42 - 00000000 ____D () C:\Users\oh\AppData\Roaming\Vodafone
2014-02-13 00:01 - 2014-02-13 00:01 - 07797992 _____ () C:\Users\oh\Downloads\ConnectifyInstaller.exe
2014-02-12 23:56 - 2014-02-12 23:56 - 00000000 ____D () C:\Users\oh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-02-12 23:56 - 2014-02-12 23:56 - 00000000 ____D () C:\Users\oh\AppData\Roaming\DropboxMaster
2014-02-12 23:54 - 2014-02-13 09:22 - 00000000 ____D () C:\Users\oh\AppData\Roaming\Dropbox
2014-02-12 23:54 - 2014-02-12 23:54 - 37660568 _____ (Dropbox, Inc.) C:\Users\oh\Downloads\Dropbox 2.6.2.exe
2014-02-12 23:54 - 2014-02-12 23:54 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ew_jubusenum_01007.Wdf
2014-02-12 23:54 - 2013-01-30 11:26 - 00076544 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_jubusenum.sys
2014-02-12 23:53 - 2014-02-13 07:44 - 00000000 ____D () C:\ProgramData\Vodafone
2014-02-12 23:53 - 2014-02-12 23:53 - 00002166 _____ () C:\Users\Public\Desktop\Vodafone Mobile Broadband.lnk
2014-02-12 23:53 - 2014-02-12 23:53 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_vodafone_K3805-z_dc_enum_01009.Wdf
2014-02-12 23:52 - 2014-02-12 23:52 - 00000000 ____D () C:\Users\oh\AppData\Local\Downloaded Installations
2014-02-12 23:52 - 2014-02-12 23:52 - 00000000 ____D () C:\ProgramData\Macrovision
2014-02-12 23:52 - 2014-02-12 23:52 - 00000000 ____D () C:\ProgramData\FLEXnet
2014-02-12 23:52 - 2014-02-12 23:52 - 00000000 ____D () C:\Program Files\Vodafone
2014-02-12 23:52 - 2014-02-12 23:52 - 00000000 ____D () C:\Program Files\Common Files\InstallShield
2014-02-12 23:51 - 2014-02-12 23:51 - 93522288 _____ () C:\Users\oh\Downloads\vmc_10.3.401.43721_RC1_setup.exe
2014-02-12 23:50 - 2014-02-12 23:50 - 00000000 ____D () C:\ProgramData\eDocPrintPro
2014-02-12 23:50 - 2014-02-12 23:50 - 00000000 ____D () C:\Program Files\GS
2014-02-12 23:50 - 2014-02-12 23:50 - 00000000 ____D () C:\Program Files\Common Files\SipgateFaxdrucker
2014-02-12 23:50 - 2013-12-18 06:13 - 00231584 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-02-12 23:48 - 2014-02-12 23:48 - 00001067 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-02-12 23:48 - 2014-02-12 23:48 - 00000000 ____D () C:\Users\oh\AppData\Roaming\Malwarebytes
2014-02-12 23:48 - 2014-02-12 23:48 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-02-12 23:48 - 2014-02-12 23:48 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2014-02-12 23:48 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-02-12 23:47 - 2014-02-12 23:47 - 00614792 _____ (Chip Digital GmbH) C:\Users\oh\Downloads\Malwarebytes Anti Malware - CHIP-Downloader.exe
2014-02-12 23:46 - 2014-02-12 23:46 - 00001105 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-02-12 23:46 - 2014-02-12 23:46 - 00000000 ____D () C:\Users\oh\AppData\Roaming\Mozilla
2014-02-12 23:46 - 2014-02-12 23:46 - 00000000 ____D () C:\Users\oh\AppData\Local\Mozilla
2014-02-12 23:46 - 2014-02-12 23:46 - 00000000 ____D () C:\ProgramData\Mozilla
2014-02-12 23:46 - 2014-02-12 23:46 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-02-12 23:46 - 2014-02-12 23:46 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-12 23:44 - 2014-02-12 23:44 - 00002185 _____ () C:\Users\Public\Desktop\avast! SafeZone.lnk
2014-02-12 23:44 - 2014-02-12 23:44 - 00002125 _____ () C:\Users\Public\Desktop\avast! Internet Security.lnk
2014-02-12 23:44 - 2014-02-12 23:44 - 00000000 ____D () C:\Users\oh\AppData\Roaming\AVAST Software
2014-02-12 23:43 - 2014-02-12 23:43 - 00775952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-02-12 23:43 - 2014-02-12 23:43 - 00410784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-02-12 23:43 - 2014-02-12 23:43 - 00270240 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-02-12 23:43 - 2014-02-12 23:43 - 00265072 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys
2014-02-12 23:43 - 2014-02-12 23:43 - 00180248 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-02-12 23:43 - 2014-02-12 23:43 - 00079720 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-02-12 23:43 - 2014-02-12 23:43 - 00067824 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-02-12 23:43 - 2014-02-12 23:43 - 00064168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-02-12 23:43 - 2014-02-12 23:43 - 00049944 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-02-12 23:43 - 2014-02-12 23:43 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-02-12 23:43 - 2014-02-12 23:43 - 00026136 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2014-02-12 23:42 - 2014-02-12 23:42 - 00000000 ____D () C:\Program Files\AVAST Software
2014-02-12 23:41 - 2014-02-13 07:54 - 00085768 _____ () C:\Users\oh\AppData\Local\GDIPFONTCACHEV1.DAT
2014-02-12 23:41 - 2014-02-12 23:41 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-02-12 23:41 - 2012-02-15 06:44 - 00826368 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2014-02-12 23:41 - 2012-02-15 05:22 - 00177152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-02-12 23:41 - 2012-02-15 05:22 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys
2014-02-12 23:41 - 2010-01-09 07:52 - 00132608 _____ (Microsoft Corporation) C:\Windows\system32\cabview.dll
2014-02-12 23:37 - 2012-06-02 23:19 - 01933848 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-02-12 23:37 - 2012-06-02 23:19 - 00577048 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-02-12 23:37 - 2012-06-02 23:19 - 00053784 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-02-12 23:37 - 2012-06-02 23:19 - 00045080 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-02-12 23:37 - 2012-06-02 23:19 - 00035864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-02-12 23:37 - 2012-06-02 23:12 - 02422272 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-02-12 23:37 - 2012-06-02 23:12 - 00088576 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-02-12 23:37 - 2012-06-02 15:19 - 00171904 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-02-12 23:37 - 2012-06-02 15:12 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-02-12 23:35 - 2014-02-12 23:35 - 00000000 ____D () C:\Program Files\CONEXANT
2014-02-12 23:35 - 2012-11-18 21:40 - 00001096 ____N () C:\Windows\system32\Drivers\SamSfPa.dat
2014-02-12 23:35 - 2009-12-16 10:26 - 00168648 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\EED32A.dll
2014-02-12 23:35 - 2009-12-16 10:26 - 00076488 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\EEL32A.dll
2014-02-12 23:35 - 2009-12-16 10:26 - 00062664 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\EEG32A.dll
2014-02-12 23:31 - 2014-02-13 09:12 - 00006656 _____ () C:\Windows\system32\bcmwlrc.dll
2014-02-12 23:31 - 2014-02-12 23:31 - 03872056 _____ (Broadcom Corporation) C:\Windows\system32\bcmihvsrv.dll
2014-02-12 23:31 - 2014-02-12 23:31 - 03764800 _____ (Broadcom Corporation) C:\Windows\system32\Drivers\BCMWL6.SYS
2014-02-12 23:31 - 2014-02-12 23:31 - 03560760 _____ (Broadcom Corporation) C:\Windows\system32\bcmihvui.dll
2014-02-12 23:31 - 2014-02-12 23:31 - 00091448 _____ (Broadcom Corporation) C:\Windows\system32\bcmwlcoi.dll
2014-02-12 23:31 - 2014-02-12 23:31 - 00000000 ____D () C:\Program Files\Broadcom
2014-02-12 23:29 - 2014-02-13 08:59 - 00000000 ____D () C:\Users\oh\AppData\Roaming\Intel
2014-02-12 23:28 - 2014-02-13 08:59 - 00012768 _____ () C:\Windows\DPINST.LOG
2014-02-12 23:28 - 2014-02-12 23:28 - 00000000 ____D () C:\Program Files\Cisco
2014-02-12 23:25 - 2014-02-12 23:25 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2014-02-12 23:02 - 2014-02-13 09:01 - 00006226 _____ () C:\Windows\PFRO.log
2014-02-12 23:02 - 2014-02-12 23:02 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-02-12 23:00 - 2010-06-10 14:15 - 00600680 _____ (NVIDIA Corporation) C:\Windows\system32\nvuninst.exe
2014-02-12 22:59 - 2014-02-12 22:59 - 00000000 ____D () C:\ProgramData\OEM
2014-02-12 22:59 - 2014-02-12 22:59 - 00000000 ____D () C:\Program Files\Acer
2014-02-12 22:59 - 2010-04-07 10:05 - 00204800 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbnet.sys
2014-02-12 22:59 - 2010-03-25 03:08 - 00105984 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ewusbmdm.sys
2014-02-12 22:59 - 2010-03-20 05:06 - 00011136 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_usbenumfilter.sys
2014-02-12 22:59 - 2010-03-20 04:56 - 00101504 _____ (Huawei Technologies Co., Ltd.) C:\Windows\system32\Drivers\ew_hwusbdev.sys
2014-02-12 22:59 - 2010-03-17 07:33 - 00861696 _____ (DiBcom SA) C:\Windows\system32\Drivers\mod7700.sys
2014-02-12 22:59 - 2010-01-18 11:48 - 00027136 _____ (Huawei Tech. Co., Ltd.) C:\Windows\system32\Drivers\ewdcsc.sys
2014-02-12 22:58 - 2014-02-12 22:59 - 00000000 ____D () C:\Program Files\HUAWEI Modem Driver
2014-02-12 22:57 - 2014-02-13 09:19 - 01472002 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-12 22:57 - 2014-02-13 08:59 - 00000000 ____D () C:\Program Files\Intel
2014-02-12 22:56 - 2014-02-12 22:59 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2014-02-12 22:56 - 2014-02-12 22:56 - 00000000 ____D () C:\Users\oh\AppData\Roaming\InstallShield
2014-02-12 22:54 - 2014-02-12 23:53 - 00000000 ____D () C:\Users\oh
2014-02-12 22:54 - 2014-02-12 23:33 - 00000000 ____D () C:\Users\oh\AppData\Local\VirtualStore
2014-02-12 22:54 - 2014-02-12 22:54 - 00001409 _____ () C:\Users\oh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-02-12 22:54 - 2014-02-12 22:54 - 00000020 ___SH () C:\Users\oh\ntuser.ini
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\oh\Startmenü
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\oh\Netzwerkumgebung
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\oh\Druckumgebung
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\oh\Documents\Eigene Musik
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\oh\Documents\Eigene Bilder
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\oh\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\oh\AppData\Local\Verlauf
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\Default\Startmenü
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\Default\Druckumgebung
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Programme
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\ProgramData\Startmenü
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\ProgramData\Dokumente
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 __SHD () C:\Recovery
2014-02-12 22:54 - 2009-07-14 05:42 - 00000000 ___RD () C:\Users\oh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-02-12 22:54 - 2009-07-14 05:37 - 00000000 ___RD () C:\Users\oh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-02-12 22:50 - 2014-02-13 11:38 - 01120871 _____ () C:\Windows\WindowsUpdate.log
2014-02-12 22:47 - 2014-02-12 22:49 - 00001313 _____ () C:\Windows\TSSysprep.log
2014-02-12 22:44 - 2014-02-12 22:54 - 00000000 ____D () C:\Windows\Panther
2014-02-12 22:09 - 2012-11-18 21:56 - 00325672 _____ (Broadcom Corporation) C:\Windows\system32\Drivers\b57nd60x.sys
2014-02-12 22:08 - 2012-11-18 21:40 - 01737272 _____ (Conexant Systems Inc.) C:\Windows\system32\CX32HP25.dll
2014-02-12 22:08 - 2012-11-18 21:40 - 00520760 _____ (Conexant Systems Inc.) C:\Windows\system32\Drivers\CHDRT32.sys
2014-02-12 22:08 - 2012-11-18 21:40 - 00428088 _____ (Conexant Systems, Inc.) C:\Windows\system32\CDolbyExt32.dll
2014-02-12 22:08 - 2012-11-18 21:40 - 00308128 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO.dll
2014-02-12 22:08 - 2012-11-18 21:40 - 00301624 _____ (Conexant Systems, Inc.) C:\Windows\system32\UCI32A55.dll
2014-02-12 22:08 - 2012-11-18 21:40 - 00076344 _____ (Conexant Systems, Inc.) C:\Windows\system32\FMPropPageExt.dll
==================== One Month Modified Files and Folders =======
2014-02-13 12:27 - 2014-02-13 12:26 - 00007505 _____ () C:\Users\oh\Downloads\FRST.txt
2014-02-13 12:26 - 2014-02-13 12:26 - 01141248 _____ (Farbar) C:\Users\oh\Downloads\FRST.exe
2014-02-13 12:26 - 2014-02-13 12:26 - 00000000 ____D () C:\FRST
2014-02-13 11:52 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache
2014-02-13 11:38 - 2014-02-12 22:50 - 01120871 _____ () C:\Windows\WindowsUpdate.log
2014-02-13 11:16 - 2009-07-14 05:34 - 00012208 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-13 11:16 - 2009-07-14 05:34 - 00012208 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-13 09:32 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-02-13 09:22 - 2014-02-12 23:54 - 00000000 ____D () C:\Users\oh\AppData\Roaming\Dropbox
2014-02-13 09:20 - 2014-02-13 09:20 - 00000000 ____D () C:\Users\oh\AppData\Roaming\FLEXnet
2014-02-13 09:19 - 2014-02-12 22:57 - 01472002 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-13 09:14 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-13 09:14 - 2009-07-14 05:39 - 00022369 _____ () C:\Windows\setupact.log
2014-02-13 09:12 - 2014-02-12 23:31 - 00006656 _____ () C:\Windows\system32\bcmwlrc.dll
2014-02-13 09:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\zh-TW
2014-02-13 09:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\zh-HK
2014-02-13 09:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\zh-CN
2014-02-13 09:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\tr-TR
2014-02-13 09:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\th-TH
2014-02-13 09:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\sv-SE
2014-02-13 09:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\sl-SI
2014-02-13 09:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\sk-SK
2014-02-13 09:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\ru-RU
2014-02-13 09:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\ro-RO
2014-02-13 09:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\pt-PT
2014-02-13 09:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\pt-BR
2014-02-13 09:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\pl-PL
2014-02-13 09:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\nl-NL
2014-02-13 09:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\nb-NO
2014-02-13 09:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\lv-LV
2014-02-13 09:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\lt-LT
2014-02-13 09:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\ko-KR
2014-02-13 09:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\ja-JP
2014-02-13 09:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\it-IT
2014-02-13 09:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\hu-HU
2014-02-13 09:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\hr-HR
2014-02-13 09:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\he-IL
2014-02-13 09:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\fr-FR
2014-02-13 09:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\fi-FI
2014-02-13 09:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\et-EE
2014-02-13 09:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\el-GR
2014-02-13 09:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\de-DE
2014-02-13 09:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\bg-BG
2014-02-13 09:12 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\ar-SA
2014-02-13 09:06 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\NDF
2014-02-13 09:01 - 2014-02-12 23:02 - 00006226 _____ () C:\Windows\PFRO.log
2014-02-13 09:01 - 2009-07-14 05:33 - 00341520 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-02-13 08:59 - 2014-02-12 23:29 - 00000000 ____D () C:\Users\oh\AppData\Roaming\Intel
2014-02-13 08:59 - 2014-02-12 23:28 - 00012768 _____ () C:\Windows\DPINST.LOG
2014-02-13 08:59 - 2014-02-12 22:57 - 00000000 ____D () C:\Program Files\Intel
2014-02-13 07:54 - 2014-02-12 23:41 - 00085768 _____ () C:\Users\oh\AppData\Local\GDIPFONTCACHEV1.DAT
2014-02-13 07:53 - 2014-02-13 07:48 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-02-13 07:51 - 2014-02-13 07:51 - 00000000 ____D () C:\Windows\PCHEALTH
2014-02-13 07:51 - 2014-02-13 07:51 - 00000000 ____D () C:\Program Files\Microsoft.NET
2014-02-13 07:51 - 2014-02-13 07:51 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER
2014-02-13 07:51 - 2014-02-13 07:48 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-02-13 07:51 - 2009-07-14 03:37 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-02-13 07:49 - 2014-02-13 07:49 - 00000000 ____D () C:\Program Files\Microsoft Analysis Services
2014-02-13 07:49 - 2009-07-14 09:56 - 00000000 ____D () C:\Windows\ShellNew
2014-02-13 07:49 - 2009-07-14 03:37 - 00000000 ____D () C:\Program Files\Common Files\System
2014-02-13 07:49 - 2009-07-14 03:04 - 00000478 _____ () C:\Windows\win.ini
2014-02-13 07:48 - 2014-02-13 07:48 - 00000000 __RHD () C:\MSOCache
2014-02-13 07:48 - 2014-02-13 07:48 - 00000000 ____D () C:\Users\oh\AppData\Local\Microsoft Help
2014-02-13 07:44 - 2014-02-12 23:53 - 00000000 ____D () C:\ProgramData\Vodafone
2014-02-13 07:42 - 2014-02-13 07:42 - 00000000 ____D () C:\Users\oh\AppData\Roaming\Vodafone
2014-02-13 00:01 - 2014-02-13 00:01 - 07797992 _____ () C:\Users\oh\Downloads\ConnectifyInstaller.exe
2014-02-12 23:56 - 2014-02-12 23:56 - 00000000 ____D () C:\Users\oh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-02-12 23:56 - 2014-02-12 23:56 - 00000000 ____D () C:\Users\oh\AppData\Roaming\DropboxMaster
2014-02-12 23:54 - 2014-02-12 23:54 - 37660568 _____ (Dropbox, Inc.) C:\Users\oh\Downloads\Dropbox 2.6.2.exe
2014-02-12 23:54 - 2014-02-12 23:54 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ew_jubusenum_01007.Wdf
2014-02-12 23:53 - 2014-02-12 23:53 - 00002166 _____ () C:\Users\Public\Desktop\Vodafone Mobile Broadband.lnk
2014-02-12 23:53 - 2014-02-12 23:53 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_vodafone_K3805-z_dc_enum_01009.Wdf
2014-02-12 23:53 - 2014-02-12 22:54 - 00000000 ____D () C:\Users\oh
2014-02-12 23:52 - 2014-02-12 23:52 - 00000000 ____D () C:\Users\oh\AppData\Local\Downloaded Installations
2014-02-12 23:52 - 2014-02-12 23:52 - 00000000 ____D () C:\ProgramData\Macrovision
2014-02-12 23:52 - 2014-02-12 23:52 - 00000000 ____D () C:\ProgramData\FLEXnet
2014-02-12 23:52 - 2014-02-12 23:52 - 00000000 ____D () C:\Program Files\Vodafone
2014-02-12 23:52 - 2014-02-12 23:52 - 00000000 ____D () C:\Program Files\Common Files\InstallShield
2014-02-12 23:51 - 2014-02-12 23:51 - 93522288 _____ () C:\Users\oh\Downloads\vmc_10.3.401.43721_RC1_setup.exe
2014-02-12 23:50 - 2014-02-12 23:50 - 00000000 ____D () C:\ProgramData\eDocPrintPro
2014-02-12 23:50 - 2014-02-12 23:50 - 00000000 ____D () C:\Program Files\GS
2014-02-12 23:50 - 2014-02-12 23:50 - 00000000 ____D () C:\Program Files\Common Files\SipgateFaxdrucker
2014-02-12 23:48 - 2014-02-12 23:48 - 00001067 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-02-12 23:48 - 2014-02-12 23:48 - 00000000 ____D () C:\Users\oh\AppData\Roaming\Malwarebytes
2014-02-12 23:48 - 2014-02-12 23:48 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-02-12 23:48 - 2014-02-12 23:48 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2014-02-12 23:47 - 2014-02-12 23:47 - 00614792 _____ (Chip Digital GmbH) C:\Users\oh\Downloads\Malwarebytes Anti Malware - CHIP-Downloader.exe
2014-02-12 23:46 - 2014-02-12 23:46 - 00001105 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-02-12 23:46 - 2014-02-12 23:46 - 00000000 ____D () C:\Users\oh\AppData\Roaming\Mozilla
2014-02-12 23:46 - 2014-02-12 23:46 - 00000000 ____D () C:\Users\oh\AppData\Local\Mozilla
2014-02-12 23:46 - 2014-02-12 23:46 - 00000000 ____D () C:\ProgramData\Mozilla
2014-02-12 23:46 - 2014-02-12 23:46 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-02-12 23:46 - 2014-02-12 23:46 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-12 23:44 - 2014-02-12 23:44 - 00002185 _____ () C:\Users\Public\Desktop\avast! SafeZone.lnk
2014-02-12 23:44 - 2014-02-12 23:44 - 00002125 _____ () C:\Users\Public\Desktop\avast! Internet Security.lnk
2014-02-12 23:44 - 2014-02-12 23:44 - 00000000 ____D () C:\Users\oh\AppData\Roaming\AVAST Software
2014-02-12 23:43 - 2014-02-12 23:43 - 00775952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-02-12 23:43 - 2014-02-12 23:43 - 00410784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-02-12 23:43 - 2014-02-12 23:43 - 00270240 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-02-12 23:43 - 2014-02-12 23:43 - 00265072 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys
2014-02-12 23:43 - 2014-02-12 23:43 - 00180248 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-02-12 23:43 - 2014-02-12 23:43 - 00079720 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-02-12 23:43 - 2014-02-12 23:43 - 00067824 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-02-12 23:43 - 2014-02-12 23:43 - 00064168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-02-12 23:43 - 2014-02-12 23:43 - 00049944 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-02-12 23:43 - 2014-02-12 23:43 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-02-12 23:43 - 2014-02-12 23:43 - 00026136 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2014-02-12 23:42 - 2014-02-12 23:42 - 00000000 ____D () C:\Program Files\AVAST Software
2014-02-12 23:41 - 2014-02-12 23:41 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-02-12 23:35 - 2014-02-12 23:35 - 00000000 ____D () C:\Program Files\CONEXANT
2014-02-12 23:33 - 2014-02-12 22:54 - 00000000 ____D () C:\Users\oh\AppData\Local\VirtualStore
2014-02-12 23:31 - 2014-02-12 23:31 - 03872056 _____ (Broadcom Corporation) C:\Windows\system32\bcmihvsrv.dll
2014-02-12 23:31 - 2014-02-12 23:31 - 03764800 _____ (Broadcom Corporation) C:\Windows\system32\Drivers\BCMWL6.SYS
2014-02-12 23:31 - 2014-02-12 23:31 - 03560760 _____ (Broadcom Corporation) C:\Windows\system32\bcmihvui.dll
2014-02-12 23:31 - 2014-02-12 23:31 - 00091448 _____ (Broadcom Corporation) C:\Windows\system32\bcmwlcoi.dll
2014-02-12 23:31 - 2014-02-12 23:31 - 00000000 ____D () C:\Program Files\Broadcom
2014-02-12 23:28 - 2014-02-12 23:28 - 00000000 ____D () C:\Program Files\Cisco
2014-02-12 23:25 - 2014-02-12 23:25 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2014-02-12 23:02 - 2014-02-12 23:02 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-02-12 23:01 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Help
2014-02-12 22:59 - 2014-02-12 22:59 - 00000000 ____D () C:\ProgramData\OEM
2014-02-12 22:59 - 2014-02-12 22:59 - 00000000 ____D () C:\Program Files\Acer
2014-02-12 22:59 - 2014-02-12 22:58 - 00000000 ____D () C:\Program Files\HUAWEI Modem Driver
2014-02-12 22:59 - 2014-02-12 22:56 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2014-02-12 22:56 - 2014-02-12 22:56 - 00000000 ____D () C:\Users\oh\AppData\Roaming\InstallShield
2014-02-12 22:56 - 2009-07-14 05:52 - 00000000 ____D () C:\Windows\system32\restore
2014-02-12 22:54 - 2014-02-12 22:54 - 00001409 _____ () C:\Users\oh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-02-12 22:54 - 2014-02-12 22:54 - 00000020 ___SH () C:\Users\oh\ntuser.ini
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\oh\Startmenü
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\oh\Netzwerkumgebung
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\oh\Druckumgebung
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\oh\Documents\Eigene Musik
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\oh\Documents\Eigene Bilder
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\oh\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\oh\AppData\Local\Verlauf
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\Default\Startmenü
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\Default\Druckumgebung
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\Programme
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\ProgramData\Startmenü
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 _SHDL () C:\ProgramData\Dokumente
2014-02-12 22:54 - 2014-02-12 22:54 - 00000000 __SHD () C:\Recovery
2014-02-12 22:54 - 2014-02-12 22:44 - 00000000 ____D () C:\Windows\Panther
2014-02-12 22:54 - 2009-07-14 03:37 - 00000000 __RHD () C:\Users\Default
2014-02-12 22:54 - 2009-07-14 03:37 - 00000000 ____D () C:\Program Files\Windows NT
2014-02-12 22:49 - 2014-02-12 22:47 - 00001313 _____ () C:\Windows\TSSysprep.log
2014-02-12 22:47 - 2009-07-14 09:56 - 00000000 ____D () C:\Windows\CSC
2014-02-12 22:47 - 2009-07-14 05:34 - 00001774 _____ () C:\Windows\DtcInstall.log
2014-02-12 22:44 - 2009-07-14 05:57 - 00025600 ___SH () C:\Windows\system32\config\BCD-Template.LOG
2014-02-12 22:44 - 2009-07-14 05:52 - 00028672 _____ () C:\Windows\system32\config\BCD-Template
Some content of TEMP:
====================
C:\Users\oh\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpy6xebz.dll
C:\Users\oh\AppData\Local\Temp\ose00000.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-02-13 11:43
==================== End Of Log ============================ --- --- ---
--- --- ---
Addition Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 12-02-2014 01
Ran by oh at 2014-02-13 12:27:16
Running from C:\Users\oh\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: avast! Internet Security (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Internet Security (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Internet Security (Enabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
==================== Installed Programs ======================
Acer ePower Management (Version: 5.00.3009 - Acer Incorporated)
avast! Internet Security (Version: 9.0.2013 - Avast Software)
Broadcom 802.11 Network Adapter (Version: 5.100.249.2 - Broadcom Corporation)
Cisco EAP-FAST Module (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (Version: 1.1.6 - Cisco Systems, Inc.)
Conexant HD Audio (Version: 4.121.0.50 - Conexant)
Dropbox (HKCU Version: 2.6.2 - Dropbox, Inc.)
HUAWEI DataCard Driver 4.05.02.00 (Version: 4.05.02.00 - Huawei technologies Co., Ltd.)
Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300 - Malwarebytes Corporation)
Microsoft Office Access MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional 2010 (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Proof (English) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Single Image 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Mozilla Firefox 22.0 (x86 de) (Version: 22.0 - Mozilla)
Mozilla Maintenance Service (Version: 22.0 - Mozilla)
NVIDIA Drivers (Version: 1.10 - NVIDIA Corporation)
sipgate Faxdrucker (Version: 1.0.0 - sipgate GmbH)
Überwachungstool für die Intel® Turbo-Boost-Technik (Version: 1.0.186.6 - Intel)
Vodafone Mobile Broadband (Version: 10.3.401.43721 - Vodafone)
==================== Restore Points =========================
12-02-2014 21:56:49 Installiert Überwachungstool für die Intel® Turbo-Boost-Technik
12-02-2014 21:57:14 Installed Intel(R) Turbo Boost Technology Monitor.
12-02-2014 21:59:44 Installiert Acer ePower Management
12-02-2014 22:28:01 Installed Intel(R) PROSet/Wireless WiFi Software.
12-02-2014 22:37:03 Windows Update
12-02-2014 22:41:02 Windows Update
12-02-2014 22:42:03 avast! antivirus system restore point
12-02-2014 22:43:53 Gerätetreiber-Paketinstallation: Avast Netzwerkdienst
12-02-2014 22:49:46 Installed sipgate Faxdrucker
12-02-2014 22:52:34 Installed Vodafone Mobile Broadband.
13-02-2014 06:47:58 Installed Microsoft Office Professional 2010
13-02-2014 07:57:47 Removed Intel(R) PROSet/Wireless WiFi-Software.
==================== Hosts content: ==========================
2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {A8F4DCF0-2159-43B5-8C60-A64185AA63BB} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-02-12] (AVAST Software)
==================== Loaded Modules (whitelisted) =============
2014-02-12 23:43 - 2014-02-12 23:43 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2009-07-13 22:03 - 2009-07-14 02:15 - 00364544 _____ () C:\Windows\system32\msjetoledb40.dll
2014-02-13 09:15 - 2014-02-13 09:15 - 00041984 _____ () c:\users\oh\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpy6xebz.dll
2013-10-19 00:55 - 2013-10-19 00:55 - 25100288 _____ () C:\Users\oh\AppData\Roaming\Dropbox\bin\libcef.dll
2014-02-12 23:46 - 2013-06-18 15:21 - 03285912 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll
2010-01-30 02:41 - 2010-01-30 02:41 - 04254560 _____ () C:\Program Files\Common Files\Microsoft Shared\office14\Cultures\office.odf
2010-02-28 02:55 - 2010-02-28 02:55 - 01040736 _____ () C:\Program Files\Microsoft Office\Office14\ADDINS\UmOutlookAddin.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
==================== Disabled items from MSCONFIG ==============
==================== Faulty Device Manager Devices =============
Name: PCI-Kommunikationscontroller (einfach)
Description: PCI-Kommunikationscontroller (einfach)
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: FingerPrinter Reader
Description: FingerPrinter Reader
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (02/13/2014 09:03:44 AM) (Source: Office Software Protection Platform Service) (User: )
Description: Acquisition of Secure Processor Certificate failed. hr=0x80072EE7
Error: (02/13/2014 09:03:44 AM) (Source: Office Software Protection Platform Service) (User: )
Description: License acquisition failure details.
hr=0x80072EE7
Error: (02/13/2014 08:14:23 AM) (Source: Office Software Protection Platform Service) (User: )
Description: Acquisition of Secure Processor Certificate failed. hr=0x80072EE7
Error: (02/13/2014 08:14:23 AM) (Source: Office Software Protection Platform Service) (User: )
Description: License acquisition failure details.
hr=0x80072EE7
Error: (02/13/2014 07:56:10 AM) (Source: Office Software Protection Platform Service) (User: )
Description: Acquisition of Secure Processor Certificate failed. hr=0x80072EE7
Error: (02/13/2014 07:56:10 AM) (Source: Office Software Protection Platform Service) (User: )
Description: License acquisition failure details.
hr=0x80072EE7
Error: (02/13/2014 07:53:00 AM) (Source: Office Software Protection Platform Service) (User: )
Description: Acquisition of Secure Processor Certificate failed. hr=0x80072EE7
Error: (02/13/2014 07:53:00 AM) (Source: Office Software Protection Platform Service) (User: )
Description: License acquisition failure details.
hr=0x80072EE7
Error: (02/13/2014 07:47:56 AM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert
.
Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess.
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {cddba2f9-50de-40c6-8df1-ef44051a25e6}
Error: (02/12/2014 10:56:49 PM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert
.
Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess.
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {0a9e2df2-af72-4e0c-8a98-fb26589c4b75}
System errors:
=============
Error: (02/13/2014 08:56:13 AM) (Source: BTHUSB) (User: )
Description: Der lokale Bluetooth-Adapter ist aus einem unbekannten Grund fehlgeschlagen und wird nicht verwendet. Der Treiber wurde entladen.
Error: (02/12/2014 11:41:38 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "kwxjrvfe" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (02/12/2014 10:50:26 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Update" wurde mit folgendem Fehler beendet:
%%-2147467243
Microsoft Office Sessions:
=========================
Error: (02/13/2014 09:03:44 AM) (Source: Office Software Protection Platform Service)(User: )
Description: hr=0x80072EE78b559c37-0117-413e-921b-b853aeb6e210
Error: (02/13/2014 09:03:44 AM) (Source: Office Software Protection Platform Service)(User: )
Description: hr=0x80072EE700010001(0x00000000, 09:03:44:900 - hxxp://go.microsoft.com/fwlink/?LinkID=120748)
00020001(0x00000000, 09:03:44:900)
00030001(0x00000000, 09:03:44:900 - hxxp://go.microsoft.com)
00030002(0x00000000, 09:03:44:900 - 0)
00040001(0x00000000, 09:03:44:900 - hxxp://go.microsoft.com)
00040002(0x00000000, 09:03:44:916 - 1, <NULL>, <NULL>, <NULL>)
00040004(0x80072F94, 09:03:44:932 - <NULL>)
00040006(0x00000000, 09:03:44:932 - 1, hxxp://go.microsoft.com, <NULL>, <local>)
00020005(0x00000000, 09:03:44:932 - 0)
00020007(0x80072EE7, 09:03:44:932)
00010002(0x80072EE7, 09:03:44:932 - <NULL>)
00010003(0x80072EE7, 09:03:44:932)
Error: (02/13/2014 08:14:23 AM) (Source: Office Software Protection Platform Service)(User: )
Description: hr=0x80072EE78b559c37-0117-413e-921b-b853aeb6e210
Error: (02/13/2014 08:14:23 AM) (Source: Office Software Protection Platform Service)(User: )
Description: hr=0x80072EE700010001(0x00000000, 08:14:23:884 - hxxp://go.microsoft.com/fwlink/?LinkID=120748)
00020001(0x00000000, 08:14:23:884)
00030001(0x00000000, 08:14:23:899 - hxxp://go.microsoft.com)
00030002(0x00000000, 08:14:23:899 - 0)
00040001(0x00000000, 08:14:23:899 - hxxp://go.microsoft.com)
00040002(0x00000000, 08:14:23:915 - 1, <NULL>, <NULL>, <NULL>)
00040004(0x80072F94, 08:14:23:930 - <NULL>)
00040006(0x00000000, 08:14:23:930 - 1, hxxp://go.microsoft.com, <NULL>, <local>)
00020005(0x00000000, 08:14:23:930 - 0)
00020007(0x80072EE7, 08:14:23:930)
00010002(0x80072EE7, 08:14:23:930 - <NULL>)
00010003(0x80072EE7, 08:14:23:930)
Error: (02/13/2014 07:56:10 AM) (Source: Office Software Protection Platform Service)(User: )
Description: hr=0x80072EE78b559c37-0117-413e-921b-b853aeb6e210
Error: (02/13/2014 07:56:10 AM) (Source: Office Software Protection Platform Service)(User: )
Description: hr=0x80072EE700010001(0x00000000, 07:56:10:340 - hxxp://go.microsoft.com/fwlink/?LinkID=120748)
00020001(0x00000000, 07:56:10:355)
00030001(0x00000000, 07:56:10:371 - hxxp://go.microsoft.com)
00030002(0x00000000, 07:56:10:371 - 0)
00040001(0x00000000, 07:56:10:371 - hxxp://go.microsoft.com)
00040002(0x00000000, 07:56:10:371 - 1, <NULL>, <NULL>, <NULL>)
00040004(0x80072F94, 07:56:10:402 - <NULL>)
00040006(0x00000000, 07:56:10:402 - 1, hxxp://go.microsoft.com, <NULL>, <local>)
00020005(0x00000000, 07:56:10:402 - 0)
00020007(0x80072EE7, 07:56:10:402)
00010002(0x80072EE7, 07:56:10:402 - <NULL>)
00010003(0x80072EE7, 07:56:10:402)
Error: (02/13/2014 07:53:00 AM) (Source: Office Software Protection Platform Service)(User: )
Description: hr=0x80072EE78b559c37-0117-413e-921b-b853aeb6e210
Error: (02/13/2014 07:53:00 AM) (Source: Office Software Protection Platform Service)(User: )
Description: hr=0x80072EE700010001(0x00000000, 07:53:00:218 - hxxp://go.microsoft.com/fwlink/?LinkID=120748)
00020001(0x00000000, 07:53:00:265)
00030001(0x00000000, 07:53:00:296 - hxxp://go.microsoft.com)
00030002(0x00000000, 07:53:00:296 - 0)
00040001(0x00000000, 07:53:00:296 - hxxp://go.microsoft.com)
00040002(0x00000000, 07:53:00:312 - 1, <NULL>, <NULL>, <NULL>)
00040004(0x80072F94, 07:53:00:374 - <NULL>)
00040006(0x00000000, 07:53:00:374 - 1, hxxp://go.microsoft.com, <NULL>, <local>)
00020005(0x00000000, 07:53:00:374 - 0)
00020007(0x80072EE7, 07:53:00:374)
00010002(0x80072EE7, 07:53:00:374 - <NULL>)
00010003(0x80072EE7, 07:53:00:374)
Error: (02/13/2014 07:47:56 AM) (Source: VSS)(User: )
Description: 0x80070005, Zugriff verweigert
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {cddba2f9-50de-40c6-8df1-ef44051a25e6}
Error: (02/12/2014 10:56:49 PM) (Source: VSS)(User: )
Description: 0x80070005, Zugriff verweigert
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {0a9e2df2-af72-4e0c-8a98-fb26589c4b75}
==================== Memory info ===========================
Percentage of memory in use: 61%
Total physical RAM: 2356.4 MB
Available physical RAM: 909.93 MB
Total Pagefile: 4711.08 MB
Available Pagefile: 3020.21 MB
Total Virtual: 2047.88 MB
Available Virtual: 1883.36 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:97.66 GB) (Free:81.49 GB) NTFS
Drive d: () (Fixed) (Total:187.33 GB) (Free:20.4 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: AABD5AB5)
Partition 1: (Not Active) - (Size=13 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=98 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=187 GB) - (Type=07 NTFS)
==================== End Of Log ============================ |