Dies sind die Logs FRST
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-10-2014 01
Ran by Gian-Luca (administrator) on GIAN-LUCA-PC on 09-10-2014 22:17:07
Running from C:\Users\Gian-Luca\Downloads
Loaded Profile: Gian-Luca (Available profiles: Gian-Luca)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe
(ASUS) C:\Program Files (x86)\ASUS\SmartLogon\smartlogon.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(ASUS) C:\Program Files (x86)\Common Files\InstantOn\InsOnSrv.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE
(SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(ASUS) C:\Program Files (x86)\Common Files\InstantOn\InsOnWMI.exe
(ASUS) C:\Program Files\P4G\BatteryLife.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(ASUS) C:\Windows\AsScrPro.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATIFCE.EXE
(Virage Logic Corporation / Sonic Focus) C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(ASUS) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
() C:\Windows\SysWOW64\ArchiveDesktopMBR\ArchiveDesktopMBR.exe
() C:\Program Files (x86)\eDealsPop\eDealsPop.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
() C:\Program Files (x86)\Bench\BService\1.1\bservice.exe
() C:\Program Files (x86)\Bench\BService\1.1\bservice64.exe
() C:\Program Files (x86)\Bench\Wd\wd.exe
() C:\Program Files (x86)\LPT\srpts.exe
() C:\Program Files (x86)\LPT\srptsl.exe
() C:\Users\Gian-Luca\AppData\Local\Smartbar\Application\Lrcnta.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2785064 2011-05-05] (Synaptics Incorporated)
HKLM\...\Run: [SynAsusAcpi] => C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe [97064 2011-05-05] (Synaptics Incorporated)
HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [361984 2011-03-21] (Alcor Micro Corp.)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2277480 2011-08-16] (Realtek Semiconductor)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2018032 2011-04-13] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe [731472 2011-02-23] (ecareme)
HKLM-x32\...\Run: [SonicMasterTray] => C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe [984400 2010-07-10] (Virage Logic Corporation / Sonic Focus)
HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5716608 2011-07-22] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS)
HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2317312 2011-09-09] (ASUS)
HKLM-x32\...\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
HKLM-x32\...\Run: [TkBellExe] => C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [296056 2012-03-13] (RealNetworks, Inc.)
HKLM-x32\...\Run: [eDealsPop] => C:\Program Files (x86)\eDealsPop\eDealsPop.exe [7168 2014-07-17] ()
HKLM-x32\...\Run: [BService] => C:\Program Files (x86)\Bench\BService\1.1\bservice.exe [52736 2014-08-20] ()
HKLM-x32\...\Run: [BService64] => C:\Program Files (x86)\Bench\BService\1.1\bservice64.exe [110592 2014-08-20] ()
HKLM-x32\...\Run: [Wd] => C:\Program Files (x86)\Bench\Wd\wd.exe [92672 2014-08-20] ()
HKLM-x32\...\Run: [Bench Communicator Watcher] => C:\Program Files (x86)\Bench\Proxy\pwdg.exe [127488 2014-09-10] ()
HKLM-x32\...\Run: [Bench Settings Cleaner] => C:\Program Files (x86)\Bench\Proxy\cl.exe [62464 2014-09-10] ()
HKLM-x32\...\RunOnce: [Browser Guardian-repairJob] => wscript.exe "C:\Users\Gian-Luca\AppData\Local\Browser Guardian\repair.js" "Browser Guardian-repairJob"
HKLM-x32\...\RunOnce: [Browser Guardian] => [X]
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-4134278005-4231936906-4289131000-1000\...\Run: [Facebook Update] => C:\Users\Gian-Luca\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-07-15] (Facebook Inc.)
HKU\S-1-5-21-4134278005-4231936906-4289131000-1000\...\Run: [EPSON SX410 Series] => C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIFCE.EXE [223232 2008-10-02] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-4134278005-4231936906-4289131000-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21648480 2014-07-02] (Skype Technologies S.A.)
HKU\S-1-5-21-4134278005-4231936906-4289131000-1000\...\Run: [Browser Infrastructure Helper] => C:\Users\Gian-Luca\AppData\Local\Smartbar\Application\Smartbar.exe [28192 2014-08-27] (Smartbar)
HKU\S-1-5-21-4134278005-4231936906-4289131000-1000\...\MountPoints2: {6badf02d-68d9-11e3-9e8d-5404a62e86ba} - G:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-4134278005-4231936906-4289131000-1000\...\MountPoints2: {97078c51-fb3c-11e2-9529-806e6f6e6963} - F:\MotorolaDeviceManagerSetup.exe -a
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk
ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FancyStart daemon.lnk
ShortcutTarget: FancyStart daemon.lnk -> C:\Windows\Installer\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}\_77B5857C27147149171BE7.exe ()
ShellIconOverlayIdentifiers: [AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\ASUSWSShellExt64.dll (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers: [AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\ASUSWSShellExt64.dll (eCareme Technologies, Inc.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyEnable: Internet Explorer proxy is enabled.
ProxyServer: http=127.0.0.1:38159
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_XV5fOZfN0BxybFzRxFN69h7ZazaAjARoertXR_8aj33qBk_a-i-Oe6LTDIzNYLWi6eIP0YGSekdrotLxanhzaeDxrNhnbXHLNPcLfF0UeinesXP8aaVulcHJTIXlr6Vzw4oDiIIgaFYRYhSYNEXxw,,&q={searchTerms}
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_XV5fOZfN0BxybFzRxFN69h7ZazaAjARoertXR_8aj33qBk_a-i-Oe6LTDIzNYLWi6eIP0YGSekdrotLxanhzaePFF2zWCi7vCK9IX5t_RNtHRUJLLkHQiNF1IlTaW8kAmpX2Z9s7Pl_Y85fcLXmjA,,
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_XV5fOZfN0BxybFzRxFN69h7ZazaAjARoertXR_8aj33qBk_a-i-Oe6LTDIzNYLWi6eIP0YGSekdrotLxanhzaeDxrNhnbXHLNPcLfF0UeinesXP8aaVulcHJTIXlr6Vzw4oDiIIgaFYRYhSYNEXxw,,&q={searchTerms}
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_XV5fOZfN0BxybFzRxFN69h7ZazaAjARoertXR_8aj33qBk_a-i-Oe6LTDIzNYLWi6eIP0YGSekdrotLxanhzaeDxrNhnbXHLNPcLfF0UeinesXP8aaVulcHJTIXlr6Vzw4oDiIIgaFYRYhSYNEXxw,,&q={searchTerms}
SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_XV5fOZfN0BxybFzRxFN69h7ZazaAjARoertXR_8aj33qBk_a-i-Oe6LTDIzNYLWi6eIP0YGSekdrotLxanhzaeDxrNhnbXHLNPcLfF0UeinesXP8aaVulcHJTIXlr6Vzw4oDiIIgaFYRYhSYNEXxw,,&q={searchTerms}
SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_XV5fOZfN0BxybFzRxFN69h7ZazaAjARoertXR_8aj33qBk_a-i-Oe6LTDIzNYLWi6eIP0YGSekdrotLxanhzaeDxrNhnbXHLNPcLfF0UeinesXP8aaVulcHJTIXlr6Vzw4oDiIIgaFYRYhSYNEXxw,,&q={searchTerms}
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_XV5fOZfN0BxybFzRxFN69h7ZazaAjARoertXR_8aj33qBk_a-i-Oe6LTDIzNYLWi6eIP0YGSekdrotLxanhzaeDxrNhnbXHLNPcLfF0UeinesXP8aaVulcHJTIXlr6Vzw4oDiIIgaFYRYhSYNEXxw,,&q={searchTerms}
BHO: Shopping Helper SmartbarEngine -> {31ad400d-1b06-4e33-a59a-90c2c140cba0} -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)
BHO: Browser Guardian BHO -> {8EB46C6E-FBA0-4915-841F-48D7EE9EA777} -> C:\Program Files (x86)\Browser Guardian\FrameworkBHO64.dll ()
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Shopping Helper SmartbarEngine -> {31ad400d-1b06-4e33-a59a-90c2c140cba0} -> C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: Browser Guardian BHO -> {8EB46C6E-FBA0-4915-841F-48D7EE9EA777} -> C:\Program Files (x86)\Browser Guardian\FrameworkBHO.dll ()
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
Toolbar: HKLM - Shopping Helper Smartbar - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\system32\mscoree.dll (Microsoft Corporation)
Toolbar: HKLM-x32 - Shopping Helper Smartbar - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
Hosts: 54.225.95.126 jkmdneioiggpdolicemlcchhiepfhebm
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=15.0.2.72 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprjplug;version=15.0.2.72 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpchromebrowserrecordext;version=15.0.2.72 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprphtml5videoshim;version=15.0.2.72 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpjplug;version=15.0.2.72 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: ZEON/PDF,version=2.0 -> C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Gian-Luca\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
Chrome:
=======
CHR HomePage: Default -> 2E533DD8941321923470521D803B4C0AE3CD24BD0D12598FAD78FC8D9D26956E
CHR Profile: C:\Users\Gian-Luca\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Gian-Luca\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-10-06]
CHR Extension: (Google Wallet) - C:\Users\Gian-Luca\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-10-06]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 ArchiveDesktopMBR; C:\Windows\SysWOW64\ArchiveDesktopMBR\ArchiveDesktopMBR.exe [60965 2014-07-28] () [File not signed]
R2 LPTSystemUpdater; C:\Program Files (x86)\LPT\srpts.exe [32800 2014-08-27] () <==== ATTENTION
S2 CursorPrivacyUtility.exe; C:\Users\Gian-Luca\AppData\Local\CursorPrivacyUtility\CursorPrivacyUtility.exe [X]
S2 DesktopMacroProcess.exe; C:\Users\Gian-Luca\AppData\Local\DesktopMacroProcess\DesktopMacroProcess.exe [X]
S2 RawSharewareTrash.exe; C:\Users\Gian-Luca\AppData\Local\RawSharewareTrash\RawSharewareTrash.exe [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S1 hyoqinbb; \??\C:\Windows\system32\drivers\hyoqinbb.sys [X]
S3 RgFltX64; \??\C:\Users\Gian-Luca\AppData\Local\DesktopMacroProcess\RgFltX64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-10-09 22:17 - 2014-10-09 22:17 - 00017689 _____ () C:\Users\Gian-Luca\Downloads\FRST.txt
2014-10-09 22:15 - 2014-10-09 22:16 - 00000000 ____D () C:\Users\Gian-Luca\Desktop\Trojaner
2014-10-09 22:11 - 2014-10-09 22:17 - 00000000 ____D () C:\FRST
2014-10-09 21:50 - 2014-10-09 21:50 - 00002658 _____ () C:\Users\Gian-Luca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-10-09 21:50 - 2014-10-09 21:50 - 00000000 ____D () C:\Program Files (x86)\LPT
2014-10-09 21:49 - 2014-10-09 21:49 - 00050477 _____ () C:\Users\Gian-Luca\Downloads\Nicht bestätigt 226186.crdownload
2014-10-09 21:49 - 2014-10-09 21:49 - 00000000 ____D () C:\Users\Gian-Luca\AppData\Local\Smartbar
2014-10-09 21:49 - 2014-10-09 21:49 - 00000000 ____D () C:\Users\Gian-Luca\AppData\Local\LPT
2014-10-09 21:49 - 2014-10-09 21:49 - 00000000 _____ () C:\Users\Gian-Luca\defogger_reenable
2014-10-09 21:48 - 2014-10-09 22:02 - 00000352 _____ () C:\Windows\Tasks\bench-sys.job
2014-10-09 21:48 - 2014-10-09 21:56 - 00000003 _____ () C:\Users\Gian-Luca\AppData\Local\proxy.log
2014-10-09 21:48 - 2014-10-09 21:51 - 00000352 _____ () C:\Windows\Tasks\bench-S-1-5-21-4134278005-4231936906-4289131000-1000.job
2014-10-09 21:48 - 2014-10-09 21:48 - 00050477 _____ () C:\Users\Gian-Luca\Downloads\Defogger.exe
2014-10-09 21:48 - 2014-10-09 21:48 - 00003248 _____ () C:\Windows\System32\Tasks\bench-sys
2014-10-09 21:48 - 2014-10-09 21:48 - 00003234 _____ () C:\Windows\System32\Tasks\bench-S-1-5-21-4134278005-4231936906-4289131000-1000
2014-10-09 21:48 - 2014-10-09 21:48 - 00000000 ____D () C:\Users\Gian-Luca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Browser Guardian
2014-10-09 21:48 - 2014-10-09 21:48 - 00000000 ____D () C:\Users\Gian-Luca\AppData\Local\Browser Guardian
2014-10-09 21:48 - 2014-10-09 21:48 - 00000000 ____D () C:\Users\Gian-Luca\AppData\Local\BenchUpdater
2014-10-09 21:48 - 2014-10-09 21:48 - 00000000 ____D () C:\Program Files (x86)\Browser Guardian
2014-10-09 21:48 - 2014-10-09 21:48 - 00000000 ____D () C:\Program Files (x86)\Bench
2014-10-09 21:33 - 2014-10-09 21:33 - 00000000 ____D () C:\Program Files (x86)\eDealsPop
2014-10-09 21:26 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-10-09 21:25 - 2014-10-09 21:27 - 00000000 ____D () C:\AdwCleaner
2014-10-09 21:23 - 2014-10-09 21:23 - 01375089 _____ () C:\Users\Gian-Luca\Downloads\adwcleaner_3.311.exe
2014-10-08 19:04 - 2014-10-08 19:04 - 00000000 ____D () C:\Users\Gian-Luca\AppData\Local\{B703F160-554A-4CD7-8A52-FC15380BDFD7}
2014-10-06 20:46 - 2014-10-06 20:46 - 00002253 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-10-06 20:46 - 2014-10-06 20:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-10-01 20:30 - 2014-09-25 04:08 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-10-01 20:30 - 2014-09-25 03:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2014-09-30 18:49 - 2014-09-30 20:09 - 00015849 _____ () C:\Users\Gian-Luca\Desktop\Französisch.odt
2014-09-25 20:43 - 2014-09-25 20:43 - 00013797 _____ () C:\Users\Gian-Luca\Desktop\Finanzen.ods
2014-09-23 19:47 - 2014-09-10 00:11 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-09-23 19:47 - 2014-09-09 23:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-09-21 20:26 - 2014-09-21 20:26 - 00000000 ____D () C:\Users\Gian-Luca\AppData\Local\{851F323C-40CF-41B7-A8CC-45E02E1C45F1}
2014-09-18 19:59 - 2014-10-08 19:38 - 00000000 ____D () C:\Users\Gian-Luca\Desktop\Rebellution
2014-09-18 17:25 - 2014-09-18 17:25 - 00000000 ____D () C:\Program Files (x86)\tooPbuyer
2014-09-17 11:15 - 2014-09-19 13:28 - 00000000 ____D () C:\ProgramData\tooPbuyer
2014-09-17 10:38 - 2014-09-17 10:38 - 00000000 ____D () C:\Users\Gian-Luca\AppData\Local\{34A929FC-CFA0-4CF7-B500-C35208DD506E}
2014-09-17 10:37 - 2014-09-17 10:37 - 00000000 ____D () C:\Users\Gian-Luca\AppData\Local\{C06501AE-5144-4FB9-AC24-5BC883DBF02D}
2014-09-14 23:07 - 2014-09-13 16:35 - 00000000 ____D () C:\Users\Gian-Luca\Desktop\5tracks+tür
2014-09-14 22:12 - 2014-09-14 22:12 - 00000000 ____D () C:\Program Files (x86)\AopptioUo
2014-09-14 22:07 - 2014-10-09 21:48 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-09-14 22:07 - 2014-09-15 12:10 - 00000000 ____D () C:\Support
2014-09-14 22:07 - 2014-09-14 22:07 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google
2014-09-14 22:07 - 2014-09-14 22:07 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo
2014-09-14 22:07 - 2014-09-14 22:07 - 00000000 ____D () C:\Users\HomeGroupUser$
2014-09-14 22:07 - 2014-09-14 22:07 - 00000000 ____D () C:\Users\Gian-Luca\AppData\Local\Comodo
2014-09-14 22:07 - 2014-09-14 22:07 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google
2014-09-14 22:07 - 2014-09-14 22:07 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo
2014-09-14 22:07 - 2014-09-14 22:07 - 00000000 ____D () C:\Users\Gast
2014-09-14 22:07 - 2014-09-14 22:07 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-09-14 22:07 - 2014-09-14 22:07 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-09-14 22:07 - 2014-09-14 22:07 - 00000000 ____D () C:\Users\Administrator
2014-09-12 18:12 - 2014-08-19 20:05 - 00374968 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-09-12 18:12 - 2014-08-19 19:39 - 00327872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-09-12 18:12 - 2014-08-19 01:01 - 23591424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-09-12 18:12 - 2014-08-19 00:29 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-09-12 18:12 - 2014-08-19 00:29 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-09-12 18:12 - 2014-08-19 00:26 - 17455104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-09-12 18:12 - 2014-08-19 00:20 - 02793984 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-09-12 18:12 - 2014-08-19 00:19 - 05833728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-09-12 18:12 - 2014-08-19 00:15 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-09-12 18:12 - 2014-08-19 00:15 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-09-12 18:12 - 2014-08-19 00:14 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-09-12 18:12 - 2014-08-19 00:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-09-12 18:12 - 2014-08-19 00:08 - 04232704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-09-12 18:12 - 2014-08-19 00:08 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-09-12 18:12 - 2014-08-19 00:08 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-09-12 18:12 - 2014-08-19 00:05 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-09-12 18:12 - 2014-08-19 00:03 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-09-12 18:12 - 2014-08-19 00:03 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-09-12 18:12 - 2014-08-19 00:03 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-09-12 18:12 - 2014-08-18 23:57 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-09-12 18:12 - 2014-08-18 23:56 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-09-12 18:12 - 2014-08-18 23:51 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-09-12 18:12 - 2014-08-18 23:46 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-09-12 18:12 - 2014-08-18 23:45 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-09-12 18:12 - 2014-08-18 23:45 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-09-12 18:12 - 2014-08-18 23:44 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-09-12 18:12 - 2014-08-18 23:44 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-09-12 18:12 - 2014-08-18 23:42 - 02185728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-09-12 18:12 - 2014-08-18 23:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-09-12 18:12 - 2014-08-18 23:39 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-09-12 18:12 - 2014-08-18 23:39 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-09-12 18:12 - 2014-08-18 23:39 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-09-12 18:12 - 2014-08-18 23:38 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-09-12 18:12 - 2014-08-18 23:37 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-09-12 18:12 - 2014-08-18 23:36 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-09-12 18:12 - 2014-08-18 23:35 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-09-12 18:12 - 2014-08-18 23:27 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-09-12 18:12 - 2014-08-18 23:25 - 00727040 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-09-12 18:12 - 2014-08-18 23:25 - 00707072 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-09-12 18:12 - 2014-08-18 23:23 - 02104832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-09-12 18:12 - 2014-08-18 23:23 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-09-12 18:12 - 2014-08-18 23:22 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-09-12 18:12 - 2014-08-18 23:19 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-09-12 18:12 - 2014-08-18 23:17 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-09-12 18:12 - 2014-08-18 23:17 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-09-12 18:12 - 2014-08-18 23:16 - 13588480 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-09-12 18:12 - 2014-08-18 23:15 - 11769856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-09-12 18:12 - 2014-08-18 23:15 - 02310656 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-09-12 18:12 - 2014-08-18 23:09 - 00603136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-09-12 18:12 - 2014-08-18 23:08 - 02014208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-09-12 18:12 - 2014-08-18 23:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-09-12 18:12 - 2014-08-18 22:55 - 01447424 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-09-12 18:12 - 2014-08-18 22:46 - 01812992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-09-12 18:12 - 2014-08-18 22:38 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-09-12 18:12 - 2014-08-18 22:38 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-09-12 18:12 - 2014-08-18 22:36 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-09-12 17:57 - 2014-06-27 04:08 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-09-12 17:57 - 2014-06-27 03:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2014-09-12 15:48 - 2014-08-01 13:53 - 01031168 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-09-12 15:48 - 2014-08-01 13:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-09-12 15:48 - 2014-06-24 05:29 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-09-12 15:48 - 2014-06-24 04:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-09-12 15:47 - 2014-09-05 04:10 - 00578048 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-09-12 15:47 - 2014-09-05 04:05 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-09-12 15:47 - 2014-07-07 04:06 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-09-12 15:47 - 2014-07-07 04:06 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-09-12 15:47 - 2014-07-07 03:40 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-09-12 15:47 - 2014-07-07 03:40 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-09-12 15:47 - 2014-07-07 03:39 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-09-09 16:19 - 2014-09-20 15:57 - 00000004 _____ () C:\Users\Gian-Luca\AppData\Roaming\appdataFr2.bin
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-10-09 22:15 - 2009-07-14 06:45 - 00018512 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-10-09 22:15 - 2009-07-14 06:45 - 00018512 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-10-09 21:56 - 2013-03-06 21:18 - 00000000 ____D () C:\Users\Gian-Luca\AppData\Roaming\Skype
2014-10-09 21:50 - 2013-09-17 08:49 - 00001116 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-10-09 21:49 - 2011-12-15 22:43 - 00000000 ____D () C:\Users\Gian-Luca
2014-10-09 21:48 - 2011-11-01 04:32 - 01304047 _____ () C:\Windows\WindowsUpdate.log
2014-10-09 21:43 - 2013-03-01 21:50 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-10-09 21:33 - 2012-01-03 19:22 - 00001154 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4134278005-4231936906-4289131000-1000UA.job
2014-10-09 21:29 - 2013-09-17 08:49 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-10-09 21:29 - 2011-12-15 22:44 - 00045056 _____ () C:\Windows\SysWOW64\acovcnt.exe
2014-10-09 21:29 - 2011-12-15 22:44 - 00000000 ___HD () C:\ASUS.DAT
2014-10-09 21:28 - 2011-04-13 03:39 - 00383460 _____ () C:\Windows\PFRO.log
2014-10-09 21:28 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-09 21:28 - 2009-07-14 06:51 - 00170347 _____ () C:\Windows\setupact.log
2014-10-09 21:27 - 2014-05-09 21:15 - 00001005 _____ () C:\Users\Gian-Luca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-10-09 21:12 - 2012-03-13 22:06 - 00003356 _____ () C:\Windows\System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-4134278005-4231936906-4289131000-1000
2014-10-09 21:12 - 2012-03-13 22:06 - 00003230 _____ () C:\Windows\System32\Tasks\RealUpgradeLogonTaskS-1-5-21-4134278005-4231936906-4289131000-1000
2014-10-08 19:05 - 2011-02-19 06:24 - 00711094 _____ () C:\Windows\system32\perfh007.dat
2014-10-08 19:05 - 2011-02-19 06:24 - 00153542 _____ () C:\Windows\system32\perfc007.dat
2014-10-08 19:05 - 2009-07-14 07:13 - 01651444 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-10-06 20:46 - 2011-04-13 04:33 - 00000000 ____D () C:\Program Files (x86)\Google
2014-10-06 20:45 - 2013-09-17 08:49 - 00004112 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-10-06 20:45 - 2013-09-17 08:49 - 00003860 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-10-06 20:45 - 2011-12-15 23:49 - 00000000 ____D () C:\Users\Gian-Luca\AppData\Local\Deployment
2014-10-06 20:20 - 2014-08-17 11:38 - 00000000 ____D () C:\ProgramData\23bbdd05ffdf2e16
2014-10-04 15:33 - 2012-01-03 19:22 - 00001132 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4134278005-4231936906-4289131000-1000Core.job
2014-10-01 20:18 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-09-27 22:02 - 2014-08-03 21:29 - 00016775 _____ () C:\Users\Gian-Luca\Desktop\Plan + Mikros.ods
2014-09-26 23:05 - 2011-12-24 20:27 - 00000000 ____D () C:\Users\Gian-Luca\AppData\Local\Windows Live
2014-09-25 21:24 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-09-15 12:18 - 2011-11-01 04:53 - 00001523 _____ () C:\Windows\system32\ServiceFilter.ini
2014-09-15 12:10 - 2014-09-04 18:58 - 00000000 ____D () C:\ProgramData\AopptioUo
2014-09-15 09:06 - 2012-01-17 20:24 - 00278152 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-09-14 22:07 - 2011-12-15 23:50 - 00000000 ____D () C:\Users\Gian-Luca\AppData\Local\Google
2014-09-14 22:07 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-09-14 22:07 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-09-12 18:10 - 2012-01-08 20:47 - 01625724 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-09-12 18:08 - 2013-08-01 11:50 - 00000000 ____D () C:\Windows\system32\MRT
2014-09-12 17:58 - 2012-01-08 20:52 - 101694776 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-09-12 17:57 - 2014-05-06 21:03 - 00000000 ___SD () C:\Windows\system32\CompatTel
Some content of TEMP:
====================
C:\Users\Gian-Luca\AppData\Local\Temp\1396331452_the_wedownload_manager.exe
C:\Users\Gian-Luca\AppData\Local\Temp\18be6784_.exe
C:\Users\Gian-Luca\AppData\Local\Temp\294823_.exe
C:\Users\Gian-Luca\AppData\Local\Temp\4NBXCMa2Et.exe
C:\Users\Gian-Luca\AppData\Local\Temp\6QmqvuNrkn.exe
C:\Users\Gian-Luca\AppData\Local\Temp\6_Offer_11.exe
C:\Users\Gian-Luca\AppData\Local\Temp\f.exe
C:\Users\Gian-Luca\AppData\Local\Temp\htmlayout.dll
C:\Users\Gian-Luca\AppData\Local\Temp\ICReinstall_FlvPlayerSetup.exe
C:\Users\Gian-Luca\AppData\Local\Temp\install167783.exe
C:\Users\Gian-Luca\AppData\Local\Temp\JUUi6cIYwV.exe
C:\Users\Gian-Luca\AppData\Local\Temp\MotoCast_Installer_2.0405.exe
C:\Users\Gian-Luca\AppData\Local\Temp\N5R9uGMJ1p.exe
C:\Users\Gian-Luca\AppData\Local\Temp\optprosetup.exe
C:\Users\Gian-Luca\AppData\Local\Temp\Quarantine.exe
C:\Users\Gian-Luca\AppData\Local\Temp\SHelp2.exe
C:\Users\Gian-Luca\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Gian-Luca\AppData\Local\Temp\vp.exe
C:\Users\Gian-Luca\AppData\Local\Temp\_is3B4C.exe
C:\Users\Gian-Luca\AppData\Local\Temp\_is6642.exe
C:\Users\Gian-Luca\AppData\Local\Temp\_isA9B8.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-09-26 19:09
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- --- Addition Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-10-2014 01
Ran by Gian-Luca at 2014-10-09 22:18:57
Running from C:\Users\Gian-Luca\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.)
ASUS Power4Gear Hybrid (HKLM\...\{33B98264-A889-4913-A0CA-C364A75032B3}) (Version: 1.1.45 - ASUS)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Browser Guardian (HKLM-x32\...\38997_Browser Guardian) (Version: 1.0 - Gratifying Apps)
eDealsPop version 1.0 (HKLM-x32\...\eDealsPop_is1) (Version: 1.0 - eDealsPop)
EPSON SX410 Series Printer Uninstall (HKLM\...\EPSON SX410 Series) (Version: - SEIKO EPSON Corporation)
Fast Boot (HKLM\...\{13F4A7F3-EABC-4261-AF6B-1317777F0755}) (Version: 1.0.9 - ASUS)
Free YouTube to MP3 Converter version 3.12.42.716 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.42.716 - DVDVideoSoft Ltd.)
Google Chrome (HKCU\...\Google Chrome) (Version: 31.0.1650.57 - Google Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 37.0.2062.124 - Google Inc.)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.)
LPT System Updater Service (x32 Version: 1.0.0.0 - LPT) Hidden <==== ATTENTION
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Antimalware Service DE-DE Language Pack (Version: 3.0.8402.2 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Security Client DE-DE Language Pack (Version: 2.1.1116.0 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: - )
OpenOffice 4.0.1 (HKLM-x32\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation)
Shopping Helper Smartbar (HKLM-x32\...\{C64BEB42-B25D-4674-BB55-4099CB720110}) (Version: 11.113.63.19229 - ReSoft Ltd.) <==== ATTENTION
Shopping Helper Smartbar Engine (HKCU\...\{8a44590d-2b8b-42ac-ab9c-f87d99475033}) (Version: 11.113.63.19229 - ReSoft Ltd.) <==== ATTENTION
Skype™ 6.18 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.18.105 - Skype Technologies S.A.)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.6.0 - Synaptics Incorporated)
Windows Live Family Safety (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden
Windows Live Language Selector (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.31.0 - ASUS)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
==================== Restore Points =========================
21-09-2014 18:35:07 Windows-Sicherung
23-09-2014 17:47:35 Windows Update
23-09-2014 19:52:04 Windows Update
28-09-2014 13:55:29 Windows Defender Checkpoint
29-09-2014 16:19:25 Windows-Sicherung
30-09-2014 15:16:06 Windows Update
01-10-2014 20:35:50 Windows Update
05-10-2014 17:00:33 Windows-Sicherung
08-10-2014 17:10:51 Windows Update
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 04:34 - 2014-10-09 21:48 - 00000872 ____A C:\Windows\system32\Drivers\etc\hosts
54.225.95.126 jkmdneioiggpdolicemlcchhiepfhebm
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {00CD8246-36F6-4085-8E4F-8FE68CFAE2A8} - System32\Tasks\Google Updater and Installer => C:\Users\Gian-Luca\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {0A593EBF-CB00-45C0-AC7C-FD49A5EBE471} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2011-06-01] (ASUS)
Task: {230A149F-9CA1-4AD9-8D1A-769F78FF3FA0} - System32\Tasks\bench-sys => C:\Program Files (x86)\Bench\Updater\updater.exe [2014-08-20] () <==== ATTENTION
Task: {2FC1F71E-D581-4B02-B4D3-FA9009BA75BD} - System32\Tasks\Real Player-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe [2012-03-13] (RealNetworks, Inc.)
Task: {3103F1B9-9AF4-406A-A492-BAF59CA5D4FF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-06] (Google Inc.)
Task: {41EC189E-B55D-416B-9EEA-00E93D424C39} - System32\Tasks\bench-S-1-5-21-4134278005-4231936906-4289131000-1000 => C:\Program Files (x86)\Bench\Updater\updater.exe [2014-08-20] () <==== ATTENTION
Task: {4414FCE9-520E-4B17-B8C9-ACB33E24AD56} - System32\Tasks\{93A1EA47-7058-4F4B-BC71-F7C1285F6180} => Chrome.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver=6.11.0.102&LastError=12002
Task: {5F5665C1-DDEC-4926-86AB-A8B0D3D59652} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2011-09-01] (ASUSTeK Computer Inc.)
Task: {60429C1D-3BBA-4A7D-BFDD-7AD08EBB917A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-06] (Google Inc.)
Task: {8363DA97-B739-4FB5-804A-E08D28E49AF4} - System32\Tasks\{2A4B2458-22F6-42FB-8299-F963093D9554} => Chrome.exe hxxp://ui.skype.com/ui/0/6.2.0.106/de/abandoninstall?source=lightinstaller&page=tsProgressBar
Task: {868D68F6-E303-445D-85BB-7621D1CB57BC} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-10] (Adobe Systems Incorporated)
Task: {96F229CF-FA4A-4468-AAFE-B4167CF44468} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {AF03C709-AA67-4B83-8EBA-F33E9F983360} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2011-05-30] (ASUS)
Task: {BA5B63A9-CBEE-4593-B651-8BB202CB4189} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4134278005-4231936906-4289131000-1000UA => C:\Users\Gian-Luca\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-15] (Facebook Inc.)
Task: {C8C7BC63-E602-4AAE-8224-4B472E41D471} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-4134278005-4231936906-4289131000-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-01-30] (RealNetworks, Inc.)
Task: {DA06E915-2502-44C4-AE09-8AB6F2D343CF} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {DA9886A5-B06D-4317-AADB-ED5FA92035B5} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-4134278005-4231936906-4289131000-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2012-01-30] (RealNetworks, Inc.)
Task: {DCBCEDBF-F270-45F6-9CC9-40CFAB5F7DC5} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-4134278005-4231936906-4289131000-1000Core => C:\Users\Gian-Luca\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-15] (Facebook Inc.)
Task: {E62F4F6B-7906-47A5-BD88-4A334F0304F0} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2011-07-22] (ASUS)
Task: {EF6A448E-2E4A-429C-AF1C-316AE24E4F33} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [2010-11-15] (ASUS)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\bench-S-1-5-21-4134278005-4231936906-4289131000-1000.job => C:\Program Files (x86)\Bench\Updater\updater.exe <==== ATTENTION
Task: C:\Windows\Tasks\bench-sys.job => C:\Program Files (x86)\Bench\Updater\updater.exe <==== ATTENTION
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4134278005-4231936906-4289131000-1000Core.job => C:\Users\Gian-Luca\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4134278005-4231936906-4289131000-1000UA.job => C:\Users\Gian-Luca\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2014-08-20 17:14 - 2014-08-20 17:14 - 00110592 _____ () C:\Program Files (x86)\Bench\BService\1.1\bhelper64.dll
2010-07-15 01:11 - 2010-07-15 01:11 - 00031360 _____ () C:\Program Files\P4G\DevMng.dll
2011-09-16 10:20 - 2011-07-26 09:37 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2011-09-16 10:21 - 2011-05-05 14:30 - 00057640 _____ () C:\Program Files\Synaptics\SynTP\SynTPEnhPS.dll
2014-07-28 01:16 - 2014-07-28 01:16 - 00060965 _____ () C:\Windows\SysWOW64\ArchiveDesktopMBR\ArchiveDesktopMBR.exe
2014-10-09 21:33 - 2014-07-17 14:14 - 00007168 _____ () C:\Program Files (x86)\eDealsPop\eDealsPop.exe
2014-08-20 17:14 - 2014-08-20 17:14 - 00052736 _____ () C:\Program Files (x86)\Bench\BService\1.1\bservice.exe
2014-08-20 17:14 - 2014-08-20 17:14 - 00110592 _____ () C:\Program Files (x86)\Bench\BService\1.1\bservice64.exe
2014-08-20 17:15 - 2014-08-20 17:15 - 00092672 _____ () C:\Program Files (x86)\Bench\Wd\wd.exe
2014-08-27 16:34 - 2014-08-27 16:34 - 00032800 _____ () C:\Program Files (x86)\LPT\srpts.exe
2014-08-27 16:34 - 2014-08-27 16:34 - 00034848 _____ () C:\Program Files (x86)\LPT\srptsl.exe
2014-08-27 16:33 - 2014-08-27 16:33 - 00023584 _____ () C:\Users\Gian-Luca\AppData\Local\Smartbar\Application\Lrcnta.exe
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
MSCONFIG\startupreg: ASUS Screen Saver Protector => C:\Windows\AsScrPro.exe
MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
========================= Accounts: ==========================
Administrator (S-1-5-21-4134278005-4231936906-4289131000-500 - Administrator - Disabled)
Gast (S-1-5-21-4134278005-4231936906-4289131000-501 - Limited - Disabled)
Gian-Luca (S-1-5-21-4134278005-4231936906-4289131000-1000 - Administrator - Enabled) => C:\Users\Gian-Luca
HomeGroupUser$ (S-1-5-21-4134278005-4231936906-4289131000-1002 - Limited - Enabled)
==================== Faulty Device Manager Devices =============
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (10/09/2014 10:15:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4
Name des fehlerhaften Moduls: ASUSWSShellExt64.dll, Version: 1.1.0.27, Zeitstempel: 0x4c7f631d
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000000051da
ID des fehlerhaften Prozesses: 0x%9
Startzeit der fehlerhaften Anwendung: 0xexplorer.exe0
Pfad der fehlerhaften Anwendung: explorer.exe1
Pfad des fehlerhaften Moduls: explorer.exe2
Berichtskennung: explorer.exe3
Error: (10/09/2014 10:15:05 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4
Name des fehlerhaften Moduls: ASUSWSShellExt64.dll, Version: 1.1.0.27, Zeitstempel: 0x4c7f631d
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000000051da
ID des fehlerhaften Prozesses: 0x%9
Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0
Pfad der fehlerhaften Anwendung: Explorer.EXE1
Pfad des fehlerhaften Moduls: Explorer.EXE2
Berichtskennung: Explorer.EXE3
Error: (10/09/2014 09:55:40 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Smartbar.exe, Version: 11.113.63.19229, Zeitstempel: 0x53fdde0e
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18409, Zeitstempel: 0x53159a86
Ausnahmecode: 0xe053534f
Fehleroffset: 0x0000c42d
ID des fehlerhaften Prozesses: 0x%9
Startzeit der fehlerhaften Anwendung: 0xSmartbar.exe0
Pfad der fehlerhaften Anwendung: Smartbar.exe1
Pfad des fehlerhaften Moduls: Smartbar.exe2
Berichtskennung: Smartbar.exe3
Error: (10/09/2014 09:55:23 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: chrome.exe, Version: 31.0.1650.57, Zeitstempel: 0x5284a422
Name des fehlerhaften Moduls: chrome.dll, Version: 31.0.1650.57, Zeitstempel: 0x528499ee
Ausnahmecode: 0x80000003
Fehleroffset: 0x003946f8
ID des fehlerhaften Prozesses: 0x1014
Startzeit der fehlerhaften Anwendung: 0xchrome.exe0
Pfad der fehlerhaften Anwendung: chrome.exe1
Pfad des fehlerhaften Moduls: chrome.exe2
Berichtskennung: chrome.exe3
Error: (10/09/2014 09:55:14 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: chrome.exe, Version: 31.0.1650.57, Zeitstempel: 0x5284a422
Name des fehlerhaften Moduls: chrome.dll, Version: 31.0.1650.57, Zeitstempel: 0x528499ee
Ausnahmecode: 0x80000003
Fehleroffset: 0x003946f8
ID des fehlerhaften Prozesses: 0x1ea8
Startzeit der fehlerhaften Anwendung: 0xchrome.exe0
Pfad der fehlerhaften Anwendung: chrome.exe1
Pfad des fehlerhaften Moduls: chrome.exe2
Berichtskennung: chrome.exe3
Error: (10/09/2014 09:51:26 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: chrome.exe, Version: 31.0.1650.57, Zeitstempel: 0x5284a422
Name des fehlerhaften Moduls: chrome.dll, Version: 31.0.1650.57, Zeitstempel: 0x528499ee
Ausnahmecode: 0x80000003
Fehleroffset: 0x003946f8
ID des fehlerhaften Prozesses: 0x1908
Startzeit der fehlerhaften Anwendung: 0xchrome.exe0
Pfad der fehlerhaften Anwendung: chrome.exe1
Pfad des fehlerhaften Moduls: chrome.exe2
Berichtskennung: chrome.exe3
Error: (10/09/2014 09:50:26 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: chrome.exe, Version: 31.0.1650.57, Zeitstempel: 0x5284a422
Name des fehlerhaften Moduls: chrome.dll, Version: 31.0.1650.57, Zeitstempel: 0x528499ee
Ausnahmecode: 0x80000003
Fehleroffset: 0x003946f8
ID des fehlerhaften Prozesses: 0x17b0
Startzeit der fehlerhaften Anwendung: 0xchrome.exe0
Pfad der fehlerhaften Anwendung: chrome.exe1
Pfad des fehlerhaften Moduls: chrome.exe2
Berichtskennung: chrome.exe3
Error: (10/06/2014 09:57:58 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521eaf24
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000053290
ID des fehlerhaften Prozesses: 0x%9
Startzeit der fehlerhaften Anwendung: 0xexplorer.exe0
Pfad der fehlerhaften Anwendung: explorer.exe1
Pfad des fehlerhaften Moduls: explorer.exe2
Berichtskennung: explorer.exe3
Error: (10/06/2014 09:57:46 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4
Name des fehlerhaften Moduls: ASUSWSShellExt64.dll, Version: 1.1.0.27, Zeitstempel: 0x4c7f631d
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000000051da
ID des fehlerhaften Prozesses: 0x%9
Startzeit der fehlerhaften Anwendung: 0xexplorer.exe0
Pfad der fehlerhaften Anwendung: explorer.exe1
Pfad des fehlerhaften Moduls: explorer.exe2
Berichtskennung: explorer.exe3
Error: (10/06/2014 09:57:35 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4
Name des fehlerhaften Moduls: ASUSWSShellExt64.dll, Version: 1.1.0.27, Zeitstempel: 0x4c7f631d
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000000051da
ID des fehlerhaften Prozesses: 0x%9
Startzeit der fehlerhaften Anwendung: 0xexplorer.exe0
Pfad der fehlerhaften Anwendung: explorer.exe1
Pfad des fehlerhaften Moduls: explorer.exe2
Berichtskennung: explorer.exe3
System errors:
=============
Error: (10/09/2014 09:33:06 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "CursorPrivacyUtility.exe" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (10/09/2014 09:32:56 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "CursorPrivacyUtility.exe" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (10/09/2014 09:30:19 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "CursorPrivacyUtility.exe" wurde nicht richtig gestartet.
Error: (10/09/2014 09:28:57 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "RawSharewareTrash.exe" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (10/09/2014 09:28:56 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "DesktopMacroProcess.exe" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (10/09/2014 09:28:05 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}
Error: (10/09/2014 09:10:15 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "CursorPrivacyUtility.exe" wurde nicht richtig gestartet.
Error: (10/09/2014 09:08:53 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "RawSharewareTrash.exe" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (10/09/2014 09:08:52 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "DesktopMacroProcess.exe" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (10/08/2014 07:15:38 PM) (Source: Application Popup) (EventID: 86) (User: )
Description: Für ein Dateiobjekt mit wartendem Löschvorgang wurde ein Vorgang angefordert, der kein Schließvorgang ist.
Microsoft Office Sessions:
=========================
Error: (10/09/2014 10:15:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: explorer.exe6.1.7601.175674d672ee4ASUSWSShellExt64.dll1.1.0.274c7f631dc000000500000000000051da
Error: (10/09/2014 10:15:05 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Explorer.EXE6.1.7601.175674d672ee4ASUSWSShellExt64.dll1.1.0.274c7f631dc000000500000000000051da
Error: (10/09/2014 09:55:40 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Smartbar.exe11.113.63.1922953fdde0eKERNELBASE.dll6.1.7601.1840953159a86e053534f0000c42d
Error: (10/09/2014 09:55:23 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: chrome.exe31.0.1650.575284a422chrome.dll31.0.1650.57528499ee80000003003946f8101401cfe3faf48bdeb8C:\Users\Gian-Luca\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\Gian-Luca\AppData\Local\Google\Chrome\Application\31.0.1650.57\chrome.dll341a5904-4fee-11e4-ba0e-5404a62e86ba
Error: (10/09/2014 09:55:14 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: chrome.exe31.0.1650.575284a422chrome.dll31.0.1650.57528499ee80000003003946f81ea801cfe3faeeb6f1d9C:\Users\Gian-Luca\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\Gian-Luca\AppData\Local\Google\Chrome\Application\31.0.1650.57\chrome.dll2e9f2583-4fee-11e4-ba0e-5404a62e86ba
Error: (10/09/2014 09:51:26 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: chrome.exe31.0.1650.575284a422chrome.dll31.0.1650.57528499ee80000003003946f8190801cfe3fa67cacbc1C:\Users\Gian-Luca\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\Gian-Luca\AppData\Local\Google\Chrome\Application\31.0.1650.57\chrome.dlla71278c7-4fed-11e4-ba0e-5404a62e86ba
Error: (10/09/2014 09:50:26 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: chrome.exe31.0.1650.575284a422chrome.dll31.0.1650.57528499ee80000003003946f817b001cfe3fa4073357dC:\Users\Gian-Luca\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\Gian-Luca\AppData\Local\Google\Chrome\Application\31.0.1650.57\chrome.dll82f41569-4fed-11e4-ba0e-5404a62e86ba
Error: (10/06/2014 09:57:58 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: explorer.exe6.1.7601.175674d672ee4ntdll.dll6.1.7601.18247521eaf24c00000050000000000053290
Error: (10/06/2014 09:57:46 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: explorer.exe6.1.7601.175674d672ee4ASUSWSShellExt64.dll1.1.0.274c7f631dc000000500000000000051da
Error: (10/06/2014 09:57:35 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: explorer.exe6.1.7601.175674d672ee4ASUSWSShellExt64.dll1.1.0.274c7f631dc000000500000000000051da
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i3-2310M CPU @ 2.10GHz
Percentage of memory in use: 44%
Total physical RAM: 4000.13 MB
Available physical RAM: 2232.15 MB
Total Pagefile: 7998.43 MB
Available Pagefile: 5883.53 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:119.24 GB) (Free:36.65 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (DATA) (Fixed) (Total:153.85 GB) (Free:0.02 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 496B9619)
Partition 1: (Not Active) - (Size=25 GB) - (Type=1C)
Partition 2: (Active) - (Size=119.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=153.9 GB) - (Type=07 NTFS)
==================== End Of Log ============================ Ich habe nun auch den 3. Schritt (Scan mit GMER) durchgeführt.
Es wurde kein Logfile erstellt. Der Scan lief ne ganze Weile, bevor sich ein Bluescreen öffnete. Dort stand, dass mein Laptop zum Schutz heruntergefahren / neu gestartet wird. |