VIRUS oder nicht? System zunächst total unstabil, jetzt läuft wieder alles ?

VIRUS oder nicht? System zunächst total unstabil, jetzt läuft wieder alles ?


Ich weiss nicht wirklich weiter. Zunächst war ich recht sicher das ich mir nen Virus oder so eingefangen hatte.

Seit ca. 1-2 Wochen folgende Symptome:

Latop (Win7) friert manchmal ein oder stürzt komplett ab (schwarzer Bildschirm & nix weiter möglich - dabei erhebliche HDD Aktivität).
Teils kommt ne Meldung das Programme geschlossen werden müssen, da Arbeitsspeicher zu gering - auch wenn nur Firefox + Exchange offen sind!

Insbesondere Firefox schien oft der Auslöser für Abstürze zu sein.

Hab nun folgende Scan bereits durch (chronologisch) - Im Anhang die Logs da als Code hier viel zu lang:

- Avast - Komplett Scan - Nix gefunden
- FRST64 - Merkwürdige System Errors etc. in der "Addition.txt"
- GMER - Find da nix auffällig, weiss aber auch nicht wonach ich suchen muss
- MalWarebytes - Nix gefunden
- MalWarebytes Anti-Root - Nix gefunden
- OTL - Merkwürdige Fehlermeldungen in der "Extras.txt"
- AdwCleaner - Einige Funde aber wohl eher harmlose Toolbars etc.
- Emisoft - Ein Paar Registry Einträge aber wohl nix wildes

Über Nacht will ich dann noch ESET Scanner laufen lassen.

Der Witz: Obwohl ich ja ausser einige belanglose Registry Einträge (Patrypoker...) nix weiter entfernt hab läuft das System im Moment wieder stabil und soweit ich erkenne ohne Macken.

Wäre dennoch dankbar, wenn mal jemand einen Blick auf die Logfiles im Anhang wirft.

/// the machine
/// TB-Ausbilder

VIRUS oder nicht? System zunächst total unstabil, jetzt läuft wieder alles ?

VIRUS oder nicht? System zunächst total unstabil, jetzt läuft wieder alles ?


Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen.

So funktioniert es:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.


VIRUS oder nicht? System zunächst total unstabil, jetzt läuft wieder alles ?

VIRUS oder nicht? System zunächst total unstabil, jetzt läuft wieder alles ?

Moin Schrauber. Sinf halt ne Menge.
Ich fang ma an...


FRST Logfile:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-12-2013 01
Ran by APB (administrator) on ACER-ULTRA on 30-12-2013 13:42:31
Running from C:\Users\APB\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Sun Microsystems, Inc.) C:\Program Files\Java\jre6\bin\jusched.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Diskeeper Corporation) C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE
(Acer Incorporated) C:\Program Files\Sleep Memory Optimizer\FFSService.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\\GoogleCrashHandler.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect\HelperService.exe
(Dropbox, Inc.) C:\Users\APB\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\\GoogleCrashHandler64.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect\ConversionService.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
(Dolby Laboratories Inc.) C:\Dolby PCEE4\pcee4.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Research in Motion\Tunnel Manager\mDNSResponder.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe
(Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL3\KHALMNPR.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Research In Motion Limited) C:\Program Files (x86)\Common Files\Research in Motion\USB Drivers\RIMBBLaunchAgent.exe
(Atheros) C:\Program Files (x86)\Atheros\Ath_WlanAgent.exe
(Research In Motion Limited) C:\Program Files (x86)\Common Files\Research in Motion\Tunnel Manager\PeerManager.exe
(Haufe-Lexware GmbH & Co. KG) C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Research In Motion Limited) C:\Program Files (x86)\Common Files\Research in Motion\Tunnel Manager\tunmgr.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Research In Motion Limited) C:\Program Files (x86)\Common Files\Research in Motion\USB Drivers\BbDevMgr.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
() C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe
() C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Theft Shield\USecuAppClient.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
() C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12459112 2012-03-16] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1158248 2012-03-09] (Realtek Semiconductor)
HKLM\...\Run: [AtherosBtStack] - C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [1021056 2012-03-08] (Atheros Communications)
HKLM\...\Run: [AthBtTray] - C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [800896 2012-03-08] (Atheros Commnucations)
HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [2822952 2012-02-24] (ELAN Microelectronics Corp.)
HKLM\...\Run: [Power Management] - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1829768 2012-02-07] (Acer Incorporated)
HKLM\...\Run: [InstantUpdate] - C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuDaemon.exe [124520 2012-02-20] ()
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Java\jre6\bin\jusched.exe [170496 2013-06-02] (Sun Microsystems, Inc.)
HKLM\...\Run: [EvtMgr6] - C:\Program Files\Logitech\SetPointP\SetPoint.exe [2991856 2013-02-21] (Logitech, Inc.)
HKLM-x32\...\Run: [BackupManagerTray] - C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [296984 2012-01-05] (NTI Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Dolby Home Theater v4] - C:\Dolby PCEE4\pcee4.exe [506712 2011-06-01] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-27] (Intel Corporation)
HKLM-x32\...\Run: [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe [1105488 2012-03-24] (Dritek System Inc.)
HKLM-x32\...\Run: [SuiteTray] - C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [341360 2011-09-20] (Egis Technology Inc.)
HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [4858968 2013-08-30] (AVAST Software)
HKLM-x32\...\Run: [RIMBBLaunchAgent.exe] - C:\Program Files (x86)\Common Files\Research in Motion\USB Drivers\RIMBBLaunchAgent.exe [267792 2013-01-17] (Research In Motion Limited)
HKLM-x32\...\Run: [RIM PeerManager] - C:\Program Files (x86)\Common Files\Research in Motion\Tunnel Manager\PeerManager.exe [4265472 2013-04-26] (Research In Motion Limited)
HKLM-x32\...\Run: [LexwareInfoService] - C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe [189808 2011-07-31] (Haufe-Lexware GmbH & Co. KG)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [20131121] - C:\Program Files\AVAST Software\Avast\Setup\emupdate\72c2e4d7-871f-4dee-b80b-4301baba235d.exe [180184 2013-11-23] (AVAST Software)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\LBTWlgn: C:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
HKCU\...\Run: [OfficeSyncProcess] - C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [720064 2013-04-22] (Microsoft Corporation)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
HKCU\...\Run: [Personal ID] - C:\coolspot AG\Personal ID\pid.exe [1134008 2009-03-04] (coolspot AG, Düsseldorf)
MountPoints2: {1cdabc58-bf86-11e2-a8d0-917478fbae53} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL D:\start.exe
HKU\Default\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [162408 2011-09-13] ()
HKU\Default\...\RunOnce: [RegAutoPlay] - C:\Program Files (x86)\Acer\clear.fi Media\RegAutoplay.exe [1845832 2013-01-22] (Acer Incorporated)
HKU\Default User\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [162408 2011-09-13] ()
HKU\Default User\...\RunOnce: [RegAutoPlay] - C:\Program Files (x86)\Acer\clear.fi Media\RegAutoplay.exe [1845832 2013-01-22] (Acer Incorporated)
Startup: C:\Users\APB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\APB\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://acer.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll (Logitech, Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GmbH)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll (Logitech, Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKLM-x32 - PDF Architect Toolbar - {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files (x86)\PDF Architect\PDFIEPlugin.dll (pdfforge GmbH)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer]

FF ProfilePath: C:\Users\APB\AppData\Roaming\Mozilla\Firefox\Profiles\h3p0lpdr.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @RIM.com/WebSLLauncher,version=1.0 - C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: avast! Ad Blocker - C:\Program Files (x86)\Mozilla Firefox\extensions\adblocker@avast.com.xpi
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt

CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "hxxp://www.google.com"
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll ()
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (RIM Handheld Application Loader) - C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll No File
CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll No File
CHR Plugin: (Java Deployment Toolkit - C:\Windows\SysWOW64\npDeployJava1.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll No File
CHR Extension: (Google Docs) - C:\Users\APB\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\APB\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\APB\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\APB\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\
CHR Extension: (Logitech SetPoint) - C:\Users\APB\AppData\Local\Google\Chrome\User Data\Default\Extensions\edaibbiobngpbmeonadpbfafbkimjbdd\6.52.74_0
CHR Extension: (Google Wallet) - C:\Users\APB\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\
CHR Extension: (Gmail) - C:\Users\APB\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM-x32\...\Chrome\Extension: [edaibbiobngpbmeonadpbfafbkimjbdd] - C:\ProgramData\Logitech\LogiSmoothChromeExt.crx

==================== Services (Whitelisted) =================

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-30] (AVAST Software)
R3 BlackBerry Device Manager; C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe [585728 2013-02-06] (Research In Motion Limited)
R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2615368 2013-01-24] (Acer Incorporated)
R2 ExpressCache; C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe [79664 2012-02-17] (Diskeeper Corporation)
R2 FFSOpzSvc; C:\Program Files\Sleep Memory Optimizer\FFSService.exe [141192 2011-09-17] (Acer Incorporated)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-03-29] ()
S3 irstrtsv; C:\Windows\SysWOW64\irstrtsv.exe [193536 2012-03-28] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165144 2012-03-29] (Intel Corporation)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [256536 2012-01-05] (NTI Corporation)
R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH)
R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH)
R2 RIM MDNS; C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\mDNSResponder.exe [389632 2013-04-26] (Apple Inc.)
R2 RIM Tunnel Service; C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\tunmgr.exe [1235456 2013-04-26] (Research In Motion Limited)
R2 RS_Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [260640 2010-01-29] (Acer Incorporated)
S3 USecuAppSvc; C:\Program Files\Acer\Acer Theft Shield\USecuAppSvc.exe [345744 2012-11-12] (Acer Incorporated)
R2 ZAtheros Wlan Agent; C:\Program Files (x86)\Atheros\Ath_WlanAgent.exe [72864 2012-02-19] (Atheros)
S2 McAfee SiteAdvisor Service; c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe [x]

==================== Drivers (Whitelisted) ====================

R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-08-30] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-08-30] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-08-30] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-08-30] ()
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-30] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-30] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-08-30] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [204880 2013-08-30] ()
R1 excfs; C:\Windows\System32\DRIVERS\excfs.sys [23344 2012-02-17] (Diskeeper Corporation)
R0 excsd; C:\Windows\System32\DRIVERS\excsd.sys [92976 2012-02-17] (Diskeeper Corporation)
R3 irstrtdv; C:\Windows\System32\DRIVERS\irstrtdv.sys [26504 2012-03-28] (Intel Corporation)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [78336 2013-01-03] (Research In Motion Limited)
R3 rimvndis; C:\Windows\System32\Drivers\rimvndis6_AMD64.sys [17920 2013-04-26] (Research in Motion Limited)
R3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys [44544 2012-12-10] (Research in Motion Ltd)
S3 usbrndis6; C:\Windows\System32\DRIVERS\usb80236.sys [19968 2013-02-12] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2013-12-30 13:42 - 2013-12-30 13:42 - 00023848 _____ C:\Users\APB\Desktop\FRST.txt
2013-12-30 13:30 - 2013-12-30 13:30 - 00000000 ____D C:\FRST
2013-12-30 13:21 - 2013-12-30 13:21 - 00377856 _____ C:\Users\APB\Desktop\4s7438ut.exe
2013-12-30 13:16 - 2013-12-30 13:16 - 01931302 _____ (Farbar) C:\Users\APB\Desktop\FRST64.exe
2013-12-30 11:31 - 2013-12-30 11:31 - 00003288 ____N C:\bootsqm.dat
2013-12-30 10:52 - 2013-12-30 10:52 - 00000000 ___DC C:\Users\APB\AppData\Local\MigWiz
2013-12-30 10:19 - 2013-05-04 17:51 - 00001228 _____ C:\Users\APB\Desktop\Explorer.lnk
2013-12-30 10:19 - 2013-05-04 15:36 - 00000700 _____ C:\Users\APB\Desktop\Biblio.lnk
2013-12-30 10:07 - 2013-12-30 10:09 - 00000000 ____D C:\Users\APB\Desktop\ACER_SAS
2013-12-29 12:17 - 2013-12-30 02:11 - 00000000 ____D C:\Program Files\CCleaner
2013-12-29 12:03 - 2013-12-29 12:03 - 00128764 _____ C:\Users\APB\Desktop\Extras.Txt
2013-12-29 12:02 - 2013-12-29 12:02 - 00107164 _____ C:\Users\APB\Desktop\OTL.Txt
2013-12-29 11:23 - 2013-12-29 11:24 - 00000000 ____D C:\AdwCleaner
2013-12-28 19:35 - 2013-12-28 19:35 - 00000000 ____D C:\Users\APB\AppData\Roaming\Malwarebytes
2013-12-28 19:34 - 2013-12-29 17:51 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-28 19:34 - 2013-12-28 19:34 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-28 19:33 - 2013-12-29 17:26 - 00000000 ____D C:\Users\APB\Downloads\ANTIVIR
2013-12-23 05:15 - 2013-12-23 05:15 - 00000000 ____D C:\Users\APB\dwhelper
2013-12-20 09:24 - 2013-12-29 17:51 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-20 09:01 - 2013-12-20 09:01 - 00000000 ____D C:\Users\APB\AppData\Local\{BDF73505-64CB-4A28-9990-C822EFCE3D12}
2013-12-19 07:37 - 2013-12-19 07:37 - 00000000 ____D C:\Users\APB\AppData\Local\{2B140492-5FC5-41A1-94C9-74DCB4805487}
2013-12-18 10:49 - 2013-12-18 10:50 - 00000000 ____D C:\Users\APB\AppData\Local\{E1DF1BD8-A55C-40BD-A4E9-1AAD3BE3CC2B}
2013-12-17 09:10 - 2013-12-17 09:11 - 00000000 ____D C:\Users\APB\AppData\Local\{B17FE4F4-478F-4693-8B38-598A83554B4A}
2013-12-16 11:49 - 2013-12-16 11:49 - 00000000 ____D C:\Users\APB\AppData\Local\{6325584A-A627-4E06-BD5E-DD2C49885B55}
2013-12-15 10:40 - 2013-12-15 10:40 - 00000000 ____D C:\Users\APB\AppData\Local\{D2324234-C310-4EC8-8C46-2FF3583558B6}
2013-12-14 09:23 - 2013-12-14 09:23 - 00000000 ____D C:\Users\APB\AppData\Local\{9BFB83A7-93D0-4DCE-87D0-07612EBEDCD1}
2013-12-13 09:14 - 2013-12-13 09:14 - 00000000 ____D C:\Users\APB\AppData\Local\{CEB7D5C0-24F2-42AB-887F-A269488BE7EF}
2013-12-13 07:28 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-13 07:28 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-13 07:28 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2013-12-13 07:28 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-12-13 07:26 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-13 07:26 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-13 07:26 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-12-13 07:26 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-12-13 07:26 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-13 07:26 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-12-13 07:26 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-13 07:26 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-13 07:26 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-13 07:26 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-12-13 07:26 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-13 07:26 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-13 07:26 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-12-13 07:26 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-12-13 07:26 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-13 07:26 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-12-13 07:26 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-12-13 07:26 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-13 07:26 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-12-13 07:26 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-12-13 07:26 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-12-13 07:26 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-13 07:26 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-13 07:26 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-12-13 07:26 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-12-13 07:26 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-13 07:26 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-13 07:26 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-12-13 07:26 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-12-13 07:26 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-12-13 07:26 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-12-12 20:25 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-12-12 20:25 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-12 20:25 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-12 20:25 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-12-12 20:25 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-12 20:25 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2013-12-12 20:25 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-12 20:25 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-12 20:25 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2013-12-12 20:25 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-12 20:25 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-12 20:25 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2013-12-12 20:25 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2013-12-12 20:25 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-12 20:25 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-12 20:25 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2013-12-12 20:25 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2013-12-12 20:25 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-12 20:25 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-12-12 12:19 - 2013-12-12 12:20 - 18277248 _____ (pdfforge                                                    ) C:\Users\APB\Downloads\PDFCreator-1_7_2_setup.exe
2013-12-12 11:24 - 2013-12-12 11:24 - 00000000 ____D C:\Users\APB\AppData\Local\{2F47591A-C639-46DF-99D6-B49855015C7F}
2013-12-11 12:17 - 2013-12-11 12:17 - 00000000 ____D C:\Users\APB\AppData\Local\{A4C4C9D7-1E95-47E6-8D33-173BA47A781F}
2013-12-03 15:04 - 2013-12-03 15:04 - 00000000 ____D C:\Users\APB\AppData\Local\{C7FABDC8-6BE3-4822-84B3-8A90A30124BB}
2013-12-01 09:40 - 2013-12-01 09:40 - 00000000 ____D C:\Users\APB\AppData\Local\{270D3B0E-0616-4AB3-A772-75895074453C}
2013-11-30 15:08 - 2013-11-30 15:08 - 00836416 _____ C:\Users\APB\Downloads\pidsetup.exe
2013-11-30 15:08 - 2013-11-30 15:08 - 00000000 ____D C:\coolspot AG
2013-11-30 10:20 - 2013-11-30 10:20 - 00000000 ____D C:\Users\APB\AppData\Local\{ABE5A90D-DB41-433E-801C-91BFF6DC92EC}

==================== One Month Modified Files and Folders =======

2013-12-30 13:42 - 2013-12-30 13:42 - 00023848 _____ C:\Users\APB\Desktop\FRST.txt
2013-12-30 13:37 - 2013-04-30 14:18 - 01314558 _____ C:\Windows\WindowsUpdate.log
2013-12-30 13:36 - 2013-05-04 15:41 - 00000000 ____D C:\Users\APB\AppData\Roaming\Skype
2013-12-30 13:30 - 2013-12-30 13:30 - 00000000 ____D C:\FRST
2013-12-30 13:21 - 2013-12-30 13:21 - 00377856 _____ C:\Users\APB\Desktop\4s7438ut.exe
2013-12-30 13:19 - 2012-03-27 19:45 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-12-30 13:16 - 2013-12-30 13:16 - 01931302 _____ (Farbar) C:\Users\APB\Desktop\FRST64.exe
2013-12-30 12:55 - 2013-05-04 15:34 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-30 11:55 - 2013-05-04 15:34 - 00001100 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-30 11:41 - 2009-07-14 05:45 - 00031248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-30 11:41 - 2009-07-14 05:45 - 00031248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-30 11:35 - 2013-05-05 13:14 - 00000000 ____D C:\Users\APB\AppData\Roaming\Dropbox
2013-12-30 11:34 - 2013-05-05 13:16 - 00000000 ___RD C:\Users\APB\Dropbox
2013-12-30 11:34 - 2013-05-04 15:34 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2013-12-30 11:33 - 2013-04-30 14:24 - 00000828 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2013-12-30 11:32 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-30 11:32 - 2009-07-14 05:51 - 00065054 _____ C:\Windows\setupact.log
2013-12-30 11:31 - 2013-12-30 11:31 - 00003288 ____N C:\bootsqm.dat
2013-12-30 10:52 - 2013-12-30 10:52 - 00000000 ___DC C:\Users\APB\AppData\Local\MigWiz
2013-12-30 10:38 - 2013-05-01 00:09 - 00700418 _____ C:\Windows\system32\perfh007.dat
2013-12-30 10:38 - 2013-05-01 00:09 - 00149182 _____ C:\Windows\system32\perfc007.dat
2013-12-30 10:38 - 2009-07-14 06:13 - 01621308 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-30 10:09 - 2013-12-30 10:07 - 00000000 ____D C:\Users\APB\Desktop\ACER_SAS
2013-12-30 10:05 - 2013-08-26 14:07 - 00000000 ____D C:\Users\APB\Documents\FORMDOC_FILES
2013-12-30 09:46 - 2013-05-04 15:43 - 00000000 ____D C:\Users\APB\AppData\Local\CrashDumps
2013-12-30 09:22 - 2013-05-04 13:24 - 00000000 ____D C:\Users\APB\AppData\Local\Deployment
2013-12-30 02:11 - 2013-12-29 12:17 - 00000000 ____D C:\Program Files\CCleaner
2013-12-29 17:54 - 2013-05-04 15:34 - 00000000 _____ C:\Windows\SysWOW64\config.nt
2013-12-29 17:52 - 2013-05-04 10:28 - 00000000 ____D C:\Users\APB
2013-12-29 17:51 - 2013-12-28 19:34 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-29 17:51 - 2013-12-20 09:24 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-29 17:51 - 2013-07-11 06:54 - 00000000 ____D C:\Users\APB\AppData\Roaming\IrfanView
2013-12-29 17:51 - 2013-06-09 18:01 - 00000000 ____D C:\Windows\Minidump
2013-12-29 17:51 - 2013-05-05 13:14 - 00000000 ____D C:\Users\APB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-12-29 17:51 - 2013-05-04 12:03 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-12-29 17:51 - 2013-05-04 10:30 - 00000000 ___RD C:\Users\APB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-12-29 17:51 - 2012-03-27 19:50 - 00000000 ____D C:\ProgramData\BackupManager
2013-12-29 17:51 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration
2013-12-29 17:51 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\AppCompat
2013-12-29 17:49 - 2013-05-04 12:03 - 00000000 ____D C:\Users\APB\AppData\Local\Mozilla
2013-12-29 17:26 - 2013-12-28 19:33 - 00000000 ____D C:\Users\APB\Downloads\ANTIVIR
2013-12-29 12:33 - 2012-03-24 02:58 - 00000000 ____D C:\Windows\Panther
2013-12-29 12:03 - 2013-12-29 12:03 - 00128764 _____ C:\Users\APB\Desktop\Extras.Txt
2013-12-29 12:02 - 2013-12-29 12:02 - 00107164 _____ C:\Users\APB\Desktop\OTL.Txt
2013-12-29 11:24 - 2013-12-29 11:23 - 00000000 ____D C:\AdwCleaner
2013-12-28 19:35 - 2013-12-28 19:35 - 00000000 ____D C:\Users\APB\AppData\Roaming\Malwarebytes
2013-12-28 19:34 - 2013-12-28 19:34 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-28 11:30 - 2013-04-30 14:24 - 00000830 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2013-12-23 11:38 - 2013-05-05 13:15 - 00000973 _____ C:\Windows\wininit.ini
2013-12-23 05:15 - 2013-12-23 05:15 - 00000000 ____D C:\Users\APB\dwhelper
2013-12-20 09:01 - 2013-12-20 09:01 - 00000000 ____D C:\Users\APB\AppData\Local\{BDF73505-64CB-4A28-9990-C822EFCE3D12}
2013-12-19 07:37 - 2013-12-19 07:37 - 00000000 ____D C:\Users\APB\AppData\Local\{2B140492-5FC5-41A1-94C9-74DCB4805487}
2013-12-18 10:50 - 2013-12-18 10:49 - 00000000 ____D C:\Users\APB\AppData\Local\{E1DF1BD8-A55C-40BD-A4E9-1AAD3BE3CC2B}
2013-12-17 09:11 - 2013-12-17 09:10 - 00000000 ____D C:\Users\APB\AppData\Local\{B17FE4F4-478F-4693-8B38-598A83554B4A}
2013-12-17 08:07 - 2010-11-21 04:47 - 00212972 _____ C:\Windows\PFRO.log
2013-12-16 11:49 - 2013-12-16 11:49 - 00000000 ____D C:\Users\APB\AppData\Local\{6325584A-A627-4E06-BD5E-DD2C49885B55}
2013-12-15 10:40 - 2013-12-15 10:40 - 00000000 ____D C:\Users\APB\AppData\Local\{D2324234-C310-4EC8-8C46-2FF3583558B6}
2013-12-15 08:50 - 2013-07-25 23:45 - 00000000 ____D C:\Windows\system32\MRT
2013-12-15 08:47 - 2013-05-07 17:42 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-12-14 18:56 - 2013-05-04 15:34 - 00000000 ____D C:\Program Files (x86)\Google
2013-12-14 09:23 - 2013-12-14 09:23 - 00000000 ____D C:\Users\APB\AppData\Local\{9BFB83A7-93D0-4DCE-87D0-07612EBEDCD1}
2013-12-13 16:55 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-12-13 09:14 - 2013-12-13 09:14 - 00000000 ____D C:\Users\APB\AppData\Local\{CEB7D5C0-24F2-42AB-887F-A269488BE7EF}
2013-12-13 08:24 - 2009-07-14 05:45 - 00469272 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-13 07:28 - 2013-05-04 11:11 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-12-12 12:20 - 2013-12-12 12:19 - 18277248 _____ (pdfforge                                                    ) C:\Users\APB\Downloads\PDFCreator-1_7_2_setup.exe
2013-12-12 11:24 - 2013-12-12 11:24 - 00000000 ____D C:\Users\APB\AppData\Local\{2F47591A-C639-46DF-99D6-B49855015C7F}
2013-12-11 16:19 - 2012-03-27 19:45 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-11 16:19 - 2012-03-27 19:45 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-11 16:19 - 2012-03-27 19:45 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-12-11 12:17 - 2013-12-11 12:17 - 00000000 ____D C:\Users\APB\AppData\Local\{A4C4C9D7-1E95-47E6-8D33-173BA47A781F}
2013-12-09 09:03 - 2013-05-14 05:47 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-12-09 09:03 - 2012-03-27 20:00 - 00000000 ____D C:\ProgramData\Skype
2013-12-03 15:04 - 2013-12-03 15:04 - 00000000 ____D C:\Users\APB\AppData\Local\{C7FABDC8-6BE3-4822-84B3-8A90A30124BB}
2013-12-01 09:40 - 2013-12-01 09:40 - 00000000 ____D C:\Users\APB\AppData\Local\{270D3B0E-0616-4AB3-A772-75895074453C}
2013-11-30 15:08 - 2013-11-30 15:08 - 00836416 _____ C:\Users\APB\Downloads\pidsetup.exe
2013-11-30 15:08 - 2013-11-30 15:08 - 00000000 ____D C:\coolspot AG
2013-11-30 10:20 - 2013-11-30 10:20 - 00000000 ____D C:\Users\APB\AppData\Local\{ABE5A90D-DB41-433E-801C-91BFF6DC92EC}

Some content of TEMP:

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

LastRegBack: 2013-12-30 08:56

==================== End Of Log ============================
--- --- ---

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-12-2013 01
Ran by APB at 2013-12-30 13:42:55
Running from C:\Users\APB\Desktop
Boot Mode: Normal

==================== Security Center ========================

AV: avast! Antivirus (Enabled - Up to date) {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AS: avast! Antivirus (Enabled - Up to date) {904CF271-6431-DA47-5FCE-A87D98DFB681}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

 clear.fi SDK - Video 2 (x32 Version: 2.1.2308 - CyberLink Corp.)
 clear.fi SDK- Movie 2 (x32 Version: 2.1.2112 - CyberLink Corp.)
7-Zip 9.20 (x64 edition) (Version: - Igor Pavlov)
Acer Backup Manager (x32 Version: - NTI Corporation)
Acer Crystal Eye Webcam (x32 Version: 1.5.2728.00 - CyberLink Corp.)
Acer ePower Management (x32 Version: 6.00.3010 - Acer Incorporated)
Acer eRecovery Management (x32 Version: 5.00.3507 - Acer Incorporated)
Acer Games (x32 Version: - WildTangent)
Acer Instant Update Service (Version: 1.00.3001 - Acer Incorporated)
Acer Registration (x32 Version: 1.04.3506 - Acer Incorporated)
Acer ScreenSaver (x32 Version: 20.12.0307.1154 - Acer Incorporated)
Acer Theft Shield (Version: 1.01.3006 - Acer Incorporated)
Acer Updater (x32 Version: 1.02.3501 - Acer Incorporated)
Acer VCM (x32 Version: 4.05.3501 - Acer Incorporated)
AcerCloud Docs (x32 Version: 1.01.2007 - Acer Incorporated)
AcerCloud Portal (x32 Version: 2.02.2018 - Acer Incorporated)
Adobe AIR (x32 Version: - Adobe Systems Incorporated)
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.170 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.170 - Adobe Systems Incorporated)
Adobe Reader X (10.1.8) MUI (x32 Version: 10.1.8 - Adobe Systems Incorporated)
Agatha Christie - Death on the Nile (x32 Version: - WildTangent)
Atheros Bluetooth Suite (64) (Version: - Atheros)
avast! Free Antivirus (x32 Version: 8.0.1497.0 - AVAST Software)
AVM FRITZ!Box Dokumentation (x32 Version:  - AVM Berlin)
AVM FRITZ!Box Druckeranschluss (x32 Version:  - AVM Berlin)
AVM FRITZ!fax für FRITZ!Box (x32 Version:  - AVM Berlin)
AX88772B Windows 7 Drivers (x32 Version: - ASIX Electronics Corporation)
Backup Manager V3 (x32 Version: - NTI Corporation)
Bejeweled 3 (x32 Version: - WildTangent)
BlackBerry Link (x32 Version: - Research in Motion Ltd.)
Chuzzle Deluxe (x32 Version: - WildTangent)
clear.fi Media (x32 Version: 2.02.2009 - Acer Incorporated)
clear.fi Photo (x32 Version: 2.02.2016 - Acer Incorporated)
CyberLink MediaEspresso (x32 Version: 6.5.1720_38230 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32 Version:  - Microsoft)
Dolby Home Theater v4 (x32 Version: 7.2.7000.7 - Dolby Laboratories Inc)
Dropbox (HKCU Version: 2.4.10 - Dropbox, Inc.)
ElsterFormular (x32 Version: 14.4.20130909 - Landesfinanzdirektion Thüringen)
eReg (x32 Version: - Logitech, Inc.)
ETDWare PS/2-X64 (Version: - ELAN Microelectronic Corp.)
Evernote v. 4.5.2 (x32 Version: - Evernote Corp.)
ExpressCache (Version: 1.0.82 - Diskeeper Corporation)
FATE (x32 Version: - WildTangent)
Final Drive: Nitro (x32 Version: - WildTangent)
Flachheizkörper-Auswahl 2011 Version 2.0 (x32 Version:  - )
FleetMon Explorer (x32 Version: 2.07 - JAKOTA Cruise Systems GmbH)
FormDocs 8.3.0 (x32 Version: 8.3.0 - FormDocs LLC)
Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Full Tilt Poker (x32 Version: 4.65.0.WIN.FullTilt.COM - )
Full Tilt Poker.Eu (x32 Version: 4.65.0.WIN.FullTilt.EU - )
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Galeria fotogràfica del Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Galerie foto Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Google Chrome (x32 Version: 31.0.1650.63 - Google Inc.)
Google Earth (x32 Version: - Google)
Google Update Helper (x32 Version: - Google Inc.)
Hydrostatix Master Suite (x32 Version: 1.0.43 - Hydrostatix)
Identity Card (x32 Version: 1.00.3501 - Acer Incorporated)
Insaniquarium Deluxe (x32 Version: - WildTangent)
Intel(R) Manageability Engine Firmware Recovery Agent (x32 Version: - Intel Corporation)
Intel(R) Management Engine Components (x32 Version: - Intel Corporation)
Intel(R) OpenCL CPU Runtime (x32 Version:  - Intel Corporation)
Intel(R) Processor Graphics (x32 Version: - Intel Corporation)
Intel(R) Rapid Start Technology (x32 Version: - Intel Corporation)
Intel(R) Rapid Storage Technology (x32 Version: - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (x32 Version: - Intel Corporation)
Intel® Trusted Connect Service Client (Version: 1.23.943.1 - Intel Corporation)
IrfanView (remove only) (x32 Version: 4.36 - Irfan Skiljan)
Java 7 Update 25 (64-bit) (Version: 7.0.250 - Oracle)
Java 7 Update 45 (x32 Version: 7.0.450 - Oracle)
Java Auto Updater (x32 Version: - Sun Microsystems, Inc.)
Java(TM) 6 Update 13 (64-bit) (Version: 6.0.130 - Sun Microsystems, Inc.)
Jewel Match 3 (x32 Version: - WildTangent)
Jewel Quest Mysteries: The Seventh Gate Collector's Edition (x32 Version: - WildTangent)
John Deere Drive Green (x32 Version: - WildTangent)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Kobo (x32 Version: 2.1.5 - Kobo Inc.)
Launch Manager (x32 Version: 5.1.15 - Acer Inc.)
Lexware Abschreibungsrechner (x32 Version: - Haufe-Lexware GmbH & Co.KG)
Lexware büro easy 2013 (x32 Version: - Haufe-Lexware GmbH & Co.KG)
Lexware Elster (x32 Version: - Haufe-Lexware GmbH & Co.KG)
Lexware Info Service (x32 Version: - Haufe-Lexware GmbH & Co.KG)
Lexware online banking (x32 Version: - Haufe-Lexware GmbH & Co.KG)
Lexware Sepa Check (x32 Version: - Haufe-Lexware GmbH & Co.KG)
Lexware Zeiterfassung (x32 Version: - Haufe-Lexware GmbH & Co.KG)
Logitech Harmony Remote Software 7 (x32 Version: - Logitech)
Logitech SetPoint 6.52 (Version: 6.52.74 - Logitech)
Logitech Unifying-Software 2.10 (Version: 2.10.37 - Logitech)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation)
Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Professional 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Single Image 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2005 Tools for Office Runtime (x32 Version: 8.0.60940.0 - Microsoft Corporation)
Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0 - Mozilla)
Mozilla Maintenance Service (x32 Version: 26.0 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft)
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft)
MyWinLocker (Version: - Egis Technology Inc.)
MyWinLocker 4 (x32 Version: - Egis Technology Inc.)
MyWinLocker Suite (x32 Version: - Egis Technology Inc.)
Office Addin (x32 Version: 2.02.2008 - Acer)
Office Addin 2003 (x32 Version: 2.02.2008 - Acer)
partypoker (x32 Version:  - PartyGaming)
PDF Architect (x32 Version: - pdfforge GmbH)
PDF Split And Merge Basic (Version: 2.2.2 - Andrea Vacondio)
PDFCreator (x32 Version: 1.7.0 - pdfforge)
Penguins! (x32 Version: - WildTangent)
Personal ID (x32 Version: 1.8.5 - coolspot AG)
Plants vs. Zombies - Game of the Year (x32 Version: - WildTangent)
PNMD (x32 Version: 1.00.0000 - NETRONIX)
Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Polar Bowler (x32 Version: - WildTangent)
Pošta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Qualcomm Atheros WiFi Driver Installation (x32 Version: 3.1 - Qualcomm Atheros)
Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Realtek High Definition Audio Driver (x32 Version: - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (x32 Version: 6.1.7601.39025 - Realtek Semiconductor Corp.)
Remote Control USB Driver (x32 Version: - )
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version:  - Microsoft)
Shredder (Version: - Egis Technology Inc.)
Shredder (x32 Version: - Egis Technology Inc.)
Skype™ 6.11 (x32 Version: 6.11.102 - Skype Technologies S.A.)
Sleep Memory Optimizer (x32 Version: 1.00.3004 - Acer Incorporated)
Slingo Deluxe (x32 Version: - WildTangent)
Smart Timer (x32 Version: 1.00.3004 - Acer Incorporated)
SSF Editor (x32 Version: 1.0.0 - SDSD)
Torchlight (x32 Version: - WildTangent)
Überwachungstool für die Intel® Turbo-Boost-Technik 2.5 (Version: - Intel)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (x32 Version: 3 - Microsoft Corporation)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2826026) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (x32 Version:  - Microsoft)
Update for Microsoft Word 2010 (KB2837593) 32-Bit Edition (x32 Version:  - Microsoft)
Update Installer for WildTangent Games App (x32 Version:  - WildTangent)
Virtual Villagers 4 - The Tree of Life (x32 Version: - WildTangent)
Visual Studio 2005 Tools for Office Second Edition Runtime (x32 Version:  - Microsoft Corporation)
Visual Studio Tools for the Office system 3.0 Runtime (x32 Version:  - Microsoft Corporation)
Visual Studio Tools for the Office system 3.0 Runtime (x32 Version: 9.0.30729 - Microsoft Corporation)
Visual Studio Tools for the Office system 3.0 Runtime Service Pack 1 (KB949258) (x32 Version: 1 - Microsoft Corporation)
Wedding Dash (x32 Version: - WildTangent)
Welcome Center (x32 Version: 1.02.3507 - Acer Incorporated)
WildTangent Games App (Acer Games) (x32 Version: - WildTangent)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 15.4.3538.0513 - Microsoft Corporation)
Windows Live Fotogaléria (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live Fotogalleri (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live Fotoğraf Galerisi (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live Fotótár (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live Galeria de Fotos (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live Galerija fotografija (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation)
Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live Language Selector (Version: 15.4.3538.0513 - Microsoft Corporation)
Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation)
Windows Live Messenger (x32 Version: 15.4.3538.0513 - Корпорация Майкрософт)
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live Temel Parçalar (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live 影像中心 (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Live 程式集 (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Liven asennustyökalu (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Liven sähköposti (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Windows Liven valokuvavalikoima (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Zuma Deluxe (x32 Version: - WildTangent)
Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт)
Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation)
معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation)

==================== Restore Points  =========================

==================== Hosts content: ==========================

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {2C04AD64-50FE-4D88-AC26-BDE2DD1FD904} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2012-03-26] (Intel Corporation)
Task: {56F06DD2-E015-43AD-B2FD-69C6114A441C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-11] (Adobe Systems Incorporated)
Task: {6450085A-4321-4BBA-8114-2546710C0CBB} - System32\Tasks\Theft Shield\AcerTheftShieldTask => C:\Program Files\Acer\Acer Theft Shield\USecuAppLauncher.exe [2012-11-12] (Acer Incorporated)
Task: {85AC4994-7CE6-4801-9FD0-E22957AA1A09} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2012-03-26] (Intel Corporation)
Task: {86171674-E24F-4CFB-85F6-495DA6CDEC29} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-08-30] (AVAST Software)
Task: {9E92F86C-CE0F-4F26-814C-D5A52B8C6234} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-05-04] (Google Inc.)
Task: {AE9AFAC4-40AC-45B6-A599-3305DA49F2FC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-05-04] (Google Inc.)
Task: {CC1E2782-52EE-4DCA-8FC9-37FE091CAC4B} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {CE86FF2C-F9C8-41A0-BFC8-067461DFA5BB} - System32\Tasks\DeviceDetector => C:\Program Files (x86)\Cyberlink\MediaEspresso\DeviceDetector\DeviceDetector.exe [2011-05-20] (CyberLink)
Task: {D10A3F32-1B9E-4820-95A8-F9460ED773B2} - System32\Tasks\Smart Timer Task Scheduler => Smart_Timer.exe
Task: {EA1E36F0-DD88-423F-A651-B4D9F2D504EF} - System32\Tasks\UALU notificatin => C:\Program Files\Acer\Acer Updater\UALU.exe [2012-02-07] (Acer Incorporated)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe

==================== Loaded Modules (whitelisted) =============

2013-05-04 11:11 - 2013-03-21 17:40 - 00111176 _____ () C:\Program Files (x86)\Acer\clear.fi plug-in\Clearfishellext_x64.dll
2013-04-30 23:55 - 2012-03-27 02:33 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2013-12-29 17:55 - 2013-12-29 13:58 - 02246144 _____ () C:\Program Files\AVAST Software\Avast\defs\13122900\algo.dll
2012-01-05 22:22 - 2012-01-05 22:22 - 00465344 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\sqlite3.dll
2012-01-05 22:22 - 2012-01-05 22:22 - 01081368 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\ACE.dll
2012-01-05 22:22 - 2012-01-05 22:22 - 00125464 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\MailConverter32.dll
2013-08-23 20:01 - 2013-08-23 20:01 - 25100288 _____ () C:\Users\APB\AppData\Roaming\Dropbox\bin\libcef.dll
2013-12-20 09:24 - 2013-12-20 09:24 - 03559024 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2013-04-30 14:24 - 2012-03-29 07:18 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\office14\Cultures\office.odf
2013-02-14 15:46 - 2013-02-14 15:46 - 01044048 _____ () C:\Program Files (x86)\Microsoft Office\Office14\ADDINS\UmOutlookAddin.dll

==================== Alternate Data Streams (whitelisted) =========

==================== Safe Mode (whitelisted) ===================

==================== Faulty Device Manager Devices =============

Name: HD WebCam
Description: USB-Videogerät
Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Manufacturer: Microsoft
Service: usbvideo
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

==================== Event log errors: =========================

Application errors:
Error: (12/30/2013 11:01:26 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "1". Fehler in Manifest- oder Richtliniendatei "2" in Zeile 3.
Ungültige XML-Syntax.

Error: (12/30/2013 11:01:26 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "1". Fehler in Manifest- oder Richtliniendatei "2" in Zeile 3.
Ungültige XML-Syntax.

Error: (12/30/2013 11:01:26 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "1". Fehler in Manifest- oder Richtliniendatei "2" in Zeile 3.
Ungültige XML-Syntax.

Error: (12/30/2013 11:01:26 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "1". Fehler in Manifest- oder Richtliniendatei "2" in Zeile 3.
Ungültige XML-Syntax.

Error: (12/30/2013 11:01:26 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "1". Fehler in Manifest- oder Richtliniendatei "2" in Zeile 3.
Ungültige XML-Syntax.

Error: (12/30/2013 11:01:26 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "1". Fehler in Manifest- oder Richtliniendatei "2" in Zeile 3.
Ungültige XML-Syntax.

Error: (12/30/2013 11:01:25 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "1". Fehler in Manifest- oder Richtliniendatei "2" in Zeile 3.
Ungültige XML-Syntax.

Error: (12/30/2013 11:01:25 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "1". Fehler in Manifest- oder Richtliniendatei "2" in Zeile 3.
Ungültige XML-Syntax.

Error: (12/30/2013 11:01:25 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "1". Fehler in Manifest- oder Richtliniendatei "2" in Zeile 3.
Ungültige XML-Syntax.

Error: (12/30/2013 11:01:25 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "1". Fehler in Manifest- oder Richtliniendatei "2" in Zeile 3.
Ungültige XML-Syntax.

System errors:
Error: (12/30/2013 01:25:19 PM) (Source: volsnap) (User: )
Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.

Error: (12/30/2013 01:21:59 PM) (Source: Ntfs) (User: )
Description: Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar.
Führen Sie auf dem Volume "My Passport" den Befehl "chkdsk" aus.

Error: (12/30/2013 01:21:59 PM) (Source: Ntfs) (User: )
Description: Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar.
Führen Sie auf dem Volume "My Passport" den Befehl "chkdsk" aus.

Error: (12/30/2013 01:21:59 PM) (Source: Ntfs) (User: )
Description: Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar.
Führen Sie auf dem Volume "My Passport" den Befehl "chkdsk" aus.

Error: (12/30/2013 01:21:59 PM) (Source: Ntfs) (User: )
Description: Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar.
Führen Sie auf dem Volume "My Passport" den Befehl "chkdsk" aus.

Error: (12/30/2013 01:21:59 PM) (Source: Ntfs) (User: )
Description: Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar.
Führen Sie auf dem Volume "My Passport" den Befehl "chkdsk" aus.

Error: (12/30/2013 01:21:59 PM) (Source: Ntfs) (User: )
Description: Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar.
Führen Sie auf dem Volume "My Passport" den Befehl "chkdsk" aus.

Error: (12/30/2013 01:21:59 PM) (Source: Ntfs) (User: )
Description: Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar.
Führen Sie auf dem Volume "My Passport" den Befehl "chkdsk" aus.

Error: (12/30/2013 01:21:59 PM) (Source: Ntfs) (User: )
Description: Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar.
Führen Sie auf dem Volume "My Passport" den Befehl "chkdsk" aus.

Error: (12/30/2013 01:21:59 PM) (Source: Ntfs) (User: )
Description: Die Dateisystemstruktur auf dem Datenträger ist beschädigt und unbrauchbar.
Führen Sie auf dem Volume "My Passport" den Befehl "chkdsk" aus.

Microsoft Office Sessions:
Error: (12/30/2013 11:01:26 AM) (Source: SideBySide)(User: )
Description: C:\Windows\system32\WFS.exeC:\Windows\system32\WFS.exe0

Error: (12/30/2013 11:01:26 AM) (Source: SideBySide)(User: )
Description: C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exeC:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe0

Error: (12/30/2013 11:01:26 AM) (Source: SideBySide)(User: )
Description: C:\Windows\system32\WFS.exeC:\Windows\system32\WFS.exe0

Error: (12/30/2013 11:01:26 AM) (Source: SideBySide)(User: )
Description: C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exeC:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe0

Error: (12/30/2013 11:01:26 AM) (Source: SideBySide)(User: )
Description: C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exeC:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe0

Error: (12/30/2013 11:01:26 AM) (Source: SideBySide)(User: )
Description: C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exeC:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe0

Error: (12/30/2013 11:01:25 AM) (Source: SideBySide)(User: )
Description: C:\Windows\ehome\ehshell.exeC:\Windows\ehome\ehshell.exe0

Error: (12/30/2013 11:01:25 AM) (Source: SideBySide)(User: )
Description: C:\Windows\system32\WindowsAnytimeUpgradeUI.exeC:\Windows\system32\WindowsAnytimeUpgradeUI.exe0

Error: (12/30/2013 11:01:25 AM) (Source: SideBySide)(User: )
Description: C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exeC:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe0

Error: (12/30/2013 11:01:25 AM) (Source: SideBySide)(User: )
Description: C:\Windows\system32\WindowsAnytimeUpgradeUI.exeC:\Windows\system32\WindowsAnytimeUpgradeUI.exe0

==================== Memory info =========================== 

Percentage of memory in use: 70%
Total physical RAM: 3934.36 MB
Available physical RAM: 1170.95 MB
Total Pagefile: 7866.89 MB
Available Pagefile: 4276.37 MB
Total Virtual: 8192 MB
Available Virtual: 8191.79 MB

==================== Drives ================================

Drive c: (ACER) (Fixed) (Total:450.53 GB) (Free:388.34 GB) NTFS

==================== MBR & Partition Table ==================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 6E8CE96C)
Partition 1: (Not Active) - (Size=15 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=451 GB) - (Type=07 NTFS)

Disk: 1 (MBR Code: Windows 7 or 8) (Size: 19 GB) (Disk ID: 37A019CD)
Partition 1: (Not Active) - (Size=4 GB) - (Type=84)
Partition 2: (Not Active) - (Size=15 GB) - (Type=73)

==================== End Of Log ============================

VIRUS oder nicht? System zunächst total unstabil, jetzt läuft wieder alles ?

VIRUS oder nicht? System zunächst total unstabil, jetzt läuft wieder alles ?

GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-12-30 13:57:57
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 WDC_WD50 rev.01.0 465,76GB
Running: 4s7438ut.exe; Driver: C:\Users\APB\AppData\Local\Temp\kxdoakob.sys

---- Kernel code sections - GMER 2.1 ----

INITKDBG  C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528                                                                                   fffff80003207000 45 bytes [00, 00, 1E, 02, 4E, 53, 49, ...]
INITKDBG  C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 575                                                                                   fffff8000320702f 16 bytes [00, 58, C0, 4F, 0B, 80, FA, ...]

---- User code sections - GMER 2.1 ----

.text     C:\Windows\System32\svchost.exe[700] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                           000000007789eecd 1 byte [62]
.text     C:\Windows\System32\svchost.exe[736] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                           000000007789eecd 1 byte [62]
.text     C:\Windows\system32\svchost.exe[1036] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                          000000007789eecd 1 byte [62]
.text     C:\Windows\Explorer.EXE[1572] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                  000000007789eecd 1 byte [62]
.text     C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe[1372] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                             000000007585a2ba 1 byte [62]
.text     C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe[2124] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                               000000007789eecd 1 byte [62]
.text     C:\Program Files\Logitech\SetPointP\SetPoint.exe[2260] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                         000000007789eecd 1 byte [62]
.text     C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE[2380] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                             000000007585a2ba 1 byte [62]
.text     C:\Program Files (x86)\PDF Architect\HelperService.exe[2168] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                   000000007585a2ba 1 byte [62]
.text     C:\Users\APB\AppData\Roaming\Dropbox\bin\Dropbox.exe[1556] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                     000000007585a2ba 1 byte [62]
.text     C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe[3180] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                     000000007585a2ba 1 byte [62]
.text     C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\mDNSResponder.exe[3252] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112  000000007585a2ba 1 byte [62]
.text     C:\Program Files (x86)\Launch Manager\LManager.exe[3260] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                       000000007585a2ba 1 byte [62]
.text     C:\Program Files\AVAST Software\Avast\AvastUI.exe[3380] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                        000000007585a2ba 1 byte [62]
.text     C:\Program Files (x86)\Common Files\Research in Motion\USB Drivers\RIMBBLaunchAgent.exe[3440] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112  000000007585a2ba 1 byte [62]
.text     C:\Windows\system32\svchost.exe[3448] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                          000000007789eecd 1 byte [62]
.text     C:\Program Files (x86)\Atheros\Ath_WlanAgent.exe[3528] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                         000000007585a2ba 1 byte [62]
.text     C:\Program Files (x86)\Common Files\Research in Motion\Tunnel Manager\PeerManager.exe[3548] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112    000000007585a2ba 1 byte [62]
.text     C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe[3576] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112           000000007585a2ba 1 byte [62]
.text     C:\Windows\system32\igfxsrvc.exe[5608] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                    0000000077a83b10 5 bytes JMP 000000010021075c
.text     C:\Windows\system32\igfxsrvc.exe[5608] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                      0000000077a87ac0 5 bytes JMP 00000001002103a4
.text     C:\Windows\system32\igfxsrvc.exe[5608] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                                         0000000077ab1430 5 bytes JMP 0000000100210b14
.text     C:\Windows\system32\igfxsrvc.exe[5608] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                                             0000000077ab1490 5 bytes JMP 0000000100210ecc
.text     C:\Windows\system32\igfxsrvc.exe[5608] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                              0000000077ab1570 5 bytes JMP 000000010021163c
.text     C:\Windows\system32\igfxsrvc.exe[5608] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                                          0000000077ab17b0 5 bytes JMP 0000000100211284
.text     C:\Windows\system32\igfxsrvc.exe[5608] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                              0000000077ab27e0 5 bytes JMP 00000001002119f4
.text     C:\Windows\system32\SearchIndexer.exe[5772] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                               0000000077a83b10 5 bytes JMP 00000001001a075c
.text     C:\Windows\system32\SearchIndexer.exe[5772] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                 0000000077a87ac0 5 bytes JMP 00000001001a03a4
.text     C:\Windows\system32\SearchIndexer.exe[5772] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                                    0000000077ab1430 5 bytes JMP 00000001001a0b14
.text     C:\Windows\system32\SearchIndexer.exe[5772] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                                        0000000077ab1490 5 bytes JMP 00000001001a0ecc
.text     C:\Windows\system32\SearchIndexer.exe[5772] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                         0000000077ab1570 5 bytes JMP 00000001001a163c
.text     C:\Windows\system32\SearchIndexer.exe[5772] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                                     0000000077ab17b0 5 bytes JMP 00000001001a1284
.text     C:\Windows\system32\SearchIndexer.exe[5772] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                         0000000077ab27e0 5 bytes JMP 00000001001a19f4
.text     C:\Windows\system32\SearchIndexer.exe[5772] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                                                    000000007789eecd 1 byte [62]
.text     C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe[5060] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory          0000000077c5fac0 5 bytes JMP 0000000100030600
.text     C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe[5060] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory              0000000077c5fb58 5 bytes JMP 0000000100030804
.text     C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe[5060] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess               0000000077c5fcb0 5 bytes JMP 0000000100030c0c
.text     C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe[5060] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory           0000000077c60038 5 bytes JMP 0000000100030a08
.text     C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe[5060] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread               0000000077c61920 5 bytes JMP 0000000100030e10
.text     C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe[5060] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                       0000000077c7c4dd 5 bytes JMP 00000001000301f8
.text     C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe[5060] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                     0000000077c81287 5 bytes JMP 00000001000303fc
.text     C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe[5060] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112          000000007585a2ba 1 byte [62]
.text     C:\Program Files\Windows Media Player\wmpnetwk.exe[6416] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                  0000000077a83b10 5 bytes JMP 000000010011075c
.text     C:\Program Files\Windows Media Player\wmpnetwk.exe[6416] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                    0000000077a87ac0 5 bytes JMP 00000001001103a4
.text     C:\Program Files\Windows Media Player\wmpnetwk.exe[6416] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                       0000000077ab1430 5 bytes JMP 0000000100110b14
.text     C:\Program Files\Windows Media Player\wmpnetwk.exe[6416] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                           0000000077ab1490 5 bytes JMP 0000000100110ecc
.text     C:\Program Files\Windows Media Player\wmpnetwk.exe[6416] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                            0000000077ab1570 5 bytes JMP 000000010011163c
.text     C:\Program Files\Windows Media Player\wmpnetwk.exe[6416] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                        0000000077ab17b0 5 bytes JMP 0000000100111284
.text     C:\Program Files\Windows Media Player\wmpnetwk.exe[6416] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                            0000000077ab27e0 5 bytes JMP 00000001001119f4
.text     C:\Program Files\Windows Media Player\wmpnetwk.exe[6416] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                                       000000007789eecd 1 byte [62]
.text     C:\Program Files\Windows Media Player\wmpnetwk.exe[6416] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity                                    000007fefe536e00 5 bytes JMP 000007ff7e551dac
.text     C:\Program Files\Windows Media Player\wmpnetwk.exe[6416] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA                                        000007fefe536f2c 5 bytes JMP 000007ff7e550ecc
.text     C:\Program Files\Windows Media Player\wmpnetwk.exe[6416] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW                                        000007fefe537220 5 bytes JMP 000007ff7e551284
.text     C:\Program Files\Windows Media Player\wmpnetwk.exe[6416] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A                                       000007fefe53739c 5 bytes JMP 000007ff7e55163c
.text     C:\Program Files\Windows Media Player\wmpnetwk.exe[6416] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W                                       000007fefe537538 5 bytes JMP 000007ff7e5519f4
.text     C:\Program Files\Windows Media Player\wmpnetwk.exe[6416] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA                                              000007fefe5375e8 5 bytes JMP 000007ff7e5503a4
.text     C:\Program Files\Windows Media Player\wmpnetwk.exe[6416] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW                                              000007fefe53790c 5 bytes JMP 000007ff7e55075c
.text     C:\Program Files\Windows Media Player\wmpnetwk.exe[6416] C:\Windows\SYSTEM32\sechost.dll!DeleteService                                               000007fefe537ab4 5 bytes JMP 000007ff7e550b14
.text     C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[6692] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory            0000000077c5fac0 5 bytes JMP 0000000100150600
.text     C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[6692] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory                0000000077c5fb58 5 bytes JMP 0000000100150804
.text     C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[6692] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                 0000000077c5fcb0 5 bytes JMP 0000000100150c0c
.text     C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[6692] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory             0000000077c60038 5 bytes JMP 0000000100150a08
.text     C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[6692] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                 0000000077c61920 5 bytes JMP 0000000100150e10
.text     C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[6692] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                         0000000077c7c4dd 5 bytes JMP 00000001001501f8
.text     C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[6692] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                       0000000077c81287 5 bytes JMP 00000001001503fc
.text     C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[6692] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112            000000007585a2ba 1 byte [62]
.text     C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[6700] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory         0000000077c5fac0 5 bytes JMP 0000000100090600
.text     C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[6700] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory             0000000077c5fb58 5 bytes JMP 0000000100090804
.text     C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[6700] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess              0000000077c5fcb0 5 bytes JMP 0000000100090c0c
.text     C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[6700] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory          0000000077c60038 5 bytes JMP 0000000100090a08
.text     C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[6700] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread              0000000077c61920 5 bytes JMP 0000000100090e10
.text     C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[6700] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                      0000000077c7c4dd 5 bytes JMP 00000001000901f8
.text     C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[6700] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                    0000000077c81287 5 bytes JMP 00000001000903fc
.text     C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[6700] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112         000000007585a2ba 1 byte [62]
.text     C:\Windows\System32\svchost.exe[7052] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                     0000000077a83b10 5 bytes JMP 000000010023075c
.text     C:\Windows\System32\svchost.exe[7052] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                       0000000077a87ac0 5 bytes JMP 00000001002303a4
.text     C:\Windows\System32\svchost.exe[7052] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory                                                          0000000077ab1430 5 bytes JMP 0000000100230b14
.text     C:\Windows\System32\svchost.exe[7052] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory                                                              0000000077ab1490 5 bytes JMP 0000000100230ecc
.text     C:\Windows\System32\svchost.exe[7052] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                                                               0000000077ab1570 5 bytes JMP 000000010023163c
.text     C:\Windows\System32\svchost.exe[7052] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory                                                           0000000077ab17b0 5 bytes JMP 0000000100231284
.text     C:\Windows\System32\svchost.exe[7052] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                               0000000077ab27e0 5 bytes JMP 00000001002319f4
.text     C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4492] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory           0000000077c5fac0 5 bytes JMP 0000000100030600
.text     C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4492] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory               0000000077c5fb58 5 bytes JMP 0000000100030804
.text     C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4492] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                0000000077c5fcb0 5 bytes JMP 0000000100030c0c
.text     C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4492] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory            0000000077c60038 5 bytes JMP 0000000100030a08
.text     C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4492] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                0000000077c61920 5 bytes JMP 0000000100030e10
.text     C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4492] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                        0000000077c7c4dd 5 bytes JMP 00000001000301f8
.text     C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4492] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                      0000000077c81287 5 bytes JMP 00000001000303fc
.text     C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4492] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112           000000007585a2ba 1 byte [62]
.text     C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[6280] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory           0000000077c5fac0 5 bytes JMP 0000000100030600
.text     C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[6280] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory               0000000077c5fb58 5 bytes JMP 0000000100030804
.text     C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[6280] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                0000000077c5fcb0 5 bytes JMP 0000000100030c0c
.text     C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[6280] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory            0000000077c60038 5 bytes JMP 0000000100030a08
.text     C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[6280] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                0000000077c61920 5 bytes JMP 0000000100030e10
.text     C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[6280] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                        0000000077c7c4dd 5 bytes JMP 00000001000301f8
.text     C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[6280] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                      0000000077c81287 5 bytes JMP 00000001000303fc
.text     C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[6280] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112           000000007585a2ba 1 byte [62]
.text     C:\Windows\system32\AUDIODG.EXE[5744] C:\Windows\System32\kernel32.dll!GetBinaryTypeW + 189                                                          000000007789eecd 1 byte [62]
.text     C:\Users\APB\Desktop\4s7438ut.exe[1224] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory                                                        0000000077c5fac0 5 bytes JMP 0000000100030600
.text     C:\Users\APB\Desktop\4s7438ut.exe[1224] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory                                                            0000000077c5fb58 5 bytes JMP 0000000100030804
.text     C:\Users\APB\Desktop\4s7438ut.exe[1224] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess                                                             0000000077c5fcb0 5 bytes JMP 0000000100030c0c
.text     C:\Users\APB\Desktop\4s7438ut.exe[1224] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory                                                         0000000077c60038 5 bytes JMP 0000000100030a08
.text     C:\Users\APB\Desktop\4s7438ut.exe[1224] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread                                                             0000000077c61920 5 bytes JMP 0000000100030e10
.text     C:\Users\APB\Desktop\4s7438ut.exe[1224] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                                                                     0000000077c7c4dd 5 bytes JMP 00000001000301f8
.text     C:\Users\APB\Desktop\4s7438ut.exe[1224] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                                                                   0000000077c81287 5 bytes JMP 00000001000303fc
.text     C:\Users\APB\Desktop\4s7438ut.exe[1224] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112                                                        000000007585a2ba 1 byte [62]
.text     C:\Users\APB\Desktop\4s7438ut.exe[1224] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity                                                     0000000075ea5181 5 bytes JMP 00000001001e1014
.text     C:\Users\APB\Desktop\4s7438ut.exe[1224] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA                                                         0000000075ea5254 5 bytes JMP 00000001001e0804
.text     C:\Users\APB\Desktop\4s7438ut.exe[1224] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigW                                                         0000000075ea53d5 5 bytes JMP 00000001001e0a08
.text     C:\Users\APB\Desktop\4s7438ut.exe[1224] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A                                                        0000000075ea54c2 5 bytes JMP 00000001001e0c0c
.text     C:\Users\APB\Desktop\4s7438ut.exe[1224] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W                                                        0000000075ea55e2 5 bytes JMP 00000001001e0e10
.text     C:\Users\APB\Desktop\4s7438ut.exe[1224] C:\Windows\SysWOW64\sechost.dll!CreateServiceA                                                               0000000075ea567c 5 bytes JMP 00000001001e01f8
.text     C:\Users\APB\Desktop\4s7438ut.exe[1224] C:\Windows\SysWOW64\sechost.dll!CreateServiceW                                                               0000000075ea589f 5 bytes JMP 00000001001e03fc
.text     C:\Users\APB\Desktop\4s7438ut.exe[1224] C:\Windows\SysWOW64\sechost.dll!DeleteService                                                                0000000075ea5a22 5 bytes JMP 00000001001e0600
.text     C:\Users\APB\Desktop\4s7438ut.exe[1224] C:\Windows\syswow64\USER32.dll!SetWinEventHook                                                               000000007600ee09 5 bytes JMP 00000001001f01f8
.text     C:\Users\APB\Desktop\4s7438ut.exe[1224] C:\Windows\syswow64\USER32.dll!UnhookWinEvent                                                                0000000076013982 5 bytes JMP 00000001001f03fc
.text     C:\Users\APB\Desktop\4s7438ut.exe[1224] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW                                                             0000000076017603 5 bytes JMP 00000001001f0804
.text     C:\Users\APB\Desktop\4s7438ut.exe[1224] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA                                                             000000007601835c 5 bytes JMP 00000001001f0600
.text     C:\Users\APB\Desktop\4s7438ut.exe[1224] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx                                                           000000007602f52b 5 bytes JMP 00000001001f0a08

---- Threads - GMER 2.1 ----

Thread    C:\Windows\system32\svchost.exe [948:3900]                                                                                                           000007fefaab2154
Thread    C:\Windows\system32\svchost.exe [400:3896]                                                                                                           000007fefaab2154
Thread    C:\Windows\System32\svchost.exe [700:1108]                                                                                                           000007fefc1ef2f4
Thread    C:\Windows\System32\svchost.exe [700:1124]                                                                                                           000007fefc016204
Thread    C:\Windows\System32\svchost.exe [700:1256]                                                                                                           000007fefb7c2070
Thread    C:\Windows\System32\svchost.exe [700:1284]                                                                                                           000007fefb625428
Thread    C:\Windows\System32\svchost.exe [700:6880]                                                                                                           000007fefe5cc608
Thread    C:\Windows\System32\svchost.exe [700:2916]                                                                                                           000007fee92a6b8c
Thread    C:\Windows\System32\svchost.exe [700:4116]                                                                                                           000007fee92a1d88
Thread    C:\Windows\System32\svchost.exe [700:1312]                                                                                                           000007fefad65fd0
Thread    C:\Windows\System32\svchost.exe [700:2208]                                                                                                           000007fefb70a828
Thread    C:\Windows\System32\svchost.exe [736:1340]                                                                                                           000007fefb2659a0
Thread    C:\Windows\System32\svchost.exe [736:1424]                                                                                                           000007fefd271a70
Thread    C:\Windows\System32\svchost.exe [736:5072]                                                                                                           000007fef5d188f8
Thread    C:\Windows\System32\svchost.exe [736:5108]                                                                                                           000007fef51544e0
Thread    C:\Windows\System32\svchost.exe [736:1804]                                                                                                           000007feed1720c0
Thread    C:\Windows\System32\svchost.exe [736:4072]                                                                                                           000007feed1726a8
Thread    C:\Windows\System32\svchost.exe [736:4860]                                                                                                           000007feed1729dc
Thread    C:\Windows\System32\svchost.exe [736:6564]                                                                                                           000007feead33efc
Thread    C:\Windows\System32\svchost.exe [736:3420]                                                                                                           000007feead78a4c
Thread    C:\Windows\System32\svchost.exe [736:6076]                                                                                                           000007feeac442c8
Thread    C:\Windows\System32\svchost.exe [736:892]                                                                                                            000007fefad65fd0
Thread    C:\Windows\System32\svchost.exe [736:4900]                                                                                                           000007fefad663ec
Thread    C:\Windows\system32\svchost.exe [964:6840]                                                                                                           000007feeb41d3c8
Thread    C:\Windows\system32\svchost.exe [964:6336]                                                                                                           000007feeb41d3c8
Thread    C:\Windows\system32\svchost.exe [964:6860]                                                                                                           000007feeb41d3c8
Thread    C:\Windows\system32\svchost.exe [964:6856]                                                                                                           000007feeb41d3c8
Thread    C:\Windows\system32\svchost.exe [964:5276]                                                                                                           000007feeb54c2d4
Thread    C:\Windows\system32\svchost.exe [964:4468]                                                                                                           000007feeb54c2d4
Thread    C:\Windows\system32\svchost.exe [964:3876]                                                                                                           000007feeb54c2d4
Thread    C:\Windows\system32\svchost.exe [964:3048]                                                                                                           000007feeb54c2d4
Thread    C:\Windows\system32\svchost.exe [964:5636]                                                                                                           000007fef5d55124
Thread    C:\Windows\system32\svchost.exe [1036:5404]                                                                                                          000007feefba506c
Thread    C:\Windows\system32\svchost.exe [1036:5408]                                                                                                          000007fef8081c20
Thread    C:\Windows\system32\svchost.exe [1036:5412]                                                                                                          000007fef8081c20
Thread    C:\Windows\system32\svchost.exe [1036:2456]                                                                                                          000007fef5d55124
Thread    C:\Windows\system32\svchost.exe [1036:6740]                                                                                                          000007fee6cccb70
Thread    C:\Windows\system32\svchost.exe [1128:1420]                                                                                                          000007fefbd28274
Thread    C:\Windows\system32\svchost.exe [1128:1540]                                                                                                          000007fefbd28274
Thread    C:\Windows\system32\svchost.exe [1244:1292]                                                                                                          000007fefb6c341c
Thread    C:\Windows\system32\svchost.exe [1244:1300]                                                                                                          000007fefb6c3a2c
Thread    C:\Windows\system32\svchost.exe [1244:1304]                                                                                                          000007fefb6c3768
Thread    C:\Windows\system32\svchost.exe [1244:1308]                                                                                                          000007fefb6c5c20
Thread    C:\Windows\system32\svchost.exe [1244:3036]                                                                                                          000007fef61cbd88
Thread    C:\Windows\system32\svchost.exe [1244:4916]                                                                                                          000007fef8505170
Thread    C:\Windows\system32\svchost.exe [1244:6544]                                                                                                          000007fef5d55124
Thread    C:\Windows\system32\svchost.exe [1244:6816]                                                                                                          000007fefb6c3900
Thread    C:\Windows\System32\spoolsv.exe [1784:3796]                                                                                                          000007fefa9410c8
Thread    C:\Windows\System32\spoolsv.exe [1784:3852]                                                                                                          000007fef6c26144
Thread    C:\Windows\System32\spoolsv.exe [1784:3856]                                                                                                          000007fefad65fd0
Thread    C:\Windows\System32\spoolsv.exe [1784:3860]                                                                                                          000007fefa903438
Thread    C:\Windows\System32\spoolsv.exe [1784:3864]                                                                                                          000007fefad663ec
Thread    C:\Windows\System32\spoolsv.exe [1784:3868]                                                                                                          000007fefa903438
Thread    C:\Windows\System32\spoolsv.exe [1784:3872]                                                                                                          000007fefad663ec
Thread    C:\Windows\System32\spoolsv.exe [1784:3904]                                                                                                          000007fef52e5e5c
Thread    C:\Windows\System32\spoolsv.exe [1784:3984]                                                                                                          000007fef5415074
Thread    C:\Windows\system32\svchost.exe [1824:1852]                                                                                                          000007fefd271a70
Thread    C:\Windows\system32\svchost.exe [1824:1856]                                                                                                          000007fefd271a70
Thread    C:\Windows\system32\svchost.exe [1824:1936]                                                                                                          000007fefd271a70
Thread    C:\Windows\system32\svchost.exe [1824:1960]                                                                                                          000007fef9a52c70
Thread    C:\Windows\system32\svchost.exe [1824:1992]                                                                                                          000007fef9a5fb40
Thread    C:\Windows\system32\svchost.exe [1824:2004]                                                                                                          000007fef9a71d20
Thread    C:\Windows\system32\svchost.exe [1824:2008]                                                                                                          000007fef9a5f6f0
Thread    C:\Windows\system32\svchost.exe [1824:1672]                                                                                                          000007fef84335c0
Thread    C:\Windows\system32\svchost.exe [1824:6000]                                                                                                          000007fef8435600
Thread    C:\Windows\system32\svchost.exe [1824:6504]                                                                                                          000007feebb82888
Thread    C:\Windows\system32\svchost.exe [1824:6532]                                                                                                          000007feebb52940
Thread    C:\Windows\system32\svchost.exe [2488:2932]                                                                                                          000007fefad65fd0
Thread    C:\Windows\system32\svchost.exe [2488:2944]                                                                                                          000007fefad663ec
Thread    C:\Windows\system32\svchost.exe [2488:6536]                                                                                                          000007feec1d8470
Thread    C:\Windows\system32\svchost.exe [2488:6540]                                                                                                          000007feec1e2418
Thread    C:\Windows\system32\svchost.exe [2488:6400]                                                                                                          000007feeb47f130
Thread    C:\Windows\system32\svchost.exe [2488:4192]                                                                                                          000007feeb474734
Thread    C:\Windows\system32\svchost.exe [2488:6284]                                                                                                          000007feeb474734
Thread    C:\Windows\system32\svchost.exe [2488:4144]                                                                                                          000007feec1e976c
Thread    C:\Windows\system32\wbem\wmiprvse.exe [5420:5488]                                                                                                    000007fef8081c20
Thread    C:\Program Files\Windows Media Player\wmpnetwk.exe [6416:5068]                                                                                       000007fefe130168
Thread    C:\Program Files\Windows Media Player\wmpnetwk.exe [6416:4944]                                                                                       000007fefbb72a7c
Thread    C:\Program Files\Windows Media Player\wmpnetwk.exe [6416:3100]                                                                                       000007fee9634830
Thread    C:\Program Files\Windows Media Player\wmpnetwk.exe [6416:5948]                                                                                       000007fef5d55124
Thread    C:\Windows\System32\svchost.exe [7052:7068]                                                                                                          000007fef8505170
Thread    C:\Windows\System32\svchost.exe [7052:2448]                                                                                                          000007fef5d59874
Thread    C:\Windows\System32\svchost.exe [6084:5748]                                                                                                          000007fee6f29688

---- Registry - GMER 2.1 ----

Reg       HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{899AC9CD-C277-40F6-88FB-A8BC50C6E288}\Connection@Name          isatap.{637B9800-7C80-4D5C-91D8-2880EB94C04D}
Reg       HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Bind             \Device\{B6DAEFB3-F26A-4480-BB27-0FEF2D71DF24}?\Device\{899AC9CD-C277-40F6-88FB-A8BC50C6E288}?\Device\{2094E1C8-9A5C-4BB7-BA6E-243B1BA58B49}?\Device\{9BB5DC1F-C610-484A-823D-6E536CDF9C41}?
Reg       HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Route            "{B6DAEFB3-F26A-4480-BB27-0FEF2D71DF24}"?"{899AC9CD-C277-40F6-88FB-A8BC50C6E288}"?"{2094E1C8-9A5C-4BB7-BA6E-243B1BA58B49}"?"{9BB5DC1F-C610-484A-823D-6E536CDF9C41}"?
Reg       HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Export           \Device\TCPIP6TUNNEL_{B6DAEFB3-F26A-4480-BB27-0FEF2D71DF24}?\Device\TCPIP6TUNNEL_{899AC9CD-C277-40F6-88FB-A8BC50C6E288}?\Device\TCPIP6TUNNEL_{2094E1C8-9A5C-4BB7-BA6E-243B1BA58B49}?\Device\TCPIP6TUNNEL_{9BB5DC1F-C610-484A-823D-6E536CDF9C41}?
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@Type                                                                                                 2
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@Start                                                                                                2
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@ErrorControl                                                                                         1
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@DisplayName                                                                                          aswFsBlk
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@Group                                                                                                FSFilter Activity Monitor
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@DependOnService                                                                                      FltMgr?
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@Description                                                                                          avast! mini-filter driver (aswFsBlk)
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@Tag                                                                                                  3
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk\Instances                                                                                            
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk\Instances@DefaultInstance                                                                            aswFsBlk Instance
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk\Instances\aswFsBlk Instance                                                                          
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk\Instances\aswFsBlk Instance@Altitude                                                                 388400
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk\Instances\aswFsBlk Instance@Flags                                                                    0
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk                                                                                                      
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@Type                                                                                                2
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@Start                                                                                               2
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@ErrorControl                                                                                        1
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@ImagePath                                                                                           \??\C:\Windows\system32\drivers\aswMonFlt.sys
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@DisplayName                                                                                         aswMonFlt
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@Group                                                                                               FSFilter Anti-Virus
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@DependOnService                                                                                     FltMgr?
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@Description                                                                                         avast! mini-filter driver (aswMonFlt)
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt\Instances                                                                                           
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt\Instances@DefaultInstance                                                                           aswMonFlt Instance
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt\Instances\aswMonFlt Instance                                                                        
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt\Instances\aswMonFlt Instance@Altitude                                                               320700
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt\Instances\aswMonFlt Instance@Flags                                                                  0
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt                                                                                                     
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRdr@ImagePath                                                                                              \SystemRoot\System32\Drivers\aswrdr2.sys
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRdr@Type                                                                                                   1
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRdr@Start                                                                                                  1
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRdr@ErrorControl                                                                                           1
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRdr@DisplayName                                                                                            aswRdr
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRdr@Group                                                                                                  PNP_TDI
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRdr@DependOnService                                                                                        tcpip?
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRdr@Description                                                                                            avast! WFP Redirect driver
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRdr\Parameters                                                                                             
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRdr\Parameters@MSIgnoreLSPDefault                                                                          
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRdr\Parameters@WSIgnoreLSPDefault                                                                          nl_lsp.dll,imon.dll,xfire_lsp.dll,mslsp.dll,mssplsp.dll,cwhook.dll,spi.dll,bmnet.dll,winsflt.dll
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRdr                                                                                                        
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRvrt@Type                                                                                                  1
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRvrt@Start                                                                                                 0
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRvrt@ErrorControl                                                                                          1
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRvrt@DisplayName                                                                                           aswRvrt
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRvrt@Description                                                                                           avast! Revert
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters                                                                                            
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters@BootCounter                                                                                91
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters@TickCounter                                                                                7658193
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters@SystemRoot                                                                                 \Device\Harddisk0\Partition3\Windows
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters@ImproperShutdown                                                                           1
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswRvrt                                                                                                       
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx@Type                                                                                                   2
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx@Start                                                                                                  1
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx@ErrorControl                                                                                           1
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx@DisplayName                                                                                            aswSnx
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx@Group                                                                                                  FSFilter Virtualization
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx@DependOnService                                                                                        FltMgr?
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx@Description                                                                                            avast! virtualization driver (aswSnx)
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx@Tag                                                                                                    2
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Instances                                                                                              
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Instances@DefaultInstance                                                                              aswSnx Instance
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Instances\aswSnx Instance                                                                              
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Instances\aswSnx Instance@Altitude                                                                     137600
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Instances\aswSnx Instance@Flags                                                                        0
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Parameters                                                                                             
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Parameters@ProgramFolder                                                                               \DosDevices\C:\Program Files\AVAST Software\Avast
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Parameters@DataFolder                                                                                  \DosDevices\C:\ProgramData\AVAST Software\Avast
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSnx                                                                                                        
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSP@Type                                                                                                    1
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSP@Start                                                                                                   1
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSP@ErrorControl                                                                                            1
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSP@DisplayName                                                                                             aswSP
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSP@Description                                                                                             avast! Self Protection
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters                                                                                              
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters@BehavShield                                                                                  1
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters@ProgramFolder                                                                                \DosDevices\C:\Program Files\AVAST Software\Avast
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters@DataFolder                                                                                   \DosDevices\C:\ProgramData\AVAST Software\Avast
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters@ProgramFilesFolder                                                                           \DosDevices\C:\Program Files
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters@GadgetFolder                                                                                 \DosDevices\C:\Program Files\Windows Sidebar\Shared Gadgets\aswSidebar.gadget
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters@NoWelcomeScreen                                                                              1
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswSP                                                                                                         
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswTdi@Type                                                                                                   1
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswTdi@Start                                                                                                  1
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswTdi@ErrorControl                                                                                           1
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswTdi@DisplayName                                                                                            avast! Network Shield Support
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswTdi@Group                                                                                                  PNP_TDI
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswTdi@DependOnService                                                                                        tcpip?
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswTdi@Description                                                                                            avast! Network Shield TDI driver
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswTdi@Tag                                                                                                    11
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswTdi                                                                                                        
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswVmm@Type                                                                                                   1
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswVmm@Start                                                                                                  0
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswVmm@ErrorControl                                                                                           1
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswVmm@DisplayName                                                                                            aswVmm
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswVmm@Description                                                                                            avast! VM Monitor
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswVmm\Parameters                                                                                             
Reg       HKLM\SYSTEM\CurrentControlSet\services\aswVmm                                                                                                        
Reg       HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@Type                                                                                         32
Reg       HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@Start                                                                                        2
Reg       HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@ErrorControl                                                                                 1
Reg       HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@ImagePath                                                                                    "C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
Reg       HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@DisplayName                                                                                  avast! Antivirus
Reg       HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@Group                                                                                        ShellSvcGroup
Reg       HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@DependOnService                                                                              aswMonFlt?RpcSS?
Reg       HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@WOW64                                                                                        1
Reg       HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@ObjectName                                                                                   LocalSystem
Reg       HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@ServiceSidType                                                                               1
Reg       HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@Description                                                                                  Verwaltet und implementiert avast! Antivirus-Dienste f?r diesen Computer. Dies beinhaltet den Echtzeit-Schutz, den Virus-Container und den Planer.
Reg       HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus                                                                                              
Reg       HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\844bf5a75a0e                                                                          
Reg       HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\c018855b6f38                                                                          
Reg       HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{899AC9CD-C277-40F6-88FB-A8BC50C6E288}@InterfaceName                               isatap.{637B9800-7C80-4D5C-91D8-2880EB94C04D}
Reg       HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{899AC9CD-C277-40F6-88FB-A8BC50C6E288}@ReusableType                                0
Reg       HKLM\SYSTEM\ControlSet002\services\aswFsBlk@Type                                                                                                     2
Reg       HKLM\SYSTEM\ControlSet002\services\aswFsBlk@Start                                                                                                    2
Reg       HKLM\SYSTEM\ControlSet002\services\aswFsBlk@ErrorControl                                                                                             1
Reg       HKLM\SYSTEM\ControlSet002\services\aswFsBlk@DisplayName                                                                                              aswFsBlk
Reg       HKLM\SYSTEM\ControlSet002\services\aswFsBlk@Group                                                                                                    FSFilter Activity Monitor
Reg       HKLM\SYSTEM\ControlSet002\services\aswFsBlk@DependOnService                                                                                          FltMgr?
Reg       HKLM\SYSTEM\ControlSet002\services\aswFsBlk@Description                                                                                              avast! mini-filter driver (aswFsBlk)
Reg       HKLM\SYSTEM\ControlSet002\services\aswFsBlk@Tag                                                                                                      3
Reg       HKLM\SYSTEM\ControlSet002\services\aswFsBlk\Instances (not active ControlSet)                                                                        
Reg       HKLM\SYSTEM\ControlSet002\services\aswFsBlk\Instances@DefaultInstance                                                                                aswFsBlk Instance
Reg       HKLM\SYSTEM\ControlSet002\services\aswFsBlk\Instances\aswFsBlk Instance (not active ControlSet)                                                      
Reg       HKLM\SYSTEM\ControlSet002\services\aswFsBlk\Instances\aswFsBlk Instance@Altitude                                                                     388400
Reg       HKLM\SYSTEM\ControlSet002\services\aswFsBlk\Instances\aswFsBlk Instance@Flags                                                                        0
Reg       HKLM\SYSTEM\ControlSet002\services\aswMonFlt@Type                                                                                                    2
Reg       HKLM\SYSTEM\ControlSet002\services\aswMonFlt@Start                                                                                                   2
Reg       HKLM\SYSTEM\ControlSet002\services\aswMonFlt@ErrorControl                                                                                            1
Reg       HKLM\SYSTEM\ControlSet002\services\aswMonFlt@ImagePath                                                                                               \??\C:\Windows\system32\drivers\aswMonFlt.sys
Reg       HKLM\SYSTEM\ControlSet002\services\aswMonFlt@DisplayName                                                                                             aswMonFlt
Reg       HKLM\SYSTEM\ControlSet002\services\aswMonFlt@Group                                                                                                   FSFilter Anti-Virus
Reg       HKLM\SYSTEM\ControlSet002\services\aswMonFlt@DependOnService                                                                                         FltMgr?
Reg       HKLM\SYSTEM\ControlSet002\services\aswMonFlt@Description                                                                                             avast! mini-filter driver (aswMonFlt)
Reg       HKLM\SYSTEM\ControlSet002\services\aswMonFlt\Instances (not active ControlSet)                                                                       
Reg       HKLM\SYSTEM\ControlSet002\services\aswMonFlt\Instances@DefaultInstance                                                                               aswMonFlt Instance
Reg       HKLM\SYSTEM\ControlSet002\services\aswMonFlt\Instances\aswMonFlt Instance (not active ControlSet)                                                    
Reg       HKLM\SYSTEM\ControlSet002\services\aswMonFlt\Instances\aswMonFlt Instance@Altitude                                                                   320700
Reg       HKLM\SYSTEM\ControlSet002\services\aswMonFlt\Instances\aswMonFlt Instance@Flags                                                                      0
Reg       HKLM\SYSTEM\ControlSet002\services\aswRdr@ImagePath                                                                                                  \SystemRoot\System32\Drivers\aswrdr2.sys
Reg       HKLM\SYSTEM\ControlSet002\services\aswRdr@Type                                                                                                       1
Reg       HKLM\SYSTEM\ControlSet002\services\aswRdr@Start                                                                                                      1
Reg       HKLM\SYSTEM\ControlSet002\services\aswRdr@ErrorControl                                                                                               1
Reg       HKLM\SYSTEM\ControlSet002\services\aswRdr@DisplayName                                                                                                aswRdr
Reg       HKLM\SYSTEM\ControlSet002\services\aswRdr@Group                                                                                                      PNP_TDI
Reg       HKLM\SYSTEM\ControlSet002\services\aswRdr@DependOnService                                                                                            tcpip?
Reg       HKLM\SYSTEM\ControlSet002\services\aswRdr@Description                                                                                                avast! WFP Redirect driver
Reg       HKLM\SYSTEM\ControlSet002\services\aswRdr\Parameters (not active ControlSet)                                                                         
Reg       HKLM\SYSTEM\ControlSet002\services\aswRdr\Parameters@MSIgnoreLSPDefault                                                                              
Reg       HKLM\SYSTEM\ControlSet002\services\aswRdr\Parameters@WSIgnoreLSPDefault                                                                              nl_lsp.dll,imon.dll,xfire_lsp.dll,mslsp.dll,mssplsp.dll,cwhook.dll,spi.dll,bmnet.dll,winsflt.dll
Reg       HKLM\SYSTEM\ControlSet002\services\aswRvrt@Type                                                                                                      1
Reg       HKLM\SYSTEM\ControlSet002\services\aswRvrt@Start                                                                                                     0
Reg       HKLM\SYSTEM\ControlSet002\services\aswRvrt@ErrorControl                                                                                              1
Reg       HKLM\SYSTEM\ControlSet002\services\aswRvrt@DisplayName                                                                                               aswRvrt
Reg       HKLM\SYSTEM\ControlSet002\services\aswRvrt@Description                                                                                               avast! Revert
Reg       HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters (not active ControlSet)                                                                        
Reg       HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters@BootCounter                                                                                    91
Reg       HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters@TickCounter                                                                                    7658193
Reg       HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters@SystemRoot                                                                                     \Device\Harddisk0\Partition3\Windows
Reg       HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters@ImproperShutdown                                                                               1
Reg       HKLM\SYSTEM\ControlSet002\services\aswSnx@Type                                                                                                       2
Reg       HKLM\SYSTEM\ControlSet002\services\aswSnx@Start                                                                                                      1
Reg       HKLM\SYSTEM\ControlSet002\services\aswSnx@ErrorControl                                                                                               1
Reg       HKLM\SYSTEM\ControlSet002\services\aswSnx@DisplayName                                                                                                aswSnx
Reg       HKLM\SYSTEM\ControlSet002\services\aswSnx@Group                                                                                                      FSFilter Virtualization
Reg       HKLM\SYSTEM\ControlSet002\services\aswSnx@DependOnService                                                                                            FltMgr?
Reg       HKLM\SYSTEM\ControlSet002\services\aswSnx@Description                                                                                                avast! virtualization driver (aswSnx)
Reg       HKLM\SYSTEM\ControlSet002\services\aswSnx@Tag                                                                                                        2
Reg       HKLM\SYSTEM\ControlSet002\services\aswSnx\Instances (not active ControlSet)                                                                          
Reg       HKLM\SYSTEM\ControlSet002\services\aswSnx\Instances@DefaultInstance                                                                                  aswSnx Instance
Reg       HKLM\SYSTEM\ControlSet002\services\aswSnx\Instances\aswSnx Instance (not active ControlSet)                                                          
Reg       HKLM\SYSTEM\ControlSet002\services\aswSnx\Instances\aswSnx Instance@Altitude                                                                         137600
Reg       HKLM\SYSTEM\ControlSet002\services\aswSnx\Instances\aswSnx Instance@Flags                                                                            0
Reg       HKLM\SYSTEM\ControlSet002\services\aswSnx\Parameters (not active ControlSet)                                                                         
Reg       HKLM\SYSTEM\ControlSet002\services\aswSnx\Parameters@ProgramFolder                                                                                   \DosDevices\C:\Program Files\AVAST Software\Avast
Reg       HKLM\SYSTEM\ControlSet002\services\aswSnx\Parameters@DataFolder                                                                                      \DosDevices\C:\ProgramData\AVAST Software\Avast
Reg       HKLM\SYSTEM\ControlSet002\services\aswSP@Type                                                                                                        1
Reg       HKLM\SYSTEM\ControlSet002\services\aswSP@Start                                                                                                       1
Reg       HKLM\SYSTEM\ControlSet002\services\aswSP@ErrorControl                                                                                                1
Reg       HKLM\SYSTEM\ControlSet002\services\aswSP@DisplayName                                                                                                 aswSP
Reg       HKLM\SYSTEM\ControlSet002\services\aswSP@Description                                                                                                 avast! Self Protection
Reg       HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters (not active ControlSet)                                                                          
Reg       HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters@BehavShield                                                                                      1
Reg       HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters@ProgramFolder                                                                                    \DosDevices\C:\Program Files\AVAST Software\Avast
Reg       HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters@DataFolder                                                                                       \DosDevices\C:\ProgramData\AVAST Software\Avast
Reg       HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters@ProgramFilesFolder                                                                               \DosDevices\C:\Program Files
Reg       HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters@GadgetFolder                                                                                     \DosDevices\C:\Program Files\Windows Sidebar\Shared Gadgets\aswSidebar.gadget
Reg       HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters@NoWelcomeScreen                                                                                  1
Reg       HKLM\SYSTEM\ControlSet002\services\aswTdi@Type                                                                                                       1
Reg       HKLM\SYSTEM\ControlSet002\services\aswTdi@Start                                                                                                      1
Reg       HKLM\SYSTEM\ControlSet002\services\aswTdi@ErrorControl                                                                                               1
Reg       HKLM\SYSTEM\ControlSet002\services\aswTdi@DisplayName                                                                                                avast! Network Shield Support
Reg       HKLM\SYSTEM\ControlSet002\services\aswTdi@Group                                                                                                      PNP_TDI
Reg       HKLM\SYSTEM\ControlSet002\services\aswTdi@DependOnService                                                                                            tcpip?
Reg       HKLM\SYSTEM\ControlSet002\services\aswTdi@Description                                                                                                avast! Network Shield TDI driver
Reg       HKLM\SYSTEM\ControlSet002\services\aswTdi@Tag                                                                                                        11
Reg       HKLM\SYSTEM\ControlSet002\services\aswVmm@Type                                                                                                       1
Reg       HKLM\SYSTEM\ControlSet002\services\aswVmm@Start                                                                                                      0
Reg       HKLM\SYSTEM\ControlSet002\services\aswVmm@ErrorControl                                                                                               1
Reg       HKLM\SYSTEM\ControlSet002\services\aswVmm@DisplayName                                                                                                aswVmm
Reg       HKLM\SYSTEM\ControlSet002\services\aswVmm@Description                                                                                                avast! VM Monitor
Reg       HKLM\SYSTEM\ControlSet002\services\aswVmm\Parameters (not active ControlSet)                                                                         
Reg       HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@Type                                                                                             32
Reg       HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@Start                                                                                            2
Reg       HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@ErrorControl                                                                                     1
Reg       HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@ImagePath                                                                                        "C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
Reg       HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@DisplayName                                                                                      avast! Antivirus
Reg       HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@Group                                                                                            ShellSvcGroup
Reg       HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@DependOnService                                                                                  aswMonFlt?RpcSS?
Reg       HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@WOW64                                                                                            1
Reg       HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@ObjectName                                                                                       LocalSystem
Reg       HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@ServiceSidType                                                                                   1
Reg       HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@Description                                                                                      Verwaltet und implementiert avast! Antivirus-Dienste f?r diesen Computer. Dies beinhaltet den Echtzeit-Schutz, den Virus-Container und den Planer.
Reg       HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\844bf5a75a0e (not active ControlSet)                                                      
Reg       HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\c018855b6f38 (not active ControlSet)                                                      

---- EOF - GMER 2.1 ----

 Malwarebytes Anti-Malware  (Test)

Datenbank Version: v2013.12.30.03

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16476
APB :: ACER-ULTRA [Administrator]

Schutz: Aktiviert

30.12.2013 14:15:37
mbam-log-2013-12-30 (14-15-37).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 381989
Laufzeit: 47 Minute(n), 42 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

MWBA Root-Kill:

Malwarebytes Anti-Rootkit BETA

(c) Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x64

Account is Administrative

Internet Explorer version: 11.0.9600.16476

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 1.696000 GHz
Memory total: 4125470720, free: 999219200

Downloaded database version: v2013.12.30.04
Downloaded database version: v2013.12.18.01
------------ Kernel report ------------
     12/30/2013 15:19:20
------------ Loaded modules -----------
----------- End -----------
Upper Device Name: \Device\Harddisk1\DR1
Upper Device Object: 0xfffffa8007d45060
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\Ide\IAAStorageDevice-1\
Lower Device Object: 0xfffffa8006aed050
Lower Device Driver Name: \Driver\iaStor\
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xfffffa8007d44060
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\Ide\IAAStorageDevice-0\
Lower Device Object: 0xfffffa8006ae9050
Lower Device Driver Name: \Driver\iaStor\
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xfffffa8007d44060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa8007be18e0, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa8007be2880, DeviceName: \Device\excsd0\, DriverName: \Driver\excsd\
DevicePointer: 0xfffffa8007d44060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa8006ae9050, DeviceName: \Device\Ide\IAAStorageDevice-0\, DriverName: \Driver\iaStor\
------------ End ----------
Alternate DeviceName: \Device\excsd0\, DriverName: \Driver\excsd\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Drive 0
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 6E8CE96C

Partition information:

    Partition 0 type is Other (0x27)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 2048  Numsec = 31744000

    Partition 1 type is Primary (0x7)
    Partition is ACTIVE.
    Partition starts at LBA: 31746048  Numsec = 204800
    Partition is not bootable

    Partition 2 type is Primary (0x7)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 31950848  Numsec = 944820224

    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0

Disk Size: 500107862016 bytes
Sector size: 512 bytes

Scanning physical sectors of unpartitioned space on drive 0 (1-2047-976753168-976773168)...
Physical Sector Size: 512
Drive: 1, DevicePointer: 0xfffffa8007d45060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa8007d45b90, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa8007be3880, DeviceName: \Device\excsd1\, DriverName: \Driver\excsd\
DevicePointer: 0xfffffa8007d45060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa8006aed050, DeviceName: \Device\Ide\IAAStorageDevice-1\, DriverName: \Driver\iaStor\
------------ End ----------
Alternate DeviceName: \Device\excsd1\, DriverName: \Driver\excsd\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
Drive 1
Scanning MBR on drive 1...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 37A019CD

Partition information:

    Partition 0 type is Other (0x84)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 2048  Numsec = 7835648

    Partition 1 type is Other (0x73)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 7839744  Numsec = 31246336

    Partition 2 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0

    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0

Disk Size: 20014718976 bytes
Sector size: 512 bytes

Scan finished

Removal queue found; removal started
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_0_i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\Bootstrap_0_1_31746048_i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_0_r.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_1_i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_1_r.mbam...
Removal finished

VIRUS oder nicht? System zunächst total unstabil, jetzt läuft wieder alles ?

VIRUS oder nicht? System zunächst total unstabil, jetzt läuft wieder alles ?

OTL logfile created on: 30.12.2013 15:39:55 - Run 1
OTL by OldTimer - Version     Folder = C:\Users\APB\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16428)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,84 Gb Total Physical Memory | 1,28 Gb Available Physical Memory | 33,21% Memory free
7,68 Gb Paging File | 4,18 Gb Available in Paging File | 54,41% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 450,53 Gb Total Space | 387,89 Gb Free Space | 86,10% Space Free | Partition Type: NTFS
Computer Name: ACER-ULTRA | User Name: APB | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days
========== Processes (SafeList) ==========
PRC - C:\Users\APB\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\APB\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files (x86)\Google\Update\\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Programme\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Programme\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - c:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Common Files\Research in Motion\Tunnel Manager\PeerManager.exe (Research In Motion Limited)
PRC - C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\tunmgr.exe (Research In Motion Limited)
PRC - C:\Program Files (x86)\PDF Architect\HelperService.exe (pdfforge GmbH)
PRC - C:\Program Files (x86)\PDF Architect\ConversionService.exe (pdfforge GmbH)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe (Research In Motion Limited)
PRC - C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\Common Files\Research in Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe ()
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Launch Manager\LMutilps32.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\LMworker.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
PRC - C:\Programme\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe ()
PRC - C:\Programme\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe ()
PRC - C:\Program Files (x86)\Atheros\Ath_WlanAgent.exe (Atheros)
PRC - C:\Programme\Acer\Acer Updater\UpdaterService.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe (NTI Corporation)
PRC - C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe (NTI Corporation)
PRC - C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe (Haufe-Lexware GmbH & Co. KG)
PRC - C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe (Acer Incorporated)
========== Modules (No Company Name) ==========
MOD - C:\Users\APB\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\ef0a534be135cd8f0d99d938d8b1814a\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\e40d894a772b2cff5ffd5a84ef20d2d4\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\71d887ce964fb69b7f03c4fe7a3f28ff\System.Configuration.ni.dll ()
MOD - C:\Program Files (x86)\Common Files\Microsoft Shared\office14\Cultures\office.odf ()
MOD - C:\Users\APB\AppData\Roaming\Dropbox\bin\libcef.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\5aa44bce7933e4de09d935848f868a4b\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\5d22a30e587e2cac106b81fb351e7c08\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\884bcbd22130ebeb1211bc7bcc3910c9\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\3a3fc0216674bdea0be809b305517c98\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\de853615c8224ba5d9aa9b76276c6d98\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\CustomMarshalers\c9786062fbb311c543497e28c1e1a0c5\CustomMarshalers.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\9a6c1b7af18b4d5a91dc7f8d6617522f\mscorlib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\cf58670896c5313b9b52f026f4455a5d\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Microsoft Office\Office14\ADDINS\UmOutlookAddin.dll ()
MOD - C:\Programme\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe ()
MOD - C:\Programme\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe ()
MOD - C:\Program Files (x86)\NTI\Acer Backup Manager\sqlite3.dll ()
========== Services (SafeList) ==========
SRV:64bit: - (IEEtwCollectorService) -- C:\Windows\SysNative\IEEtwCollector.exe (Microsoft Corporation)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (avast! Antivirus) -- C:\Programme\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (AdobeARMservice) -- c:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (RIM MDNS) -- C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\mDNSResponder.exe (Apple Inc.)
SRV - (RIM Tunnel Service) -- C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\tunmgr.exe (Research In Motion Limited)
SRV - (PDF Architect Helper Service) -- C:\Program Files (x86)\PDF Architect\HelperService.exe (pdfforge GmbH)
SRV - (PDF Architect Service) -- C:\Program Files (x86)\PDF Architect\ConversionService.exe (pdfforge GmbH)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (LBTServ) -- C:\Programme\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (BlackBerry Device Manager) -- C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe (Research In Motion Limited)
SRV - (CCDMonitorService) -- C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe (Acer Incorporated)
SRV - (USecuAppSvc) -- C:\Programme\Acer\Acer Theft Shield\USecuAppSvc.exe (Acer Incorporated)
SRV - (cphs) -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe (Intel Corporation)
SRV - (UNS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe ()
SRV - (jhi_service) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation)
SRV - (irstrtsv) -- C:\Windows\SysWOW64\irstrtsv.exe (Intel Corporation)
SRV - (DsiWMIService) -- C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
SRV - (AtherosSvc) -- C:\Program Files (x86)\Bluetooth Suite\adminservice.exe (Atheros Commnucations)
SRV - (Intel(R) -- C:\Programme\Intel\iCLS Client\HeciServer.exe (Intel(R) Corporation)
SRV - (GREGService) -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Acer Incorporated)
SRV - (ZAtheros Wlan Agent) -- C:\Program Files (x86)\Atheros\Ath_WlanAgent.exe (Atheros)
SRV - (ExpressCache) -- C:\Programme\Diskeeper Corporation\ExpressCache\ExpressCache.exe (Diskeeper Corporation)
SRV - (ePowerSvc) -- C:\Programme\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated)
SRV - (Live Updater Service) -- C:\Programme\Acer\Acer Updater\UpdaterService.exe (Acer Incorporated)
SRV - (TurboBoost) -- C:\Programme\Intel\TurboBoost\TurboBoost.exe (Intel(R) Corporation)
SRV - (NTI IScheduleSvc) -- C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe (NTI Corporation)
SRV - (FFSOpzSvc) -- C:\Programme\Sleep Memory Optimizer\FFSService.exe (Acer Incorporated)
SRV - (EgisTec Ticket Service) -- C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe (Egis Technology Inc. )
SRV - (wlidsvc) -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
SRV - (GamesAppService) -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (wlcrasvc) -- C:\Programme\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (RS_Service) -- C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe (Acer Incorporated)
SRV - (osppsvc) -- C:\Programme\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (aswSnx) -- C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)
DRV:64bit: - (aswSP) -- C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:64bit: - (aswVmm) -- C:\Windows\SysNative\drivers\aswVmm.sys ()
DRV:64bit: - (aswRdr) -- C:\Windows\SysNative\drivers\aswRdr2.sys (AVAST Software)
DRV:64bit: - (aswRvrt) -- C:\Windows\SysNative\drivers\aswRvrt.sys ()
DRV:64bit: - (aswTdi) -- C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software)
DRV:64bit: - (aswMonFlt) -- C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswFsBlk) -- C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:64bit: - (mwlPSDVDisk) -- C:\Windows\SysNative\drivers\mwlPSDVDisk.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDFilter) -- C:\Windows\SysNative\drivers\mwlPSDFilter.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDNServ) -- C:\Windows\SysNative\drivers\mwlPSDNserv.sys (Egis Technology Inc.)
DRV:64bit: - (rimvndis) -- C:\Windows\SysNative\drivers\rimvndis6_AMD64.sys (Research in Motion Limited)
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (usbrndis6) -- C:\Windows\SysNative\drivers\usb80236.sys (Microsoft Corporation)
DRV:64bit: - (RimUsb) -- C:\Windows\SysNative\drivers\RimUsb_AMD64.sys (Research In Motion Limited)
DRV:64bit: - (LEqdUsb) -- C:\Windows\SysNative\drivers\LEqdUsb.sys (Logitech, Inc.)
DRV:64bit: - (LHidFilt) -- C:\Windows\SysNative\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LMouFilt) -- C:\Windows\SysNative\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LHidEqd) -- C:\Windows\SysNative\drivers\LHidEqd.sys (Logitech, Inc.)
DRV:64bit: - (RimVSerPort) -- C:\Windows\SysNative\drivers\RimSerial_AMD64.sys (Research in Motion Ltd)
DRV:64bit: - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (MEIx64) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (irstrtdv) -- C:\Windows\SysNative\drivers\irstrtdv.sys (Intel Corporation)
DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (RSUSBVSTOR) -- C:\Windows\SysNative\drivers\RtsUVStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (BtFilter) -- C:\Windows\SysNative\drivers\btfilter.sys (Atheros)
DRV:64bit: - (BTATH_RCP) -- C:\Windows\SysNative\drivers\btath_rcp.sys (Atheros)
DRV:64bit: - (BTATH_LWFLT) -- C:\Windows\SysNative\drivers\btath_lwflt.sys (Atheros)
DRV:64bit: - (BTATH_HCRP) -- C:\Windows\SysNative\drivers\btath_hcrp.sys (Atheros)
DRV:64bit: - (AthBTPort) -- C:\Windows\SysNative\drivers\btath_flt.sys (Atheros)
DRV:64bit: - (BTATH_BUS) -- C:\Windows\SysNative\drivers\btath_bus.sys (Atheros)
DRV:64bit: - (btath_avdt) -- C:\Windows\SysNative\drivers\btath_avdt.sys (Atheros)
DRV:64bit: - (BTATH_A2DP) -- C:\Windows\SysNative\drivers\btath_a2dp.sys (Atheros)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (iusb3xhc) -- C:\Windows\SysNative\drivers\iusb3xhc.sys (Intel Corporation)
DRV:64bit: - (iusb3hub) -- C:\Windows\SysNative\drivers\iusb3hub.sys (Intel Corporation)
DRV:64bit: - (iusb3hcs) -- C:\Windows\SysNative\drivers\iusb3hcs.sys (Intel Corporation)
DRV:64bit: - (ETD) -- C:\Windows\SysNative\drivers\ETD.sys (ELAN Microelectronics Corp.)
DRV:64bit: - (excsd) -- C:\Windows\SysNative\drivers\excsd.sys (Diskeeper Corporation)
DRV:64bit: - (excfs) -- C:\Windows\SysNative\drivers\excfs.sys (Diskeeper Corporation)
DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (TurboB) -- C:\Windows\SysNative\drivers\TurboB.sys (Intel(R) Corporation)
DRV:64bit: - (IntcDAud) -- C:\Windows\SysNative\drivers\IntcDAud.sys (Intel(R) Corporation)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) -- C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (WSDScan) -- C:\Windows\SysNative\drivers\WSDScan.sys (Microsoft Corporation)
DRV:64bit: - (ROOTMODEM) -- C:\Windows\SysNative\drivers\rootmdm.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (NTIDrvr) -- C:\Windows\SysNative\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV:64bit: - (UBHelper) -- C:\Windows\SysNative\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://acer.msn.com
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:8.0.1497
FF - prefs.js..extensions.enabledAddons: FFPDFArchitectConverter%40pdfarchitect.com:1.0
FF - prefs.js..extensions.enabledAddons: %7BF003DA68-8256-4b37-A6C4-350FA04494DF%7D:6.5
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:26.0
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\system32\npDeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.45.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013.09.11 07:45:36 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\FFPDFArchitectConverter@pdfarchitect.com: C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2013.06.16 05:56:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F003DA68-8256-4b37-A6C4-350FA04494DF}: C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2013.06.24 09:43:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 26.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 26.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 26.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 26.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2013.05.04 12:03:48 | 000,000,000 | ---D | M] (No name found) -- C:\Users\APB\AppData\Roaming\mozilla\Extensions
[2013.12.29 17:57:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\APB\AppData\Roaming\mozilla\Firefox\Profiles\h3p0lpdr.default\extensions
[2013.12.20 09:24:42 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\extensions
[2013.12.20 09:24:42 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\browser\extensions
[2013.12.20 09:24:47 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2013.06.16 05:56:15 | 000,000,000 | ---D | M] (PDF Architect Converter For Firefox) -- C:\PROGRAM FILES (X86)\PDF ARCHITECT\FFPDFARCHITECTEXT
[2013.09.11 07:45:36 | 000,000,000 | ---D | M] (avast! Online Security) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2013.06.24 09:43:16 | 000,000,000 | ---D | M] (Logitech SetPoint) -- C:\PROGRAM FILES\LOGITECH\SETPOINTP\LOGISMOOTHFIREFOXEXT
========== Chrome  ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - homepage: hxxp://www.google.com
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
CHR - plugin: RIM Handheld Application Loader (Enabled) = C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll
CHR - plugin: Intel\u00AE Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
CHR - plugin: Intel\u00AE Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
CHR - plugin: Java(TM) Platform SE 7 U25 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll
CHR - plugin: Java Deployment Toolkit (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll
CHR - Extension: Google Docs = C:\Users\APB\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\APB\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\APB\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google-Suche = C:\Users\APB\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\\
CHR - Extension: Logitech SetPoint = C:\Users\APB\AppData\Local\Google\Chrome\User Data\Default\Extensions\edaibbiobngpbmeonadpbfafbkimjbdd\6.52.74_0\
CHR - Extension: Google Wallet = C:\Users\APB\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\\
CHR - Extension: Google Mail = C:\Users\APB\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2009.06.10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Programme\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (Logitech SetPoint) - {AF949550-9094-4807-95EC-D1C317803333} - C:\Programme\Logitech\SetPointP\SetPointSmooth.dll (Logitech, Inc.)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Programme\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (PDF Architect Helper) - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GmbH)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Logitech SetPoint) - {AF949550-9094-4807-95EC-D1C317803333} - C:\Programme\Logitech\SetPointP\32-bit\SetPointSmooth.dll (Logitech, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Programme\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (PDF Architect Toolbar) - {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files (x86)\PDF Architect\PDFIEPlugin.dll (pdfforge GmbH)
O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [AthBtTray] C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (Atheros Commnucations)
O4:64bit: - HKLM..\Run: [AtherosBtStack] C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Atheros Communications)
O4:64bit: - HKLM..\Run: [ETDCtrl] C:\Programme\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.)
O4:64bit: - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [InstantUpdate] C:\Programme\Acer\Acer Instant Service\InstantUpdate\iuDaemon.exe ()
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Power Management] C:\Programme\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [RtHDVBg_Dolby] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [20131121] C:\Program Files\AVAST Software\Avast\setup\emupdate\72c2e4d7-871f-4dee-b80b-4301baba235d.exe (AVAST Software)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe (NTI Corporation)
O4 - HKLM..\Run: [Dolby Home Theater v4] C:\Dolby PCEE4\pcee4.exe (Dolby Laboratories Inc.)
O4 - HKLM..\Run: [LexwareInfoService] C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe (Haufe-Lexware GmbH & Co. KG)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [RIM PeerManager] C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\PeerManager.exe (Research In Motion Limited)
O4 - HKLM..\Run: [RIMBBLaunchAgent.exe] C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
O4 - HKLM..\Run: [SuiteTray] C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
O4 - HKCU..\Run: [Personal ID] C:\coolspot AG\Personal ID\pid.exe (coolspot AG, Düsseldorf)
O4 - HKLM..\RunOnce: [ Malwarebytes Anti-Malware ] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Users\APB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\APB\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O8:64bit: - Extra context menu item: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8:64bit: - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105 File not found
O8:64bit: - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MICROS~4\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8 - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105 File not found
O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MICROS~4\Office14\EXCEL.EXE/3000 File not found
O9:64bit: - Extra Button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: fritz.box ([]* in Local intranet)
O15 - HKCU\..Trusted Ranges: Range1 ([*] in Local intranet)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 10.25.2)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 10.25.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7E733ADF-00F4-4012-AA5C-A807FDCD2CBD}: DhcpNameServer =
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Programme\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
========== Files/Folders - Created Within 60 Days ==========
[2013.12.30 15:19:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
[2013.12.30 15:19:19 | 000,117,464 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2013.12.30 15:18:25 | 000,089,304 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2013.12.30 15:18:21 | 000,000,000 | ---D | C] -- C:\Users\APB\Desktop\mbar
[2013.12.30 14:13:32 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2013.12.30 14:12:13 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\APB\Desktop\OTL.exe
[2013.12.30 13:30:06 | 000,000,000 | ---D | C] -- C:\FRST
[2013.12.30 13:16:33 | 001,931,302 | ---- | C] (Farbar) -- C:\Users\APB\Desktop\FRST64.exe
[2013.12.30 10:52:29 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\MigWiz
[2013.12.30 10:10:58 | 000,000,000 | ---D | C] -- C:\Users\APB\Desktop\ACER_DESKTOP
[2013.12.30 10:07:52 | 000,000,000 | ---D | C] -- C:\Users\APB\Desktop\ACER_SAS
[2013.12.29 12:17:06 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2013.12.29 11:23:15 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2013.12.28 19:35:04 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Roaming\Malwarebytes
[2013.12.28 19:34:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.12.28 19:34:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013.12.28 19:34:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013.12.23 05:15:36 | 000,000,000 | ---D | C] -- C:\Users\APB\dwhelper
[2013.12.20 09:24:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2013.12.20 09:01:32 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{BDF73505-64CB-4A28-9990-C822EFCE3D12}
[2013.12.19 07:37:09 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{2B140492-5FC5-41A1-94C9-74DCB4805487}
[2013.12.18 10:49:59 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{E1DF1BD8-A55C-40BD-A4E9-1AAD3BE3CC2B}
[2013.12.17 09:10:51 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{B17FE4F4-478F-4693-8B38-598A83554B4A}
[2013.12.16 11:49:35 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{6325584A-A627-4E06-BD5E-DD2C49885B55}
[2013.12.15 10:40:25 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{D2324234-C310-4EC8-8C46-2FF3583558B6}
[2013.12.14 18:56:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2013.12.14 09:23:04 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{9BFB83A7-93D0-4DCE-87D0-07612EBEDCD1}
[2013.12.13 09:14:43 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{CEB7D5C0-24F2-42AB-887F-A269488BE7EF}
[2013.12.13 07:28:16 | 012,625,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmploc.DLL
[2013.12.13 07:28:15 | 012,625,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmploc.DLL
[2013.12.13 07:28:15 | 011,410,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmp.dll
[2013.12.13 07:28:13 | 014,631,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmp.dll
[2013.12.13 07:26:31 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2013.12.13 07:26:30 | 000,574,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2013.12.13 07:26:29 | 000,440,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2013.12.13 07:26:29 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2013.12.13 07:26:29 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2013.12.13 07:26:29 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2013.12.13 07:26:28 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2013.12.13 07:26:28 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2013.12.13 07:26:28 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2013.12.13 07:26:27 | 000,817,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2013.12.13 07:26:27 | 000,708,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2013.12.13 07:26:27 | 000,703,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2013.12.13 07:26:27 | 000,553,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2013.12.13 07:26:24 | 001,995,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2013.12.13 07:26:24 | 001,928,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2013.12.13 07:26:22 | 005,769,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2013.12.12 20:25:23 | 000,335,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msieftp.dll
[2013.12.12 20:25:21 | 000,301,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msieftp.dll
[2013.12.12 20:25:20 | 000,465,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMPhoto.dll
[2013.12.12 20:25:20 | 000,417,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMPhoto.dll
[2013.12.12 20:25:19 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imagehlp.dll
[2013.12.12 20:25:07 | 000,230,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\portcls.sys
[2013.12.12 20:25:06 | 000,150,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wshom.ocx
[2013.12.12 20:25:06 | 000,116,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\drmk.sys
[2013.12.12 20:25:05 | 000,202,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\scrrun.dll
[2013.12.12 20:25:05 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\scrrun.dll
[2013.12.12 20:25:05 | 000,156,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cscript.exe
[2013.12.12 20:25:05 | 000,126,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cscript.exe
[2013.12.12 20:25:05 | 000,121,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wshom.ocx
[2013.12.12 11:24:21 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{2F47591A-C639-46DF-99D6-B49855015C7F}
[2013.12.11 12:17:21 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{A4C4C9D7-1E95-47E6-8D33-173BA47A781F}
[2013.12.03 15:04:38 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{C7FABDC8-6BE3-4822-84B3-8A90A30124BB}
[2013.12.01 09:57:37 | 000,000,000 | ---D | C] -- C:\Users\APB\Application Data
[2013.12.01 09:40:12 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{270D3B0E-0616-4AB3-A772-75895074453C}
[2013.11.30 15:08:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Personal ID
[2013.11.30 15:08:28 | 000,000,000 | ---D | C] -- C:\coolspot AG
[2013.11.30 10:20:46 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{ABE5A90D-DB41-433E-801C-91BFF6DC92EC}
[2013.11.29 10:58:52 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{44231D47-34AB-4D3F-9F4A-F9F867514BEC}
[2013.11.28 19:44:44 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{DC06D0A3-0B3D-4D74-B884-9D71AE1932F6}
[2013.11.28 09:46:15 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\.elfohilfe
[2013.11.28 09:43:17 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Roaming\elsterformular
[2013.11.28 09:43:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ElsterFormular
[2013.11.28 09:43:07 | 000,000,000 | ---D | C] -- C:\ProgramData\elsterformular
[2013.11.28 09:42:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ElsterFormular
[2013.11.28 06:21:59 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{FDBF0089-7962-42C5-B792-2B4AA57F0B7B}
[2013.11.27 11:45:14 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{0B14E3BE-F507-4BB9-9BAD-B7B69972D9BA}
[2013.11.25 10:32:10 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{7DA4428D-449B-48BE-AE5D-D1E0A228B667}
[2013.11.24 10:52:53 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{D2831063-2855-4D8F-B8A1-FCF3396191BE}
[2013.11.23 09:48:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Buderus
[2013.11.23 09:48:11 | 000,000,000 | ---D | C] -- C:\Users\APB\Documents\Buderus
[2013.11.23 09:48:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Buderus
[2013.11.23 08:06:16 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{E759CCF0-AF69-42F6-9378-73A3A247BDF8}
[2013.11.22 12:26:40 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{BEBB9594-A8BA-484B-967B-D8058C5A7025}
[2013.11.21 10:29:58 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{39DAADD9-ACC9-4F96-BA25-AE1D5CDBD812}
[2013.11.20 16:30:54 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\FullTiltPoker.eu
[2013.11.20 16:30:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Full Tilt Poker.Eu
[2013.11.20 16:30:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Full Tilt Poker.Eu
[2013.11.20 16:27:53 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\cache
[2013.11.20 16:27:47 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\FullTiltPoker
[2013.11.20 16:27:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Full Tilt Poker
[2013.11.20 16:27:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Full Tilt Poker
[2013.11.20 08:14:18 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{91583922-03CE-48C5-8987-D0B82C31A7DA}
[2013.11.20 07:35:04 | 000,028,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IEUDINIT.EXE
[2013.11.20 07:27:29 | 000,940,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2013.11.20 07:27:29 | 000,194,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\elshyph.dll
[2013.11.20 07:27:26 | 001,228,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll
[2013.11.20 07:27:26 | 001,051,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
[2013.11.20 07:27:26 | 000,942,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jsIntl.dll
[2013.11.20 07:27:26 | 000,774,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2013.11.20 07:27:26 | 000,645,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jsIntl.dll
[2013.11.20 07:27:26 | 000,626,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2013.11.20 07:27:26 | 000,616,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
[2013.11.20 07:27:26 | 000,616,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat
[2013.11.20 07:27:26 | 000,610,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2013.11.20 07:27:26 | 000,548,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2013.11.20 07:27:26 | 000,453,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2013.11.20 07:27:26 | 000,413,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2013.11.20 07:27:26 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2013.11.20 07:27:26 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2013.11.20 07:27:26 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll
[2013.11.20 07:27:26 | 000,235,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2013.11.20 07:27:26 | 000,235,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\elshyph.dll
[2013.11.20 07:27:26 | 000,233,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2013.11.20 07:27:26 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2013.11.20 07:27:26 | 000,167,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe
[2013.11.20 07:27:26 | 000,164,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2013.11.20 07:27:26 | 000,151,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
[2013.11.20 07:27:26 | 000,147,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll
[2013.11.20 07:27:26 | 000,143,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe
[2013.11.20 07:27:26 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
[2013.11.20 07:27:26 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
[2013.11.20 07:27:26 | 000,131,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll
[2013.11.20 07:27:26 | 000,127,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
[2013.11.20 07:27:26 | 000,116,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2013.11.20 07:27:26 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2013.11.20 07:27:26 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
[2013.11.20 07:27:26 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
[2013.11.20 07:27:26 | 000,101,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll
[2013.11.20 07:27:26 | 000,090,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe
[2013.11.20 07:27:26 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013.11.20 07:27:26 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2013.11.20 07:27:26 | 000,084,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2013.11.20 07:27:26 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll
[2013.11.20 07:27:26 | 000,083,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
[2013.11.20 07:27:26 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll
[2013.11.20 07:27:26 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx
[2013.11.20 07:27:26 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013.11.20 07:27:26 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013.11.20 07:27:26 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2013.11.20 07:27:26 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
[2013.11.20 07:27:26 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
[2013.11.20 07:27:26 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll
[2013.11.20 07:27:26 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll
[2013.11.20 07:27:26 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2013.11.20 07:27:26 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
[2013.11.20 07:27:26 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2013.11.20 07:27:26 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
[2013.11.20 07:27:26 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll
[2013.11.20 07:27:26 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll
[2013.11.20 07:27:26 | 000,040,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll
[2013.11.20 07:27:26 | 000,034,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
[2013.11.20 07:27:26 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2013.11.20 07:27:26 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
[2013.11.20 07:27:26 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
[2013.11.20 07:27:26 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe
[2013.11.20 07:27:26 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe
[2013.11.20 07:27:26 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2013.11.19 19:48:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\partypoker
[2013.11.19 17:02:29 | 000,000,000 | ---D | C] -- C:\Users\APB\PARTYPOKERPokerDir
[2013.11.19 13:15:50 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{FB1A619F-E64A-440F-9D14-421C43A94066}
[2013.11.18 08:45:01 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{051C067B-CA6D-41F1-87D8-3A2C8FE76FC5}
[2013.11.16 17:49:35 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Roaming\cef-cache
[2013.11.16 17:49:31 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Roaming\Party
[2013.11.16 17:49:08 | 000,000,000 | ---D | C] -- C:\Programs
[2013.11.16 17:26:33 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{1865F77F-CFB2-4ACF-ACB7-66C28C429C2A}
[2013.11.15 20:33:30 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{D28A5EFD-C381-4640-87B9-9E61093E4A84}
[2013.11.15 12:27:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2013.11.15 12:27:52 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2013.11.15 11:17:41 | 000,000,000 | ---D | C] -- C:\Windows\Offline Address Books
[2013.11.15 08:33:04 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{D6B39F1C-5489-4E24-BE4B-BE1E9ECD63EB}
[2013.11.14 07:52:09 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{754DA478-7EC0-4FB6-AEEB-1F7828ED5D63}
[2013.11.13 07:25:20 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{176EA23E-A1B6-4DCF-8B64-A2EE816029E0}
[2013.11.13 07:22:56 | 001,474,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll
[2013.11.13 07:22:48 | 001,930,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\authui.dll
[2013.11.13 07:22:47 | 001,796,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\authui.dll
[2013.11.13 07:22:46 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\credui.dll
[2013.11.13 07:22:46 | 000,190,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SmartcardCredentialProvider.dll
[2013.11.13 07:22:46 | 000,152,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SmartcardCredentialProvider.dll
[2013.11.13 07:22:38 | 001,447,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2013.11.13 07:22:38 | 000,307,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll
[2013.11.13 07:22:38 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspicli.dll
[2013.11.13 07:22:37 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspisrv.dll
[2013.11.13 07:22:37 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secur32.dll
[2013.11.13 07:22:33 | 000,404,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\gdi32.dll
[2013.11.13 07:22:30 | 000,830,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\nshwfp.dll
[2013.11.13 07:22:30 | 000,656,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\nshwfp.dll
[2013.11.13 07:22:30 | 000,324,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FWPUCLNT.DLL
[2013.11.13 07:22:30 | 000,216,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\FWPUCLNT.DLL
[2013.11.12 13:53:09 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\Citrix
[2013.11.12 07:52:28 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{F11E7D11-2937-48B2-A702-A10625B22078}
[2013.11.11 19:52:06 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{CD841451-6712-481A-85EC-E0A2717E3AAD}
[2013.11.11 07:51:42 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{8D6C97A9-F929-4105-A37F-B2D048FA8243}
[2013.11.10 10:37:54 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{B007BD3B-DB79-482E-A35D-5FE225F3FCD9}
[2013.11.09 10:13:10 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{87578B61-976E-4E06-94C3-8489247E39DC}
[2013.11.08 10:40:34 | 000,000,000 | ---D | C] -- C:\Users\APB\.pdfsam
[2013.11.08 10:36:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Split And Merge Basic
[2013.11.08 10:36:27 | 000,000,000 | ---D | C] -- C:\Program Files\PDF Split And Merge Basic
[2013.11.08 09:13:44 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{33BFB54D-CFA5-4899-BD6B-C60EE3AC5CB2}
[2013.11.07 13:14:05 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{E72E13C9-9399-42EF-87CB-3D249A177C96}
[2013.11.06 16:54:47 | 000,000,000 | ---D | C] -- C:\Users\APB\AppData\Local\{6A44BC39-62EA-4A6F-A46A-29848E98009F}
[2 C:\Users\APB\Desktop\*.tmp files -> C:\Users\APB\Desktop\*.tmp -> ]
========== Files - Modified Within 60 Days ==========
[2013.12.30 15:19:19 | 000,117,464 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2013.12.30 15:19:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.12.30 15:18:25 | 000,089,304 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2013.12.30 14:55:35 | 000,001,104 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.12.30 14:19:27 | 001,233,962 | ---- | M] () -- C:\Users\APB\Desktop\adwcleaner.exe
[2013.12.30 14:13:34 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
[2013.12.30 14:12:20 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\APB\Desktop\OTL.exe
[2013.12.30 13:21:16 | 000,377,856 | ---- | M] () -- C:\Users\APB\Desktop\4s7438ut.exe
[2013.12.30 13:16:58 | 001,931,302 | ---- | M] (Farbar) -- C:\Users\APB\Desktop\FRST64.exe
[2013.12.30 11:55:00 | 000,001,100 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.12.30 11:41:38 | 000,031,248 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.12.30 11:41:38 | 000,031,248 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.12.30 11:33:02 | 000,000,828 | ---- | M] () -- C:\Windows\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
[2013.12.30 11:32:23 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.12.30 11:32:14 | 3094,102,016 | -HS- | M] () -- C:\hiberfil.sys
[2013.12.30 11:31:46 | 000,003,288 | ---- | M] () -- C:\bootsqm.dat
[2013.12.30 10:38:43 | 001,621,308 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.12.30 10:38:43 | 000,700,418 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2013.12.30 10:38:43 | 000,655,090 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.12.30 10:38:43 | 000,149,182 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2013.12.30 10:38:43 | 000,121,962 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.12.29 17:54:16 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2013.12.28 11:30:11 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
[2013.12.23 11:38:09 | 000,000,973 | ---- | M] () -- C:\Windows\wininit.ini
[2013.12.23 11:38:08 | 000,001,053 | ---- | M] () -- C:\Users\APB\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013.12.13 08:24:22 | 000,469,272 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013.12.11 16:19:15 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2013.12.11 16:19:14 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013.11.26 11:18:23 | 000,004,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2013.11.26 10:48:07 | 000,066,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2013.11.26 10:46:25 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2013.11.26 10:27:54 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2013.11.26 10:21:24 | 000,574,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2013.11.26 10:18:39 | 000,139,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2013.11.26 10:18:09 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2013.11.26 10:16:57 | 000,708,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2013.11.26 09:57:44 | 000,218,624 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2013.11.26 09:35:02 | 005,769,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2013.11.26 09:32:08 | 000,440,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2013.11.26 09:28:16 | 000,553,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2013.11.26 09:02:16 | 001,995,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2013.11.26 08:32:06 | 001,928,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2013.11.26 07:34:55 | 000,703,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2013.11.26 07:34:27 | 000,817,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2013.11.24 11:23:14 | 000,000,106 | ---- | M] () -- C:\Windows\DTABegleit.INI
[2013.11.23 19:26:20 | 000,417,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\WMPhoto.dll
[2013.11.23 18:47:34 | 000,465,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WMPhoto.dll
[2013.11.20 16:28:49 | 022,734,832 | ---- | M] () -- C:\Users\APB\AppData\Local\TempFullTiltPokerEuSetup.exe
[2013.11.20 07:27:29 | 000,940,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2013.11.20 07:27:29 | 000,194,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\elshyph.dll
[2013.11.20 07:27:26 | 001,228,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll
[2013.11.20 07:27:26 | 001,051,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
[2013.11.20 07:27:26 | 000,942,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jsIntl.dll
[2013.11.20 07:27:26 | 000,774,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2013.11.20 07:27:26 | 000,645,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jsIntl.dll
[2013.11.20 07:27:26 | 000,626,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2013.11.20 07:27:26 | 000,616,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
[2013.11.20 07:27:26 | 000,616,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat
[2013.11.20 07:27:26 | 000,610,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2013.11.20 07:27:26 | 000,548,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2013.11.20 07:27:26 | 000,453,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2013.11.20 07:27:26 | 000,413,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2013.11.20 07:27:26 | 000,337,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2013.11.20 07:27:26 | 000,296,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2013.11.20 07:27:26 | 000,247,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll
[2013.11.20 07:27:26 | 000,235,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2013.11.20 07:27:26 | 000,235,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\elshyph.dll
[2013.11.20 07:27:26 | 000,233,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2013.11.20 07:27:26 | 000,195,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2013.11.20 07:27:26 | 000,167,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe
[2013.11.20 07:27:26 | 000,164,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2013.11.20 07:27:26 | 000,151,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
[2013.11.20 07:27:26 | 000,147,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll
[2013.11.20 07:27:26 | 000,143,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe
[2013.11.20 07:27:26 | 000,139,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
[2013.11.20 07:27:26 | 000,135,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
[2013.11.20 07:27:26 | 000,131,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll
[2013.11.20 07:27:26 | 000,127,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
[2013.11.20 07:27:26 | 000,116,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2013.11.20 07:27:26 | 000,112,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2013.11.20 07:27:26 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
[2013.11.20 07:27:26 | 000,105,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
[2013.11.20 07:27:26 | 000,101,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll
[2013.11.20 07:27:26 | 000,090,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe
[2013.11.20 07:27:26 | 000,086,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013.11.20 07:27:26 | 000,086,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2013.11.20 07:27:26 | 000,084,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2013.11.20 07:27:26 | 000,083,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll
[2013.11.20 07:27:26 | 000,083,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
[2013.11.20 07:27:26 | 000,081,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll
[2013.11.20 07:27:26 | 000,077,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx
[2013.11.20 07:27:26 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013.11.20 07:27:26 | 000,071,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013.11.20 07:27:26 | 000,069,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2013.11.20 07:27:26 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
[2013.11.20 07:27:26 | 000,062,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
[2013.11.20 07:27:26 | 000,062,464 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll
[2013.11.20 07:27:26 | 000,061,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll
[2013.11.20 07:27:26 | 000,061,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2013.11.20 07:27:26 | 000,056,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
[2013.11.20 07:27:26 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2013.11.20 07:27:26 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
[2013.11.20 07:27:26 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll
[2013.11.20 07:27:26 | 000,048,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll
[2013.11.20 07:27:26 | 000,040,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll
[2013.11.20 07:27:26 | 000,034,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
[2013.11.20 07:27:26 | 000,032,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2013.11.20 07:27:26 | 000,030,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
[2013.11.20 07:27:26 | 000,024,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
[2013.11.20 07:27:26 | 000,016,284 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
[2013.11.20 07:27:26 | 000,016,284 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
[2013.11.20 07:27:26 | 000,013,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe
[2013.11.20 07:27:26 | 000,013,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe
[2013.11.20 07:27:26 | 000,012,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2013.11.12 13:53:05 | 000,102,248 | ---- | M] () -- C:\Users\APB\GoToAssistDownloadHelper.exe
[2 C:\Users\APB\Desktop\*.tmp files -> C:\Users\APB\Desktop\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013.12.30 14:19:19 | 001,233,962 | ---- | C] () -- C:\Users\APB\Desktop\adwcleaner.exe
[2013.12.30 14:13:34 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
[2013.12.30 13:21:05 | 000,377,856 | ---- | C] () -- C:\Users\APB\Desktop\4s7438ut.exe
[2013.12.30 11:31:46 | 000,003,288 | ---- | C] () -- C:\bootsqm.dat
[2013.12.30 10:19:21 | 000,001,228 | ---- | C] () -- C:\Users\APB\Desktop\Explorer.lnk
[2013.12.30 10:19:21 | 000,000,700 | ---- | C] () -- C:\Users\APB\Desktop\Biblio.lnk
[2013.11.20 16:28:49 | 022,734,832 | ---- | C] () -- C:\Users\APB\AppData\Local\TempFullTiltPokerEuSetup.exe
[2013.11.20 07:27:26 | 000,016,284 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2013.11.20 07:27:26 | 000,016,284 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2013.11.12 13:53:04 | 000,102,248 | ---- | C] () -- C:\Users\APB\GoToAssistDownloadHelper.exe
[2013.10.19 10:04:45 | 000,000,106 | ---- | C] () -- C:\Windows\DTABegleit.INI
[2013.10.04 14:21:16 | 000,000,017 | ---- | C] () -- C:\Users\APB\AppData\Local\resmon.resmoncfg
[2013.09.22 14:04:13 | 000,013,312 | ---- | C] () -- C:\Users\APB\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013.08.25 08:51:52 | 000,000,179 | ---- | C] () -- C:\Windows\ODBC.INI
[2013.06.22 07:15:44 | 000,000,421 | ---- | C] () -- C:\Users\APB\AppData\Roaming\1_and_1_redirect.xml
[2013.06.09 08:58:08 | 000,000,160 | ---- | C] () -- C:\Windows\DeskCalc.INI
[2013.05.18 08:12:31 | 001,599,202 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013.05.05 13:15:06 | 000,000,973 | ---- | C] () -- C:\Windows\wininit.ini
[2013.05.04 13:10:46 | 000,007,053 | ---- | C] () -- C:\Users\APB\AppData\Roaming\e458452195.prf
[2013.05.04 13:10:38 | 000,000,417 | ---- | C] () -- C:\Users\APB\AppData\Roaming\redirect.xml
[2013.05.01 00:03:19 | 000,000,267 | ---- | C] () -- C:\Windows\LaunApp.ini
[2013.04.30 23:55:55 | 000,755,188 | ---- | C] () -- C:\Windows\SysWow64\igkrng700.bin
[2013.04.30 23:55:55 | 000,561,508 | ---- | C] () -- C:\Windows\SysWow64\igfcg700m.bin
[2013.04.30 23:55:54 | 013,024,768 | ---- | C] () -- C:\Windows\SysWow64\ig7icd32.dll
[2013.04.30 23:55:54 | 000,058,880 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2013.04.30 23:54:41 | 000,001,327 | ---- | C] () -- C:\Windows\WPatchProgress.ini
[2012.10.07 11:23:10 | 000,207,488 | ---- | C] () -- C:\Windows\SysWow64\LXPrnUtil10.dll
[2012.10.07 11:23:08 | 000,138,368 | ---- | C] () -- C:\Windows\SysWow64\LxDNTvmc100.dll
[2012.10.07 11:23:08 | 000,074,368 | ---- | C] () -- C:\Windows\SysWow64\LxDNTvm100.dll
[2012.10.07 11:23:06 | 000,318,592 | ---- | C] () -- C:\Windows\SysWow64\LxDNT100.dll
[2012.03.27 20:17:54 | 000,000,445 | ---- | C] () -- C:\Windows\Prelaunch.ini
[2012.03.27 20:17:54 | 000,000,395 | ---- | C] () -- C:\Windows\WisPriority.ini
[2012.03.27 20:17:54 | 000,000,168 | ---- | C] () -- C:\Windows\WisLangCode.ini
[2012.03.07 00:40:52 | 000,001,536 | ---- | C] () -- C:\Windows\SysWow64\IusEventLog.dll
Alt 31.12.2013, 09:22   #6
VIRUS oder nicht? System zunächst total unstabil, jetzt läuft wieder alles ? - Standard

VIRUS oder nicht? System zunächst total unstabil, jetzt läuft wieder alles ?

OTL Extras:

OTL Extras logfile created on: 30.12.2013 15:39:55 - Run 1
OTL by OldTimer - Version     Folder = C:\Users\APB\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16428)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
3,84 Gb Total Physical Memory | 1,28 Gb Available Physical Memory | 33,21% Memory free
7,68 Gb Paging File | 4,18 Gb Available in Paging File | 54,41% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 450,53 Gb Total Space | 387,89 Gb Free Space | 86,10% Space Free | Partition Type: NTFS
Computer Name: ACER-ULTRA | User Name: APB | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- Reg Error: Value error.
http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- Reg Error: Value error.
http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
"EnableFirewall" = 1
"DisableNotifications" = 0
"EnableFirewall" = 1
"DisableNotifications" = 0
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- ()
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- ()
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- ()
"C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- ()
========== Vista Active Open Ports Exception List ==========
"{036ECD61-665B-4800-84EB-346492F853D9}" = lport=8080 | protocol=6 | dir=in | app=c:\program files (x86)\common files\research in motion\nginx\nginx.exe | 
"{0B8A38DF-65FA-4788-99A0-79BBA5D7BDBF}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | 
"{0D942463-9853-4E9B-A4A5-6DA1344E47A6}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | 
"{1427466A-B1D9-462E-AD3C-8835E757188A}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{1D59C561-62E1-462B-8634-42DE0247FB47}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | 
"{283EDACB-9CAE-45D1-B034-EBD0FC9578E3}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{2F7E7CD7-8D52-4723-82D0-12DA0E230071}" = rport=10243 | protocol=6 | dir=out | app=system | 
"{3540CCDD-89D3-4012-B9A2-0BDE088FE243}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{36E4D13D-3A1F-4F5E-96F9-7BF62A6BA9E0}" = rport=445 | protocol=6 | dir=out | app=system | 
"{4350D173-2DD9-4405-9A13-639278A0B0D9}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{491A05A3-FC23-4184-9090-7BC1CD1E5CF8}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{6EA027FC-C9DA-4094-B5BC-E44A55CBCEB4}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{737A6122-B71B-4274-8FC3-6CA95E300473}" = lport=137 | protocol=17 | dir=in | app=system | 
"{7575D93E-D9D1-40E3-B66E-4C4C4A77F9BC}" = lport=139 | protocol=6 | dir=in | app=system | 
"{8EDB2601-9A23-45AA-93FA-446788A011BD}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{97ACFF37-642D-46E2-A8F2-18F7B2887FFB}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{A1C952B8-5BAB-4F79-B4C0-BCD7DF8E24F6}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe | 
"{AD229DC5-BAC4-4292-A274-6175A0FBBE5F}" = rport=138 | protocol=17 | dir=out | app=system | 
"{AF483AF8-CA82-4151-A396-461A1F3FE95B}" = rport=139 | protocol=6 | dir=out | app=system | 
"{B02E0073-EAE9-49D3-A926-C273FF8C5898}" = lport=138 | protocol=17 | dir=in | app=system | 
"{B9D75F4C-C67C-4B2A-90AF-F499373FB1D9}" = lport=10243 | protocol=6 | dir=in | app=system | 
"{C9948D02-CA64-43DC-8253-FD7A40664727}" = lport=445 | protocol=6 | dir=in | app=system | 
"{CF05244A-C76A-42E5-9789-337EA4A4FE81}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{ED457866-9FE5-493E-8CB1-1A72D2B88C68}" = rport=137 | protocol=17 | dir=out | app=system | 
"{FA3D8509-0268-4D9C-BD46-7CE7C058D431}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
========== Vista Active Application Exception List ==========
"{04BFB58E-7F0B-491F-9FB8-DEDD92D1B09A}" = protocol=6 | dir=in | app=c:\users\apb\appdata\roaming\dropbox\bin\dropbox.exe | 
"{08F6C765-3723-4096-B2F5-8E6788AF93F9}" = protocol=6 | dir=in | svc=* | app=c:\program files (x86)\common files\research in motion\tunnel manager\tunmgr.exe | 
"{0D5BCA22-479C-422C-9283-ED723573DFC9}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{0F1CADB4-1EC3-4AC6-B578-CAFD8FF8A784}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe | 
"{11E2E1EE-6842-4E7C-B608-DEF4C35EFEEC}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 | 
"{17602986-267F-44BC-A523-4EAE209A09D5}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{1976D439-C1D3-4298-A16D-1D75806A47FB}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe | 
"{1B6BDF63-0C4A-4960-8941-D055EDA1A38C}" = protocol=6 | dir=in | svc=* | app=c:\program files (x86)\common files\research in motion\tunnel manager\mdnsresponder.exe | 
"{1C3E3C6C-1A2B-4F3D-8E54-FBE938CABF76}" = protocol=17 | dir=in | app=c:\users\apb\appdata\local\temp\smallinstaller\installfiles\ccdd.exe | 
"{1E2AACED-747E-40ED-9EF2-7D9C38CC4EF0}" = protocol=17 | dir=in | svc=* | app=c:\program files (x86)\common files\research in motion\tunnel manager\tunmgr.exe | 
"{24DB28D7-D17C-4383-B1C9-F857D2149C40}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi media\windowsupnpmv.exe | 
"{2C4BC1C5-F510-487B-BC74-572396894DB4}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{2C91CB71-D229-4AA5-9E94-94E5DBB7A5F3}" = protocol=6 | dir=in | app=c:\program files (x86)\sdsd\ssf editor\ssfeditor.exe | 
"{31A6A4D9-C983-431C-B508-1AB8C3D570F1}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | 
"{32A3C026-B7BE-4E77-9672-DC45FEF3A986}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi media\dmcdaemon.exe | 
"{3AC1E7F3-32F1-4161-BA87-1F020ADA09D0}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | 
"{40069544-5AB1-4596-8F31-9E8F19319174}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{45A67AF6-AEBC-4819-967C-9023297F2289}" = protocol=58 | dir=in | app=system | 
"{4D480D2A-822F-4F13-8EF7-2E092B766E50}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\windowsupnp.exe | 
"{4FCE9769-DA42-4598-96B5-C1B4C37F7B99}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{567EB23C-C461-4FED-8E42-30C5EAF7F3D9}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe | 
"{5A7BCB0C-3CAA-4D9A-A780-675AD582C740}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi media\windowsupnpmv.exe | 
"{61854202-5C83-4BCE-9A9A-DAF6BCE79CB0}" = dir=in | app=c:\program files\acer\acer theft shield\usecuappclient.exe | 
"{64B5ABB9-511C-469C-BCFB-7EE8188AF49E}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | 
"{65D4E9CB-458B-43B4-843E-449812300F59}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{6F23BC36-9165-44FE-92CB-2634D262B4FC}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{76E2A7F9-2B4E-4712-8BDD-8C68EA84D10A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{787F8A49-BE93-4372-BB3E-D54F6AAA2E9A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{7A63FA1A-335A-4483-B649-BF3460F9047E}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\research in motion\tunnel manager\peermanager.exe | 
"{7E38CDFC-43CE-44AA-897B-4995D6F3D29E}" = dir=in | app=c:\program files (x86)\acer\acer vcm\rs_service.exe | 
"{7F61D764-2350-43ED-A442-FB6C9A82510A}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | 
"{80D76908-1E1A-40D2-BF97-CAFFF6321E2D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{863C1002-7F5B-4B44-8C84-6B8FC2BD2DF3}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{8672422C-2C3D-41B0-8B62-D47D8526CE5D}" = protocol=17 | dir=in | svc=* | app=c:\program files (x86)\common files\research in motion\tunnel manager\mdnsresponder.exe | 
"{86F87E59-6227-4FE5-A49F-44BDE47FBBF3}" = protocol=17 | dir=in | app=c:\users\apb\appdata\roaming\dropbox\bin\dropbox.exe | 
"{A0331BE6-7988-41E2-8EAD-B3D9B6B55A28}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\windowsupnp.exe | 
"{A19F079E-F930-46C3-B7AA-BF49789C65A7}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi media\dmcdaemon.exe | 
"{A370B58E-6C64-4E64-B771-590DC6996FB0}" = dir=in | app=c:\program files (x86)\acer\acer vcm\vc.exe | 
"{A69D056D-DE79-4C01-B205-BB81CC3DF544}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | 
"{AB4BAFF7-F46D-4D6D-903D-A21815216EE5}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | 
"{C65A4485-7EF5-4C24-8379-BA0C8FAC20F8}" = dir=in | app=c:\program files (x86)\acer\clear.fi sdk20\movie\playmovie.exe | 
"{C75C906D-2F31-46F9-8760-DAB3DB9AAFFE}" = protocol=6 | dir=in | app=c:\users\apb\appdata\local\temp\smallinstaller\installfiles\ccdd.exe | 
"{C8B77245-BD31-40C1-B7B1-A6C4D57967B4}" = dir=in | app=c:\program files (x86)\acer\clear.fi sdk21\movie\playmovie.exe | 
"{CA791863-3B18-4923-90EA-A9E783181CC9}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | 
"{CD74CFEE-EB7B-4B45-BA21-21CDC77E450D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{CFB8EFFE-E96E-470A-ABB1-D06CE65D554A}" = dir=in | app=c:\program files (x86)\acer\clear.fi sdk21\video\musicplayer.exe | 
"{D29E1956-B2E1-42D9-AC50-81623E7EE659}" = protocol=6 | dir=out | app=system | 
"{E6A1B84C-39EE-44A7-9544-449346257A09}" = protocol=17 | dir=in | app=c:\program files (x86)\sdsd\ssf editor\ssfeditor.exe | 
"{E704795C-AC5F-4EB6-95D8-A989BCE90839}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | 
"{E76DF1C7-9FAC-41A3-BE24-6493F480E320}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\dmcdaemon.exe | 
"{EA6B5601-F9FB-4EAF-B0A6-868B0FB47F48}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\dmcdaemon.exe | 
"{F492F653-3690-4B30-A6ED-ED24933E4DA5}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{F5624989-CAE1-412E-8592-BB372D110A1A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{F9133A55-84AD-4105-A6B2-6030B00B17C6}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{FB99D473-23F7-46BF-92A0-F478A096404B}" = dir=in | app=c:\program files (x86)\acer\clear.fi sdk21\video\videoplayer.exe | 
"TCP Query User{040CCEA6-0A04-4171-9B41-9A8ACA820B30}C:\program files (x86)\nas utility\pnmd\pnmd.exe" = protocol=6 | dir=in | app=c:\program files (x86)\nas utility\pnmd\pnmd.exe | 
"TCP Query User{0F798DB0-69D9-4197-9691-22207FAE3455}C:\users\apb\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\apb\appdata\roaming\dropbox\bin\dropbox.exe | 
"TCP Query User{513A8EF8-6274-49F5-BBDE-272EF9BC6CF9}C:\users\apb\appdata\local\temp\_istmp1.dir\_ins5576._mp" = protocol=6 | dir=in | app=c:\users\apb\appdata\local\temp\_istmp1.dir\_ins5576._mp | 
"TCP Query User{5939E3E8-073C-4951-A6B8-40B05C1C0720}C:\program files (x86)\acer\acer cloud\sdd.exe" = protocol=6 | dir=in | app=c:\program files (x86)\acer\acer cloud\sdd.exe | 
"TCP Query User{6057385B-A57F-495D-9212-9AAC0CECE5E2}C:\program files (x86)\fritz!\frifax32.exe" = protocol=6 | dir=in | app=c:\program files (x86)\fritz!\frifax32.exe | 
"TCP Query User{6528D010-CD58-43A1-A6D3-1A20853E46DE}C:\users\apb\downloads\dtrace_fuer_fritzbox_fon_1.03\dtrace32.exe" = protocol=6 | dir=in | app=c:\users\apb\downloads\dtrace_fuer_fritzbox_fon_1.03\dtrace32.exe | 
"TCP Query User{A3A5A6F6-807A-4010-89E1-E63BDFAEDFF3}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe" = protocol=6 | dir=in | app=c:\windows\microsoft.net\framework\v2.0.50727\vbc.exe | 
"TCP Query User{D7A03031-BA3A-43E0-BFA2-2A746282E7DD}C:\users\apb\downloads\longshine\pnmd\pnmd\program files\nas utility\pnmd\pnmd.exe" = protocol=6 | dir=in | app=c:\users\apb\downloads\longshine\pnmd\pnmd\program files\nas utility\pnmd\pnmd.exe | 
"UDP Query User{30AF1455-26F1-4FF6-B2A0-C6256AFDDCF8}C:\program files (x86)\acer\acer cloud\sdd.exe" = protocol=17 | dir=in | app=c:\program files (x86)\acer\acer cloud\sdd.exe | 
"UDP Query User{430E0D5B-9D5B-4D9B-803E-73F3A815AD66}C:\users\apb\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\apb\appdata\roaming\dropbox\bin\dropbox.exe | 
"UDP Query User{A0BF85E2-5970-4C30-9607-BAF6F1BF85F5}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe" = protocol=17 | dir=in | app=c:\windows\microsoft.net\framework\v2.0.50727\vbc.exe | 
"UDP Query User{C2672462-F539-491B-8B61-1EE203792B2C}C:\program files (x86)\fritz!\frifax32.exe" = protocol=17 | dir=in | app=c:\program files (x86)\fritz!\frifax32.exe | 
"UDP Query User{C7F3CCE7-98B0-4AFB-A1BB-98381D85404E}C:\users\apb\downloads\longshine\pnmd\pnmd\program files\nas utility\pnmd\pnmd.exe" = protocol=17 | dir=in | app=c:\users\apb\downloads\longshine\pnmd\pnmd\program files\nas utility\pnmd\pnmd.exe | 
"UDP Query User{D30BAA69-C238-474F-8FB6-2387AE1E2593}C:\users\apb\downloads\dtrace_fuer_fritzbox_fon_1.03\dtrace32.exe" = protocol=17 | dir=in | app=c:\users\apb\downloads\dtrace_fuer_fritzbox_fon_1.03\dtrace32.exe | 
"UDP Query User{F35FD89E-A146-4361-8CED-B7D9CA15F7A9}C:\program files (x86)\nas utility\pnmd\pnmd.exe" = protocol=17 | dir=in | app=c:\program files (x86)\nas utility\pnmd\pnmd.exe | 
"UDP Query User{FE9FFAC2-B56A-4713-8EFC-058B730F295E}C:\users\apb\appdata\local\temp\_istmp1.dir\_ins5576._mp" = protocol=17 | dir=in | app=c:\users\apb\appdata\local\temp\_istmp1.dir\_ins5576._mp | 
--- --- ---


