Code:
Emsisoft Emergency Kit - Version 9.0
Letztes Update: 15.04.2015 19:08:39
Benutzerkonto: EROL-PC\EROL
Scan-Einstellungen:
Scan Methode: Detail-Scan
Objekte: Rootkits, Speicher, Traces, C:\
PUPs-Erkennung: An
Archiv-Scan: An
ADS Scan: An
Dateitypen-Filter: Aus
Erweitertes Caching: An
Direkter Festplattenzugriff: Aus
Scan-Beginn: 15.04.2015 19:09:22
Value: HKEY_USERS\S-1-5-21-1924032147-3410277532-354269451-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLETASKMGR gefunden: Setting.DisableTaskMgr (A)
Value: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLEREGISTRYTOOLS gefunden: Setting.DisableRegistryTools (A)
Value: HKEY_USERS\S-1-5-21-1924032147-3410277532-354269451-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLEREGISTRYTOOLS gefunden: Setting.DisableRegistryTools (A)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\0a0fc379.qua -> (Quarantine-8) -> (NSIS o) -> zlib_nsis0003 gefunden: Trojan.GenericKD.2238938 (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\0a0fc379.qua -> (Quarantine-8) -> (NSIS o) -> zlib_nsis0015 gefunden: Trojan.GenericKD.2238289 (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\0a0fc379.qua -> (Quarantine-8) -> (NSIS o) -> zlib_nsis0020 gefunden: Trojan.GenericKD.2238376 (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\0a80b711.qua -> (Quarantine-8) gefunden: Gen:Variant.Adware.SoftPulse.9 (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\1a11bfa6.qua -> (Quarantine-8) gefunden: Trojan.GenericKD.2241563 (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\1a50ca65.qua -> (Quarantine-8) -> (Quarantine-PE) gefunden: Adware.Eorezo.BZ (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\2ef3d0b2.qua -> (Quarantine-8) gefunden: Gen:Variant.Adware.SoftPulse.9 (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\3922a9a2.qua -> (Quarantine-8) gefunden: Adware.Generic.1217714 (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\39a7dd54.qua -> (Quarantine-8) gefunden: Application.Agent.ID (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\3b868f34.qua -> (Quarantine-8) gefunden: Adware.SearchProtect.W (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\46389bfc.qua -> (Quarantine-8) gefunden: Gen:Variant.Strictor.79122 (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\480b9308.qua -> (Quarantine-8) -> (Quarantine-PE) gefunden: Adware.Eorezo.BZ (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\484ae366.qua -> (Quarantine-8) gefunden: Gen:Variant.Zusy.124370 (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\50ddca42.qua -> (Quarantine-8) gefunden: Gen:Variant.Zusy.124370 (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\535fbaac.qua -> (Quarantine-8) gefunden: Trojan.GenericKD.2238376 (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\5397a177.qua -> (Quarantine-8) gefunden: Trojan.GenericKD.2180595 (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\539bca22.qua -> (Quarantine-8) gefunden: Gen:Variant.Zusy.124370 (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\53ab4448.qua -> (Quarantine-8) gefunden: Adware.Generic.1217714 (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\53b4e593.qua -> (Quarantine-8) gefunden: Trojan.GenericKD.2241294 (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\58019145.qua -> (Quarantine-8) gefunden: Adware.SearchProtect.W (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\5bc2c797.qua -> (Quarantine-8) gefunden: Gen:Variant.Strictor.79122 (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\5c8cbf7f.qua -> (Quarantine-8) gefunden: Adware.SearchProtect.W (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\7698e88f.qua -> (Quarantine-8) gefunden: Gen:Variant.Adware.SoftPulse.9 (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\7c191a0d.qua -> (Quarantine-8) gefunden: Gen:Variant.Graftor.182037 (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\7c27f07d.qua -> (Quarantine-8) gefunden: Application.OptimizerPro.V (B)
Gescannt 295895
Gefunden 28
Scan-Ende: 15.04.2015 21:47:21
Scan-Zeit: 2:37:59
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\7c27f07d.qua Quarantäne Application.OptimizerPro.V (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\7c191a0d.qua Quarantäne Gen:Variant.Graftor.182037 (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\7698e88f.qua Quarantäne Gen:Variant.Adware.SoftPulse.9 (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\5c8cbf7f.qua Quarantäne Adware.SearchProtect.W (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\5bc2c797.qua Quarantäne Gen:Variant.Strictor.79122 (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\58019145.qua Quarantäne Adware.SearchProtect.W (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\53b4e593.qua Quarantäne Trojan.GenericKD.2241294 (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\53ab4448.qua Quarantäne Adware.Generic.1217714 (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\539bca22.qua Quarantäne Gen:Variant.Zusy.124370 (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\5397a177.qua Quarantäne Trojan.GenericKD.2180595 (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\535fbaac.qua Quarantäne Trojan.GenericKD.2238376 (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\50ddca42.qua Quarantäne Gen:Variant.Zusy.124370 (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\484ae366.qua Quarantäne Gen:Variant.Zusy.124370 (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\480b9308.qua Quarantäne Adware.Eorezo.BZ (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\46389bfc.qua Quarantäne Gen:Variant.Strictor.79122 (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\3b868f34.qua Quarantäne Adware.SearchProtect.W (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\39a7dd54.qua Quarantäne Application.Agent.ID (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\3922a9a2.qua Quarantäne Adware.Generic.1217714 (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\2ef3d0b2.qua Quarantäne Gen:Variant.Adware.SoftPulse.9 (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\1a50ca65.qua Quarantäne Adware.Eorezo.BZ (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\1a11bfa6.qua Quarantäne Trojan.GenericKD.2241563 (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\0a80b711.qua Quarantäne Gen:Variant.Adware.SoftPulse.9 (B)
C:\ProgramData\Avira\AntiVir Desktop\INFECTED\0a0fc379.qua Quarantäne Trojan.GenericKD.2238376 (B)
Value: HKEY_USERS\S-1-5-21-1924032147-3410277532-354269451-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLEREGISTRYTOOLS Quarantäne Setting.DisableRegistryTools (A)
Value: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLEREGISTRYTOOLS Quarantäne Setting.DisableRegistryTools (A)
Value: HKEY_USERS\S-1-5-21-1924032147-3410277532-354269451-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLETASKMGR Quarantäne Setting.DisableTaskMgr (A)
Quarantäne 26 Avira Antivirus sagt mir das er 40 Viren oder unerwünschte Programme gefundet hat ... :balla: Aber die ganzen Popup's im Firefox sind jetzt wieder weg :bussi:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-04-2015 04
Ran by EROL (administrator) on EROL-PC on 15-04-2015 22:09:29
Running from C:\Users\EROL\Desktop
Loaded Profiles: EROL (Available profiles: EROL)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Lavasoft Limited) C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
(Steganos Software GmbH) C:\Program Files (x86)\OkayFreedom\OkayFreedomService.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Steganos Software GmbH) C:\Program Files (x86)\OkayFreedom\OkayFreedomClient.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Acer) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(CyberLink Corp.) C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
(Acer Corp.) C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\PMVService.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Lavasoft Limited) C:\Program Files (x86)\Ad-Aware Antivirus\AdAware.exe
(GFI Software) C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_169.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_17_0_0_169.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [mwlDaemon] => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8060960 2009-08-06] (Realtek Semiconductor)
HKLM\...\Run: [Acer ePower Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [828960 2009-08-05] (Acer Incorporated)
HKLM\...\Run: [EPSON Stylus DX3800 Series] => C:\Windows\system32\spool\DRIVERS\x64\3\E_FATIACE.EXE /F "C:\Windows\TEMP\E_S2D9F.tmp" /EF "HKLM"
HKLM\...\Run: [SBRegRebootCleaner] => C:\Program Files (x86)\Ad-Aware Antivirus\SBRC.exe [201608 2012-09-20] (GFI Software)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [41056 2013-05-08] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [261888 2009-08-21] (NewTech Infosystems, Inc.)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1194504 2009-08-27] (Dritek System Inc.)
HKLM-x32\...\Run: [ArcadeDeluxeAgent] => C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe [128296 2009-07-31] (CyberLink Corp.)
HKLM-x32\...\Run: [PlayMovie] => C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\PMVService.exe [181480 2009-08-04] (Acer Corp.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Ad-Aware Antivirus] => "C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher" --windows-run
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2014-10-11] (Apple Inc.)
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1065024 2014-05-02] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [704512 2015-03-17] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [129272 2015-03-16] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-1924032147-3410277532-354269451-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-11-20] (Apple Inc.)
HKU\S-1-5-21-1924032147-3410277532-354269451-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [31340640 2015-02-26] (Skype Technologies S.A.)
HKU\S-1-5-21-1924032147-3410277532-354269451-1001\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59720 2013-11-20] (Apple Inc.)
HKU\S-1-5-21-1924032147-3410277532-354269451-1001\...\Run: [OKAYFREEDOM_Agent] => C:\Program Files (x86)\OkayFreedom\OkayFreedomClient.exe [6553000 2015-02-18] (Steganos Software GmbH)
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => No File
BootExecute: autocheck autochk * sdnclean64.exe
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-1924032147-3410277532-354269451-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1924032147-3410277532-354269451-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-1924032147-3410277532-354269451-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM-x32 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-04-15] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-15] (Oracle Corporation)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2012-01-25] (SEIKO EPSON CORPORATION)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-10-21] (Microsoft Corporation.)
Toolbar: HKLM-x32 - E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll [2014-11-27] (SEIKO EPSON CORPORATION)
Toolbar: HKU\S-1-5-21-1924032147-3410277532-354269451-1001 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKU\S-1-5-21-1924032147-3410277532-354269451-1001 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL No File
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\EROL\AppData\Roaming\Mozilla\Firefox\Profiles\tm9r20kd.default-1418645245816
FF SearchEngineOrder.3: Bing
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-15] ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-15] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-15] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-04-17] (Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll [2013-05-08] (Adobe Systems Inc.)
FF Extension: No Name - C:\Users\EROL\AppData\Roaming\Mozilla\Firefox\Profiles\tm9r20kd.default-1418645245816\Extensions\bingsearch.full@microsoft.com [2015-03-26]
FF Extension: OkayFreedom - C:\Users\EROL\AppData\Roaming\Mozilla\Firefox\Profiles\tm9r20kd.default-1418645245816\Extensions\{DB981CCA-088E-4731-A4A2-2FE218703C0E}.xpi [2015-03-31]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2015-04-14]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-04-14]
FF HKLM-x32\...\Firefox\Extensions: [e-webprint@epson.com] - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on
FF Extension: E-Web Print - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on [2015-01-07]
Chrome:
=======
CHR Profile: C:\Users\EROL\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Bookmark Manager) - C:\Users\EROL\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-03-11]
CHR Extension: (No Name) - C:\Users\EROL\AppData\Local\Google\Chrome\User Data\Default\Extensions\jldhpllghnbhlbpcmnajkpdmadaolakh [2015-03-27]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\EROL\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-11]
CHR Extension: (Skype Click to Call) - C:\Users\EROL\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-11-06]
CHR Extension: (No Name) - C:\Users\EROL\AppData\Local\Google\Chrome\User Data\Default\Extensions\lnmengjdnfjbochkdkcjbbpildacancp [2015-04-05]
CHR Extension: (Google Wallet) - C:\Users\EROL\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-01]
CHR Extension: (No Name) - C:\Users\EROL\AppData\Local\Google\Chrome\User Data\Default\Extensions\oamjbefinnglappklpabmhpbcdiephoo [2015-03-28]
CHR Extension: (pnmjaflneibolacpepklokkjnakmikmg) - C:\Users\EROL\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnmjaflneibolacpepklokkjnakmikmg [2015-03-15]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1924032147-3410277532-354269451-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [kfecnpmgnlnbmipaogfhoacoioifjgko] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [kfecnpmgnlnbmipaogfhoacoioifjgko] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 Ad-Aware Service; C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe [1236336 2013-06-13] (Lavasoft Limited)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [432888 2015-03-17] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [432888 2015-03-17] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [201008 2015-03-16] (Avira Operations GmbH & Co. KG)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [144560 2012-05-17] (Seiko Epson Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation)
R2 OkayFreedom VPN Starter Service; C:\Program Files (x86)\OkayFreedom\OkayFreedomService.exe [326072 2015-02-18] (Steganos Software GmbH)
R2 SBAMSvc; C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [3677000 2012-09-20] (GFI Software)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [128536 2015-03-17] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132120 2015-03-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2015-03-17] (Avira Operations GmbH & Co. KG)
R3 cleanhlp; C:\eek\bin\cleanhlp64.sys [57024 2015-04-15] (Emsisoft GmbH)
S3 gfiark; C:\Windows\System32\drivers\gfiark.sys [41032 2013-05-23] (ThreatTrack Security)
R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [14456 2013-08-29] (GFI Software)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-03-17] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-03-17] (Malwarebytes Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 cpuz134; \??\C:\Users\EROL\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [X]
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-15 19:04 - 2015-04-15 19:04 - 00000747 _____ () C:\Users\EROL\Desktop\Start Emsisoft Emergency Kit.lnk
2015-04-15 18:56 - 2015-04-15 19:05 - 00000000 ____D () C:\eek
2015-04-14 19:49 - 2015-04-14 19:49 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-04-14 18:55 - 2015-04-14 18:55 - 00003132 _____ () C:\Users\EROL\Desktop\JRT.txt
2015-04-14 18:51 - 2015-04-14 18:51 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-EROL-PC-Windows-7-Home-Premium-(64-bit).dat
2015-04-14 18:50 - 2015-04-14 18:50 - 00000000 ____D () C:\RegBackup
2015-04-13 20:46 - 2015-04-13 20:50 - 00000000 ____D () C:\AdwCleaner
2015-04-13 20:44 - 2015-04-13 20:45 - 00085608 _____ () C:\Users\EROL\Desktop\mbam3.txt
2015-04-13 20:43 - 2015-04-13 20:44 - 00080241 _____ () C:\Users\EROL\Desktop\mbam2.txt
2015-04-13 20:14 - 2015-04-13 20:43 - 00095465 _____ () C:\Users\EROL\Desktop\mbam1.txt
2015-04-12 20:38 - 2015-04-15 22:07 - 00000000 ____D () C:\Users\EROL\Desktop\FRST-OlderVersion
2015-04-12 15:11 - 2015-04-12 15:11 - 00037908 _____ () C:\ComboFix.txt
2015-04-12 14:32 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-04-12 14:32 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-04-12 14:32 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-04-12 14:32 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-04-12 14:32 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-04-12 14:32 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2015-04-12 14:32 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2015-04-12 14:32 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2015-04-12 14:28 - 2015-04-12 15:11 - 00000000 ____D () C:\Qoobox
2015-04-12 14:27 - 2015-04-12 15:07 - 00000000 ____D () C:\Windows\erdnt
2015-04-12 12:04 - 2015-04-12 12:04 - 05617275 ____R (Swearware) C:\Users\EROL\Desktop\ComboFix.exe
2015-04-12 11:33 - 2015-04-12 11:33 - 00001268 _____ () C:\Users\EROL\Desktop\Revo Uninstaller.lnk
2015-04-12 11:33 - 2015-04-12 11:33 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2015-04-12 11:11 - 2015-04-12 11:11 - 00472176 _____ () C:\Windows\Minidump\041215-18142-01.dmp
2015-04-12 10:07 - 2015-04-12 10:07 - 00048195 _____ () C:\Users\EROL\Desktop\gmer.txt
2015-04-12 09:57 - 2015-04-12 09:57 - 00000470 _____ () C:\Users\EROL\Desktop\defogger_disable.log
2015-04-12 09:57 - 2015-04-11 09:15 - 00380416 _____ () C:\Users\EROL\Desktop\Gmer-19357.exe
2015-04-12 09:57 - 2015-04-11 09:12 - 00050477 _____ () C:\Users\EROL\Desktop\Defogger.exe
2015-04-12 09:47 - 2015-04-14 21:51 - 00031265 _____ () C:\Users\EROL\Desktop\Addition.txt
2015-04-12 09:44 - 2015-04-15 22:10 - 00020190 _____ () C:\Users\EROL\Desktop\FRST.txt
2015-04-12 09:44 - 2015-04-15 22:09 - 00000000 ____D () C:\FRST
2015-04-12 09:42 - 2015-04-15 22:07 - 02097664 _____ (Farbar) C:\Users\EROL\Desktop\FRST64.exe
2015-04-11 23:47 - 2015-04-11 23:47 - 00008963 _____ () C:\Users\EROL\Desktop\1104.txt
2015-04-11 23:19 - 2015-04-13 19:08 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-11 23:19 - 2015-04-11 23:19 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-04-11 23:19 - 2015-04-11 23:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-04-11 23:19 - 2015-04-11 23:19 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-04-11 23:19 - 2015-04-11 23:19 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-04-11 23:19 - 2015-03-17 06:15 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-04-11 23:19 - 2015-03-17 06:15 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-04-11 23:19 - 2015-03-17 06:15 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-04-11 09:18 - 2015-04-11 09:18 - 00000000 _____ () C:\Users\EROL\defogger_reenable
2015-04-05 18:26 - 2015-04-05 18:26 - 00000000 ____D () C:\Users\EROL\AppData\Roaming\Avira
2015-04-05 18:20 - 2015-04-05 18:15 - 00044088 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2015-04-05 18:13 - 2015-03-17 13:01 - 00132120 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2015-04-05 18:13 - 2015-03-17 13:01 - 00128536 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2015-04-05 18:13 - 2015-03-17 13:01 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2015-04-05 18:02 - 2015-04-05 18:02 - 00000000 ____D () C:\Windows\pss
2015-04-05 17:34 - 2015-04-05 17:34 - 00001211 _____ () C:\Users\Public\Desktop\Avira.lnk
2015-04-05 17:33 - 2015-04-11 19:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-04-05 17:33 - 2015-04-05 18:13 - 00000000 ____D () C:\ProgramData\Avira
2015-04-05 17:33 - 2015-04-05 18:13 - 00000000 ____D () C:\Program Files (x86)\Avira
2015-04-05 17:33 - 2015-04-05 17:33 - 00000000 ____D () C:\ProgramData\Package Cache
2015-04-05 17:18 - 2015-04-10 22:09 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2015-04-05 17:18 - 2015-04-05 17:22 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2015-04-05 17:18 - 2015-04-05 17:18 - 00001395 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2015-04-05 17:18 - 2015-04-05 17:18 - 00001383 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2015-04-05 17:18 - 2015-04-05 17:18 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2015-04-05 17:18 - 2015-04-05 17:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2015-04-05 17:18 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
2015-04-05 12:21 - 2015-04-05 12:22 - 00291696 _____ () C:\Windows\Minidump\040515-28080-01.dmp
2015-04-05 00:23 - 2015-04-05 00:23 - 00000000 ___SD () C:\Windows\SysWOW64\GWX
2015-04-05 00:23 - 2015-04-05 00:23 - 00000000 ___SD () C:\Windows\system32\GWX
2015-04-04 20:10 - 2015-04-04 23:43 - 00008856 _____ () C:\Windows\SysWOW64\29xyOff.ini
2015-04-04 20:10 - 2015-04-04 23:43 - 00008856 _____ () C:\Windows\system32\29xyOff.ini
2015-04-03 23:02 - 2015-04-04 17:18 - 00000000 ____D () C:\Users\EROL\Desktop\Bewerbung
2015-03-31 11:02 - 2015-04-15 16:50 - 00000000 ____D () C:\Users\EROL\AppData\Roaming\Steganos VPN
2015-03-31 11:02 - 2015-04-03 21:03 - 00000000 ____D () C:\Users\EROL\AppData\Roaming\Steganos
2015-03-31 11:02 - 2015-03-31 11:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OkayFreedom
2015-03-31 11:02 - 2015-03-31 11:02 - 00000000 ____D () C:\Program Files (x86)\OkayFreedom
2015-03-28 17:52 - 2015-03-28 17:52 - 00300623 _____ () C:\Users\EROL\Downloads\Futbol Canlı Sonuçlar, Canlı maç sonuçları - iddaa.com.htm
2015-03-28 17:52 - 2015-03-28 17:52 - 00000000 ____D () C:\Users\EROL\Downloads\Futbol Canlı Sonuçlar, Canlı maç sonuçları - iddaa.com-Dateien
2015-03-25 10:59 - 2015-03-11 06:06 - 00943616 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-03-25 10:59 - 2015-03-11 06:06 - 00760832 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-03-25 10:59 - 2015-03-11 06:06 - 00677888 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-03-25 10:59 - 2015-03-11 06:06 - 00414720 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-03-25 10:59 - 2015-03-11 06:05 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-03-25 10:59 - 2015-03-11 06:05 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-03-25 10:59 - 2015-03-11 06:05 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-03-25 10:59 - 2015-03-11 06:02 - 01107456 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-03-23 09:46 - 2015-03-23 09:46 - 00000000 ___HD () C:\Users\Public\B95565D26D9A9DC2AD95815626DF35B1
2015-03-22 19:07 - 2015-04-11 23:15 - 00000000 ____D () C:\Users\EROL\AppData\Local\004578DC-1427047646-DE11-8C4E-95D864771729
2015-03-22 09:28 - 2015-03-22 09:28 - 00291696 _____ () C:\Windows\Minidump\032215-18720-01.dmp
2015-03-18 16:07 - 2015-03-18 16:07 - 00000000 ____D () C:\Users\EROL\Option
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-15 22:08 - 2010-10-15 23:34 - 00003922 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{48FD094E-AFAF-4EC8-9EB3-9106BB6B89F2}
2015-04-15 21:34 - 2015-01-07 14:34 - 00000911 _____ () C:\Windows\Tasks\EPSON XP-225 Series Update {DA9064A8-56DA-49F8-8F27-85D2FF2069A9}.job
2015-04-15 18:59 - 2013-11-24 18:07 - 00000000 ____D () C:\Users\EROL\Downloads\MSN Deutschland Aktuelle Nachrichten, Outlook.com Email und Skype Login-Dateien
2015-04-15 18:28 - 2009-10-17 08:14 - 01698247 _____ () C:\Windows\WindowsUpdate.log
2015-04-15 18:20 - 2012-10-12 12:11 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-04-15 18:20 - 2011-10-03 11:34 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-04-15 18:20 - 2010-11-02 19:07 - 00000000 ____D () C:\Users\EROL\AppData\Local\Adobe
2015-04-15 16:59 - 2009-07-14 06:45 - 00025840 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-15 16:59 - 2009-07-14 06:45 - 00025840 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-15 16:54 - 2014-11-26 20:52 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-04-15 16:54 - 2013-07-15 12:34 - 00000000 ____D () C:\Program Files (x86)\Java
2015-04-15 16:52 - 2013-08-29 01:44 - 00001872 _____ () C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
2015-04-15 16:50 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-15 16:50 - 2009-07-14 06:51 - 00192306 _____ () C:\Windows\setupact.log
2015-04-15 16:49 - 2015-03-12 22:13 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-04-15 16:38 - 2012-10-12 12:11 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-15 16:38 - 2009-08-22 10:34 - 01717214 _____ () C:\Windows\PFRO.log
2015-04-15 16:37 - 2012-10-12 12:11 - 00003796 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-04-13 20:50 - 2015-02-25 12:34 - 00000000 ____D () C:\Windows\system32\log
2015-04-13 20:23 - 2009-07-27 22:41 - 00000000 ____D () C:\Windows\Panther
2015-04-13 18:39 - 2015-02-10 02:08 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2015-04-12 15:11 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2015-04-12 15:04 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2015-04-12 14:08 - 2011-10-27 14:22 - 00000000 ____D () C:\Users\EROL\AppData\Roaming\Skype
2015-04-12 11:11 - 2014-08-24 16:33 - 523873432 _____ () C:\Windows\MEMORY.DMP
2015-04-12 11:11 - 2014-08-24 16:33 - 00000000 ____D () C:\Windows\Minidump
2015-04-12 10:00 - 2009-10-17 18:03 - 00714532 _____ () C:\Windows\system32\perfh007.dat
2015-04-12 10:00 - 2009-10-17 18:03 - 00154584 _____ () C:\Windows\system32\perfc007.dat
2015-04-12 10:00 - 2009-07-14 07:13 - 01538900 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-12 09:29 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PLA
2015-04-11 23:56 - 2014-02-26 03:13 - 01472526 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2015-04-11 09:18 - 2009-12-09 21:35 - 00000000 ____D () C:\Users\EROL
2015-04-05 18:55 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-04-05 18:47 - 2015-02-25 12:51 - 00000000 ____D () C:\ProgramData\dcd3ad0177264843bc5000b01d833e70
2015-04-05 18:34 - 2015-02-22 16:51 - 00000000 ____D () C:\ProgramData\{9d4d7a04-c0f0-47e9-9d4d-d7a04c0fe813}
2015-04-05 18:34 - 2015-02-22 16:27 - 00000000 ____D () C:\ProgramData\{1f0c2576-5236-741c-1f0c-c257652395d9}
2015-04-05 12:27 - 2010-10-08 14:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Okey+
2015-04-05 10:48 - 2015-02-22 16:45 - 00000000 ___HD () C:\Users\Public\Temp
2015-04-05 10:46 - 2015-02-22 16:47 - 00000126 _____ () C:\Users\EROL\AppData\Roaming\WB.CFG
2015-04-04 23:33 - 2009-07-14 04:34 - 00000612 _____ () C:\Windows\win.ini
2015-04-02 10:08 - 2015-03-11 17:03 - 00000004 _____ () C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-04-01 18:03 - 2009-08-22 07:40 - 00000000 ____D () C:\Program Files (x86)\Google
2015-03-26 11:58 - 2014-09-21 15:55 - 00000000 ___RD () C:\Program Files (x86)\Skype
2015-03-26 11:58 - 2011-10-27 14:22 - 00000000 ____D () C:\ProgramData\Skype
2015-03-26 11:23 - 2014-12-11 12:19 - 00000000 ____D () C:\Windows\system32\appraiser
2015-03-26 11:23 - 2014-05-09 22:42 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-03-24 11:28 - 2014-12-29 19:24 - 00000000 ____D () C:\Users\EROL\AppData\Local\Unity
2015-03-20 01:13 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2015-03-18 12:42 - 2013-11-19 19:18 - 00000000 ____D () C:\Users\EROL\AppData\Roaming\Apple Computer
2015-03-18 12:42 - 2013-11-19 19:18 - 00000000 ____D () C:\Users\EROL\AppData\Local\Apple Computer
==================== Files in the root of some directories =======
2014-11-20 12:45 - 2014-11-20 12:45 - 6000640 _____ () C:\Program Files (x86)\GUT4C3D.tmp
2015-02-22 16:47 - 2015-04-05 10:46 - 0000126 _____ () C:\Users\EROL\AppData\Roaming\WB.CFG
2010-10-03 23:03 - 2013-11-13 19:00 - 0000124 _____ () C:\Users\EROL\AppData\Roaming\wklnhst.dat
2014-06-23 22:44 - 2014-07-07 23:23 - 0001097 _____ () C:\Users\EROL\AppData\Local\cookies.ini
2015-02-24 11:57 - 2015-02-24 11:57 - 0274045 _____ () C:\Users\EROL\AppData\Local\dsi1.dat
2015-02-24 11:57 - 2015-02-24 11:57 - 0161916 _____ () C:\Users\EROL\AppData\Local\dsi2.dat
2015-03-11 18:30 - 2015-03-11 18:30 - 0001643 _____ () C:\Users\EROL\AppData\Local\MyWinLockerInstaller.txt-20150311.log
2015-03-12 12:54 - 2015-03-12 12:58 - 0006477 _____ () C:\Users\EROL\AppData\Local\MyWinLockerInstaller.txt-20150312.log
2009-10-17 08:15 - 2009-10-17 08:17 - 0007768 _____ () C:\ProgramData\ArcadeDeluxe3.log
2009-08-22 10:44 - 2009-07-18 03:57 - 0036136 _____ (Oberon Media) C:\ProgramData\FullRemove.exe
Some content of TEMP:
====================
C:\Users\EROL\AppData\Local\temp\avgnt.exe
C:\Users\EROL\AppData\Local\temp\jre-8u45-windows-au.exe
C:\Users\EROL\AppData\Local\temp\Quarantine.exe
C:\Users\EROL\AppData\Local\temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-04-14 22:24
==================== End Of Log ============================ --- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-04-2015 04
Ran by EROL at 2015-04-15 22:11:15
Running from C:\Users\EROL\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avira Desktop (Enabled - Out of date) {4D041356-F94D-285F-8768-AAE50FA36859}
AV: Lavasoft Ad-Aware (Enabled - Out of date) {E0D97DD4-42BA-B3F2-A5A7-22E9ACE81FC7}
AS: Avira Desktop (Enabled - Out of date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Lavasoft Ad-Aware (Enabled - Out of date) {5BB89C30-6480-BC7C-9F17-199BD76F557A}
AS: Spybot - Search and Destroy (Enabled - Out of date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
FW: Lavasoft Ad-Aware (Disabled) {D8E2FCF1-08D5-B2AA-8EF8-8BDC523B58BC}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Acer Arcade Deluxe (HKLM-x32\...\InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}) (Version: 3.0.6731 - CyberLink Corp.)
Acer Arcade Deluxe (x32 Version: 3.0.6731 - CyberLink Corp.) Hidden
Acer Backup Manager (HKLM-x32\...\InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}) (Version: 2.0.0.22 - NewTech Infosystems)
Acer Crystal Eye webcam Ver:1.1.74.216 (HKLM-x32\...\{D0ACE89D-EC7F-470F-80BE-4C98ED366B32}) (Version: 1.1.74.216 - Chicony Electronics Co.,Ltd.)
Acer ePower Management (HKLM-x32\...\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 4.05.3002 - Acer Incorporated)
Acer eRecovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.05.3003 - Acer Incorporated)
Acer GameZone Console (HKLM-x32\...\{8ed9688e-4f79-4308-91ca-f1c37ca142b4}_is1) (Version: 5.1.0.2 - Oberon Media, Inc.)
Acer GridVista (HKLM-x32\...\GridVista) (Version: 3.01.0730 - Acer Inc.)
Acer Registration (HKLM-x32\...\Acer Registration) (Version: 1.02.3004 - Acer Incorporated)
Acer ScreenSaver (HKLM-x32\...\Acer Screensaver) (Version: 1.7.0715 - Acer Incorporated)
Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
Ad-Aware Antivirus (HKLM-x32\...\{944167EA-7F89-4705-8DCD-1D63B53141B0}) (Version: 10.5.3.4405 - Lavasoft)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.7.0.1530 - Adobe Systems Incorporated)
Adobe Flash Player 17 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Reader 9.5.5 MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-A91000000001}) (Version: 9.5.5 - Adobe Systems Incorporated)
Apple Application Support (HKLM-x32\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Avira (HKLM-x32\...\{b5675cc4-ab8b-4945-8c1d-4c5479556d6a}) (Version: 1.1.34.19732 - Avira Operations GmbH & Co. KG)
Avira (x32 Version: 1.1.34.19732 - Avira Operations GmbH & Co. KG) Hidden
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 15.0.8.656 - Avira)
Backup Manager Basic (x32 Version: 2.0.0.22 - NewTech Infosystems) Hidden
Bing Bar (HKLM-x32\...\{B4089055-D468-45A4-A6BA-5A138DD715FC}) (Version: 7.0.850.0 - Microsoft Corporation)
Broadcom Gigabit NetLink Controller (HKLM\...\{96F70DF8-160F-4F9C-9B9E-2A9B439B4EB9}) (Version: 12.26.02 - Broadcom Corporation)
Disneys Sport - Goofy Skateboarding (HKLM-x32\...\Disney's Extremely Goofy Skateboarding) (Version: - )
eBay Worldwide (HKLM-x32\...\{AAF89271-2594-468D-B578-96B2E30C41C4}) (Version: 2.1.0703 - OEM)
Epson Connect Printer Setup (HKLM-x32\...\{D9B1D51B-EB56-410D-AEB5-1CCFAC4B6C8C}) (Version: 1.3.0 - SEIKO EPSON CORPORATION)
Epson Easy Photo Print 2 (HKLM-x32\...\{71E90740-5E5F-4D43-AB8F-CAC1D93DBB5B}) (Version: 2.5.0.0 - SEIKO EPSON CORPORATION)
Epson Event Manager (HKLM-x32\...\{0F13C24A-FFE2-4CD0-8E0B-DC804E0A0E0B}) (Version: 3.10.0035 - Seiko Epson Corporation)
Epson E-Web Print (HKLM-x32\...\{682A3328-9621-4BAD-91FA-873A076610C4}) (Version: 1.21.0000 - SEIKO EPSON CORPORATION)
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation)
EPSON XP-225 Series Printer Uninstall (HKLM\...\EPSON XP-225 Series) (Version: - SEIKO EPSON Corporation)
EPSON-Handbücher (HKLM-x32\...\{84CECC1B-21EF-41B1-9A91-3E724E5D99D3}) (Version: 1.32.0.0 - SEIKO EPSON CORPORATION)
EpsonNet Print (HKLM\...\{DF5200AB-5AE6-4598-846B-8ABC3AE121B1}) (Version: 3.0.2.0 - SEIKO EPSON Corporation)
iCloud (HKLM\...\{81E20D41-C277-4526-934D-F2380AF91B78}) (Version: 3.1.0.40 - Apple Inc.)
Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3001 - Acer Incorporated)
Java 8 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation)
Junk Mail filter update (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Launch Manager (HKLM-x32\...\LManager) (Version: 3.0.03 - Acer Inc.)
Malwarebytes Anti-Malware Version 2.1.4.1018 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.4.1018 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Office PowerPoint Viewer 2007 (German) (HKLM-x32\...\{95120000-00AF-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Professional Edition 2003 (HKLM-x32\...\{90110407-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Office Suite Activation Assistant (HKLM-x32\...\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.9 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Sync Framework Runtime Native v1.0 (x86) (HKLM-x32\...\{8A74E887-8F0F-4017-AF53-CBA42211AAA5}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft Sync Framework Services Native v1.0 (x86) (HKLM-x32\...\{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{402ED4A1-8F5B-387A-8688-997ABF58B8F2}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Works (HKLM-x32\...\{62F7DA7E-CCCB-439C-A760-00C3926E761F}) (Version: 9.7.0621 - Microsoft Corporation)
Mozilla Firefox 37.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 37.0.1 (x86 de)) (Version: 37.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 36.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
NTI Backup Now 5 (HKLM-x32\...\InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}) (Version: 5.1.2.627 - NewTech Infosystems)
NTI Backup Now Standard (x32 Version: 5.1.2.627 - NewTech Infosystems) Hidden
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.5 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\...\{1C4551A6-4743-4093-91E4-1477CD655043}) (Version: 9.09.0203 - NVIDIA Corporation)
OkayFreedom (HKLM-x32\...\{3F3FB10C-7175-4D38-9335-3488B89C12AF}) (Version: 1.4.3 - Steganos Software GmbH)
Okey+ 2.1 (HKLM-x32\...\Okey+_is1) (Version: - Böcek Yazýlým)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5911 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7100.30093 - Realtek Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
SAMSUNG Mobile Composite Device Software (HKLM\...\SAMSUNG Mobile Composite Device) (Version: - )
Samsung Mobile Modem Device Software (HKLM\...\Samsung Mobile Modem Device) (Version: - )
SAMSUNG Mobile Modem Driver Set (HKLM\...\SAMSUNG Mobile Modem) (Version: - )
Samsung Mobile phone USB driver Drive Software (HKLM\...\Samsung Mobile phone USB driver Drive) (Version: - )
SAMSUNG Mobile USB Modem 1.0 Software (HKLM\...\SAMSUNG Mobile USB Modem 1.0) (Version: - )
SAMSUNG Mobile USB Modem Software (HKLM\...\SAMSUNG Mobile USB Modem) (Version: - )
SAMSUNG USB Mobile Device Software (HKLM\...\SAMSUNG USB Mobile Device) (Version: - )
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
Skype™ 7.2 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.2.103 - Skype Technologies S.A.)
Software Updater (HKLM-x32\...\{FA7EE274-7370-43B7-9A45-A39B17CCCDC5}) (Version: 4.3.3 - SEIKO EPSON CORPORATION)
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
VTech Download Agent Library (x32 Version: 1.00.0000 - VTech) Hidden
Welcome Center (HKLM-x32\...\Acer Welcome Center) (Version: 1.00.3005 - Acer Incorporated)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8117.0416 - Microsoft Corporation)
Windows Live ID-Anmelde-Assistent (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\...\{586509F0-350D-48B5-B763-9CC2F8D96C4C}) (Version: 14.0.8117.416 - Microsoft Corporation)
Windows Live-Uploadtool (HKLM-x32\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
==================== Restore Points =========================
04-04-2015 09:44:40 Windows Update
05-04-2015 00:22:18 Windows Update
05-04-2015 19:00:10 Windows-Sicherung
11-04-2015 23:50:37 Windows Update
12-04-2015 11:34:47 Revo Uninstaller's restore point - BoBrowser
12-04-2015 11:39:16 Revo Uninstaller's restore point - BoBrowser
12-04-2015 15:22:37 Windows Update
12-04-2015 19:19:11 Windows-Sicherung
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 04:34 - 2015-04-12 15:01 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {00249043-353C-425A-A270-D8304F2C8EAD} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {0B2D1DBB-44FA-452D-A231-B92997632E04} - \ZMCRFF No Task File <==== ATTENTION
Task: {0C6332C4-2A83-4FC4-85A4-1C4C27D1F6EF} - System32\Tasks\Ad-Aware Antivirus Scheduled Scan => C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher.exe [2013-06-13] (Lavasoft Limited)
Task: {138FE3C3-34E0-4253-AADC-A834BF454125} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [2014-06-24] (Safer-Networking Ltd.)
Task: {15946D7B-34C4-4FAF-9EBF-C9B36F57813F} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-25] (Microsoft Corporation)
Task: {1A3E4FE1-733D-4311-A064-C05602E64BC9} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {1ED94779-D16C-4CD7-BA75-ACD32DC71EA7} - System32\Tasks\{5C5454C9-4FF7-4D9B-8168-B4ADBFB532A3} => pcalua.exe -a C:\Users\EROL\AppData\Roaming\sweet-page\UninstallManager.exe -c -ptid=cor
Task: {2620644B-202A-4B6F-988C-3161F554610E} - System32\Tasks\{585D4E66-9B7D-4B34-AE74-B6C858012A68} => C:\Program Files\Batak4\Batak.exe
Task: {2F5C3C1A-E7D8-422B-8B72-067EFCB6E426} - System32\Tasks\{48C4EDAE-2B03-4D61-9031-1C6CC3104DA6} => pcalua.exe -a C:\Windows\SysWOW64\Samsung_USB_Drivers\2\SSM_Uninstall.exe
Task: {4345FB31-628A-42CA-BC8A-4DDEC2C8E12C} - System32\Tasks\{08389B0D-B0E4-49AB-B8FD-A240B4A96C43} => pcalua.exe -a C:\Windows\SysWOW64\Samsung_USB_Drivers\5\SSSDUninstall.exe
Task: {462ADBF5-7072-4715-8F00-885403D152CF} - System32\Tasks\{8FD4BD32-5AFB-4265-B8DA-333ED1CBAD08} => pcalua.exe -a C:\Users\EROL\Downloads\epson375869eu(1).exe -d C:\Users\EROL\Downloads
Task: {4CDF805B-7549-4CBE-89DA-8DE73C0BAD65} - System32\Tasks\{EB51D504-1FAC-497A-A67B-A70FBE7DB3CD} => C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher.exe [2013-06-13] (Lavasoft Limited)
Task: {50E25B8D-3A25-497D-8821-605C4CE9F525} - System32\Tasks\{1EE10A4C-0ACA-456B-B852-F923D5D0ACE6} => C:\Program Files (x86)\Microsoft Office\OFFICE11\MSACCESS.EXE [2010-01-14] (Microsoft Corporation)
Task: {5B2558E1-A057-46EC-982E-E6C2F169C161} - System32\Tasks\EPSON XP-225 Series Update {DA9064A8-56DA-49F8-8F27-85D2FF2069A9} => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSNFE.EXE [2013-11-21] (SEIKO EPSON CORPORATION)
Task: {67D15269-582C-425F-9C72-F1EC6DC12842} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [2014-06-24] (Safer-Networking Ltd.)
Task: {67DE4505-8964-4C77-80A6-6F9CFB42B4C6} - System32\Tasks\{76B6EB2E-1365-46EA-B693-530717E5371D} => pcalua.exe -a C:\Users\EROL\Downloads\5609-batak-ihaleli-tamindir.com\batak-ihaleli-tamindir.com\batak4kur.exe -d C:\Users\EROL\Downloads\5609-batak-ihaleli-tamindir.com\batak-ihaleli-tamindir.com
Task: {82461E53-52F3-4CC5-8F6D-2DD44AE1F00D} - System32\Tasks\{AA56D811-B658-40C5-BF73-83680E2BBC25} => pcalua.exe -a C:\Windows\SysWOW64\Samsung_USB_Drivers\1\SS_Uninstall.exe
Task: {89E9CC8F-583F-4631-B69C-E939243DA08A} - System32\Tasks\{77355BBA-AB49-4BC3-9494-9094B7615DEC} => pcalua.exe -a C:\Windows\SysWOW64\Samsung_USB_Drivers\7\SSECUninstall.exe
Task: {A1EB057F-80A2-425D-8970-4314C0D727F1} - System32\Tasks\{81EBBBC1-8E1F-4BCA-9A1E-99068531EEDC} => pcalua.exe -a "C:\Users\EROL\Downloads\5609-batak-ihaleli-tamindir.com (1)\batak-ihaleli-tamindir.com\batak4kur.exe" -d "C:\Users\EROL\Downloads\5609-batak-ihaleli-tamindir.com (1)\batak-ihaleli-tamindir.com"
Task: {B008D2DB-D259-4520-BEAE-D808D076818A} - System32\Tasks\{1D1FFBF9-53D2-493E-A59E-D2B647F3A5BE} => C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher.exe [2013-06-13] (Lavasoft Limited)
Task: {B0217FE0-495C-490A-BB56-79ABF62F641C} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {BE31CAA5-4A2A-42E2-9054-20CCD65D205B} - System32\Tasks\{11F68C3A-BA55-46BB-BA57-8FC636D2C17E} => C:\Program Files\Batak4\Batak.exe
Task: {C0020C13-A6BF-4CED-9194-39A192D3B0CB} - System32\Tasks\{885C3099-5D08-4F87-B40C-FC838B023C4D} => pcalua.exe -a C:\Users\EROL\AppData\Local\Temp\Temp1_batak-ihaleli-indirline.com.zip\batak-ihaleli-indirline.com\batak4kur.exe
Task: {C3704AC7-FD37-45AA-90FF-FA7478FE2EB6} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-15] (Adobe Systems Incorporated)
Task: {C49ECB39-6FD0-4A01-AACA-ABBBDFA1D846} - System32\Tasks\{6E1DF063-C740-4606-8282-1399C48D708C} => Firefox.exe
Task: {D2358CEF-B5B4-440B-A128-95F96C22F099} - System32\Tasks\{D39E6D99-9FB1-459D-9A5E-A83528C5BC81} => C:\Program Files\Batak4\Batak.exe
Task: {F0505E72-8A87-4043-BEDF-88569FB995C0} - System32\Tasks\{CF659C13-1743-4AD8-8DCD-5B70213A4392} => Firefox.exe
Task: {F4F8214F-8FD5-400A-930D-2FA7E805B268} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [2014-06-27] (Safer-Networking Ltd.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\EPSON XP-225 Series Update {DA9064A8-56DA-49F8-8F27-85D2FF2069A9}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSNFE.EXE:/EXE:{DA9064A8-56DA-49F8-8F27-85D2FF2069A9} /F:UpdateSYSTEM
Searches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
==================== Loaded Modules (whitelisted) ==============
2014-02-12 20:58 - 2014-02-12 20:58 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 14:05 - 2014-10-11 14:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2009-02-03 02:33 - 2009-02-03 02:33 - 00460199 _____ () C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\sqlite3.dll
2008-09-29 02:55 - 2008-09-29 02:55 - 01076224 _____ () C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\ACE.dll
2015-04-05 17:18 - 2014-05-13 12:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2015-04-05 17:18 - 2014-05-13 12:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2015-04-05 17:18 - 2014-05-13 12:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2015-04-05 17:18 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
2015-04-05 17:18 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll
2013-09-14 01:51 - 2013-09-14 01:51 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services\zlib1.dll
2013-09-14 01:50 - 2013-09-14 01:50 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services\libxml2.dll
2013-08-29 01:59 - 2014-12-19 06:01 - 00192376 _____ () C:\Program Files (x86)\Ad-Aware Antivirus\Definitions\libBase64.dll
2013-08-29 01:59 - 2014-12-19 06:01 - 00180088 _____ () C:\Program Files (x86)\Ad-Aware Antivirus\Definitions\libMachoUniv.dll
2015-04-15 16:37 - 2015-04-15 18:20 - 16863920 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\ProgramData\Temp:0B9176C0
AlternateDataStreams: C:\ProgramData\Temp:1D32EC29
AlternateDataStreams: C:\ProgramData\Temp:5D7E5A8F
AlternateDataStreams: C:\ProgramData\Temp:93DE1838
AlternateDataStreams: C:\ProgramData\Temp:AB689DEA
AlternateDataStreams: C:\ProgramData\Temp:ABE89FFE
AlternateDataStreams: C:\ProgramData\Temp:E1F04E8D
AlternateDataStreams: C:\ProgramData\Temp:E3C56885
AlternateDataStreams: C:\Users\EROL\AppData\Roaming\Microsoft\Windows\Start Menu\MSN Deutschland Aktuelle Nachrichten, Outlook.com Email und Skype Login..website:TASKICON_0FA6946226F21BD7E8F75BBFA031461487075638
AlternateDataStreams: C:\Users\EROL\AppData\Roaming\Microsoft\Windows\Start Menu\MSN Deutschland Aktuelle Nachrichten, Outlook.com Email und Skype Login..website:TASKICON_1FA6946226F21BD7E8F75BBFA031461135116317
AlternateDataStreams: C:\Users\EROL\AppData\Roaming\Microsoft\Windows\Start Menu\MSN Deutschland Aktuelle Nachrichten, Outlook.com Email und Skype Login..website:TASKICON_2FA6946226F21BD7E8F75BBFA03146-12823272
AlternateDataStreams: C:\Users\EROL\AppData\Roaming\Microsoft\Windows\Start Menu\MSN Deutschland Aktuelle Nachrichten, Outlook.com Email und Skype Login..website:TASKICON_3FA6946226F21BD7E8F75BBFA03146-1180859722
AlternateDataStreams: C:\Users\EROL\AppData\Roaming\Microsoft\Windows\Start Menu\MSN Deutschland Aktuelle Nachrichten, Outlook.com Email und Skype Login..website:TASKICON_4FA6946226F21BD7E8F75BBFA031461739172809
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ad-Aware Service => ""="Ad-Aware Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ad-Aware Service => ""="Ad-Aware Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MSIServer => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SBAMSvc => ""="Service"
==================== EXE Association (whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1924032147-3410277532-354269451-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\EROL\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.178.1
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\Services: Avira.OE.ServiceHost => 2
MSCONFIG\startupfolder: C:^Users^EROL^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^setup.lnk => C:\Windows\pss\setup.lnk.Startup
MSCONFIG\startupfolder: C:^Users^EROL^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^SuperOptimizer.lnk => C:\Windows\pss\SuperOptimizer.lnk.Startup
MSCONFIG\startupreg: Elite Unzip AppIntegrator 32-bit => C:\PROGRA~2\ELITEU~2\bar\1.bin\AppIntegrator.exe
MSCONFIG\startupreg: Elite Unzip AppIntegrator 64-bit => C:\PROGRA~2\ELITEU~2\bar\1.bin\AppIntegrator64.exe
MSCONFIG\startupreg: PLFSetI => C:\Windows\PLFSetI.exe
MSCONFIG\startupreg: Registry Helper => "C:\Program Files (x86)\Registry Helper\RegistryHelper.Exe" /boot
==================== Accounts: =============================
Administrator (S-1-5-21-1924032147-3410277532-354269451-500 - Administrator - Disabled)
EROL (S-1-5-21-1924032147-3410277532-354269451-1001 - Administrator - Enabled) => C:\Users\EROL
Gast (S-1-5-21-1924032147-3410277532-354269451-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1924032147-3410277532-354269451-1002 - Limited - Enabled)
==================== Faulty Device Manager Devices =============
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (04/15/2015 06:40:24 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1". Fehler in Manifest- oder Richtliniendatei "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2" in Zeile WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".
Definition: WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
Error: (04/15/2015 06:40:23 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1".
Die abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (04/15/2015 06:40:22 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1".
Die abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (04/15/2015 06:40:22 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1".
Die abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (04/15/2015 06:40:22 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1".
Die abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (04/15/2015 06:17:29 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1". Fehler in Manifest- oder Richtliniendatei "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2" in Zeile WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".
Definition: WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
Error: (04/15/2015 06:17:28 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1".
Die abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (04/15/2015 06:17:28 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1".
Die abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (04/15/2015 06:17:28 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1".
Die abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (04/15/2015 06:17:28 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1".
Die abhängige Assemblierung "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
System errors:
=============
Error: (04/15/2015 04:50:00 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Das System wurde zuvor am 15.04.2015 um 16:48:34 unerwartet heruntergefahren.
Microsoft Office Sessions:
=========================
Error: (04/15/2015 06:40:24 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1"C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.ExeC:\Program Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL8
Error: (04/15/2015 06:40:23 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"c:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\WksWP.exe
Error: (04/15/2015 06:40:22 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\wksss.exe
Error: (04/15/2015 06:40:22 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"c:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\WksCal.exe
Error: (04/15/2015 06:40:22 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"c:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\wksdb.exe
Error: (04/15/2015 06:17:29 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1"C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.ExeC:\Program Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL8
Error: (04/15/2015 06:17:28 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"c:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\WksWP.exe
Error: (04/15/2015 06:17:28 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"C:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\wksss.exe
Error: (04/15/2015 06:17:28 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"c:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\WksCal.exe
Error: (04/15/2015 06:17:28 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"c:\Windows\Installer\{62F7DA7E-CCCB-439C-A760-00C3926E761F}\wksdb.exe
==================== Memory info ===========================
Processor: Intel(R) Core(TM)2 Duo CPU T6600 @ 2.20GHz
Percentage of memory in use: 56%
Total physical RAM: 4090.93 MB
Available physical RAM: 1775.91 MB
Total Pagefile: 8180.04 MB
Available Pagefile: 5400.62 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB
==================== Drives ================================
Drive c: (ACER) (Fixed) (Total:453.94 GB) (Free:384.52 GB) NTFS ==>[System with boot components (obtained from reading drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: 5CAE5CAE)
Partition 1: (Not Active) - (Size=11.7 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=453.9 GB) - (Type=07 NTFS)
==================== End Of Log ============================ |