mausi1987 | 25.12.2013 11:26 | Morgen,
vielen Dank für die schnelle Antwort :daumenhoc stimmt hab ganz vergessen zu schreiben, dass ich eine 32-bit Version hab...
hab den scan gemacht....dabei kam leider gleich eine Fehlermeldung :( ... hier ein bild davon http://img5.fotos-hochladen.net/uplo...qiwzkupb89.jpg
hier die log Dateien:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 23-12-2013 01
Ran by Vera (administrator) on ENVY on 25-12-2013 11:04:12
Running from C:\Users\Vera\Downloads
Microsoft Windows 8.1 (X86) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgrsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgcsrvx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Sphinx Software) C:\Program Files\Windows7FirewallControl\Windows7FirewallService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgwdsvc.exe
(Intel Corporation) C:\Windows\System32\DptfParticipantDisplayService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel Corporation) C:\Windows\System32\DptfParticipantProcessorService.exe
(Intel Corporation) C:\Windows\System32\DptfPolicyCriticalService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgnsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgemcx.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(AnVir Software) C:\Program Files\AnVir Task Manager\AnVir.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20315_x86__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
(Microsoft Corporation) C:\Windows\System32\RuntimeBroker.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\AP\RtkNGUI.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgui.exe
(Sphinx Software) C:\Program Files\Windows7FirewallControl\Windows7FirewallControl.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Microsoft Corporation) C:\Windows\WinStore\WSHost.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Reader_6.3.9600.16422_x86__8wekyb3d8bbwe\glcnd.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Microsoft Corporation) C:\Windows\System32\ThumbnailExtractionHost.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtkNGUI] - C:\Program Files\Realtek\Audio\AP\RtkNGUI.exe [2644624 2013-08-12] (Realtek Semiconductor)
HKLM\...\Run: [AVG_UI] - C:\Program Files\AVG\AVG2014\avgui.exe [4956176 2013-11-07] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [Windows7FirewallControl] - C:\Program Files\Windows7FirewallControl\Windows7FirewallControl.exe [806912 2012-09-21] (Sphinx Software)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2440944 2013-08-12] (Synaptics Incorporated)
HKLM\...\Run: [DptfPolicyLpmServiceHelper] - C:\Windows\System32\DptfPolicyLpmServiceHelper.exe [65536 2013-08-12] (Intel Corporation)
HKLM\...\RunOnce: [NCPluginUpdater] - "c:\program files\hewlett-packard\hp health check\activecheck\product_line\NCPluginUpdater.exe" Update [21720 2013-12-12] (Hewlett-Packard)
HKCU\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\DefaultAppPool\...\RunOnce: [WAB Migrate] - C:\Program Files\Windows Mail\wab.exe [ 2013-08-22] (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://t.hp13.de.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_TIMESTAMP = 0x69BC7EE69DE8CE01
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {9738F719-F1B1-44B7-A0DB-391B4A01DFEB} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKCU - DefaultScope {CF59A579-B6EA-41AE-A82C-0C6522D8FFC1} URL = hxxp://search.softonic.com/MOY00621/tb_v1?q={searchTerms}&SearchSource=4&cc=&mi=f0f07445000000000000f6b7e20a6491&r=62
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKCU - {9738F719-F1B1-44B7-A0DB-391B4A01DFEB} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKCU - {CF59A579-B6EA-41AE-A82C-0C6522D8FFC1} URL = hxxp://search.softonic.com/MOY00621/tb_v1?q={searchTerms}&SearchSource=4&cc=&mi=f0f07445000000000000f6b7e20a6491&r=62
SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
BHO: PassShow - {2d661e5b-7d7a-417c-b5b5-6479017bb314} - C:\Program Files\PassShow\150.dll ()
BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\4z8phjxb.default
FF Plugin: @adobe.com/ShockwavePlayer - C:\windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: PutLocker Downloader - C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\4z8phjxb.default\Extensions\ptl@ptl.com.xpi
FF HKCU\...\Firefox\Extensions: [{57c20073-e24b-4b2a-aa91-70d1ad526cbf}] - C:\Program Files\PassShow\150.xpi
FF Extension: No Name - C:\Program Files\PassShow\150.xpi
FF Extension: No Name - C:\Program Files\PassShow\150.xpi
========================== Services (Whitelisted) =================
R2 AVGIDSAgent; C:\Program Files\AVG\AVG2014\avgidsagent.exe [3478544 2013-11-11] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\AVG2014\avgwdsvc.exe [348008 2013-09-24] (AVG Technologies CZ, s.r.o.)
S2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [1678040 2013-12-17] (Broadcom Corporation.)
S3 BstHdAndroidSvc; C:\Program Files\BlueStacks\HD-Service.exe [393032 2013-07-04] (BlueStack Systems, Inc.)
S3 BstHdLogRotatorSvc; C:\Program Files\BlueStacks\HD-LogRotatorService.exe [384840 2013-07-04] (BlueStack Systems, Inc.)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [248320 2013-08-22] (Microsoft Corporation)
R2 DptfParticipantDisplayService; C:\Windows\system32\DptfParticipantDisplayService.exe [97792 2013-08-12] (Intel Corporation)
R2 DptfParticipantProcessorService; C:\Windows\system32\DptfParticipantProcessorService.exe [69632 2013-08-12] (Intel Corporation)
R2 DptfPolicyCriticalService; C:\Windows\system32\DptfPolicyCriticalService.exe [56832 2013-08-12] (Intel Corporation)
S2 DptfPolicyLpmService; C:\Windows\system32\DptfPolicyLpmService.exe [76288 2013-08-12] (Intel Corporation)
S2 H2OWTBSRV; C:\Program Files\Insyde Soware\Services\H2OWTB.exe [408576 2012-10-22] (Insyde Software Corp.)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 MuteLEDService; C:\Program Files\Pegatron\MuteLED\MuteLEDService.exe [15872 2012-08-07] (Pegatron Corp.)
S3 ScDeviceEnum; C:\Windows\System32\ScDeviceEnum.dll [105472 2013-08-22] (Microsoft Corporation)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [66560 2013-10-19] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [278264 2013-08-22] (Microsoft Corporation)
S3 WEPHOSTSVC; C:\Windows\system32\wephostsvc.dll [20992 2013-08-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [22240 2013-08-22] (Microsoft Corporation)
R2 Windows7FirewallService; C:\Program Files\Windows7FirewallControl\Windows7FirewallService.exe [491520 2012-09-21] (Sphinx Software)
S2 WiseBootAssistant; C:\Program Files\Wise\Wise Care 365\BootTime.exe [580232 2013-12-09] (WiseCleaner.com)
S3 workfolderssvc; C:\Windows\system32\workfolderssvc.dll [1210368 2013-10-22] (Microsoft Corporation)
U3 楗敳潂瑯獁楳瑳湡t; 㩃停潲牧浡䘠汩獥坜獩履楗敳䌠牡㘳尵潂瑯楔敭攮數吀Ķ" [x]
==================== Drivers (Whitelisted) ====================
S0 Avgbootx; C:\Windows\System32\DRIVERS\avgbootx.sys [17424 2013-09-04] (AVG Technologies CZ, s.r.o.)
R1 Avgdiskx; C:\Windows\System32\DRIVERS\avgdiskx.sys [120600 2013-11-05] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [209176 2013-11-04] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [147768 2013-10-24] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\Windows\system32\DRIVERS\avgidsshimw8x.sys [22840 2013-09-17] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [176952 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [222520 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [102712 2013-10-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [27448 2013-09-10] (AVG Technologies CZ, s.r.o.)
R1 Avgwfpx; C:\Windows\system32\DRIVERS\avgwfpx.sys [196920 2013-10-21] (AVG Technologies CZ, s.r.o.)
R1 BasicRender; C:\Windows\System32\drivers\BasicRender.sys [25600 2013-08-22] (Microsoft Corporation)
R3 BcmNfcIc; C:\Windows\System32\drivers\BcmNfcIc.sys [67352 2013-03-30] (Broadcom Corporation.)
R3 BCMSDH43XX; C:\Windows\system32\DRIVERS\bcmdhd63.sys [519344 2013-08-12] (Broadcom)
R2 BstHdDrv; C:\Program Files\BlueStacks\HD-Hypervisor-x86.sys [63816 2013-07-04] (BlueStack Systems)
S3 BthA2DP; C:\Windows\system32\drivers\BthA2DP.sys [107648 2013-08-22] (Microsoft Corporation)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [185856 2013-08-22] (Microsoft Corporation)
R3 BthMini; C:\Windows\System32\Drivers\BTHMINI.sys [24064 2013-08-22] (Microsoft Corporation)
S3 btwampfl; C:\Windows\System32\drivers\btwampfl.sys [144600 2013-12-17] (Broadcom Corporation.)
R3 BtwSerialBus; C:\Windows\System32\drivers\BtwSerialBus.sys [130776 2013-12-17] (Broadcom Corporation.)
R3 camera; C:\Windows\system32\DRIVERS\camera.sys [202752 2013-08-12] (Intel Corporation)
R0 ChaabiDriver; C:\Windows\System32\drivers\ChaabiDriver.sys [73232 2013-08-12] (Intel Corporation)
R0 clvpep; C:\Windows\System32\drivers\clvpep.sys [81648 2013-08-12] (Intel Corporation)
R3 DptfDevDisplay; C:\Windows\System32\drivers\DptfDevDisplay.sys [35840 2013-08-12] (Intel Corporation)
R3 DptfDevGen; C:\Windows\System32\drivers\DptfDevGen.sys [41472 2013-08-12] (Intel Corporation)
R3 DptfDevProc; C:\Windows\System32\drivers\DptfDevProc.sys [60928 2013-08-12] (Intel Corporation)
R3 DptfManager; C:\Windows\System32\drivers\DptfManager.sys [155136 2013-08-12] (Intel Corporation)
S3 GPIO; C:\Windows\System32\drivers\iaiogpio.sys [22016 2013-07-23] (Intel Corporation)
R3 GPIOCLV; C:\Windows\System32\drivers\GPIOCLV.sys [22016 2013-08-12] (Intel Corporation)
S3 GpioVirtual; C:\Windows\System32\drivers\GpioVirtual.sys [11264 2012-09-17] (Windows (R) Win 7 DDK provider)
R3 igdperf32; C:\Windows\system32\DRIVERS\igdperf32.sys [4096 2013-09-04] ()
S3 imx175; C:\Windows\System32\drivers\imx175.sys [57344 2013-01-08] (Intel Corporation)
R0 inteli2c; C:\Windows\System32\drivers\inteli2c.sys [48880 2013-08-12] (Intel Corporation)
R3 IntelSST; C:\Windows\system32\drivers\isstrtc.sys [240640 2013-08-12] (Intel(R) Corporation)
R3 ISCIRSA; C:\Program Files\Insyde Soware\Services\H2OWTB.bin [12896 2012-09-18] (Windows (R) Win 7 DDK provider)
R0 Lm3554; C:\Windows\System32\drivers\lm3554.sys [34816 2013-08-12] (Intel Corporation)
R0 LNWIPC; C:\Windows\System32\drivers\LNWIPC.sys [25840 2013-08-12] (Intel Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R0 MBI; C:\Windows\System32\drivers\MBI.sys [16112 2013-08-12] (Intel Corporation)
R3 MSICReg; C:\Windows\System32\drivers\MSICReg.sys [17408 2013-08-12] (Intel Corporation)
R3 ov2720; C:\Windows\System32\drivers\ov2720.sys [44544 2013-08-12] (Intel Corporation)
R3 ov8830; C:\Windows\System32\drivers\ov8830.sys [61952 2013-08-12] (Intel Corporation)
R3 rtii2sac; C:\Windows\system32\DRIVERS\rtii2sac.sys [130560 2013-08-12] (Realtek Semiconductor Corp.)
R3 SensorsHIDClassDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [187392 2013-08-22] (Microsoft Corporation)
R3 SensorsServiceDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [187392 2013-08-22] (Microsoft Corporation)
R3 spi; C:\Windows\System32\drivers\spi.sys [46592 2013-08-12] (Intel Corporation)
R3 SynRMIHID; C:\Windows\System32\drivers\SynRMIHID.sys [35056 2013-08-12] (Synaptics Incorporated)
R3 Uart16550pc; C:\Windows\System32\drivers\Uart16550pc.sys [40960 2013-08-12] (Intel Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [93024 2013-08-22] (Microsoft Corporation)
R3 WUDFSensorLP; C:\Windows\system32\DRIVERS\WUDFRd.sys [187392 2013-08-22] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-12-25 11:02 - 2013-12-25 11:03 - 00024399 _____ C:\Users\Vera\Downloads\Addition.txt
2013-12-25 11:00 - 2013-12-25 11:05 - 00016397 _____ C:\Users\Vera\Downloads\FRST.txt
2013-12-25 11:00 - 2013-12-25 11:00 - 00000000 ____D C:\FRST
2013-12-25 10:58 - 2013-12-25 10:59 - 01061545 _____ (Farbar) C:\Users\Vera\Downloads\FRST.exe
2013-12-25 10:51 - 2013-12-25 11:04 - 00020290 _____ C:\WINDOWS\WindowsUpdate.log
2013-12-25 10:51 - 2013-12-25 10:53 - 00358080 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-12-25 10:49 - 2013-12-25 10:49 - 00000000 _____ C:\WINDOWS\setuperr.log
2013-12-25 10:49 - 2013-12-25 10:49 - 00000000 _____ C:\WINDOWS\setupact.log
2013-12-24 23:26 - 2013-12-24 23:26 - 00001079 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-24 23:26 - 2013-12-24 23:26 - 00000000 ____D C:\Users\Vera\AppData\Roaming\Malwarebytes
2013-12-24 23:26 - 2013-12-24 23:26 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-24 23:26 - 2013-12-24 23:26 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-12-24 23:26 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2013-12-24 23:25 - 2013-12-24 23:25 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Vera\Downloads\mbam-setup-1.75.0.1300.exe
2013-12-24 23:07 - 2013-12-24 23:09 - 00000000 ____D C:\AdwCleaner
2013-12-24 23:05 - 2013-12-24 23:05 - 01233962 _____ C:\Users\Vera\Downloads\adwcleaner_3.016.exe
2013-12-24 22:07 - 2013-12-25 10:54 - 00000328 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-24 18:20 - 2013-12-24 18:20 - 00000000 ____D C:\Users\Vera\Documents\Podcast Studio
2013-12-24 18:19 - 2013-12-24 18:19 - 00000000 ____D C:\Users\Vera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\concept design
2013-12-24 18:19 - 2013-12-24 18:19 - 00000000 ____D C:\Program Files\concept design
2013-12-24 18:17 - 2013-12-24 18:20 - 00000000 ____D C:\Users\Vera\Documents\onlineTV 8
2013-12-24 18:17 - 2013-12-24 18:20 - 00000000 ____D C:\Users\Vera\AppData\Roaming\concept design
2013-12-24 18:17 - 2013-12-24 18:17 - 00000000 ____D C:\Users\Vera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FRANZIS
2013-12-24 18:17 - 2013-12-24 18:17 - 00000000 ____D C:\Program Files\FRANZIS
2013-12-24 18:17 - 2012-03-01 11:08 - 00966144 _____ (Online Media Technologies Ltd.) C:\WINDOWS\system32\NCTAudioInformation2.dll
2013-12-24 18:17 - 2012-03-01 11:08 - 00877568 _____ (NCT Company Ltd.) C:\WINDOWS\system32\NCTAudioFile2.dll
2013-12-24 18:17 - 2012-03-01 11:08 - 00634880 _____ (Online Media Technologies Ltd.) C:\WINDOWS\system32\NCTAudioEditor2.dll
2013-12-24 18:17 - 2012-03-01 11:08 - 00522752 _____ (Online Media Technologies Ltd.) C:\WINDOWS\system32\NCTAudioTransform2.dll
2013-12-24 18:17 - 2012-03-01 11:08 - 00467968 _____ (Online Media Technologies Ltd.) C:\WINDOWS\system32\NCTAudioRecord2.dll
2013-12-24 18:17 - 2012-03-01 11:08 - 00467456 _____ (Online Media Technologies Ltd.) C:\WINDOWS\system32\NCTAudioPlayer2.dll
2013-12-24 18:17 - 2012-03-01 11:08 - 00307200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr70.dll
2013-12-24 18:17 - 2012-02-11 21:07 - 00413696 _____ (Gabest) C:\WINDOWS\system32\flvsplitter.ax
2013-12-24 18:17 - 2011-03-29 12:52 - 00962560 _____ (East Wind Software) C:\WINDOWS\system32\advdaudio.ocx
2013-12-24 18:17 - 2011-03-29 12:52 - 00110080 _____ C:\WINDOWS\system32\advd.dll
2013-12-24 18:17 - 2011-03-29 12:52 - 00023040 _____ C:\WINDOWS\system32\auth.dll
2013-12-24 18:17 - 2003-08-07 14:01 - 00237568 _____ C:\WINDOWS\system32\lame_enc.dll
2013-12-24 17:02 - 2013-12-24 17:02 - 00000000 ____D C:\Program Files\ESET
2013-12-24 15:48 - 2013-12-24 15:48 - 25335488 _____ C:\Users\Vera\Downloads\OnlineTV8-worldwide_CHIP-Adventskalender.exe
2013-12-23 23:04 - 2013-12-23 23:04 - 00000000 ____D C:\Program Files\PassShow
2013-12-23 22:54 - 2013-12-23 22:54 - 00001262 _____ C:\Users\Public\Desktop\Wise Program Uninstaller.lnk
2013-12-23 22:26 - 2013-12-23 22:26 - 00000406 _____ C:\WINDOWS\Tasks\Wise Care 365.job
2013-12-23 22:26 - 2013-12-23 22:26 - 00000386 _____ C:\WINDOWS\Tasks\Wise Turbo Checker.job
2013-12-23 20:27 - 2013-12-25 10:56 - 00000000 ____D C:\Users\Vera\AppData\Roaming\Wise Care 365
2013-12-23 20:27 - 2013-12-23 22:54 - 00000000 ____D C:\Program Files\Wise
2013-12-23 20:27 - 2013-12-23 20:27 - 00001130 _____ C:\Users\Public\Desktop\Wise Care 365.lnk
2013-12-23 20:26 - 2013-12-23 20:26 - 08072536 _____ (WiseCleaner.com ) C:\Users\Vera\Downloads\WiseCare365292_CHIP.exe
2013-12-21 22:25 - 2013-12-21 23:09 - 00000000 ____D C:\Users\Vera\AppData\Roaming\vlc
2013-12-21 22:25 - 2013-12-21 22:25 - 00001040 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-12-21 22:24 - 2013-12-21 22:24 - 00000000 ____D C:\Program Files\VideoLAN
2013-12-17 22:47 - 2013-12-17 22:47 - 01678040 _____ (Broadcom Corporation.) C:\WINDOWS\system32\BtwRSupportService.exe
2013-12-17 22:47 - 2013-12-17 22:47 - 00144600 _____ (Broadcom Corporation.) C:\WINDOWS\system32\Drivers\btwampfl.sys
2013-12-17 22:47 - 2013-12-17 22:47 - 00130776 _____ (Broadcom Corporation.) C:\WINDOWS\system32\Drivers\BtwSerialBus.sys
2013-12-17 22:47 - 2013-12-17 22:47 - 00060120 _____ (Broadcom Corporation.) C:\WINDOWS\system32\btwdi.dll
2013-12-17 00:02 - 2013-11-12 00:41 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2013-12-17 00:02 - 2013-11-12 00:27 - 00701440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2013-12-17 00:02 - 2013-11-11 01:50 - 00036696 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys
2013-12-17 00:02 - 2013-11-09 11:54 - 00261464 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2013-12-17 00:02 - 2013-11-09 06:56 - 01391104 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe
2013-12-17 00:02 - 2013-11-08 09:40 - 00244736 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2013-12-17 00:02 - 2013-11-08 05:26 - 11674624 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2013-12-17 00:02 - 2013-11-08 05:15 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2013-12-17 00:02 - 2013-11-08 04:51 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbici.dll
2013-12-17 00:02 - 2013-11-08 04:30 - 01128448 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2013-12-17 00:02 - 2013-11-08 04:05 - 00734208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2013-12-17 00:02 - 2013-11-05 15:08 - 00478720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2013-12-17 00:02 - 2013-11-05 14:57 - 00479744 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2013-12-17 00:02 - 2013-11-05 14:33 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2013-12-17 00:02 - 2013-11-04 06:52 - 01307480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2013-12-17 00:02 - 2013-11-04 06:52 - 00320856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2013-12-17 00:02 - 2013-11-04 03:28 - 01816576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll
2013-12-17 00:02 - 2013-11-04 02:30 - 01765376 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2013-12-17 00:02 - 2013-11-04 01:45 - 02038784 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
2013-12-17 00:02 - 2013-11-01 11:17 - 00077144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2013-12-17 00:02 - 2013-11-01 06:57 - 00544768 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcli.dll
2013-12-17 00:02 - 2013-10-31 00:50 - 05753688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2013-12-17 00:02 - 2013-10-31 00:39 - 01381184 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2013-12-17 00:02 - 2013-10-31 00:39 - 01270640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2013-12-17 00:02 - 2013-10-31 00:39 - 01261320 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2013-12-17 00:02 - 2013-10-31 00:39 - 01159080 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2013-12-17 00:02 - 2013-10-26 21:28 - 00120152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\SerCx2.sys
2013-12-17 00:02 - 2013-10-24 10:12 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredentialMigrationHandler.dll
2013-12-17 00:02 - 2013-10-17 11:36 - 02266624 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2013-12-17 00:02 - 2013-10-05 13:05 - 01765384 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2013-12-17 00:02 - 2013-10-05 13:05 - 00406400 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2013-12-15 15:17 - 2013-11-23 05:13 - 00348160 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPhoto.dll
2013-12-15 15:17 - 2013-11-23 04:30 - 03423232 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll
2013-12-15 15:17 - 2013-11-23 04:11 - 00463360 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe
2013-12-15 15:17 - 2013-11-09 06:52 - 00485888 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAgent.exe
2013-12-15 15:17 - 2013-11-09 06:52 - 00240128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2013-12-15 11:27 - 2013-12-15 11:27 - 00017408 ___SH C:\Users\Vera\Documents\Thumbs.db
2013-12-15 11:18 - 2013-12-23 23:06 - 00000000 ____D C:\Users\Vera\AppData\Roaming\ChemTable Software
2013-12-15 11:18 - 2013-12-23 23:06 - 00000000 ____D C:\Users\Vera\AppData\Local\ChemTable Software
2013-12-15 11:17 - 2013-12-15 12:58 - 00000000 ____D C:\Users\Vera\AppData\Local\AnVir
2013-12-15 11:17 - 2013-12-15 11:17 - 09062640 _____ C:\Users\Vera\Downloads\AnVirTaskManager.exe
2013-12-15 11:17 - 2013-12-15 11:17 - 00001052 _____ C:\Users\Vera\AppData\Roaming\Microsoft\Windows\Start Menu\AnVir Task Manager.lnk
2013-12-15 11:17 - 2013-12-15 11:17 - 00001028 _____ C:\Users\Vera\Desktop\AnVir Task Manager.lnk
2013-12-15 11:17 - 2013-12-15 11:17 - 00000000 ____D C:\Users\Vera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVir Task Manager
2013-12-15 11:17 - 2013-12-15 11:17 - 00000000 ____D C:\Program Files\AnVir Task Manager
2013-12-13 18:59 - 2013-11-08 07:19 - 03494400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2013-12-13 18:56 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2013-12-13 18:56 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2013-12-13 18:56 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2013-12-13 18:56 - 2013-11-26 09:13 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2013-12-13 18:56 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2013-12-13 18:56 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2013-12-13 18:56 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2013-12-13 18:56 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2013-12-13 18:56 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2013-12-13 18:55 - 2013-10-19 08:14 - 00070680 _____ (Microsoft Corporation) C:\WINDOWS\system32\imagehlp.dll
2013-12-13 18:48 - 2013-10-15 09:03 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrrun.dll
2013-12-13 18:25 - 2013-12-13 17:59 - 00020103 ____R C:\Users\Vera\Documents\2013_Adventsgewinnspiele.ods
2013-12-10 22:00 - 2013-12-15 14:44 - 00000000 _____ C:\WINDOWS\system32\scurlcache.bin
2013-12-09 19:51 - 2013-12-16 21:31 - 00000000 ____D C:\Program Files\Norman
2013-12-09 19:32 - 2013-12-05 14:16 - 292128108 _____ C:\Users\Vera\Desktop\tag05_32bitnorman.zip
2013-12-08 20:07 - 2013-12-08 20:07 - 00000000 ____D C:\Users\Vera\AppData\Roaming\Boomzap
2013-12-08 18:57 - 2013-12-08 20:02 - 473814458 _____ C:\Users\Vera\Downloads\Death at Cape Porto - A Dana Knightstone Novel CE (1).rar
2013-12-08 18:41 - 2013-12-08 18:41 - 00000000 ____D C:\Users\Vera\AppData\Roaming\casualArts
2013-12-08 18:41 - 2013-12-08 18:41 - 00000000 ____D C:\ProgramData\casualArts
2013-12-08 18:27 - 2013-12-08 18:39 - 00000000 ____D C:\WINDOWS\Christmas Wonderland 4
2013-12-08 18:27 - 2013-12-08 18:39 - 00000000 ____D C:\Program Files\Christmas Wonderland 4
2013-12-08 18:04 - 2013-12-08 20:03 - 1439777004 _____ C:\Users\Vera\Downloads\Nancy Drew 29 - The Silent Spy.rar
2013-12-08 17:55 - 2013-12-08 18:33 - 139867357 _____ C:\Users\Vera\Downloads\Christmas Wonderland 4.rar
2013-12-08 11:43 - 2013-12-08 11:45 - 00000000 ____D C:\Users\Vera\Downloads\PC Welt backup
2013-12-08 11:40 - 2013-12-08 11:42 - 00000000 ___HD C:\ProgramData\sysnfxo
2013-12-08 11:39 - 2013-12-08 11:39 - 00000000 ____D C:\ProgramData\PC-WELT Backup Easy
2013-12-06 17:16 - 2013-12-06 17:17 - 24979036 _____ C:\Users\Vera\Downloads\tag06backup.zip
2013-12-02 20:11 - 2013-12-02 20:11 - 04978424 _____ (EaseUS ) C:\Users\Vera\Downloads\EaseUSDataRecoveryWizardPro-7.0.exe
2013-12-01 22:03 - 2013-12-01 22:04 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-26 20:49 - 2013-11-26 20:48 - 00014136 _____ (Hewlett-Packard Development Company, L.P.) C:\WINDOWS\system32\Drivers\SP63665.dll
==================== One Month Modified Files and Folders =======
2013-12-25 11:05 - 2013-12-25 11:00 - 00016397 _____ C:\Users\Vera\Downloads\FRST.txt
2013-12-25 11:04 - 2013-12-25 10:51 - 00020290 _____ C:\WINDOWS\WindowsUpdate.log
2013-12-25 11:03 - 2013-12-25 11:02 - 00024399 _____ C:\Users\Vera\Downloads\Addition.txt
2013-12-25 11:00 - 2013-12-25 11:00 - 00000000 ____D C:\FRST
2013-12-25 11:00 - 2013-10-19 20:40 - 00000000 ____D C:\Users\Vera
2013-12-25 11:00 - 2013-10-19 20:39 - 02014084 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-12-25 11:00 - 2013-08-22 09:17 - 00000000 ____D C:\WINDOWS\system32\sru
2013-12-25 11:00 - 2013-07-15 19:51 - 00000326 _____ C:\WINDOWS\Tasks\HPCeeScheduleForVera.job
2013-12-25 10:59 - 2013-12-25 10:58 - 01061545 _____ (Farbar) C:\Users\Vera\Downloads\FRST.exe
2013-12-25 10:59 - 2013-07-14 09:11 - 00000000 ____D C:\ProgramData\MFAData
2013-12-25 10:59 - 2013-07-13 17:34 - 00000627 _____ C:\WINDOWS\system32\DOErrors.log
2013-12-25 10:59 - 2013-07-13 17:34 - 00000000 _____ C:\WINDOWS\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2013-12-25 10:56 - 2013-12-23 20:27 - 00000000 ____D C:\Users\Vera\AppData\Roaming\Wise Care 365
2013-12-25 10:55 - 2013-10-19 21:05 - 00000000 __RDO C:\Users\Vera\SkyDrive
2013-12-25 10:54 - 2013-12-24 22:07 - 00000328 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-25 10:53 - 2013-12-25 10:51 - 00358080 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-12-25 10:53 - 2013-08-22 08:23 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-12-25 10:49 - 2013-12-25 10:49 - 00000000 _____ C:\WINDOWS\setuperr.log
2013-12-25 10:49 - 2013-12-25 10:49 - 00000000 _____ C:\WINDOWS\setupact.log
2013-12-25 06:37 - 2013-07-20 14:22 - 00000000 ____D C:\Program Files\Google
2013-12-24 23:26 - 2013-12-24 23:26 - 00001079 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-24 23:26 - 2013-12-24 23:26 - 00000000 ____D C:\Users\Vera\AppData\Roaming\Malwarebytes
2013-12-24 23:26 - 2013-12-24 23:26 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-24 23:26 - 2013-12-24 23:26 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-12-24 23:26 - 2013-10-28 23:28 - 00061952 ___SH C:\Users\Vera\Desktop\Thumbs.db
2013-12-24 23:25 - 2013-12-24 23:25 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Vera\Downloads\mbam-setup-1.75.0.1300.exe
2013-12-24 23:10 - 2013-08-22 07:13 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2013-12-24 23:09 - 2013-12-24 23:07 - 00000000 ____D C:\AdwCleaner
2013-12-24 23:05 - 2013-12-24 23:05 - 01233962 _____ C:\Users\Vera\Downloads\adwcleaner_3.016.exe
2013-12-24 22:04 - 2013-08-22 07:13 - 39059456 _____ C:\WINDOWS\system32\config\SOFTWARE.bak
2013-12-24 22:04 - 2013-08-22 07:13 - 00237568 _____ C:\WINDOWS\system32\config\DEFAULT.bak
2013-12-24 22:04 - 2013-08-22 07:13 - 00028672 _____ C:\WINDOWS\system32\config\SAM.bak
2013-12-24 22:04 - 2013-08-22 07:13 - 00024576 _____ C:\WINDOWS\system32\config\SECURITY.bak
2013-12-24 21:36 - 2013-08-22 09:17 - 00000000 ____D C:\WINDOWS\Microsoft.NET
2013-12-24 18:34 - 2013-08-22 09:17 - 00000000 ____D C:\WINDOWS\AppReadiness
2013-12-24 18:20 - 2013-12-24 18:20 - 00000000 ____D C:\Users\Vera\Documents\Podcast Studio
2013-12-24 18:20 - 2013-12-24 18:17 - 00000000 ____D C:\Users\Vera\Documents\onlineTV 8
2013-12-24 18:20 - 2013-12-24 18:17 - 00000000 ____D C:\Users\Vera\AppData\Roaming\concept design
2013-12-24 18:19 - 2013-12-24 18:19 - 00000000 ____D C:\Users\Vera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\concept design
2013-12-24 18:19 - 2013-12-24 18:19 - 00000000 ____D C:\Program Files\concept design
2013-12-24 18:17 - 2013-12-24 18:17 - 00000000 ____D C:\Users\Vera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FRANZIS
2013-12-24 18:17 - 2013-12-24 18:17 - 00000000 ____D C:\Program Files\FRANZIS
2013-12-24 17:02 - 2013-12-24 17:02 - 00000000 ____D C:\Program Files\ESET
2013-12-24 15:48 - 2013-12-24 15:48 - 25335488 _____ C:\Users\Vera\Downloads\OnlineTV8-worldwide_CHIP-Adventskalender.exe
2013-12-23 23:06 - 2013-12-15 11:18 - 00000000 ____D C:\Users\Vera\AppData\Roaming\ChemTable Software
2013-12-23 23:06 - 2013-12-15 11:18 - 00000000 ____D C:\Users\Vera\AppData\Local\ChemTable Software
2013-12-23 23:04 - 2013-12-23 23:04 - 00000000 ____D C:\Program Files\PassShow
2013-12-23 22:54 - 2013-12-23 22:54 - 00001262 _____ C:\Users\Public\Desktop\Wise Program Uninstaller.lnk
2013-12-23 22:54 - 2013-12-23 20:27 - 00000000 ____D C:\Program Files\Wise
2013-12-23 22:26 - 2013-12-23 22:26 - 00000406 _____ C:\WINDOWS\Tasks\Wise Care 365.job
2013-12-23 22:26 - 2013-12-23 22:26 - 00000386 _____ C:\WINDOWS\Tasks\Wise Turbo Checker.job
2013-12-23 20:29 - 2013-10-19 21:36 - 00000000 ___DC C:\WINDOWS\Panther
2013-12-23 20:27 - 2013-12-23 20:27 - 00001130 _____ C:\Users\Public\Desktop\Wise Care 365.lnk
2013-12-23 20:26 - 2013-12-23 20:26 - 08072536 _____ (WiseCleaner.com ) C:\Users\Vera\Downloads\WiseCare365292_CHIP.exe
2013-12-22 11:26 - 2013-08-22 09:17 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2013-12-21 23:09 - 2013-12-21 22:25 - 00000000 ____D C:\Users\Vera\AppData\Roaming\vlc
2013-12-21 22:25 - 2013-12-21 22:25 - 00001040 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-12-21 22:24 - 2013-12-21 22:24 - 00000000 ____D C:\Program Files\VideoLAN
2013-12-21 21:27 - 2013-08-22 09:17 - 00000000 ____D C:\WINDOWS\rescache
2013-12-21 11:30 - 2013-08-22 07:13 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM
2013-12-17 22:47 - 2013-12-17 22:47 - 01678040 _____ (Broadcom Corporation.) C:\WINDOWS\system32\BtwRSupportService.exe
2013-12-17 22:47 - 2013-12-17 22:47 - 00144600 _____ (Broadcom Corporation.) C:\WINDOWS\system32\Drivers\btwampfl.sys
2013-12-17 22:47 - 2013-12-17 22:47 - 00130776 _____ (Broadcom Corporation.) C:\WINDOWS\system32\Drivers\BtwSerialBus.sys
2013-12-17 22:47 - 2013-12-17 22:47 - 00060120 _____ (Broadcom Corporation.) C:\WINDOWS\system32\btwdi.dll
2013-12-17 20:22 - 2013-08-22 09:17 - 00000000 ___RD C:\WINDOWS\ToastData
2013-12-17 20:22 - 2013-08-22 09:17 - 00000000 ____D C:\WINDOWS\WinStore
2013-12-17 20:22 - 2013-08-22 09:17 - 00000000 ____D C:\WINDOWS\system32\de-DE
2013-12-17 20:22 - 2013-08-22 09:17 - 00000000 ____D C:\WINDOWS\MediaViewer
2013-12-17 20:22 - 2013-08-22 09:17 - 00000000 ____D C:\WINDOWS\FileManager
2013-12-17 20:22 - 2013-08-22 09:17 - 00000000 ____D C:\WINDOWS\Camera
2013-12-16 23:57 - 2013-07-23 17:13 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-12-16 23:54 - 2013-07-13 21:06 - 88123800 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-12-16 21:31 - 2013-12-09 19:51 - 00000000 ____D C:\Program Files\Norman
2013-12-15 14:44 - 2013-12-10 22:00 - 00000000 _____ C:\WINDOWS\system32\scurlcache.bin
2013-12-15 12:58 - 2013-12-15 11:17 - 00000000 ____D C:\Users\Vera\AppData\Local\AnVir
2013-12-15 12:58 - 2013-11-11 19:33 - 00080384 ___SH C:\Users\Vera\Downloads\Thumbs.db
2013-12-15 11:27 - 2013-12-15 11:27 - 00017408 ___SH C:\Users\Vera\Documents\Thumbs.db
2013-12-15 11:17 - 2013-12-15 11:17 - 09062640 _____ C:\Users\Vera\Downloads\AnVirTaskManager.exe
2013-12-15 11:17 - 2013-12-15 11:17 - 00001052 _____ C:\Users\Vera\AppData\Roaming\Microsoft\Windows\Start Menu\AnVir Task Manager.lnk
2013-12-15 11:17 - 2013-12-15 11:17 - 00001028 _____ C:\Users\Vera\Desktop\AnVir Task Manager.lnk
2013-12-15 11:17 - 2013-12-15 11:17 - 00000000 ____D C:\Users\Vera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVir Task Manager
2013-12-15 11:17 - 2013-12-15 11:17 - 00000000 ____D C:\Program Files\AnVir Task Manager
2013-12-13 17:59 - 2013-12-13 18:25 - 00020103 ____R C:\Users\Vera\Documents\2013_Adventsgewinnspiele.ods
2013-12-08 20:07 - 2013-12-08 20:07 - 00000000 ____D C:\Users\Vera\AppData\Roaming\Boomzap
2013-12-08 20:03 - 2013-12-08 18:04 - 1439777004 _____ C:\Users\Vera\Downloads\Nancy Drew 29 - The Silent Spy.rar
2013-12-08 20:02 - 2013-12-08 18:57 - 473814458 _____ C:\Users\Vera\Downloads\Death at Cape Porto - A Dana Knightstone Novel CE (1).rar
2013-12-08 18:41 - 2013-12-08 18:41 - 00000000 ____D C:\Users\Vera\AppData\Roaming\casualArts
2013-12-08 18:41 - 2013-12-08 18:41 - 00000000 ____D C:\ProgramData\casualArts
2013-12-08 18:39 - 2013-12-08 18:27 - 00000000 ____D C:\WINDOWS\Christmas Wonderland 4
2013-12-08 18:39 - 2013-12-08 18:27 - 00000000 ____D C:\Program Files\Christmas Wonderland 4
2013-12-08 18:33 - 2013-12-08 17:55 - 139867357 _____ C:\Users\Vera\Downloads\Christmas Wonderland 4.rar
2013-12-08 15:20 - 2013-07-13 20:11 - 00000977 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-12-08 15:20 - 2013-07-13 20:11 - 00000000 ____D C:\Program Files\CCleaner
2013-12-08 13:00 - 2013-10-19 20:40 - 00000000 ____D C:\Users\DefaultAppPool
2013-12-08 12:58 - 2013-07-14 19:47 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-12-08 11:45 - 2013-12-08 11:43 - 00000000 ____D C:\Users\Vera\Downloads\PC Welt backup
2013-12-08 11:42 - 2013-12-08 11:40 - 00000000 ___HD C:\ProgramData\sysnfxo
2013-12-08 11:39 - 2013-12-08 11:39 - 00000000 ____D C:\ProgramData\PC-WELT Backup Easy
2013-12-06 20:44 - 2013-09-27 21:11 - 00000000 ____D C:\ProgramData\AVG2014
2013-12-06 17:17 - 2013-12-06 17:16 - 24979036 _____ C:\Users\Vera\Downloads\tag06backup.zip
2013-12-05 14:16 - 2013-12-09 19:32 - 292128108 _____ C:\Users\Vera\Desktop\tag05_32bitnorman.zip
2013-12-04 01:05 - 2013-08-22 09:18 - 00693240 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2013-12-04 01:05 - 2013-08-22 09:18 - 00105464 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2013-12-03 21:37 - 2013-08-22 09:17 - 00000000 ____D C:\WINDOWS\system32\NDF
2013-12-02 20:11 - 2013-12-02 20:11 - 04978424 _____ (EaseUS ) C:\Users\Vera\Downloads\EaseUSDataRecoveryWizardPro-7.0.exe
2013-12-01 22:04 - 2013-12-01 22:03 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-29 22:36 - 2013-07-14 19:47 - 00000000 ____D C:\Users\Vera\AppData\Local\Mozilla
2013-11-26 20:48 - 2013-11-26 20:49 - 00014136 _____ (Hewlett-Packard Development Company, L.P.) C:\WINDOWS\system32\Drivers\SP63665.dll
2013-11-26 19:56 - 2013-09-27 21:13 - 00000967 _____ C:\Users\Public\Desktop\AVG 2014.lnk
2013-11-26 11:11 - 2013-12-13 18:56 - 17112576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2013-11-26 09:38 - 2013-12-13 18:56 - 02166784 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2013-11-26 09:16 - 2013-12-13 18:56 - 04243968 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2013-11-26 09:13 - 2013-12-13 18:56 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2013-11-26 08:32 - 2013-12-13 18:56 - 01928192 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2013-11-26 08:26 - 2013-12-13 18:56 - 11221504 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2013-11-26 07:34 - 2013-12-13 18:56 - 00703488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2013-11-26 07:33 - 2013-12-13 18:56 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2013-11-26 07:27 - 2013-12-13 18:56 - 01157632 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe
[2013-11-22 19:52] - [2013-10-22 07:03] - 2065448 ____A (Microsoft Corporation) 1A0BC9598E4A58FC84570FFF5A108E58
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-12-24 21:36
==================== End Of Log ============================ --- --- ---
--- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 23-12-2013 01
Ran by Vera at 2013-12-25 11:02:17
Running from C:\Users\Vera\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {B5F5C120-2089-702E-0001-553BB0D5A664}
==================== Installed Programs ======================
Adobe Shockwave Player 11.6 (Version: 11.6.5.635)
AnVir Task Manager
AVG 2014 (Version: 14.0.3658)
AVG 2014 (Version: 14.0.4259)
AVG 2014 (Version: 2014.0.4259)
BlueStacks App Player (Version: 0.7.15.909)
BlueStacks Notification Center (Version: 0.7.15.909)
Bonjour (Version: 3.0.0.10)
CCleaner (Version: 4.08)
ClipGrab 3.3.0.2
concept/design Video Jukebox (Version: 1.3.0.0)
Connected Music powered by Universal Music Group version 1.0 (Version: 1.0)
D3DX10 (Version: 15.4.2368.0902)
Energy Star (Version: 1.0.9)
ESET Online Scanner v3
Foxit Reader (Version: 6.0.5.618)
FRANZIS onlineTV 8 (Version: 8.5.0.10)
Hewlett-Packard ACLM.NET v1.2.1.1 (Version: 1.00.0000)
HP Customer Experience Enhancements (Version: 6.0.1.7)
HP Documentation (Version: 1.1.0.0)
HP Postscript Converter (Version: 3.1.3591)
HP Quick Launch (Version: 3.0.6)
HP Recovery Manager (Version: 8.00)
HP Registration Service (Version: 1.0.5976.4186)
HP Utility Center (Version: 1.0.7)
Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300)
Microsoft Application Error Reporting (Version: 12.0.6012.5000)
Microsoft Office (Version: 14.0.6120.5004)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Mozilla Firefox 25.0.1 (x86 de) (Version: 25.0.1)
Mozilla Maintenance Service (Version: 25.0.1)
MSVCRT (Version: 15.4.2862.0708)
MuteLED (Version: 1.0.1)
OpenOffice.org 3.4.1 (Version: 3.41.9593)
PassShow
PDF24 Creator 5.6.0
Realtek I2S Audio (Version: 6.2.9200.3062)
Skype™ 6.3 (Version: 6.3.105)
swMSM (Version: 12.0.0.1)
Synaptics ClickPad Driver (Version: 16.5.3.3)
Visual Studio 2012 x86 Redistributables (Version: 14.0.0.1)
VLC media player 2.1.2 (Version: 2.1.2)
Windows Live Communications Platform (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3555.0308)
Windows Live Fotogalerie (Version: 15.4.3502.0922)
Windows Live Installer (Version: 15.4.3502.0922)
Windows Live Movie Maker (Version: 15.4.3502.0922)
Windows Live Photo Common (Version: 15.4.3502.0922)
Windows Live Photo Gallery (Version: 15.4.3502.0922)
Windows Live PIMT Platform (Version: 15.4.3508.1109)
Windows Live SOXE (Version: 15.4.3502.0922)
Windows Live SOXE Definitions (Version: 15.4.3502.0922)
Windows Live UX Platform (Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (Version: 15.4.3508.1109)
Windows Live Writer (Version: 15.4.3502.0922)
Windows Live Writer Resources (Version: 15.4.3502.0922)
Windows7FirewallControl (i386) 5.1.7.69 (Version: 5.1.7.69)
Windows-Treiberpaket - Broadcom (bcmfn2) System (02/07/2013 5.93.97.108) (Version: 02/07/2013 5.93.97.108)
Windows-Treiberpaket - Broadcom (bcmfn2) System (08/30/2012 20.43.14.119) (Version: 08/30/2012 20.43.14.119)
Windows-Treiberpaket - Broadcom (BcmNfcIc) System (09/26/2012 1.0.0.3400) (Version: 09/26/2012 1.0.0.3400)
Windows-Treiberpaket - Broadcom (BCMSDH43XX) Net (02/07/2013 5.93.97.108) (Version: 02/07/2013 5.93.97.108)
Windows-Treiberpaket - Broadcom (BCMSDH43XX) Net (09/28/2012 5.93.97.76) (Version: 09/28/2012 5.93.97.76)
Windows-Treiberpaket - Broadcom (BtwSerialBus) System (02/07/2013 12.0.0.5500) (Version: 02/07/2013 12.0.0.5500)
Windows-Treiberpaket - Broadcom (BtwSerialBus) System (09/07/2012 12.0.0.2211) (Version: 09/07/2012 12.0.0.2211)
Windows-Treiberpaket - Broadcom (BtwSerialBus) System (09/18/2013 12.0.0.8020) (Version: 09/18/2013 12.0.0.8020)
Windows-Treiberpaket - Broadcom (WUDFRd) Proximity (09/26/2012 1.0.0.3400) (Version: 09/26/2012 1.0.0.3400)
WinRAR 4.20 (32-Bit) (Version: 4.20.0)
Wise Care 365 Version 2.92 (Version: 2.92)
Wise Program Uninstaller 1.58 (Version: 1.58)
==================== Restore Points =========================
24-12-2013 20:47:03 Installed AdblockIE
24-12-2013 21:28:28 Removed AdblockIE
==================== Hosts content: ==========================
2013-08-22 07:13 - 2013-08-22 07:13 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {00BC77BF-3352-4FE8-9617-4F1B27BEC19A} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup
Task: {0EF1E798-E530-406D-B9D1-FC971D274DD3} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company)
Task: {17233BE9-87E9-40B0-B003-AE9D2B92CBBE} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask
Task: {1D58B002-7629-4AB1-AB48-6747F39114E3} - System32\Tasks\HPCeeScheduleForVera => C:\Program Files\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-13] (Hewlett-Packard)
Task: {1D6E6525-B3F6-493D-B3C5-E22D57E7968E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater\HPSFUpdater.exe
Task: {247BD142-0549-4E91-84B0-172C25563718} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation)
Task: {2BE65564-89D1-4396-A5CC-D7D9283FC4A1} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task
Task: {392EB017-207C-42BF-A061-F3BE721F456C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {4B7EF56A-8A42-4BD2-BB5C-7C389AC54A37} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
Task: {54B8BA50-9657-4AE9-8594-01EEC150B12D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company)
Task: {5700ACE8-D0AF-4BA7-98B6-1033521A877A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {608034F0-4E48-4263-969E-E5EEBD7158F8} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: {6E84A59B-1863-4B21-8BD8-C9B20FD15484} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {7C7CF1DA-F461-4850-96B2-ADCA8A67E59C} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {83D4F220-BE56-4EB8-A338-7DD20B99B139} - System32\Tasks\{8EBCB31B-136D-463E-837F-94B1A93EA2BB} => Iexplore.exe hxxp://ui.skype.com/ui/0/6.6.0.106/de/go/help.faq.installer?LastError=1603
Task: {8B5819AE-7B44-478B-A3D3-8846AF160A8F} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate
Task: {92ED6570-4654-4BFA-9A6C-1084C6939C16} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work
Task: {997C8BBD-710B-4E66-B5BC-CC09575A58D2} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance
Task: {9CAFC8FD-000D-4D6F-AE09-2E532661C8FB} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2013-11-22] (Hewlett-Packard)
Task: {A1518A1B-1C36-4A4F-A9DA-371B59EF730F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis Install => C:\Program Files\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-09-27] (Hewlett-Packard Company)
Task: {A5D45ED3-F524-4574-8F39-527F3729D1E2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\System32\tzsync.exe [2013-08-22] (Microsoft Corporation)
Task: {AF580DE3-C4FA-47A2-A0AF-2423C4D4F872} - System32\Tasks\{5F267B9B-AA6A-458B-A05D-254F88D4420E} => Iexplore.exe hxxp://ui.skype.com/ui/0/6.6.0.106/de/go/help.faq.installer?LastError=1603
Task: {C0D0F7C4-419F-41B3-90A2-FE79270B828A} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask
Task: {CF5A1DDC-D14D-4D59-AD49-A19A645B087B} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization
Task: {DCF55BED-B1DF-4ABF-8D85-6542C7007799} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE
Task: {DD0A18B5-5082-4954-AAB1-C10C16F5BA0F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-11-22] (Piriform Ltd)
Task: {E4C8774A-2818-45A4-8A6D-11DDF6348886} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task
Task: {F3424C57-1DD3-4530-AF5A-11E5CC4640D5} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\System32\MRT.exe [2013-12-16] (Microsoft Corporation)
Task: {F9826C00-4366-4F2C-B8F9-9F5D51612586} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2013-11-22] (Hewlett-Packard)
Task: {FAB49829-3EE7-4234-BE84-277862F2A57C} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {FBD3B736-2A1E-416B-87C7-CF06435BCED7} - System32\Tasks\{5A602A3D-9673-4FC9-A639-B8360B97DF0F} => Iexplore.exe hxxp://ui.skype.com/ui/0/6.6.0.106/de/go/help.faq.installer?LastError=1603
Task: {FDD40609-3A9B-445C-ACB4-54AA42B3E8D1} - System32\Tasks\AnVir Task Manager => C:\Program Files\AnVir Task Manager\AnVir.exe [2013-12-04] (AnVir Software)
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\HPCeeScheduleForVera.job => C:\Program Files\Hewlett-Packard\HP Ceement\HPCEE.exe
Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
Task: C:\WINDOWS\Tasks\Wise Care 365.job => C:\Program Files\Wise\Wise Care 365\WiseTray.exe
Task: C:\WINDOWS\Tasks\Wise Turbo Checker.job => C:\Program Files\Wise\Wise Care 365\WiseTurbo.exe
==================== Loaded Modules (whitelisted) =============
2013-12-23 23:04 - 2013-12-23 23:04 - 00146432 _____ () C:\Program Files\PassShow\150.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\Users\Vera\SkyDrive:ms-properties
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\gpioclv.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\inteli2c.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\lnwipc.sys => ""="Driver"
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (12/24/2013 11:32:13 PM) (Source: Customer Experience Improvement Program) (User: )
Description: 80070005
Error: (12/24/2013 11:28:40 PM) (Source: Application Hang) (User: )
Description: Programm mbam.exe, Version 1.75.0.1 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: bb8
Startzeit: 01cf00f745f53c5a
Endzeit: 15
Anwendungspfad: C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
Berichts-ID: a975bd45-6cea-11e3-aff6-93210c6d75bc
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (12/24/2013 11:18:31 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: HPPU.exe, Version: 1.0.0.0, Zeitstempel: 0x50079e34
Name des fehlerhaften Moduls: d2d1.dll, Version: 6.3.9600.16399, Zeitstempel: 0x522ea12a
Ausnahmecode: 0xc0000005
Fehleroffset: 0x002202e3
ID des fehlerhaften Prozesses: 0x18f4
Startzeit der fehlerhaften Anwendung: 0xHPPU.exe0
Pfad der fehlerhaften Anwendung: HPPU.exe1
Pfad des fehlerhaften Moduls: HPPU.exe2
Berichtskennung: HPPU.exe3
Vollständiger Name des fehlerhaften Pakets: HPPU.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: HPPU.exe5
Error: (12/24/2013 11:11:35 PM) (Source: BstHdAndroidSvc) (User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
Error: (12/24/2013 10:55:12 PM) (Source: Customer Experience Improvement Program) (User: )
Description: 80070005
Error: (12/24/2013 10:29:50 PM) (Source: Microsoft-Windows-RestartManager) (User: ENVY)
Description: Die Anwendung oder der Dienst "Internet Explorer" konnte nicht heruntergefahren werden.
Error: (12/24/2013 10:29:50 PM) (Source: Microsoft-Windows-RestartManager) (User: ENVY)
Description: Die Anwendung oder der Dienst "Internet Explorer" konnte nicht heruntergefahren werden.
Error: (12/24/2013 10:17:46 PM) (Source: Application Hang) (User: )
Description: Programm Windows7FirewallControl.exe, Version 5.1.7.69 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 1614
Startzeit: 01cf00ebdd2d2e3f
Endzeit: 4294967295
Anwendungspfad: C:\Program Files\Windows7FirewallControl\Windows7FirewallControl.exe
Berichts-ID: d3e0e6bd-6ce0-11e3-aff5-a002ced271bf
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (12/24/2013 10:01:52 PM) (Source: Customer Experience Improvement Program) (User: )
Description: 80070005
Error: (12/24/2013 09:36:47 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1".
Die abhängige Assemblierung "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
System errors:
=============
Error: (12/25/2013 10:56:09 AM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}NT-AUTORITÄTLokaler DienstS-1-5-19LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (12/25/2013 10:53:49 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "H2OWTBSRV" wurde mit folgendem Fehler beendet:
%%1
Error: (12/25/2013 10:53:38 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "HP Software Framework Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (12/25/2013 10:53:38 AM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst HP Software Framework Service erreicht.
Error: (12/25/2013 10:52:39 AM) (Source: volmgr) (User: )
Description: Die Initialisierung des Speicherabbildes ist fehlgeschlagen.
Error: (12/25/2013 10:53:04 AM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am 25.12.2013 um 10:51:24 unerwartet heruntergefahren.
Error: (12/24/2013 11:18:01 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: ComputerstandardLokalAktivierung{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}NT-AUTORITÄTLokaler DienstS-1-5-19LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (12/24/2013 11:11:41 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "H2OWTBSRV" wurde mit folgendem Fehler beendet:
%%1
Error: (12/24/2013 11:11:35 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "BlueStacks Android Service" wurde mit folgendem Fehler beendet:
%%1064
Error: (12/24/2013 11:11:33 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "HP Software Framework Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Microsoft Office Sessions:
=========================
Error: (12/24/2013 11:32:13 PM) (Source: Customer Experience Improvement Program)(User: )
Description: 80070005
Error: (12/24/2013 11:28:40 PM) (Source: Application Hang)(User: )
Description: mbam.exe1.75.0.1bb801cf00f745f53c5a15C:\Program Files\Malwarebytes' Anti-Malware\mbam.exea975bd45-6cea-11e3-aff6-93210c6d75bc
Error: (12/24/2013 11:18:31 PM) (Source: Application Error)(User: )
Description: HPPU.exe1.0.0.050079e34d2d1.dll6.3.9600.16399522ea12ac0000005002202e318f401cf00f611e96512C:\Program Files\Hewlett-Packard\HP Utility Center\HPPU.exeC:\WINDOWS\SYSTEM32\d2d1.dll518d0674-6ce9-11e3-aff6-93210c6d75bc
Error: (12/24/2013 11:11:35 PM) (Source: BstHdAndroidSvc)(User: )
Description: Der Dienst kann nicht gestartet werden. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
bei BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
bei System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)
Error: (12/24/2013 10:55:12 PM) (Source: Customer Experience Improvement Program)(User: )
Description: 80070005
Error: (12/24/2013 10:29:50 PM) (Source: Microsoft-Windows-RestartManager)(User: ENVY)
Description: 1C:\Program Files\Internet Explorer\iexplore.exeInternet Explorer0111751040
Error: (12/24/2013 10:29:50 PM) (Source: Microsoft-Windows-RestartManager)(User: ENVY)
Description: 1C:\Program Files\Internet Explorer\iexplore.exeInternet Explorer0111757760
Error: (12/24/2013 10:17:46 PM) (Source: Application Hang)(User: )
Description: Windows7FirewallControl.exe5.1.7.69161401cf00ebdd2d2e3f4294967295C:\Program Files\Windows7FirewallControl\Windows7FirewallControl.exed3e0e6bd-6ce0-11e3-aff5-a002ced271bf
Error: (12/24/2013 10:01:52 PM) (Source: Customer Experience Improvement Program)(User: )
Description: 80070005
Error: (12/24/2013 09:36:47 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"C:\Program Files\OpenOffice.org 3\Basis\program\python-core-2.6.1\lib\distutils\command\wininst-9.0-amd64.exe
CodeIntegrity Errors:
===================================
Date: 2013-12-09 20:14:38.625
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Norman\Nse\bin\ndiskio.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2013-12-09 20:13:36.130
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Norman\Nse\bin\ndiskio.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2013-12-09 20:12:32.554
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Norman\Nse\bin\ndiskio.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2013-12-09 20:11:28.782
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Norman\Nse\bin\ndiskio.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2013-12-09 20:10:26.225
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Norman\Nse\bin\ndiskio.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2013-12-09 20:09:24.003
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Norman\Nse\bin\ndiskio.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2013-12-09 20:08:15.181
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Norman\Nse\bin\ndiskio.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2013-12-09 20:08:11.759
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\Drivers\nvcv32mf.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2013-12-09 20:07:12.792
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Norman\Nse\bin\ndiskio.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2013-12-09 20:07:09.724
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Norman\Nse\bin\ndiskio.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
==================== Memory info ===========================
Percentage of memory in use: 60%
Total physical RAM: 1994.41 MB
Available physical RAM: 780.93 MB
Total Pagefile: 3658.41 MB
Available Pagefile: 2272.36 MB
Total Virtual: 2047.88 MB
Available Virtual: 1857.49 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:44.83 GB) (Free:12.6 GB) NTFS
Drive d: (RECOVERY) (Fixed) (Total:12.6 GB) (Free:1.32 GB) NTFS ==>[System with boot components (obtained from reading drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 58 GB) (Disk ID: 994F330E)
Partition: GPT Partition Type
==================== End Of Log ============================ |