|
Plagegeister aller Art und deren Bekämpfung: SD-Karte: DCIM.exe ist keine zulässige win32-AnwendungWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
25.12.2012, 17:52 | #1 | |
| SD-Karte: DCIM.exe ist keine zulässige win32-Anwendung hey Leute, oben genannte Fehlermeldung kommt mir entgegen,sobald ich probiere meinen Ordner mit Foto zu öffnen. Windows zeigt ihn als .exe an und nicht mehr als ordner. Dummerweise habe ich mit AVG und Malwarebytes schon gescannt und gelöscht- habe später gelesen dass dies besser nicht voreilig geschehen sollte. Nun hab ich in der AVG history nochmal nachgeschaut: Der Wurm heisst "Worm/VB.ADVW". Weiß jemand bescheid?die logfile von malware spuckt nach scan der sd-karte nun nichts mehr aus. vielen dank für eure hilfe! niemand eine idee? Zitat:
|
27.12.2012, 09:15 | #2 | ||
/// Winkelfunktion /// TB-Süch-Tiger™ | SD-Karte: DCIM.exe ist keine zulässige win32-Anwendung Hallo und
__________________Zitat:
Schön und wo sind die Logs dazu? Solche Angaben reichen nicht, bitte poste die vollständigen Angaben/Logs der Virenscanner siehe http://www.trojaner-board.de/125889-...tml#post941520 Bitte alles nach Möglichkeit hier in CODE-Tags posten.
__________________ |
31.07.2013, 00:32 | #3 |
| SD-Karte: DCIM.exe ist keine zulässige win32-Anwendung hallo!
__________________ist zwar schon lange her,aber nun wieder aktuell!den scan mit hijckthis oder Malwarebytes vollziehen?was wäre eher anzuraten? Code:
ATTFilter Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 01:16:00, on 31.07.2013 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v10.0 (10.00.9200.16635) Boot mode: Normal Running processes: C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskhost.exe C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Windows\System32\M-AudioTaskBarIcon.exe C:\Windows\System32\pspcontr.exe C:\Program Files\DivX\DivX Update\DivXUpdate.exe C:\Program Files\Common Files\Ulead Systems\AutoDetector\Monitor.exe C:\Program Files\AVG\AVG2013\avgui.exe C:\Program Files\AVG Secure Search\vprot.exe C:\Program Files\Skype\Phone\Skype.exe C:\Users\Seegas\AppData\Roaming\Dropbox\bin\Dropbox.exe C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE C:\Program Files\NVIDIA Corporation\Display\nvtray.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe C:\Program Files\Winamp\winamp.exe C:\Program Files\Last.fm\LastFM.exe C:\Program Files\VideoLAN\VLC\vlc.exe C:\Windows\system32\cmd.exe C:\Windows\explorer.exe C:\Windows\system32\conhost.exe C:\Users\Seegas\Desktop\HiJackThis204.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: (no name) - - (no file) R3 - URLSearchHook: (no name) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - (no file) O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file) O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: Use the DivX Plus Web Player to watch web videos with less interruptions and smoother playback on supported sites - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O3 - Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file) O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [M-Audio Taskbar Icon] C:\Windows\system32\M-AudioTaskBarIcon.exe O4 - HKLM\..\Run: [PspContr] PspContr.Exe O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2013\avgui.exe" /TRAYONLY O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe" O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun O4 - Startup: Dropbox.lnk = C:\Users\Seegas\AppData\Roaming\Dropbox\bin\Dropbox.exe O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Free YouTube Download - C:\Users\Seegas\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file) O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\14.0.1\ViProtocol.dll O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O20 - AppInit_DLLs: O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgidsagent.exe O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgwdsvc.exe O23 - Service: Intel(R) PROSet Monitoring Service - Intel Corporation - C:\Windows\system32\IProsetMonitor.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe O23 - Service: Realtek11nSU - Realtek - C:\Program Files\Realtek\11n USB Wireless LAN Utility\RtlService.exe O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe O23 - Service: @C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe O23 - Service: vToolbarUpdater14.0.1 - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe -- End of file - 9670 bytes und hier nochmal die log von MBAM... Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.07.30.10 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 10.0.9200.16635 Seegas :: SHORE-STATION [Administrator] 31.07.2013 01:22:59 MBAM-log-2013-07-31 (01-30-47).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 286719 Laufzeit: 7 Minute(n), 24 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 4 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System|DisableTaskMgr (PUM.Hijack.TaskManager) -> Bösartig: (1) Gut: (0) -> Keine Aktion durchgeführt. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System|DisableRegistryTools (PUM.Hijack.Regedit) -> Bösartig: (1) Gut: (0) -> Keine Aktion durchgeführt. HKCU\SOFTWARE\Policies\Microsoft\Windows\System|DisableCMD (PUM.Hijack.CMDPrompt) -> Bösartig: (1) Gut: (0) -> Keine Aktion durchgeführt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL|CheckedValue (PUM.Hijack.System.Hidden) -> Bösartig: (0) Gut: (1) -> Keine Aktion durchgeführt. Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) |
31.07.2013, 08:41 | #4 |
/// Winkelfunktion /// TB-Süch-Tiger™ | SD-Karte: DCIM.exe ist keine zulässige win32-Anwendung Bitte die Finger von HijackThis lassen! Das Tool ist schon lange unbrauchbar Was ist nun mit dem Log von AVG? Bitte auch ein Log mit Farbars Tool machen: Scan mit Farbar's Recovery Scan Tool (FRST) Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ Logfiles bitte immer in CODE-Tags posten |
31.07.2013, 11:29 | #5 |
| SD-Karte: DCIM.exe ist keine zulässige win32-Anwendung AVG sagt: Code:
ATTFilter "";"Virus identifiziert: Worm/VB.ADVW, E:\$RECYCLE.BIN.exe";"Gesichert" "";"Virus identifiziert: Worm/VB.ADVW, E:\Audio.exe";"Gesichert" "";"Virus identifiziert: Worm/VB.ADVW, E:\fotos.exe";"Gesichert" "";"Virus identifiziert: Worm/VB.ADVW, E:\SHORE-STATION.exe";"Gesichert" Farbar sagt seit ner guten halben stunde "backing up registry,this can take a few seconds". ist das normal? hab auch wohl noch n anderen wurm,der verhindert,den task-manager zu öffnen- mann,mann,mann. |
31.07.2013, 13:36 | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ | SD-Karte: DCIM.exe ist keine zulässige win32-Anwendung Ist FRST mittlerweile weiter?
__________________ --> SD-Karte: DCIM.exe ist keine zulässige win32-Anwendung |
31.07.2013, 13:48 | #7 |
| SD-Karte: DCIM.exe ist keine zulässige win32-Anwendung nein,Farbar reagiert gar nicht,auch bei erneutem herunterladen!woran liegt das?gibt es kein anderes Programm,mit dem ich da arbeiten kann? |
31.07.2013, 16:06 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | SD-Karte: DCIM.exe ist keine zulässige win32-Anwendung Starte Windows mal im abgesicherten Modus und versuch FRST nochmal
__________________ Logfiles bitte immer in CODE-Tags posten |
02.08.2013, 09:59 | #9 |
| SD-Karte: DCIM.exe ist keine zulässige win32-Anwendung FRST.txt: Code:
ATTFilter can result of Farbar Recovery Scan Tool (FRST) (x86) Version: 30-07-2013 04 Ran by Seegas (administrator) on 01-08-2013 20:55:36 Running from C:\Users\Seegas\Desktop Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Safe Mode (with Networking) ==================== Processes (Whitelisted) =================== (Microsoft Corporation) C:\Windows\system32\userinit.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7731744 2009-09-02] (Realtek Semiconductor) HKLM\...\Run: [WinampAgent] - C:\Program Files\Winamp\winampa.exe [74752 2010-12-07] (Nullsoft, Inc.) HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM\...\Run: [M-Audio Taskbar Icon] - C:\Windows\system32\M-AudioTaskBarIcon.exe [643592 2009-09-23] (Avid Technology, Inc.) HKLM\...\Run: [PspContr] - C:\Windows\system32\PspContr.Exe [376832 2004-03-11] (Philips Speech Processing) HKLM\...\Run: [DivXUpdate] - C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1230704 2011-03-21] () HKLM\...\Run: [Ulead AutoDetector v2] - C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe [90112 2004-08-27] (Ulead Systems, Inc.) HKLM\...\Run: [AVG_UI] - C:\Program Files\AVG\AVG2013\avgui.exe [4411440 2013-07-01] (AVG Technologies CZ, s.r.o.) HKLM\...\Run: [vProt] - C:\Program Files\AVG Secure Search\vprot.exe [2285232 2013-08-01] () HKLM\...\InprocServer32: [Default-cscui] <==== ATTENTION! HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [17418928 2012-07-13] (Skype Technologies S.A.) HKCU\...\Winlogon: [Shell] explorer.exe <==== ATTENTION MountPoints2: {697da9f3-0f59-11e0-8119-806e6f6e6963} - F:\setup.exe HKU\Gast\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [ 2010-04-01] (DT Soft Ltd) HKU\Gast\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [ 2012-07-13] (Skype Technologies S.A.) HKU\Gast\...\Run: [ICQ] - C:\Program Files\ICQ7.2\ICQ.exe [ 2011-01-05] (ICQ, LLC.) Startup: C:\Users\Seegas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Seegas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Seegas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.icq.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,ICQ Search = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd URLSearchHook: (No Name) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - No File SearchScopes: HKCU - {3A5EF8C0-948A-4039-A01E-FC04D9B0E3F5} URL = hxxp://nl.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=827316&p={searchTerms} SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) BHO: DivX HiQ - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: No Name - {95B7759C-8C7F-4BF1-B163-73684A933233} - No File BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) Toolbar: HKLM - No Name - {95B7759C-8C7F-4BF1-B163-73684A933233} - No File Toolbar: HKCU -No Name - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - No File DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\15.4.0\ViProtocol.dll (AVG Secure Search) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Seegas\AppData\Roaming\Mozilla\Firefox\Profiles\0r0ve8pn.default FF user.js: detected! => C:\Users\Seegas\AppData\Roaming\Mozilla\Firefox\Profiles\0r0ve8pn.default\user.js FF SelectedSearchEngine: Google FF Homepage: hxxp://www.google.de/ FF Keyword.URL: hxxp://vshare.toolbarhome.com/search.aspx?srch=ku&q= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\15.4.0\\npsitesafety.dll (AVG Technologies) FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF SearchPlugin: C:\Users\Seegas\AppData\Roaming\Mozilla\Firefox\Profiles\0r0ve8pn.default\searchplugins\icqplugin-1.xml FF SearchPlugin: C:\Users\Seegas\AppData\Roaming\Mozilla\Firefox\Profiles\0r0ve8pn.default\searchplugins\icqplugin-2.xml FF SearchPlugin: C:\Users\Seegas\AppData\Roaming\Mozilla\Firefox\Profiles\0r0ve8pn.default\searchplugins\icqplugin.xml FF SearchPlugin: C:\Users\Seegas\AppData\Roaming\Mozilla\Firefox\Profiles\0r0ve8pn.default\searchplugins\searchplugins-backup FF SearchPlugin: C:\Users\Seegas\AppData\Roaming\Mozilla\Firefox\Profiles\0r0ve8pn.default\searchplugins\web-search.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml FF Extension: No Name - C:\Users\Seegas\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} FF Extension: No Name - C:\Users\Seegas\AppData\Roaming\Mozilla\Firefox\Profiles\0r0ve8pn.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} FF Extension: No Name - C:\Users\Seegas\AppData\Roaming\Mozilla\Firefox\Profiles\0r0ve8pn.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF Extension: Default - C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video FF Extension: No Name - C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video FF HKLM\...\Firefox\Extensions: [{6904342A-8307-11DF-A508-4AE2DFD72085}] C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa FF Extension: No Name - C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa FF HKLM\...\Firefox\Extensions: [avg@toolbar] C:\ProgramData\AVG Secure Search\FireFoxExt\15.4.0.5 FF Extension: AVG Security Toolbar - C:\ProgramData\AVG Secure Search\FireFoxExt\15.4.0.5 ========================== Services (Whitelisted) ================= S2 AVGIDSAgent; C:\Program Files\AVG\AVG2013\avgidsagent.exe [4939312 2013-07-04] (AVG Technologies CZ, s.r.o.) S2 avgwd; C:\Program Files\AVG\AVG2013\avgwdsvc.exe [283136 2013-07-23] (AVG Technologies CZ, s.r.o.) S2 Intel(R) PROSet Monitoring Service; C:\Windows\system32\IProsetMonitor.exe [110752 2010-09-22] (Intel Corporation) S2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S2 Realtek11nSU; C:\Program Files\Realtek\11n USB Wireless LAN Utility\RtlService.exe [40960 2009-12-07] (Realtek) S3 TuneUp.Defrag; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [435008 2011-05-22] (TuneUp Software) S2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [1051968 2010-09-30] (TuneUp Software) S2 vToolbarUpdater15.4.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\ToolbarUpdater.exe [1616048 2013-08-01] (AVG Secure Search) ==================== Drivers (Whitelisted) ==================== S1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [208184 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [60216 2013-07-20] (AVG Technologies CZ, s.r.o.) S1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [22328 2013-03-01] (AVG Technologies CZ, s.r.o.) S1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [171320 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [246072 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [96568 2013-07-01] (AVG Technologies CZ, s.r.o.) R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [39224 2013-07-10] (AVG Technologies CZ, s.r.o.) R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [182072 2013-03-21] (AVG Technologies CZ, s.r.o.) R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [37664 2013-08-01] (AVG Technologies) S3 CrystalSysInfo; C:\Program Files\MediaCoder\SysInfo.sys [15152 2007-09-25] () S3 EverestDriver; C:\Program Files\Lavalys\EVEREST Home Edition\kerneld.wnt [7168 2005-08-18] () S3 MADFUOZONE; C:\Windows\System32\DRIVERS\MAudioOzone_DFU.sys [42248 2009-09-23] (M-Audio) S3 MAUSBOZONE; C:\Windows\System32\DRIVERS\MAudioOzone.sys [158344 2009-09-23] (Avid Technology, Inc.) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) S3 RTCore32; C:\Program Files\MSI Afterburner\RTCore32.sys [5632 2011-09-06] () S0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2010-12-24] (Duplex Secure Ltd.) S3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [10064 2010-02-24] (TuneUp Software) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-01 12:25 - 2013-08-01 12:25 - 00003715 _____ C:\Program Files\Mozilla Firefoxavg-secure-search.xml 2013-08-01 11:24 - 2013-08-01 11:24 - 00847144 _____ C:\Windows\Minidump\080113-27518-01.dmp 2013-07-31 17:11 - 2013-07-31 17:11 - 00395024 _____ C:\Windows\Minidump\073113-40326-01.dmp 2013-07-31 16:36 - 2013-07-31 16:36 - 00413240 _____ C:\Windows\Minidump\073113-39483-01.dmp 2013-07-31 16:28 - 2013-07-31 16:28 - 00459136 _____ C:\Windows\Minidump\073113-35256-01.dmp 2013-07-31 16:11 - 2013-07-31 16:11 - 00394024 _____ C:\Windows\Minidump\073113-35209-01.dmp 2013-07-31 15:07 - 2013-07-31 15:07 - 00002562 _____ C:\Windows\diagwrn.xml 2013-07-31 15:07 - 2013-07-31 15:07 - 00001908 _____ C:\Windows\diagerr.xml 2013-07-31 14:47 - 2013-07-31 14:47 - 01222064 _____ (Farbar) C:\Users\Seegas\Desktop\FRST.exe 2013-07-31 11:59 - 2013-07-31 11:59 - 00732952 _____ C:\Windows\Minidump\073113-49140-01.dmp 2013-07-31 11:30 - 2013-07-31 11:30 - 00000000 ____D C:\FRST 2013-07-31 01:22 - 2013-07-31 01:22 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-07-31 01:22 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-07-31 00:24 - 2013-07-31 00:24 - 00000000 ____D C:\Users\Seegas\Desktop\Mucke 2013 2013-07-30 18:26 - 2013-04-17 09:02 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2013-07-30 07:05 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 14329856 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 13760512 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 03419136 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 02877440 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-30 01:08 - 2013-07-30 01:08 - 02284544 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 02046976 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 01988096 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 01441280 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-07-30 01:08 - 2013-07-30 01:08 - 01400416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-07-30 01:08 - 2013-07-30 01:08 - 01158144 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 01080832 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00906240 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00745472 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00719360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00629248 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00604160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00361984 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-07-30 01:08 - 2013-07-30 01:08 - 00357888 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00242200 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00232960 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00204800 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00187392 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00138752 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00137216 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00125440 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00117248 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00110592 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00079872 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00073728 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-07-30 01:08 - 2013-07-30 01:08 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-07-30 01:06 - 2013-07-30 01:11 - 00010332 _____ C:\Windows\IE10_main.log 2013-07-30 00:49 - 2013-08-01 12:25 - 00000000 ____D C:\ProgramData\AVG Secure Search 2013-07-30 00:49 - 2013-08-01 12:25 - 00000000 ____D C:\Program Files\AVG Secure Search 2013-07-30 00:49 - 2013-08-01 12:24 - 00037664 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx86.sys 2013-07-30 00:49 - 2013-07-30 00:49 - 00000000 ____D C:\Users\Seegas\AppData\Local\AVG Secure Search 2013-07-30 00:49 - 2013-07-30 00:49 - 00000000 ____D C:\Program Files\Common Files\AVG Secure Search 2013-07-30 00:44 - 2013-05-10 05:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll 2013-07-30 00:44 - 2013-04-26 06:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2013-07-30 00:44 - 2013-04-26 01:30 - 01505280 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll 2013-07-30 00:43 - 2013-06-05 05:05 - 02347520 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-30 00:43 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-30 00:43 - 2013-05-13 06:45 - 01160192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-07-30 00:43 - 2013-05-13 06:45 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-07-30 00:43 - 2013-05-13 06:45 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-07-30 00:43 - 2013-05-13 05:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe 2013-07-30 00:43 - 2013-05-13 05:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll 2013-07-30 00:43 - 2013-05-08 07:38 - 01293672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-07-30 00:43 - 2013-05-06 07:06 - 03968872 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2013-07-30 00:43 - 2013-05-06 07:06 - 03913576 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-07-30 00:43 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-30 00:24 - 2013-08-01 20:19 - 00000000 ____D C:\ProgramData\NVIDIA 2013-07-30 00:24 - 2013-07-30 00:24 - 00000020 ___SH C:\Users\UpdatusUser\ntuser.ini 2013-07-30 00:24 - 2013-07-30 00:24 - 00000000 _SHDL C:\Users\UpdatusUser\Startmenü 2013-07-30 00:24 - 2013-07-30 00:24 - 00000000 _SHDL C:\Users\UpdatusUser\Netzwerkumgebung 2013-07-30 00:24 - 2013-07-30 00:24 - 00000000 _SHDL C:\Users\UpdatusUser\Druckumgebung 2013-07-30 00:24 - 2013-07-30 00:24 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Musik 2013-07-30 00:24 - 2013-07-30 00:24 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Bilder 2013-07-30 00:24 - 2013-07-30 00:24 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Verlauf 2013-07-30 00:24 - 2013-07-30 00:24 - 00000000 ____D C:\Program Files\AGEIA Technologies 2013-07-30 00:24 - 2013-07-30 00:24 - 00000000 ____D C:\36451beb2f9b1baa17dfcfb1f71c53 2013-07-30 00:24 - 2013-01-15 16:03 - 00000000 ____D C:\Users\UpdatusUser\AppData\Roaming\TuneUp Software 2013-07-30 00:24 - 2011-05-16 23:10 - 00000000 ____D C:\Users\UpdatusUser\AppData\Roaming\Macromedia 2013-07-30 00:24 - 2011-04-21 11:51 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Microsoft Help 2013-07-30 00:23 - 2013-07-30 00:24 - 00000000 ____D C:\Windows\B9DB4C7601A446D58910F7AA6376DBAF.TMP 2013-07-30 00:23 - 2013-07-30 00:23 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2013-07-30 00:23 - 2013-06-21 14:02 - 00053024 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2013-07-30 00:23 - 2013-06-21 11:52 - 04192544 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2013-07-30 00:23 - 2013-06-21 11:52 - 03045664 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc.dll 2013-07-30 00:23 - 2013-06-21 11:52 - 02555168 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2013-07-30 00:23 - 2013-06-21 11:52 - 00640288 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2013-07-30 00:23 - 2013-06-21 11:52 - 00223008 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2013-07-30 00:23 - 2013-06-21 11:52 - 00062752 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2013-07-30 00:22 - 2013-07-30 00:45 - 00000000 ____D C:\Users\Seegas\AppData\Roaming\DeepBurner 2013-07-30 00:22 - 2013-06-21 14:02 - 21102368 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv32.dll 2013-07-30 00:22 - 2013-06-21 14:02 - 17560352 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2013-07-30 00:22 - 2013-06-21 14:02 - 13411896 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2um.dll 2013-07-30 00:22 - 2013-06-21 14:02 - 12427240 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dum.dll 2013-07-30 00:22 - 2013-06-21 14:02 - 09069344 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2013-07-30 00:22 - 2013-06-21 14:02 - 07687592 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2013-07-30 00:22 - 2013-06-21 14:02 - 06324360 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2013-07-30 00:22 - 2013-06-21 14:02 - 02777888 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2013-07-30 00:22 - 2013-06-21 14:02 - 02597856 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi.dll 2013-07-30 00:22 - 2013-06-21 14:02 - 02002720 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2013-07-30 00:22 - 2013-06-21 14:02 - 01024288 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco3232049.dll 2013-07-30 00:22 - 2013-06-21 14:02 - 00893728 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco3232049.dll 2013-07-30 00:22 - 2013-06-21 14:02 - 00467232 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR.dll 2013-07-30 00:22 - 2013-06-21 14:02 - 00465184 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC.dll 2013-07-30 00:22 - 2013-06-21 14:02 - 00016437 _____ C:\Windows\system32\nvinfo.pb 2013-07-30 00:22 - 2013-02-25 07:27 - 00154400 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda32v.sys 2013-07-30 00:22 - 2013-02-25 07:27 - 00028448 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap32.dll 2013-07-30 00:22 - 2013-01-29 10:35 - 00892704 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco3220103.dll 2013-07-30 00:21 - 2013-07-30 00:21 - 00001055 _____ C:\Users\Seegas\Desktop\DeepBurner.lnk 2013-07-30 00:21 - 2013-07-30 00:21 - 00001055 _____ C:\Users\Gast\Desktop\DeepBurner.lnk 2013-07-30 00:21 - 2013-07-30 00:21 - 00001055 _____ C:\Users\Administrator\Desktop\DeepBurner.lnk 2013-07-30 00:21 - 2013-07-30 00:21 - 00000000 ____D C:\Program Files\Astonsoft 2013-07-29 00:18 - 2013-07-29 00:18 - 00000356 _____ C:\Windows\Tasks\{FF57897C-1895-470E-96CD-C0F923DEEC95}.job 2013-07-28 23:31 - 2013-07-29 10:47 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-07-28 21:43 - 2013-07-28 21:43 - 00013712 _____ C:\Windows\system32\y 2013-07-28 21:43 - 2013-07-28 21:43 - 00013712 _____ C:\Windows\system32\w 2013-07-28 21:43 - 2013-07-28 21:43 - 00013712 _____ C:\Windows\system32\rar.exe 2013-07-20 01:51 - 2013-07-20 01:51 - 00246072 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avglogx.sys 2013-07-20 01:50 - 2013-07-20 01:50 - 00208184 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdriverx.sys 2013-07-20 01:50 - 2013-07-20 01:50 - 00171320 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgldx86.sys 2013-07-20 01:50 - 2013-07-20 01:50 - 00060216 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidshx.sys 2013-07-10 01:32 - 2013-07-10 01:32 - 00039224 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx86.sys ==================== One Month Modified Files and Folders ======= 2013-08-01 20:53 - 2010-12-24 14:36 - 01806107 _____ C:\Windows\WindowsUpdate.log 2013-08-01 20:49 - 2010-12-24 19:14 - 00000000 ____D C:\Users\Seegas\AppData\Roaming\Skype 2013-08-01 20:26 - 2009-07-14 06:34 - 00015152 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-01 20:26 - 2009-07-14 06:34 - 00015152 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-01 20:24 - 2010-12-24 14:38 - 00005374 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-01 20:23 - 2012-02-06 13:16 - 00000000 ____D C:\ProgramData\MFAData 2013-08-01 20:21 - 2011-04-06 22:24 - 00000000 ___RD C:\Users\Seegas\Dropbox 2013-08-01 20:21 - 2011-04-06 22:23 - 00000000 ____D C:\Users\Seegas\AppData\Roaming\Dropbox 2013-08-01 20:19 - 2013-07-30 00:24 - 00000000 ____D C:\ProgramData\NVIDIA 2013-08-01 20:19 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-01 20:19 - 2009-07-14 06:39 - 00001365 _____ C:\Windows\setupact.log 2013-08-01 12:57 - 2012-12-13 13:08 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-01 12:25 - 2013-08-01 12:25 - 00003715 _____ C:\Program Files\Mozilla Firefoxavg-secure-search.xml 2013-08-01 12:25 - 2013-07-30 00:49 - 00000000 ____D C:\ProgramData\AVG Secure Search 2013-08-01 12:25 - 2013-07-30 00:49 - 00000000 ____D C:\Program Files\AVG Secure Search 2013-08-01 12:24 - 2013-07-30 00:49 - 00037664 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx86.sys 2013-08-01 11:24 - 2013-08-01 11:24 - 00847144 _____ C:\Windows\Minidump\080113-27518-01.dmp 2013-08-01 11:24 - 2010-12-24 17:31 - 342830378 _____ C:\Windows\MEMORY.DMP 2013-08-01 11:24 - 2010-12-24 17:31 - 00000000 ____D C:\Windows\Minidump 2013-08-01 11:11 - 2010-12-24 14:56 - 00111002 _____ C:\Windows\PFRO.log 2013-08-01 11:11 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\AppCompat 2013-07-31 17:11 - 2013-07-31 17:11 - 00395024 _____ C:\Windows\Minidump\073113-40326-01.dmp 2013-07-31 16:36 - 2013-07-31 16:36 - 00413240 _____ C:\Windows\Minidump\073113-39483-01.dmp 2013-07-31 16:28 - 2013-07-31 16:28 - 00459136 _____ C:\Windows\Minidump\073113-35256-01.dmp 2013-07-31 16:11 - 2013-07-31 16:11 - 00394024 _____ C:\Windows\Minidump\073113-35209-01.dmp 2013-07-31 15:07 - 2013-07-31 15:07 - 00002562 _____ C:\Windows\diagwrn.xml 2013-07-31 15:07 - 2013-07-31 15:07 - 00001908 _____ C:\Windows\diagerr.xml 2013-07-31 15:07 - 2009-07-14 06:39 - 00000000 _____ C:\Windows\setuperr.log 2013-07-31 14:47 - 2013-07-31 14:47 - 01222064 _____ (Farbar) C:\Users\Seegas\Desktop\FRST.exe 2013-07-31 11:59 - 2013-07-31 11:59 - 00732952 _____ C:\Windows\Minidump\073113-49140-01.dmp 2013-07-31 11:32 - 2010-12-24 20:23 - 00000000 ____D C:\Users\Seegas\AppData\Local\Last.fm 2013-07-31 11:32 - 2010-12-24 20:23 - 00000000 ____D C:\Program Files\Last.fm 2013-07-31 11:31 - 2013-02-06 19:16 - 00000951 _____ C:\Users\Public\Desktop\AVG 2013.lnk 2013-07-31 11:30 - 2013-07-31 11:30 - 00000000 ____D C:\FRST 2013-07-31 01:22 - 2013-07-31 01:22 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-07-31 00:56 - 2010-12-24 19:37 - 00000000 ____D C:\Users\Seegas\AppData\Roaming\vlc 2013-07-31 00:24 - 2013-07-31 00:24 - 00000000 ____D C:\Users\Seegas\Desktop\Mucke 2013 2013-07-30 17:09 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache 2013-07-30 15:39 - 2011-04-06 22:23 - 00000000 ____D C:\Users\Seegas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-07-30 07:08 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET 2013-07-30 06:59 - 2009-07-14 06:33 - 00440488 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-30 06:57 - 2009-07-14 10:56 - 00000000 ____D C:\Program Files\Windows Journal 2013-07-30 06:57 - 2009-07-14 06:52 - 00000000 ____D C:\Program Files\Windows Defender 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\zh-TW 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\zh-HK 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\zh-CN 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\tr-TR 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\sv-SE 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\ru-RU 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\pt-PT 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\pt-BR 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\pl-PL 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\nl-NL 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\nb-NO 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\ko-KR 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\ja-JP 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\it-IT 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\hu-HU 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\fr-FR 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\fi-FI 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\el-GR 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE 2013-07-30 01:20 - 2010-12-26 18:43 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-07-30 01:11 - 2013-07-30 01:06 - 00010332 _____ C:\Windows\IE10_main.log 2013-07-30 01:08 - 2013-07-30 01:08 - 14329856 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 13760512 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 03419136 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 02877440 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-30 01:08 - 2013-07-30 01:08 - 02284544 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 02046976 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 01988096 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 01441280 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-07-30 01:08 - 2013-07-30 01:08 - 01400416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-07-30 01:08 - 2013-07-30 01:08 - 01158144 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 01080832 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00906240 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00745472 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00719360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00629248 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00604160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00361984 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-07-30 01:08 - 2013-07-30 01:08 - 00357888 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00242200 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00232960 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00204800 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00187392 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00138752 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00137216 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00125440 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00117248 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00110592 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00079872 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00073728 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-07-30 01:08 - 2013-07-30 01:08 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-07-30 01:03 - 2011-01-05 14:23 - 00000000 ____D C:\Users\Seegas\Desktop\Uni 2013-07-30 00:57 - 2012-12-13 13:08 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-07-30 00:57 - 2011-06-07 22:00 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-07-30 00:54 - 2011-02-04 13:59 - 00000000 ____D C:\Program Files\Philips Speech 2013-07-30 00:50 - 2012-12-13 12:10 - 00000000 ____D C:\Users\Seegas\AppData\Local\Avg2013 2013-07-30 00:49 - 2013-07-30 00:49 - 00000000 ____D C:\Users\Seegas\AppData\Local\AVG Secure Search 2013-07-30 00:49 - 2013-07-30 00:49 - 00000000 ____D C:\Program Files\Common Files\AVG Secure Search 2013-07-30 00:45 - 2013-07-30 00:22 - 00000000 ____D C:\Users\Seegas\AppData\Roaming\DeepBurner 2013-07-30 00:26 - 2011-01-04 16:37 - 00000000 ____D C:\Users\Seegas\AppData\Local\Adobe 2013-07-30 00:24 - 2013-07-30 00:24 - 00000020 ___SH C:\Users\UpdatusUser\ntuser.ini 2013-07-30 00:24 - 2013-07-30 00:24 - 00000000 _SHDL C:\Users\UpdatusUser\Startmenü 2013-07-30 00:24 - 2013-07-30 00:24 - 00000000 _SHDL C:\Users\UpdatusUser\Netzwerkumgebung 2013-07-30 00:24 - 2013-07-30 00:24 - 00000000 _SHDL C:\Users\UpdatusUser\Druckumgebung 2013-07-30 00:24 - 2013-07-30 00:24 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Musik 2013-07-30 00:24 - 2013-07-30 00:24 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Bilder 2013-07-30 00:24 - 2013-07-30 00:24 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Verlauf 2013-07-30 00:24 - 2013-07-30 00:24 - 00000000 ____D C:\Program Files\AGEIA Technologies 2013-07-30 00:24 - 2013-07-30 00:24 - 00000000 ____D C:\36451beb2f9b1baa17dfcfb1f71c53 2013-07-30 00:24 - 2013-07-30 00:23 - 00000000 ____D C:\Windows\B9DB4C7601A446D58910F7AA6376DBAF.TMP 2013-07-30 00:24 - 2011-03-28 22:34 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2013-07-30 00:23 - 2013-07-30 00:23 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2013-07-30 00:23 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Help 2013-07-30 00:21 - 2013-07-30 00:21 - 00001055 _____ C:\Users\Seegas\Desktop\DeepBurner.lnk 2013-07-30 00:21 - 2013-07-30 00:21 - 00001055 _____ C:\Users\Gast\Desktop\DeepBurner.lnk 2013-07-30 00:21 - 2013-07-30 00:21 - 00001055 _____ C:\Users\Administrator\Desktop\DeepBurner.lnk 2013-07-30 00:21 - 2013-07-30 00:21 - 00000000 ____D C:\Program Files\Astonsoft 2013-07-30 00:21 - 2012-01-21 21:57 - 00000000 ____D C:\Users\Administrator 2013-07-30 00:21 - 2010-12-24 15:44 - 00000000 ____D C:\Users\Gast 2013-07-30 00:21 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system 2013-07-29 16:16 - 2012-12-13 13:06 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-07-29 10:47 - 2013-07-28 23:31 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-07-29 00:18 - 2013-07-29 00:18 - 00000356 _____ C:\Windows\Tasks\{FF57897C-1895-470E-96CD-C0F923DEEC95}.job 2013-07-29 00:18 - 2010-12-24 19:14 - 00000000 ____D C:\ProgramData\Skype 2013-07-28 22:18 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\wfp 2013-07-28 22:18 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\registration 2013-07-28 22:18 - 2009-07-14 04:37 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2013-07-28 21:43 - 2013-07-28 21:43 - 00013712 _____ C:\Windows\system32\y 2013-07-28 21:43 - 2013-07-28 21:43 - 00013712 _____ C:\Windows\system32\w 2013-07-28 21:43 - 2013-07-28 21:43 - 00013712 _____ C:\Windows\system32\rar.exe 2013-07-28 21:22 - 2010-12-24 14:36 - 00000000 ____D C:\Users\Seegas 2013-07-28 21:20 - 2009-07-14 06:53 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-07-20 01:51 - 2013-07-20 01:51 - 00246072 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avglogx.sys 2013-07-20 01:50 - 2013-07-20 01:50 - 00208184 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdriverx.sys 2013-07-20 01:50 - 2013-07-20 01:50 - 00171320 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgldx86.sys 2013-07-20 01:50 - 2013-07-20 01:50 - 00060216 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidshx.sys 2013-07-10 01:32 - 2013-07-10 01:32 - 00039224 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx86.sys Files to move or delete: ==================== C:\Windows\Tasks\{FF57897C-1895-470E-96CD-C0F923DEEC95}.job ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-30 17:01 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 30-07-2013 04 Ran by Seegas at 2013-08-01 21:00:53 Running from C:\Users\Seegas\Desktop Boot Mode: Safe Mode (with Networking) ========================================================== ==================== Installed Programs ======================= Update for Microsoft Office 2007 (KB2508958) Adobe AIR (Version: 2.6.0.19140) Adobe Audition 3.0 (Version: 3.0) Adobe Flash Player 11 ActiveX (Version: 11.7.700.224) Adobe Flash Player 11 Plugin (Version: 11.8.800.94) Adobe Reader X - Deutsch (Version: 10.0.0) Analog Factory SE 1.2 ASIO4ALL (Version: 2.10) Audacity 1.3.12 (Unicode) AVG 2013 (Version: 13.0.3209) AVG 2013 (Version: 13.0.3392) AVG 2013 (Version: 2013.0.3392) Balsamiq Mockups For Desktop (Version: 2.0.21) Cisco EAP-FAST Module (Version: 2.2.14) Cisco LEAP Module (Version: 1.0.19) Cisco PEAP Module (Version: 1.1.6) D3DX10 (Version: 15.4.2368.0902) DivX-Setup (Version: 2.4.1.4) DLL Cure v2.8 (Version: 2.8) Driver & Utility (Version: 2.3) Dropbox (HKCU Version: 2.0.22) EasyBits GO EVEREST Home Edition v2.20 (Version: 2.20) FL Studio v7.0 Free YouTube Download version 2.10.33.324 GIMP 2.8.0 (Version: 2.8.0) Huur- en zorgtoeslag 2011 ICQ7.5 (Version: 7.5) Intel(R) Network Connections 15.7.176.0 (Version: 15.7.176.0) Java Auto Updater (Version: 2.0.3.1) Java(TM) 6 Update 24 (Version: 6.0.240) Last.fm Scrobbler 2.1.33 Live 8.0.4 Live 8.1.3 Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300) M-Audio Ozone Driver 6.0.2 (x86) (Version: 6.0.2) MediaCoder 0.7.5.4799 (Version: 0.7.5.4799) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6012.5000) Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Access MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Access Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000) Microsoft Office Excel MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office File Validation Add-In (Version: 14.0.5130.5003) Microsoft Office Groove MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Groove Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office InfoPath MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1) Microsoft Office OneNote MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Outlook MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office PowerPoint MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (Spanish) 2007 (Version: 12.0.6612.1000) Microsoft Office Proofing (English) 2007 (Version: 12.0.4518.1014) Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Publisher MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Shared MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Word MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219) Mozilla Firefox 22.0 (x86 de) (Version: 22.0) Mozilla Maintenance Service (Version: 22.0) MSI Afterburner 2.3.0 (Version: 2.3.0) MSI Kombustor 2.4.2 MSVCRT (Version: 15.4.2862.0708) Native Instruments Massive Native Instruments Massive (Version: 1.1.5.1967) No23 Recorder (Version: 2.1.0.3) NVIDIA 3D Vision Controller-Treiber 320.49 (Version: 320.49) NVIDIA 3D Vision Treiber 320.49 (Version: 320.49) NVIDIA Grafiktreiber 320.49 (Version: 320.49) NVIDIA HD-Audiotreiber 1.3.24.2 (Version: 1.3.24.2) NVIDIA Install Application (Version: 2.1002.124.810) NVIDIA PhysX (Version: 9.13.0604) NVIDIA PhysX-Systemsoftware 9.13.0604 (Version: 9.13.0604) NVIDIA Stereoscopic 3D Driver (Version: 7.17.13.2049) NVIDIA Systemsteuerung 320.49 (Version: 320.49) NVIDIA Update Components (Version: 4.11.9) PDFCreator (Version: 1.2.0) Pro Evolution Soccer 2011 (Version: 1.01.0000) Project64 1.6 (Version: 1.6) Realtek High Definition Audio Driver (Version: 6.0.1.5930) REALTEK Wireless LAN Driver and Utility (Version: 1.00.0142) rekordbox 1.4.1 (Version: 1.4.1) SampleTank 2 (Version: 2.5.2) Skype Click to Call (Version: 5.6.8442) Skype™ 5.10 (Version: 5.10.116) SpeechMike Executive SPSS 16.0 for Windows (Version: 16.0.1) Spybot - Search & Destroy (Version: 1.6.2) Steinberg Hypersonic v1.0 TuneUp Utilities (Version: 9.0.4700.23) TuneUp Utilities Language Pack (en-US) (Version: 9.0.4700.23) Ulead PhotoImpact 10 ESD (Version: 10.0) Uninstall 1.0.0.1 Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596802) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition Update for Microsoft Office Access 2007 Help (KB963663) Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office Infopath 2007 Help (KB963662) Update for Microsoft Office OneNote 2007 Help (KB963670) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition Update for Microsoft Office Outlook 2007 Help (KB963677) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2817563) 32-Bit Edition Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Publisher 2007 Help (KB963667) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) VC80CRTRedist - 8.0.50727.4053 (Version: 1.1.0) VLC media player 1.1.5 (Version: 1.1.5) Winamp (Version: 5.601 ) Winamp Erkennungs-Plug-in (HKCU Version: 1.0.0.1) Windows Live Communications Platform (Version: 15.4.3502.0922) Windows Live Essentials (Version: 15.4.3502.0922) Windows Live Essentials (Version: 15.4.3508.1109) Windows Live Fotogalerie (Version: 15.4.3502.0922) Windows Live ID Sign-in Assistant (Version: 7.250.4225.0) Windows Live Installer (Version: 15.4.3502.0922) Windows Live Movie Maker (Version: 15.4.3502.0922) Windows Live Photo Common (Version: 15.4.3502.0922) Windows Live Photo Gallery (Version: 15.4.3502.0922) Windows Live PIMT Platform (Version: 15.4.3508.1109) Windows Live SOXE (Version: 15.4.3502.0922) Windows Live SOXE Definitions (Version: 15.4.3502.0922) Windows Live UX Platform (Version: 15.4.3502.0922) Windows Live UX Platform Language Pack (Version: 15.4.3508.1109) WinRAR ==================== Restore Points ========================= 31-07-2013 17:02:26 Geplanter Prüfpunkt ==================== Hosts content: ========================== 2009-07-14 04:04 - 2013-07-29 19:19 - 00000578 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 download.com.vn 127.0.0.1 www.download.com.vn 127.0.0.1 9down.com 127.0.0.1 www.9down.com 127.0.0.1 download.eset.com 127.0.0.1 www.download.com 127.0.0.1 download.f-secure.com 127.0.0.1 mirror02.gdata.de 127.0.0.1 download.avg.com 127.0.0.1 spftrl.digitalriver.com 127.0.0.1 www.grisoft.cz 127.0.0.1 download1us.softpedia.com 127.0.0.1 download.softpedia.com 127.0.0.1 www.bitdefender.co.uk 127.0.0.1 www.bitdefender.com 127.0.0.1 www.kaspersky.com 127.0.0.1 bkav.com.vn 127.0.0.1 www.bkav.com.vn 127.0.0.1 www.symantec.com 127.0.0.1 free.avg.com ==================== Scheduled Tasks (whitelisted) ============= Task: {0D141843-7766-494A-ADC9-F91AD8CBA2C0} - System32\Tasks\ROC_REG_JAN_DELETE => C:\ProgramData\AVG January 2013 Campaign\ROC.exe [2013-01-17] () Task: {16924F50-FE2E-4D86-ACC7-F895567069A1} - System32\Tasks\Adobe Reader and Acrobat Manager => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-11-10] (Adobe Systems Incorporated) Task: {3538EACD-6BF5-49E0-8380-24F02CA1DE19} - System32\Tasks\Java Update Scheduler => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-10-29] (Sun Microsystems, Inc.) Task: {48B8E07D-D8C2-4B32-A001-C7DAC9BD10DB} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task Task: {7461A3C3-9291-479D-8145-456B715A56A8} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => C:\Windows\system32\rundll32.exe [2009-07-14] (Microsoft Corporation) Task: {9EBF682A-FDC6-4C00-898C-8052B544B048} - System32\Tasks\{0937F2CA-6493-4F83-84C0-0FFFBE49A4E2} => c:\program files\mozilla firefox\firefox.exe [2013-07-28] (Mozilla Corporation) Task: {A5FE7939-F158-4ABA-8C27-8C6F3B5C8A0D} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance => C:\Program Files\TuneUp Utilities 2010\OneClick.exe [2010-09-30] (TuneUp Software) Task: {A60EA6F2-A754-42AD-99F6-E45B1CDE232E} - System32\Tasks\Microsoft\Windows\WindowsBackup\Windows Backup Monitor => C:\Windows\system32\sdclt.exe [2010-11-20] (Microsoft Corporation) Task: {BB27A3C9-1EAB-4351-B7C9-A877D5BC0079} - System32\Tasks\{3EEBF002-A757-4F5A-8886-DB894EEFB07C} => C:\Program Files\Skype\\Phone\Skype.exe [2012-07-13] (Skype Technologies S.A.) Task: {C3D1FE1F-14BC-4CEF-B80D-623ECCBD8FBA} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-30] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\ROC_REG_JAN_DELETE.job => C:\ProgramData\AVG January 2013 Campaign\ROC.exe Task: C:\Windows\Tasks\{FF57897C-1895-470E-96CD-C0F923DEEC95}.job => c:\program files\mozilla firefox\firefox.exe ==================== Faulty Device Manager Devices ============= Name: Security Processor Loader Driver Description: Security Processor Loader Driver Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: spldr Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: sptd Description: sptd Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: sptd Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Microsoft PS/2-Maus Description: Microsoft PS/2-Maus Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Event log errors: ========================= Application errors: ================== Error: (08/01/2013 08:59:22 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich. Error: (08/01/2013 08:59:22 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (08/01/2013 08:59:22 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (08/01/2013 08:24:11 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich. Error: (08/01/2013 08:24:11 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (08/01/2013 08:24:11 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (08/01/2013 11:29:16 AM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich. Error: (08/01/2013 11:29:16 AM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (08/01/2013 11:29:16 AM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (08/01/2013 11:17:25 AM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich. System errors: ============= Error: (08/01/2013 08:57:20 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (08/01/2013 08:57:20 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (08/01/2013 08:57:20 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (08/01/2013 08:55:32 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (08/01/2013 08:55:32 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (08/01/2013 08:55:32 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (08/01/2013 08:55:27 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuchanbieter-Host" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (08/01/2013 08:55:24 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (08/01/2013 08:55:24 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (08/01/2013 08:55:24 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Microsoft Office Sessions: ========================= ==================== Memory info =========================== Percentage of memory in use: 23% Total physical RAM: 3063.09 MB Available physical RAM: 2330.61 MB Total Pagefile: 6124.48 MB Available Pagefile: 5447.67 MB Total Virtual: 2047.88 MB Available Virtual: 1924.39 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:420.6 GB) (Free:296.6 GB) NTFS Drive d: (Volume) (Fixed) (Total:195.31 GB) (Free:143.36 GB) NTFS Drive e: (Media) (Fixed) (Total:781.25 GB) (Free:220.65 GB) NTFS Drive f: (GRMCHPFRER_DE_DVD) (CDROM) (Total:2.29 GB) (Free:0 GB) UDF ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1397 GB) (Disk ID: 3FF1B45F) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=421 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=781 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=195 GB) - (Type=OF Extended) ==================== End Of Log ============================ |
02.08.2013, 13:35 | #10 |
/// Winkelfunktion /// TB-Süch-Tiger™ | SD-Karte: DCIM.exe ist keine zulässige win32-Anwendung Laufwerksemulationen abschalten mit Defogger Downloade Dir bitte defogger von jpshortstuff auf Deinem Desktop.
Rootkitscan mit GMER Bitte lade dir GMER herunter: (Dateiname zufällig)
Tauchen Probleme auf?
__________________ Logfiles bitte immer in CODE-Tags posten |
08.08.2013, 14:08 | #11 |
| SD-Karte: DCIM.exe ist keine zulässige win32-Anwendung .log von defogger: Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 14:54 on 08/08/2013 (Seegas) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... SPTD -> Disabled -=E.O.F=- Code:
ATTFilter GMER 2.1.19163 - hxxp://www.gmer.net Rootkit scan 2013-08-08 15:07:31 Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1 ST31500341AS rev.CC1H 1397,27GB Running: gmer_2.1.19163.exe; Driver: C:\Users\Seegas\AppData\Local\Temp\kgtorpob.sys ---- Kernel code sections - GMER 2.1 ---- .text ntkrnlpa.exe!ZwRollbackEnlistment + 140D 8264A9F5 1 Byte [06] .text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 826841F2 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3} ---- Devices - GMER 2.1 ---- AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\ Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x17 0xD6 0x4F 0x43 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x67 0xC7 0x77 0xC6 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x17 0xB9 0xF5 0x85 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\ Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x17 0xD6 0x4F 0x43 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x67 0xC7 0x77 0xC6 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x17 0xB9 0xF5 0x85 ... ---- EOF - GMER 2.1 ---- |
08.08.2013, 15:19 | #12 |
/// Winkelfunktion /// TB-Süch-Tiger™ | SD-Karte: DCIM.exe ist keine zulässige win32-Anwendung Adware/Junkware/Toolbars entfernen 1. Schritt: adwCleaner Downloade Dir bitte AdwCleaner auf deinen Desktop.
2. Schritt: JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
3. Schritt: Frisches Log mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ Logfiles bitte immer in CODE-Tags posten |
08.08.2013, 23:15 | #13 |
| SD-Karte: DCIM.exe ist keine zulässige win32-Anwendung adw-log: Code:
ATTFilter # AdwCleaner v2.306 - Datei am 08/08/2013 um 23:56:26 erstellt # Aktualisiert am 19/07/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits) # Benutzer : Seegas - SHORE-STATION # Bootmodus : Abgesicherter Modus mit Netzwerkunterstützung # Ausgeführt unter : C:\Users\Seegas\Desktop\virus removal\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** Datei Gelöscht : C:\Program Files\Mozilla Firefox\searchplugins\avg-secure-search.xml Datei Gelöscht : C:\Users\Seegas\AppData\Roaming\Mozilla\Firefox\Profiles\0r0ve8pn.default\searchplugins\icqplugin.xml Datei Gelöscht : C:\Users\Seegas\AppData\Roaming\Mozilla\Firefox\Profiles\0r0ve8pn.default\searchplugins\icqplugin-1.xml Datei Gelöscht : C:\Users\Seegas\AppData\Roaming\Mozilla\Firefox\Profiles\0r0ve8pn.default\searchplugins\icqplugin-2.xml Datei Gelöscht : C:\Users\Seegas\AppData\Roaming\Mozilla\Firefox\Profiles\0r0ve8pn.default\searchplugins\web-search.xml Ordner Gelöscht : C:\Program Files\AVG Secure Search Ordner Gelöscht : C:\Program Files\Common Files\AVG Secure Search Ordner Gelöscht : C:\Program Files\Common Files\DVDVideoSoft\TB Ordner Gelöscht : C:\Program Files\ICQ6Toolbar Ordner Gelöscht : C:\ProgramData\AVG Secure Search Ordner Gelöscht : C:\ProgramData\ICQ\ICQToolbar Ordner Gelöscht : C:\Users\Seegas\AppData\Local\AVG Secure Search Ordner Gelöscht : C:\Users\Seegas\AppData\Local\Conduit Ordner Gelöscht : C:\Users\Seegas\AppData\LocalLow\AVG Secure Search Ordner Gelöscht : C:\Users\Seegas\AppData\LocalLow\Conduit Ordner Gelöscht : C:\Users\Seegas\AppData\LocalLow\PriceGong Ordner Gelöscht : C:\Users\Seegas\AppData\Roaming\dvdvideosoftiehelpers Ordner Gelöscht : C:\Users\Seegas\AppData\Roaming\Mozilla\Firefox\Profiles\0r0ve8pn.default\extensions\{ACAA314B-EEBA-48E4-AD47-84E31C44796C} ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\PriceGong Schlüssel Gelöscht : HKCU\Software\AVG Secure Search Schlüssel Gelöscht : HKCU\Software\Conduit Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{872B5B88-9DB5-4310-BDD0-AC189557E5F5} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKLM\SOFTWARE\14919ea49a8f3b4aa3cf1058d9a64cec Schlüssel Gelöscht : HKLM\Software\AVG Secure Search Schlüssel Gelöscht : HKLM\Software\AVG Security Toolbar Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Conduit.Engine Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2269050 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1 Schlüssel Gelöscht : HKLM\Software\ICQ\ICQToolbar Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706} Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin Schlüssel Gelöscht : HKLM\SOFTWARE\Software Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{872B5B88-9DB5-4310-BDD0-AC189557E5F5}] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt] Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar] ***** [Internet Browser] ***** -\\ Internet Explorer v10.0.9200.16635 Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://start.icq.com/ --> hxxp://www.google.com Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - ICQ Search] = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd --> hxxp://www.google.com -\\ Mozilla Firefox v22.0 (de) Datei : C:\Users\Seegas\AppData\Roaming\Mozilla\Firefox\Profiles\0r0ve8pn.default\prefs.js C:\Users\Seegas\AppData\Roaming\Mozilla\Firefox\Profiles\0r0ve8pn.default\user.js ... Gelöscht ! Gelöscht : user_pref("avg.install.installDirPath", "C:\\ProgramData\\AVG Secure Search\\FireFoxExt\\14.0.0.14")[...] Gelöscht : user_pref("avg.install.userHPSettings", "hxxp://start.icq.com/"); Gelöscht : user_pref("extensions.vshare@toolbar.update.enabled", false); Gelöscht : user_pref("icqtoolbar.allowSendURL", false); Gelöscht : user_pref("icqtoolbar.engineVerified", false); Gelöscht : user_pref("icqtoolbar.geolastmodified", 1322227240); Gelöscht : user_pref("icqtoolbar.hiddenElements", "itb_options"); Gelöscht : user_pref("icqtoolbar.history", "%23%20%23%20%23%20%23%20*%20Patrick%20Jakob%20Los%20Wechsel%20du%20[...] Gelöscht : user_pref("icqtoolbar.icqgeo", 49); Gelöscht : user_pref("icqtoolbar.installTime", "1322655727"); Gelöscht : user_pref("icqtoolbar.installsource", "1"); Gelöscht : user_pref("icqtoolbar.newtab_state", "1"); Gelöscht : user_pref("icqtoolbar.numberOfSearches", 0); Gelöscht : user_pref("icqtoolbar.previousFFVersion", "3.6.24"); Gelöscht : user_pref("icqtoolbar.skip_default_search", "no"); Gelöscht : user_pref("icqtoolbar.suggestions", false); Gelöscht : user_pref("icqtoolbar.uninstStatSent", true); Gelöscht : user_pref("icqtoolbar.uniqueID", "130726364013072628301307455483409"); Gelöscht : user_pref("icqtoolbar.usageStatstTimestamp", 1322655730); Gelöscht : user_pref("icqtoolbar.version", "1.4.1"); Gelöscht : user_pref("icqtoolbar.voucherHideClicks", 0); Gelöscht : user_pref("icqtoolbar.voucherMoreLinkClicks", 0); Gelöscht : user_pref("icqtoolbar.voucherRedeemClicks", 0); Gelöscht : user_pref("icqtoolbar.voucherWasShown", 0); Gelöscht : user_pref("icqtoolbar.xmlEnableSuggestions", false); Gelöscht : user_pref("icqtoolbar.xmlLanguage", "de"); Gelöscht : user_pref("keyword.URL", "hxxp://vshare.toolbarhome.com/search.aspx?srch=ku&q="); Gelöscht : user_pref("vshare.install.date", "1301702400000"); Gelöscht : user_pref("vshare.install.dumpFileCount", 0); Gelöscht : user_pref("vshare.install.dumpFileDisabled", false); Gelöscht : user_pref("vshare.install.finished", "1.0.0"); Gelöscht : user_pref("vshare.install.guid", "{a958a450-8b3f-4b82-a001-0a7f45645f11}"); Gelöscht : user_pref("vshare.install.istoolbarhp", true); Gelöscht : user_pref("vshare.install.istoolbarsearch", true); Gelöscht : user_pref("vshare.install.laststatreq", "1301702400000"); Gelöscht : user_pref("vshare.install.newtab", true); Gelöscht : user_pref("vshare.install.overlayVersion", 1); Gelöscht : user_pref("vshare.install.userHPSettings", ""); Gelöscht : user_pref("vshare.install.userSPSettings", ""); Datei : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\8qk3rnlp.default\prefs.js [OK] Die Datei ist sauber. ************************* AdwCleaner[R1].txt - [10132 octets] - [08/08/2013 23:55:56] AdwCleaner[S1].txt - [10074 octets] - [08/08/2013 23:56:26] ########## EOF - C:\AdwCleaner[S1].txt - [10135 octets] ########## Code:
ATTFilter Junkware Removal Tool (JRT) by Thisisu Version: 5.3.8 (08.07.2013:4) OS: Windows 7 Home Premium x86 Ran by Seegas on 09.08.2013 at 0:06:45,23 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\trolltech ~~~ Files Successfully deleted: [File] "C:\Windows\system32\authuitu.dll" Successfully deleted: [File] "C:\Windows\system32\turegopt.exe" ~~~ Folders Successfully deleted: [Empty Folder] C:\Users\Seegas\appdata\local\{020E55B0-30AA-42FF-9656-C753EFC86A3E} Successfully deleted: [Empty Folder] C:\Users\Seegas\appdata\local\{0A8236BA-E1FD-4EB8-BB07-D1E27812DD1B} Successfully deleted: [Empty Folder] C:\Users\Seegas\appdata\local\{0D9732AA-0223-4027-808F-165D014DE4CE} Successfully deleted: [Empty Folder] C:\Users\Seegas\appdata\local\{1D3F8E5F-0F15-417F-AE9B-C9F0526B9EA1} Successfully deleted: [Empty Folder] C:\Users\Seegas\appdata\local\{2F4A376D-0D8B-4830-A861-8E6C727F0D3D} Successfully deleted: [Empty Folder] C:\Users\Seegas\appdata\local\{3BA5225F-0E5F-4823-B185-42610620AED9} Successfully deleted: [Empty Folder] C:\Users\Seegas\appdata\local\{4130B0CE-FC1B-48B9-AC38-1A902618340F} Successfully deleted: [Empty Folder] C:\Users\Seegas\appdata\local\{48976423-2E5B-41BF-8B7B-A4F6F45CBD6F} Successfully deleted: [Empty Folder] C:\Users\Seegas\appdata\local\{661D8880-F65E-441F-A9EA-045E14E570D3} Successfully deleted: [Empty Folder] C:\Users\Seegas\appdata\local\{680F2031-7582-4B28-A291-3F478005C8EC} Successfully deleted: [Empty Folder] C:\Users\Seegas\appdata\local\{8BD0C256-8C18-45E8-93C6-6A26D9F78355} Successfully deleted: [Empty Folder] C:\Users\Seegas\appdata\local\{8FC21185-82D4-4BCF-A0DE-3CE7337E232A} Successfully deleted: [Empty Folder] C:\Users\Seegas\appdata\local\{913D4376-22F7-4790-98C2-8D1710C21A02} Successfully deleted: [Empty Folder] C:\Users\Seegas\appdata\local\{9E41E17B-8D97-49CF-AE7A-7FC01E9CA743} Successfully deleted: [Empty Folder] C:\Users\Seegas\appdata\local\{B07AF434-C159-49F4-BFD3-35D0E53801E8} Successfully deleted: [Empty Folder] C:\Users\Seegas\appdata\local\{BDC60D6A-4576-4122-B343-C4FFB6AFCFC9} Successfully deleted: [Empty Folder] C:\Users\Seegas\appdata\local\{C1767E83-F0CE-440E-81E0-3DD54E3BAEAC} Successfully deleted: [Empty Folder] C:\Users\Seegas\appdata\local\{C9D8BABB-C12A-4E9E-94DF-00156E4237D1} Successfully deleted: [Empty Folder] C:\Users\Seegas\appdata\local\{E19A156C-E072-4A07-8E52-D3F1AB60A916} Successfully deleted: [Empty Folder] C:\Users\Seegas\appdata\local\{F0CF5075-3D07-4661-B14E-42882052C94C} ~~~ FireFox Emptied folder: C:\Users\Seegas\AppData\Roaming\mozilla\firefox\profiles\0r0ve8pn.default\minidumps [31 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 09.08.2013 at 0:07:53,00 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 08-08-2013 02 Ran by Seegas (administrator) on 09-08-2013 00:13:41 Running from C:\Users\Seegas\Desktop Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Safe Mode (with Networking) ==================== Processes (Whitelisted) =================== (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7731744 2009-09-02] (Realtek Semiconductor) HKLM\...\Run: [WinampAgent] - C:\Program Files\Winamp\winampa.exe [74752 2010-12-07] (Nullsoft, Inc.) HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM\...\Run: [M-Audio Taskbar Icon] - C:\Windows\system32\M-AudioTaskBarIcon.exe [643592 2009-09-23] (Avid Technology, Inc.) HKLM\...\Run: [PspContr] - C:\Windows\system32\PspContr.Exe [376832 2004-03-11] (Philips Speech Processing) HKLM\...\Run: [DivXUpdate] - C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1230704 2011-03-21] () HKLM\...\Run: [Ulead AutoDetector v2] - C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe [90112 2004-08-27] (Ulead Systems, Inc.) HKLM\...\Run: [AVG_UI] - C:\Program Files\AVG\AVG2013\avgui.exe [4411440 2013-07-01] (AVG Technologies CZ, s.r.o.) HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [17418928 2012-07-13] (Skype Technologies S.A.) HKCU\...\RunOnce: [Report] - C:\AdwCleaner[S1].txt [10205 2013-08-08] () HKCU\...\Winlogon: [Shell] explorer.exe <==== ATTENTION MountPoints2: {697da9f3-0f59-11e0-8119-806e6f6e6963} - F:\setup.exe HKU\Gast\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [ 2010-04-01] (DT Soft Ltd) HKU\Gast\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [ 2012-07-13] (Skype Technologies S.A.) HKU\Gast\...\Run: [ICQ] - C:\Program Files\ICQ7.2\ICQ.exe [ 2011-01-05] (ICQ, LLC.) Startup: C:\Users\Seegas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Seegas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Seegas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {3A5EF8C0-948A-4039-A01E-FC04D9B0E3F5} URL = hxxp://nl.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=827316&p={searchTerms} BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) BHO: DivX HiQ - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Seegas\AppData\Roaming\Mozilla\Firefox\Profiles\0r0ve8pn.default FF SelectedSearchEngine: Google FF Homepage: hxxp://www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF SearchPlugin: C:\Users\Seegas\AppData\Roaming\Mozilla\Firefox\Profiles\0r0ve8pn.default\searchplugins\searchplugins-backup FF Extension: No Name - C:\Users\Seegas\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} FF Extension: No Name - C:\Users\Seegas\AppData\Roaming\Mozilla\Firefox\Profiles\0r0ve8pn.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF Extension: Default - C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF Extension: Default - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video FF Extension: No Name - C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video FF HKLM\...\Firefox\Extensions: [{6904342A-8307-11DF-A508-4AE2DFD72085}] C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa FF Extension: No Name - C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa ========================== Services (Whitelisted) ================= S2 AVGIDSAgent; C:\Program Files\AVG\AVG2013\avgidsagent.exe [4939312 2013-07-04] (AVG Technologies CZ, s.r.o.) S2 avgwd; C:\Program Files\AVG\AVG2013\avgwdsvc.exe [283136 2013-07-23] (AVG Technologies CZ, s.r.o.) S2 Intel(R) PROSet Monitoring Service; C:\Windows\system32\IProsetMonitor.exe [110752 2010-09-22] (Intel Corporation) S2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S2 Realtek11nSU; C:\Program Files\Realtek\11n USB Wireless LAN Utility\RtlService.exe [40960 2009-12-07] (Realtek) S3 TuneUp.Defrag; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [435008 2011-05-22] (TuneUp Software) S2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [1051968 2010-09-30] (TuneUp Software) S2 vToolbarUpdater15.4.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\ToolbarUpdater.exe [x] ==================== Drivers (Whitelisted) ==================== S1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [208184 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [60216 2013-07-20] (AVG Technologies CZ, s.r.o.) S1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [22328 2013-03-01] (AVG Technologies CZ, s.r.o.) S1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [171320 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [246072 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [96568 2013-07-01] (AVG Technologies CZ, s.r.o.) R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [39224 2013-07-10] (AVG Technologies CZ, s.r.o.) R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [182072 2013-03-21] (AVG Technologies CZ, s.r.o.) R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [37664 2013-08-01] (AVG Technologies) S3 CrystalSysInfo; C:\Program Files\MediaCoder\SysInfo.sys [15152 2007-09-25] () S3 EverestDriver; C:\Program Files\Lavalys\EVEREST Home Edition\kerneld.wnt [7168 2005-08-18] () S3 MADFUOZONE; C:\Windows\System32\DRIVERS\MAudioOzone_DFU.sys [42248 2009-09-23] (M-Audio) S3 MAUSBOZONE; C:\Windows\System32\DRIVERS\MAudioOzone.sys [158344 2009-09-23] (Avid Technology, Inc.) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) S3 RTCore32; C:\Program Files\MSI Afterburner\RTCore32.sys [5632 2011-09-06] () S4 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2010-12-24] (Duplex Secure Ltd.) S3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [10064 2010-02-24] (TuneUp Software) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-09 00:06 - 2013-08-09 00:06 - 00000000 ____D C:\Windows\ERUNT 2013-08-09 00:02 - 2013-08-09 00:02 - 00325056 _____ C:\Windows\Minidump\080913-24975-01.dmp 2013-08-08 23:59 - 2013-08-08 23:59 - 00297024 _____ C:\Windows\Minidump\080813-27549-01.dmp 2013-08-08 23:56 - 2013-08-08 23:56 - 00010205 _____ C:\AdwCleaner[S1].txt 2013-08-08 23:55 - 2013-08-08 23:56 - 00010132 _____ C:\AdwCleaner[R1].txt 2013-08-08 23:50 - 2013-08-08 23:50 - 00669752 _____ C:\Windows\Minidump\080813-27440-01.dmp 2013-08-08 23:43 - 2013-08-08 23:43 - 00464328 _____ C:\Windows\Minidump\080813-30357-01.dmp 2013-08-08 21:27 - 2013-08-08 21:27 - 00319696 _____ C:\Windows\Minidump\080813-32947-01.dmp 2013-08-08 21:23 - 2013-08-08 21:23 - 00357656 _____ C:\Windows\Minidump\080813-26894-01.dmp 2013-08-08 20:19 - 2013-08-09 00:11 - 00000000 ____D C:\Users\Seegas\Desktop\virus removal 2013-08-08 14:54 - 2013-08-08 14:55 - 00000020 _____ C:\Users\Seegas\defogger_reenable 2013-08-08 14:53 - 2013-08-08 14:53 - 00523264 _____ C:\Windows\Minidump\080813-30997-01.dmp 2013-08-08 14:51 - 2013-08-08 14:51 - 00347400 _____ C:\Windows\Minidump\080813-29608-01.dmp 2013-08-08 14:43 - 2013-08-08 14:43 - 00639672 _____ C:\Windows\Minidump\080813-30186-01.dmp 2013-08-02 12:03 - 2013-08-02 12:03 - 00382808 _____ C:\Windows\Minidump\080213-25162-01.dmp 2013-08-02 11:18 - 2013-08-02 11:18 - 00277272 _____ C:\Windows\Minidump\080213-23743-01.dmp 2013-08-02 11:07 - 2013-08-02 11:07 - 00498944 _____ C:\Windows\Minidump\080213-30404-01.dmp 2013-08-02 11:04 - 2013-08-02 11:04 - 00225288 _____ C:\Windows\Minidump\080213-23337-01.dmp 2013-08-02 02:10 - 2013-07-31 10:57 - 125532593 _____ C:\Users\Seegas\Desktop\wow.mp4 2013-08-01 12:25 - 2013-08-01 12:25 - 00003715 _____ C:\Program Files\Mozilla Firefoxavg-secure-search.xml 2013-08-01 11:24 - 2013-08-01 11:24 - 00847144 _____ C:\Windows\Minidump\080113-27518-01.dmp 2013-07-31 17:11 - 2013-07-31 17:11 - 00395024 _____ C:\Windows\Minidump\073113-40326-01.dmp 2013-07-31 16:36 - 2013-07-31 16:36 - 00413240 _____ C:\Windows\Minidump\073113-39483-01.dmp 2013-07-31 16:28 - 2013-07-31 16:28 - 00459136 _____ C:\Windows\Minidump\073113-35256-01.dmp 2013-07-31 16:11 - 2013-07-31 16:11 - 00394024 _____ C:\Windows\Minidump\073113-35209-01.dmp 2013-07-31 15:07 - 2013-07-31 15:07 - 00002562 _____ C:\Windows\diagwrn.xml 2013-07-31 15:07 - 2013-07-31 15:07 - 00001908 _____ C:\Windows\diagerr.xml 2013-07-31 14:47 - 2013-08-09 00:12 - 01230104 _____ (Farbar) C:\Users\Seegas\Desktop\FRST.exe 2013-07-31 11:59 - 2013-07-31 11:59 - 00732952 _____ C:\Windows\Minidump\073113-49140-01.dmp 2013-07-31 11:30 - 2013-07-31 11:30 - 00000000 ____D C:\FRST 2013-07-31 01:22 - 2013-07-31 01:22 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-07-31 01:22 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-07-31 00:24 - 2013-07-31 00:24 - 00000000 ____D C:\Users\Seegas\Desktop\Mucke 2013 2013-07-30 18:26 - 2013-04-17 09:02 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2013-07-30 07:05 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 14329856 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 13760512 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 03419136 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 02877440 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-30 01:08 - 2013-07-30 01:08 - 02284544 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 02046976 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 01988096 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 01441280 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-07-30 01:08 - 2013-07-30 01:08 - 01400416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-07-30 01:08 - 2013-07-30 01:08 - 01158144 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 01080832 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00906240 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00745472 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00719360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00629248 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00604160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00361984 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-07-30 01:08 - 2013-07-30 01:08 - 00357888 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00242200 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00232960 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00204800 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00187392 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00138752 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00137216 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00125440 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00117248 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00110592 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00079872 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00073728 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-07-30 01:08 - 2013-07-30 01:08 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-07-30 01:06 - 2013-07-30 01:11 - 00010332 _____ C:\Windows\IE10_main.log 2013-07-30 00:49 - 2013-08-01 12:24 - 00037664 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx86.sys 2013-07-30 00:44 - 2013-05-10 05:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll 2013-07-30 00:44 - 2013-04-26 06:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2013-07-30 00:44 - 2013-04-26 01:30 - 01505280 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll 2013-07-30 00:43 - 2013-06-05 05:05 - 02347520 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-30 00:43 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-30 00:43 - 2013-05-13 06:45 - 01160192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-07-30 00:43 - 2013-05-13 06:45 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-07-30 00:43 - 2013-05-13 06:45 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-07-30 00:43 - 2013-05-13 05:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe 2013-07-30 00:43 - 2013-05-13 05:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll 2013-07-30 00:43 - 2013-05-08 07:38 - 01293672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-07-30 00:43 - 2013-05-06 07:06 - 03968872 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2013-07-30 00:43 - 2013-05-06 07:06 - 03913576 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-07-30 00:43 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-30 00:24 - 2013-08-08 23:59 - 00000000 ____D C:\ProgramData\NVIDIA 2013-07-30 00:24 - 2013-07-30 00:24 - 00000020 ___SH C:\Users\UpdatusUser\ntuser.ini 2013-07-30 00:24 - 2013-07-30 00:24 - 00000000 _SHDL C:\Users\UpdatusUser\Startmenü 2013-07-30 00:24 - 2013-07-30 00:24 - 00000000 _SHDL C:\Users\UpdatusUser\Netzwerkumgebung 2013-07-30 00:24 - 2013-07-30 00:24 - 00000000 _SHDL C:\Users\UpdatusUser\Druckumgebung 2013-07-30 00:24 - 2013-07-30 00:24 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Musik 2013-07-30 00:24 - 2013-07-30 00:24 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Bilder 2013-07-30 00:24 - 2013-07-30 00:24 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Verlauf 2013-07-30 00:24 - 2013-07-30 00:24 - 00000000 ____D C:\Program Files\AGEIA Technologies 2013-07-30 00:24 - 2013-07-30 00:24 - 00000000 ____D C:\36451beb2f9b1baa17dfcfb1f71c53 2013-07-30 00:24 - 2013-01-15 16:03 - 00000000 ____D C:\Users\UpdatusUser\AppData\Roaming\TuneUp Software 2013-07-30 00:24 - 2011-05-16 23:10 - 00000000 ____D C:\Users\UpdatusUser\AppData\Roaming\Macromedia 2013-07-30 00:24 - 2011-04-21 11:51 - 00000000 ____D C:\Users\UpdatusUser\AppData\Local\Microsoft Help 2013-07-30 00:23 - 2013-07-30 00:24 - 00000000 ____D C:\Windows\B9DB4C7601A446D58910F7AA6376DBAF.TMP 2013-07-30 00:23 - 2013-07-30 00:23 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2013-07-30 00:23 - 2013-06-21 14:02 - 00053024 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2013-07-30 00:23 - 2013-06-21 11:52 - 04192544 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2013-07-30 00:23 - 2013-06-21 11:52 - 03045664 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc.dll 2013-07-30 00:23 - 2013-06-21 11:52 - 02555168 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2013-07-30 00:23 - 2013-06-21 11:52 - 00640288 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2013-07-30 00:23 - 2013-06-21 11:52 - 00223008 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2013-07-30 00:23 - 2013-06-21 11:52 - 00062752 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2013-07-30 00:22 - 2013-07-30 00:45 - 00000000 ____D C:\Users\Seegas\AppData\Roaming\DeepBurner 2013-07-30 00:22 - 2013-06-21 14:02 - 21102368 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv32.dll 2013-07-30 00:22 - 2013-06-21 14:02 - 17560352 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2013-07-30 00:22 - 2013-06-21 14:02 - 13411896 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2um.dll 2013-07-30 00:22 - 2013-06-21 14:02 - 12427240 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dum.dll 2013-07-30 00:22 - 2013-06-21 14:02 - 09069344 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2013-07-30 00:22 - 2013-06-21 14:02 - 07687592 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2013-07-30 00:22 - 2013-06-21 14:02 - 06324360 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2013-07-30 00:22 - 2013-06-21 14:02 - 02777888 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2013-07-30 00:22 - 2013-06-21 14:02 - 02597856 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi.dll 2013-07-30 00:22 - 2013-06-21 14:02 - 02002720 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2013-07-30 00:22 - 2013-06-21 14:02 - 01024288 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco3232049.dll 2013-07-30 00:22 - 2013-06-21 14:02 - 00893728 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco3232049.dll 2013-07-30 00:22 - 2013-06-21 14:02 - 00467232 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR.dll 2013-07-30 00:22 - 2013-06-21 14:02 - 00465184 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC.dll 2013-07-30 00:22 - 2013-06-21 14:02 - 00016437 _____ C:\Windows\system32\nvinfo.pb 2013-07-30 00:22 - 2013-02-25 07:27 - 00154400 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda32v.sys 2013-07-30 00:22 - 2013-02-25 07:27 - 00028448 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap32.dll 2013-07-30 00:22 - 2013-01-29 10:35 - 00892704 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco3220103.dll 2013-07-30 00:21 - 2013-07-30 00:21 - 00001055 _____ C:\Users\Seegas\Desktop\DeepBurner.lnk 2013-07-30 00:21 - 2013-07-30 00:21 - 00001055 _____ C:\Users\Gast\Desktop\DeepBurner.lnk 2013-07-30 00:21 - 2013-07-30 00:21 - 00001055 _____ C:\Users\Administrator\Desktop\DeepBurner.lnk 2013-07-30 00:21 - 2013-07-30 00:21 - 00000000 ____D C:\Program Files\Astonsoft 2013-07-29 00:18 - 2013-07-29 00:18 - 00000356 _____ C:\Windows\Tasks\{FF57897C-1895-470E-96CD-C0F923DEEC95}.job 2013-07-28 23:31 - 2013-07-29 10:47 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-07-28 21:43 - 2013-07-28 21:43 - 00013712 _____ C:\Windows\system32\y 2013-07-28 21:43 - 2013-07-28 21:43 - 00013712 _____ C:\Windows\system32\w 2013-07-28 21:43 - 2013-07-28 21:43 - 00013712 _____ C:\Windows\system32\rar.exe 2013-07-20 01:51 - 2013-07-20 01:51 - 00246072 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avglogx.sys 2013-07-20 01:50 - 2013-07-20 01:50 - 00208184 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdriverx.sys 2013-07-20 01:50 - 2013-07-20 01:50 - 00171320 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgldx86.sys 2013-07-20 01:50 - 2013-07-20 01:50 - 00060216 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidshx.sys 2013-07-10 01:32 - 2013-07-10 01:32 - 00039224 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx86.sys ==================== One Month Modified Files and Folders ======= 2013-08-09 00:12 - 2013-07-31 14:47 - 01230104 _____ (Farbar) C:\Users\Seegas\Desktop\FRST.exe 2013-08-09 00:12 - 2010-12-24 19:14 - 00000000 ____D C:\Users\Seegas\AppData\Roaming\Skype 2013-08-09 00:11 - 2013-08-08 20:19 - 00000000 ____D C:\Users\Seegas\Desktop\virus removal 2013-08-09 00:08 - 2010-12-24 14:38 - 00005374 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-09 00:06 - 2013-08-09 00:06 - 00000000 ____D C:\Windows\ERUNT 2013-08-09 00:02 - 2013-08-09 00:02 - 00325056 _____ C:\Windows\Minidump\080913-24975-01.dmp 2013-08-09 00:02 - 2010-12-24 17:31 - 292459969 _____ C:\Windows\MEMORY.DMP 2013-08-09 00:02 - 2010-12-24 17:31 - 00000000 ____D C:\Windows\Minidump 2013-08-09 00:01 - 2011-04-06 22:23 - 00000000 ____D C:\Users\Seegas\AppData\Roaming\Dropbox 2013-08-09 00:00 - 2011-04-06 22:24 - 00000000 ___RD C:\Users\Seegas\Dropbox 2013-08-08 23:59 - 2013-08-08 23:59 - 00297024 _____ C:\Windows\Minidump\080813-27549-01.dmp 2013-08-08 23:59 - 2013-07-30 00:24 - 00000000 ____D C:\ProgramData\NVIDIA 2013-08-08 23:59 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-08 23:59 - 2009-07-14 06:39 - 00002709 _____ C:\Windows\setupact.log 2013-08-08 23:56 - 2013-08-08 23:56 - 00010205 _____ C:\AdwCleaner[S1].txt 2013-08-08 23:56 - 2013-08-08 23:55 - 00010132 _____ C:\AdwCleaner[R1].txt 2013-08-08 23:50 - 2013-08-08 23:50 - 00669752 _____ C:\Windows\Minidump\080813-27440-01.dmp 2013-08-08 23:47 - 2010-12-24 14:36 - 01949161 _____ C:\Windows\WindowsUpdate.log 2013-08-08 23:43 - 2013-08-08 23:43 - 00464328 _____ C:\Windows\Minidump\080813-30357-01.dmp 2013-08-08 21:27 - 2013-08-08 21:27 - 00319696 _____ C:\Windows\Minidump\080813-32947-01.dmp 2013-08-08 21:23 - 2013-08-08 21:23 - 00357656 _____ C:\Windows\Minidump\080813-26894-01.dmp 2013-08-08 20:57 - 2012-12-13 13:08 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-08 20:05 - 2009-07-14 06:34 - 00015152 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-08 20:05 - 2009-07-14 06:34 - 00015152 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-08 20:01 - 2012-02-06 13:16 - 00000000 ____D C:\ProgramData\MFAData 2013-08-08 14:55 - 2013-08-08 14:54 - 00000020 _____ C:\Users\Seegas\defogger_reenable 2013-08-08 14:54 - 2010-12-24 14:36 - 00000000 ____D C:\Users\Seegas 2013-08-08 14:53 - 2013-08-08 14:53 - 00523264 _____ C:\Windows\Minidump\080813-30997-01.dmp 2013-08-08 14:51 - 2013-08-08 14:51 - 00347400 _____ C:\Windows\Minidump\080813-29608-01.dmp 2013-08-08 14:43 - 2013-08-08 14:43 - 00639672 _____ C:\Windows\Minidump\080813-30186-01.dmp 2013-08-02 12:03 - 2013-08-02 12:03 - 00382808 _____ C:\Windows\Minidump\080213-25162-01.dmp 2013-08-02 11:18 - 2013-08-02 11:18 - 00277272 _____ C:\Windows\Minidump\080213-23743-01.dmp 2013-08-02 11:07 - 2013-08-02 11:07 - 00498944 _____ C:\Windows\Minidump\080213-30404-01.dmp 2013-08-02 11:04 - 2013-08-02 11:04 - 00225288 _____ C:\Windows\Minidump\080213-23337-01.dmp 2013-08-01 12:25 - 2013-08-01 12:25 - 00003715 _____ C:\Program Files\Mozilla Firefoxavg-secure-search.xml 2013-08-01 12:24 - 2013-07-30 00:49 - 00037664 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx86.sys 2013-08-01 11:24 - 2013-08-01 11:24 - 00847144 _____ C:\Windows\Minidump\080113-27518-01.dmp 2013-08-01 11:11 - 2010-12-24 14:56 - 00111002 _____ C:\Windows\PFRO.log 2013-08-01 11:11 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\AppCompat 2013-07-31 17:11 - 2013-07-31 17:11 - 00395024 _____ C:\Windows\Minidump\073113-40326-01.dmp 2013-07-31 16:36 - 2013-07-31 16:36 - 00413240 _____ C:\Windows\Minidump\073113-39483-01.dmp 2013-07-31 16:28 - 2013-07-31 16:28 - 00459136 _____ C:\Windows\Minidump\073113-35256-01.dmp 2013-07-31 16:11 - 2013-07-31 16:11 - 00394024 _____ C:\Windows\Minidump\073113-35209-01.dmp 2013-07-31 15:07 - 2013-07-31 15:07 - 00002562 _____ C:\Windows\diagwrn.xml 2013-07-31 15:07 - 2013-07-31 15:07 - 00001908 _____ C:\Windows\diagerr.xml 2013-07-31 15:07 - 2009-07-14 06:39 - 00000000 _____ C:\Windows\setuperr.log 2013-07-31 11:59 - 2013-07-31 11:59 - 00732952 _____ C:\Windows\Minidump\073113-49140-01.dmp 2013-07-31 11:32 - 2010-12-24 20:23 - 00000000 ____D C:\Users\Seegas\AppData\Local\Last.fm 2013-07-31 11:32 - 2010-12-24 20:23 - 00000000 ____D C:\Program Files\Last.fm 2013-07-31 11:31 - 2013-02-06 19:16 - 00000951 _____ C:\Users\Public\Desktop\AVG 2013.lnk 2013-07-31 11:30 - 2013-07-31 11:30 - 00000000 ____D C:\FRST 2013-07-31 10:57 - 2013-08-02 02:10 - 125532593 _____ C:\Users\Seegas\Desktop\wow.mp4 2013-07-31 01:22 - 2013-07-31 01:22 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-07-31 00:56 - 2010-12-24 19:37 - 00000000 ____D C:\Users\Seegas\AppData\Roaming\vlc 2013-07-31 00:24 - 2013-07-31 00:24 - 00000000 ____D C:\Users\Seegas\Desktop\Mucke 2013 2013-07-30 17:09 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache 2013-07-30 15:39 - 2011-04-06 22:23 - 00000000 ____D C:\Users\Seegas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2013-07-30 07:08 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET 2013-07-30 06:59 - 2009-07-14 06:33 - 00440488 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-30 06:57 - 2009-07-14 10:56 - 00000000 ____D C:\Program Files\Windows Journal 2013-07-30 06:57 - 2009-07-14 06:52 - 00000000 ____D C:\Program Files\Windows Defender 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\zh-TW 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\zh-HK 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\zh-CN 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\tr-TR 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\sv-SE 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\ru-RU 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\pt-PT 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\pt-BR 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\pl-PL 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\nl-NL 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\nb-NO 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\ko-KR 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\ja-JP 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\it-IT 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\hu-HU 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\fr-FR 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\fi-FI 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\el-GR 2013-07-30 06:57 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\de-DE 2013-07-30 01:20 - 2010-12-26 18:43 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-07-30 01:11 - 2013-07-30 01:06 - 00010332 _____ C:\Windows\IE10_main.log 2013-07-30 01:08 - 2013-07-30 01:08 - 14329856 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 13760512 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 03419136 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 02877440 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-30 01:08 - 2013-07-30 01:08 - 02284544 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 02046976 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 01988096 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 01441280 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-07-30 01:08 - 2013-07-30 01:08 - 01400416 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-07-30 01:08 - 2013-07-30 01:08 - 01158144 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 01080832 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00906240 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00745472 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00719360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00629248 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00604160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00361984 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-07-30 01:08 - 2013-07-30 01:08 - 00357888 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00242200 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00232960 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00226816 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00204800 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00187392 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00138752 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00137216 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00125440 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00117248 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00110592 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00079872 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00073728 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-07-30 01:08 - 2013-07-30 01:08 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-07-30 01:08 - 2013-07-30 01:08 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-07-30 01:08 - 2013-07-30 01:08 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-07-30 01:03 - 2011-01-05 14:23 - 00000000 ____D C:\Users\Seegas\Desktop\Uni 2013-07-30 00:57 - 2012-12-13 13:08 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-07-30 00:57 - 2011-06-07 22:00 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-07-30 00:54 - 2011-02-04 13:59 - 00000000 ____D C:\Program Files\Philips Speech 2013-07-30 00:50 - 2012-12-13 12:10 - 00000000 ____D C:\Users\Seegas\AppData\Local\Avg2013 2013-07-30 00:45 - 2013-07-30 00:22 - 00000000 ____D C:\Users\Seegas\AppData\Roaming\DeepBurner 2013-07-30 00:26 - 2011-01-04 16:37 - 00000000 ____D C:\Users\Seegas\AppData\Local\Adobe 2013-07-30 00:24 - 2013-07-30 00:24 - 00000020 ___SH C:\Users\UpdatusUser\ntuser.ini 2013-07-30 00:24 - 2013-07-30 00:24 - 00000000 _SHDL C:\Users\UpdatusUser\Startmenü 2013-07-30 00:24 - 2013-07-30 00:24 - 00000000 _SHDL C:\Users\UpdatusUser\Netzwerkumgebung 2013-07-30 00:24 - 2013-07-30 00:24 - 00000000 _SHDL C:\Users\UpdatusUser\Druckumgebung 2013-07-30 00:24 - 2013-07-30 00:24 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Musik 2013-07-30 00:24 - 2013-07-30 00:24 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Bilder 2013-07-30 00:24 - 2013-07-30 00:24 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Verlauf 2013-07-30 00:24 - 2013-07-30 00:24 - 00000000 ____D C:\Program Files\AGEIA Technologies 2013-07-30 00:24 - 2013-07-30 00:24 - 00000000 ____D C:\36451beb2f9b1baa17dfcfb1f71c53 2013-07-30 00:24 - 2013-07-30 00:23 - 00000000 ____D C:\Windows\B9DB4C7601A446D58910F7AA6376DBAF.TMP 2013-07-30 00:24 - 2011-03-28 22:34 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2013-07-30 00:23 - 2013-07-30 00:23 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2013-07-30 00:23 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Help 2013-07-30 00:21 - 2013-07-30 00:21 - 00001055 _____ C:\Users\Seegas\Desktop\DeepBurner.lnk 2013-07-30 00:21 - 2013-07-30 00:21 - 00001055 _____ C:\Users\Gast\Desktop\DeepBurner.lnk 2013-07-30 00:21 - 2013-07-30 00:21 - 00001055 _____ C:\Users\Administrator\Desktop\DeepBurner.lnk 2013-07-30 00:21 - 2013-07-30 00:21 - 00000000 ____D C:\Program Files\Astonsoft 2013-07-30 00:21 - 2012-01-21 21:57 - 00000000 ____D C:\Users\Administrator 2013-07-30 00:21 - 2010-12-24 15:44 - 00000000 ____D C:\Users\Gast 2013-07-30 00:21 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system 2013-07-29 16:16 - 2012-12-13 13:06 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-07-29 10:47 - 2013-07-28 23:31 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-07-29 00:18 - 2013-07-29 00:18 - 00000356 _____ C:\Windows\Tasks\{FF57897C-1895-470E-96CD-C0F923DEEC95}.job 2013-07-29 00:18 - 2010-12-24 19:14 - 00000000 ____D C:\ProgramData\Skype 2013-07-28 22:18 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\wfp 2013-07-28 22:18 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\registration 2013-07-28 22:18 - 2009-07-14 04:37 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2013-07-28 21:43 - 2013-07-28 21:43 - 00013712 _____ C:\Windows\system32\y 2013-07-28 21:43 - 2013-07-28 21:43 - 00013712 _____ C:\Windows\system32\w 2013-07-28 21:43 - 2013-07-28 21:43 - 00013712 _____ C:\Windows\system32\rar.exe 2013-07-28 21:20 - 2009-07-14 06:53 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-07-20 01:51 - 2013-07-20 01:51 - 00246072 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avglogx.sys 2013-07-20 01:50 - 2013-07-20 01:50 - 00208184 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdriverx.sys 2013-07-20 01:50 - 2013-07-20 01:50 - 00171320 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgldx86.sys 2013-07-20 01:50 - 2013-07-20 01:50 - 00060216 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidshx.sys 2013-07-10 01:32 - 2013-07-10 01:32 - 00039224 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx86.sys Files to move or delete: ==================== C:\Windows\Tasks\{FF57897C-1895-470E-96CD-C0F923DEEC95}.job ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-30 17:01 ==================== End Of Log ============================ --- --- --- Addition-log: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 08-08-2013 02 Ran by Seegas at 2013-08-09 00:13:57 Running from C:\Users\Seegas\Desktop Boot Mode: Safe Mode (with Networking) ========================================================== ==================== Installed Programs ======================= Update for Microsoft Office 2007 (KB2508958) Adobe AIR (Version: 2.6.0.19140) Adobe Audition 3.0 (Version: 3.0) Adobe Flash Player 11 ActiveX (Version: 11.7.700.224) Adobe Flash Player 11 Plugin (Version: 11.8.800.94) Adobe Reader X - Deutsch (Version: 10.0.0) Analog Factory SE 1.2 ASIO4ALL (Version: 2.10) Audacity 1.3.12 (Unicode) AVG 2013 (Version: 13.0.3209) AVG 2013 (Version: 13.0.3392) AVG 2013 (Version: 2013.0.3392) Balsamiq Mockups For Desktop (Version: 2.0.21) Cisco EAP-FAST Module (Version: 2.2.14) Cisco LEAP Module (Version: 1.0.19) Cisco PEAP Module (Version: 1.1.6) D3DX10 (Version: 15.4.2368.0902) DivX-Setup (Version: 2.4.1.4) DLL Cure v2.8 (Version: 2.8) Driver & Utility (Version: 2.3) Dropbox (HKCU Version: 2.0.22) EasyBits GO EVEREST Home Edition v2.20 (Version: 2.20) FL Studio v7.0 Free YouTube Download version 2.10.33.324 GIMP 2.8.0 (Version: 2.8.0) Huur- en zorgtoeslag 2011 ICQ7.5 (Version: 7.5) Intel(R) Network Connections 15.7.176.0 (Version: 15.7.176.0) Java Auto Updater (Version: 2.0.3.1) Java(TM) 6 Update 24 (Version: 6.0.240) Last.fm Scrobbler 2.1.33 Live 8.0.4 Live 8.1.3 Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300) M-Audio Ozone Driver 6.0.2 (x86) (Version: 6.0.2) MediaCoder 0.7.5.4799 (Version: 0.7.5.4799) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6012.5000) Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Access MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Access Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000) Microsoft Office Excel MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office File Validation Add-In (Version: 14.0.5130.5003) Microsoft Office Groove MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Groove Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office InfoPath MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1) Microsoft Office OneNote MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Outlook MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office PowerPoint MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (Spanish) 2007 (Version: 12.0.6612.1000) Microsoft Office Proofing (English) 2007 (Version: 12.0.4518.1014) Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Publisher MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Shared MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Word MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219) Mozilla Firefox 22.0 (x86 de) (Version: 22.0) Mozilla Maintenance Service (Version: 22.0) MSI Afterburner 2.3.0 (Version: 2.3.0) MSI Kombustor 2.4.2 MSVCRT (Version: 15.4.2862.0708) Native Instruments Massive Native Instruments Massive (Version: 1.1.5.1967) No23 Recorder (Version: 2.1.0.3) NVIDIA 3D Vision Controller-Treiber 320.49 (Version: 320.49) NVIDIA 3D Vision Treiber 320.49 (Version: 320.49) NVIDIA Grafiktreiber 320.49 (Version: 320.49) NVIDIA HD-Audiotreiber 1.3.24.2 (Version: 1.3.24.2) NVIDIA Install Application (Version: 2.1002.124.810) NVIDIA PhysX (Version: 9.13.0604) NVIDIA PhysX-Systemsoftware 9.13.0604 (Version: 9.13.0604) NVIDIA Stereoscopic 3D Driver (Version: 7.17.13.2049) NVIDIA Systemsteuerung 320.49 (Version: 320.49) NVIDIA Update Components (Version: 4.11.9) PDFCreator (Version: 1.2.0) Pro Evolution Soccer 2011 (Version: 1.01.0000) Project64 1.6 (Version: 1.6) Realtek High Definition Audio Driver (Version: 6.0.1.5930) REALTEK Wireless LAN Driver and Utility (Version: 1.00.0142) rekordbox 1.4.1 (Version: 1.4.1) SampleTank 2 (Version: 2.5.2) Skype Click to Call (Version: 5.6.8442) Skype™ 5.10 (Version: 5.10.116) SpeechMike Executive SPSS 16.0 for Windows (Version: 16.0.1) Spybot - Search & Destroy (Version: 1.6.2) Steinberg Hypersonic v1.0 TuneUp Utilities (Version: 9.0.4700.23) TuneUp Utilities Language Pack (en-US) (Version: 9.0.4700.23) Ulead PhotoImpact 10 ESD (Version: 10.0) Uninstall 1.0.0.1 Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596802) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition Update for Microsoft Office Access 2007 Help (KB963663) Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office Infopath 2007 Help (KB963662) Update for Microsoft Office OneNote 2007 Help (KB963670) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition Update for Microsoft Office Outlook 2007 Help (KB963677) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2817563) 32-Bit Edition Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Publisher 2007 Help (KB963667) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) VC80CRTRedist - 8.0.50727.4053 (Version: 1.1.0) VLC media player 1.1.5 (Version: 1.1.5) Winamp (Version: 5.601 ) Winamp Erkennungs-Plug-in (HKCU Version: 1.0.0.1) Windows Live Communications Platform (Version: 15.4.3502.0922) Windows Live Essentials (Version: 15.4.3502.0922) Windows Live Essentials (Version: 15.4.3508.1109) Windows Live Fotogalerie (Version: 15.4.3502.0922) Windows Live ID Sign-in Assistant (Version: 7.250.4225.0) Windows Live Installer (Version: 15.4.3502.0922) Windows Live Movie Maker (Version: 15.4.3502.0922) Windows Live Photo Common (Version: 15.4.3502.0922) Windows Live Photo Gallery (Version: 15.4.3502.0922) Windows Live PIMT Platform (Version: 15.4.3508.1109) Windows Live SOXE (Version: 15.4.3502.0922) Windows Live SOXE Definitions (Version: 15.4.3502.0922) Windows Live UX Platform (Version: 15.4.3502.0922) Windows Live UX Platform Language Pack (Version: 15.4.3508.1109) WinRAR ==================== Restore Points ========================= 31-07-2013 17:02:26 Geplanter Prüfpunkt 08-08-2013 18:08:36 Windows-Sicherung ==================== Hosts content: ========================== 2009-07-14 04:04 - 2013-07-29 19:19 - 00000578 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 download.com.vn 127.0.0.1 www.download.com.vn 127.0.0.1 9down.com 127.0.0.1 www.9down.com 127.0.0.1 download.eset.com 127.0.0.1 www.download.com 127.0.0.1 download.f-secure.com 127.0.0.1 mirror02.gdata.de 127.0.0.1 download.avg.com 127.0.0.1 spftrl.digitalriver.com 127.0.0.1 www.grisoft.cz 127.0.0.1 download1us.softpedia.com 127.0.0.1 download.softpedia.com 127.0.0.1 www.bitdefender.co.uk 127.0.0.1 www.bitdefender.com 127.0.0.1 www.kaspersky.com 127.0.0.1 bkav.com.vn 127.0.0.1 www.bkav.com.vn 127.0.0.1 www.symantec.com 127.0.0.1 free.avg.com ==================== Scheduled Tasks (whitelisted) ============= Task: {0D141843-7766-494A-ADC9-F91AD8CBA2C0} - System32\Tasks\ROC_REG_JAN_DELETE => C:\ProgramData\AVG January 2013 Campaign\ROC.exe [2013-01-17] () Task: {16924F50-FE2E-4D86-ACC7-F895567069A1} - System32\Tasks\Adobe Reader and Acrobat Manager => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-11-10] (Adobe Systems Incorporated) Task: {3538EACD-6BF5-49E0-8380-24F02CA1DE19} - System32\Tasks\Java Update Scheduler => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-10-29] (Sun Microsystems, Inc.) Task: {48B8E07D-D8C2-4B32-A001-C7DAC9BD10DB} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task Task: {7461A3C3-9291-479D-8145-456B715A56A8} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => C:\Windows\system32\rundll32.exe [2009-07-14] (Microsoft Corporation) Task: {9EBF682A-FDC6-4C00-898C-8052B544B048} - System32\Tasks\{0937F2CA-6493-4F83-84C0-0FFFBE49A4E2} => c:\program files\mozilla firefox\firefox.exe [2013-07-28] (Mozilla Corporation) Task: {A5FE7939-F158-4ABA-8C27-8C6F3B5C8A0D} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance => C:\Program Files\TuneUp Utilities 2010\OneClick.exe [2010-09-30] (TuneUp Software) Task: {A60EA6F2-A754-42AD-99F6-E45B1CDE232E} - System32\Tasks\Microsoft\Windows\WindowsBackup\Windows Backup Monitor => C:\Windows\system32\sdclt.exe [2010-11-20] (Microsoft Corporation) Task: {BB27A3C9-1EAB-4351-B7C9-A877D5BC0079} - System32\Tasks\{3EEBF002-A757-4F5A-8886-DB894EEFB07C} => C:\Program Files\Skype\\Phone\Skype.exe [2012-07-13] (Skype Technologies S.A.) Task: {C3D1FE1F-14BC-4CEF-B80D-623ECCBD8FBA} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-30] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\ROC_REG_JAN_DELETE.job => C:\ProgramData\AVG January 2013 Campaign\ROC.exe Task: C:\Windows\Tasks\{FF57897C-1895-470E-96CD-C0F923DEEC95}.job => c:\program files\mozilla firefox\firefox.exe ==================== Faulty Device Manager Devices ============= Name: Security Processor Loader Driver Description: Security Processor Loader Driver Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: spldr Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Microsoft PS/2-Maus Description: Microsoft PS/2-Maus Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: i8042prt Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Event log errors: ========================= Application errors: ================== Error: (08/09/2013 00:07:59 AM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich. Error: (08/09/2013 00:07:59 AM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (08/09/2013 00:07:59 AM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. System errors: ============= Error: (08/09/2013 00:12:11 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (08/09/2013 00:12:11 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (08/09/2013 00:12:11 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (08/09/2013 00:12:01 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (08/09/2013 00:12:01 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (08/09/2013 00:12:01 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (08/09/2013 00:11:59 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (08/09/2013 00:11:59 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (08/09/2013 00:11:59 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (08/09/2013 00:10:45 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computerbrowser" ist vom Dienst "Server" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Microsoft Office Sessions: ========================= ==================== Memory info =========================== Percentage of memory in use: 32% Total physical RAM: 3063.09 MB Available physical RAM: 2054.42 MB Total Pagefile: 6124.48 MB Available Pagefile: 5253.98 MB Total Virtual: 2047.88 MB Available Virtual: 1919.53 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:420.6 GB) (Free:295.75 GB) NTFS Drive d: (Volume) (Fixed) (Total:195.31 GB) (Free:143.36 GB) NTFS Drive e: (Media) (Fixed) (Total:781.25 GB) (Free:165.43 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1397 GB) (Disk ID: 3FF1B45F) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=421 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=781 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=195 GB) - (Type=OF Extended) ==================== End Of Log ============================ |
09.08.2013, 10:48 | #14 |
/// Winkelfunktion /// TB-Süch-Tiger™ | SD-Karte: DCIM.exe ist keine zulässige win32-Anwendung Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKCU\...\Winlogon: [Shell] explorer.exe <==== ATTENTION C:\Windows\system32\y C:\Windows\system32\w C:\Windows\system32\rar.exe C:\Windows\Tasks\{FF57897C-1895-470E-96CD-C0F923DEEC95}.job Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ Logfiles bitte immer in CODE-Tags posten |
09.08.2013, 15:54 | #15 |
| SD-Karte: DCIM.exe ist keine zulässige win32-Anwendung hey,habe nun nochmal windows installiert,um überhaupt wieder auf das betriebssytem zugreifen zu können- der bildschirm war wieder schwarz und lediglich der mauszeiger war zu sehen. bestimmte ordner sind immer noch infiziert ("...keine win32-anwendung). trotzdem die o.g. schritte gehen? |
Themen zu SD-Karte: DCIM.exe ist keine zulässige win32-Anwendung |
.exe, avg, bescheid, besser, fehlermeldung, gescannt, java/exploit.cve-2011-3544.ac, logfile, malwarebytes, nicht mehr, nichts, pum.hijack.cmdprompt, pum.hijack.regedit, pum.hijack.system.hidden, pum.hijack.taskmanager, pup.optional.opencandy, sd-karte, sobald, win32-anwendung, windows, worm/vb.advw, wurm, zulässige |