![]() |
|
Log-Analyse und Auswertung: Problem: Internet Explorer Meldung getwindowinfoWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
| ![]() Problem: Internet Explorer Meldung getwindowinfo Hallo an alle, ich verwende für das Internet Firefox. Umso mehr wundert es mich, dass ich ein Problem mit dem Internet Explorer habe. Seit gestern öffnet sich dieser mit der Meldung "Webseite kann nicht geöffnet werden". In der Anzeige steht "hxxp://www_getwindowinfo/". Immer wenn ich den IE schließen möchte, öffnet sich dieser einfach wieder mit der oben erwähnten Meldung. Ich habe schon den Avira und den Malwarebytes drüberlaufen lassen. Leider hat nichts etwas gebracht. Handelt es sich hierbei überhaupt um einen Virus? Hat jemand einen Vorschlag, wie ich weiter vorgehen soll. FRST Log Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-09-2013 Ran by Gaga (administrator) on DAVID on 13-09-2013 09:38:23 Running from C:\Users\Gaga\Downloads Microsoft® Windows Vista™ Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (AVG Technologies CZ, s.r.o.) C:\PROGRA~1\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgcsrvx.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (Cisco Systems, Inc.) C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgwdsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (hxxp://libusb-win32.sourceforge.net) C:\Windows\system32\libusbd-nt.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe () C:\Windows\system32\PnkBstrA.exe () C:\Windows\system32\PnkBstrB.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Syntek America Inc.) C:\Windows\System32\StkCSrv.exe (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgnsx.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe () C:\Program Files\phonostar-Player\phonostarTimer.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Spotify Ltd) C:\Users\Gaga\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Windows\System32\mobsync.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe (combib) C:\Program Files\ComBib\Herrnhuter Losungen\Herrnhuter Losungen.exe (Windows Net) C:\Users\Gaga\AppData\Roaming\Windows Net Data\net.exe (SAMSUNG Electronics) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe (Samsung Electronics Co., Ltd.) C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe (SAMSUNG Electronics co., LTD.) C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe (Simplygen) C:\Program Files\HomeTab\ProtectedSearch.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgcsrvx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgcsrvx.exe (Microsoft Corporation) C:\Windows\system32\wuauclt.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe (Microsoft Corporation) C:\Windows\system32\conime.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6111232 2008-04-17] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1029416 2007-10-26] (Synaptics, Inc.) HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [178712 2008-07-22] (Intel Corporation) HKLM\...\Run: [WinampAgent] - C:\Program Files\Winamp\winampa.exe [36352 2008-08-04] () HKLM\...\Run: [QuickTime Task] - C:\Program Files\K-Lite Codec Pack\QuickTime\QTTask.exe [417792 2009-09-05] (Apple Inc.) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [141600 2009-10-28] (Apple Inc.) HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup HKLM\...\Run: [NvMediaCenter] - RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [CloneCDTray] - C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe [57344 2009-01-30] (SlySoft, Inc.) HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [40368 2011-08-31] (Adobe Systems Incorporated) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-03-29] (Adobe Systems Incorporated) HKLM\...\Run: [Samsung PanelMgr] - C:\Windows\Samsung\PanelMgr\SSMMgr.exe [618496 2010-06-07] () HKLM\...\Run: [AVG_UI] - C:\Program Files\AVG\AVG2013\avgui.exe [4411440 2013-08-15] (AVG Technologies CZ, s.r.o.) HKLM\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] - C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [522232 2012-09-26] (Cisco Systems, Inc.) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM\...\Policies\Explorer: [NoDrives] 0 HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKCU\...\Run: [phonostarTimer] - C:\Program Files\phonostar-Player\phonostarTimer.exe [42496 2012-10-13] () HKCU\...\Run: [phonostar-PlayerTimer] - C:\Program Files\phonostar-Player\phonostarTimer.exe [42496 2012-10-13] () HKCU\...\Run: [Spotify Web Helper] - C:\Users\Gaga\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1104384 2013-07-07] (Spotify Ltd) HKCU\...\Policies\Explorer: [NoDrives] 0 HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter Startup: C:\Users\Gaga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Herrnhuter Losungen.LNK ShortcutTarget: Herrnhuter Losungen.LNK -> C:\Program Files\ComBib\Herrnhuter Losungen\Herrnhuter Losungen.exe (combib) Startup: C:\Users\Gaga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\net.lnk ShortcutTarget: net.lnk -> C:\Users\Gaga\AppData\Roaming\Windows Net Data\net.exe (Windows Net) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) BHO: No Name - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.) BHO: softonic-de3 Toolbar - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKCU -softonic-de3 Toolbar - {CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\AVG2012\avgpp.dll No File Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default FF NewTab: about:home FF Homepage: about:home FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.) FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.) FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc) FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @pack.google.com/Google Updater;version=14 - C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google) FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin: @real.com/nppl3260;version=6.0.11.2321 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpjplug;version=6.0.12.1483 - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.6 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin HKCU: @phonostar.de/phonostar - C:\Program Files\phonostar-Player\npphonostarDetectNP.dll ( ) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Gaga\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\11-suche.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\bibleservercom-lut.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\bibleservercom-ng.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\imdb.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\lastminute.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\webde-suche.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\wolframalpha.xml FF SearchPlugin: C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\searchplugins\youtube-videosuche.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\babylon.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\qvo6.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\avg-secure-search.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: pricealarm - C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Extensions\EFGLQA@78ETGYN-0W7FN789T87.COM FF Extension: Microsoft .NET Framework Assistant - C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} FF Extension: HomeTab - C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Extensions\{ad7ef860-f366-4be1-8d12-4363b9356947} FF Extension: ST-de3 Community Toolbar - C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065} FF Extension: FoxyDeal - C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Extensions\{F58A62EB-38DC-43C4-A539-DC52E135208D} FF Extension: OberonGameHost - C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Extensions\OberonGameHost@OberonGames.com.xpi FF Extension: toolbar - C:\Users\Gaga\AppData\Roaming\Mozilla\Firefox\Profiles\6yfegq12.default\Extensions\toolbar@web.de.xpi FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF HKLM\...\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG Secure Search\FireFoxExt\15.5.0.2 FF Extension: AVG Security Toolbar - C:\ProgramData\AVG Secure Search\FireFoxExt\15.5.0.2 FF StartMenuInternet: FIREFOX.EXE - C:\Program Files\Mozilla Firefox\firefox.exe hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=sc&from=cor&uid=WDCXWD3200BEVT-35ZCT0_WD-WXE808LXD518XD518&ts=1379006862 ========================== Services (Whitelisted) ================= R2 Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [144672 2009-08-28] (Apple Inc.) R2 AVGIDSAgent; C:\Program Files\AVG\AVG2013\avgidsagent.exe [4939312 2013-07-04] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files\AVG\AVG2013\avgwdsvc.exe [283136 2013-07-23] (AVG Technologies CZ, s.r.o.) R2 libusbd; C:\Windows\System32\libusbd-nt.exe [18944 2005-03-09] (hxxp://libusb-win32.sourceforge.net) R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S4 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [44384 2010-12-10] (Microsoft Corporation) R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [66872 2009-09-11] () R2 PnkBstrB; C:\Windows\system32\PnkBstrB.exe [107832 2009-09-11] () R2 StkSSrv; C:\Windows\System32\StkCSrv.exe [31248 2008-01-16] (Syntek America Inc.) R2 vpnagent; C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe [479224 2012-09-26] (Cisco Systems, Inc.) S4 vToolbarUpdater15.5.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe [1643184 2013-08-18] (AVG Secure Search) ==================== Drivers (Whitelisted) ==================== R2 ACEDRV05; C:\Windows\system32\drivers\ACEDRV05.sys [97792 2008-12-25] (Protect Software GmbH) S3 acsint; C:\Windows\System32\DRIVERS\acsint.sys [38440 2012-09-26] (Cisco Systems, Inc.) S3 acsmux; C:\Windows\System32\DRIVERS\acsmux.sys [57256 2012-09-26] (Cisco Systems, Inc.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [208184 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [60216 2013-07-20] (AVG Technologies CZ, s.r.o.) R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [22328 2013-09-10] (AVG Technologies CZ, s.r.o.) R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [171320 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [246072 2013-07-20] (AVG Technologies CZ, s.r.o.) R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [96568 2013-07-01] (AVG Technologies CZ, s.r.o.) R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [39224 2013-09-05] (AVG Technologies CZ, s.r.o.) R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [182072 2013-03-21] (AVG Technologies CZ, s.r.o.) S4 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [37664 2013-08-18] (AVG Technologies) R0 CLFS; C:\Windows\System32\CLFS.sys [247352 2008-01-21] (Microsoft Corporation) R3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [34760 2007-02-16] (SlySoft, Inc.) R1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [26024 2010-01-01] (Elaborate Bytes AG) R2 KMDFMEMIO; C:\Windows\System32\DRIVERS\kmdfmemio.sys [13312 2008-06-25] (SAMSUNG ELECTRONICS CO., LTD.) R3 libusb0; C:\Windows\System32\drivers\libusb0.sys [33792 2005-03-09] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation) S3 MBAMSwissArmy; C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2013-09-13] (Malwarebytes Corporation) R0 sptd; C:\Windows\System32\Drivers\sptd.sys [717296 2008-11-05] () R2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [5120 2009-07-29] (Samsung Electronics) R3 StkCMini; C:\Windows\System32\Drivers\StkCMini.sys [1363088 2008-03-28] (Syntek) S3 USBTINSP; C:\Windows\System32\DRIVERS\tinspusb.sys [123392 2008-12-05] (Texas Instruments) R3 WmBEnum; C:\Windows\System32\drivers\WmBEnum.sys [10144 2005-04-12] (Logitech Inc.) S3 WmFilter; C:\Windows\System32\drivers\WmFilter.sys [22240 2005-04-12] (Logitech Inc.) S3 WmHidLo; C:\Windows\System32\drivers\WmHidLo.sys [17632 2005-04-12] (Logitech Inc.) S3 WmVirHid; C:\Windows\System32\drivers\WmVirHid.sys [5600 2005-04-12] (Logitech Inc.) R3 WmXlCore; C:\Windows\System32\drivers\WmXlCore.sys [45504 2005-04-12] (Logitech Inc.) S3 ADDMEM; \??\C:\Users\Gaga\AppData\Local\Temp\__Samsung_Update\ADDMEM.SYS [x] U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation) S3 catchme; \??\C:\Users\Gaga\AppData\Local\Temp\catchme.sys [x] S2 DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-13 09:37 - 2013-09-13 09:37 - 00000000 ____D C:\FRST 2013-09-13 09:36 - 2013-09-13 09:36 - 01082459 _____ (Farbar) C:\Users\Gaga\Downloads\FRST.exe 2013-09-13 09:02 - 2013-09-13 09:02 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys 2013-09-13 00:29 - 2013-09-13 00:29 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Gaga\Downloads\mbam-setup-1.75.0.1300.exe 2013-09-13 00:29 - 2013-09-13 00:29 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Malwarebytes 2013-09-13 00:29 - 2013-09-13 00:29 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-13 00:29 - 2013-09-13 00:29 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-09-13 00:29 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-09-12 23:41 - 2013-09-12 23:53 - 00000000 ____D C:\ComboFix 2013-09-12 21:45 - 2013-09-12 22:01 - 00000000 ____D C:\Windows\erdnt 2013-09-12 21:44 - 2013-09-12 21:44 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\TeamViewer 2013-09-12 21:43 - 2013-09-12 21:43 - 00000000 ____D C:\MaxAVLiveUpdate 2013-09-12 21:27 - 2013-09-12 21:29 - 00000000 ____D C:\ProgramData\Max Secure 2013-09-12 21:26 - 2013-09-12 21:27 - 68987384 _____ (Max Secure Software ) C:\Users\Gaga\Desktop\MaxSpywaredetector.exe 2013-09-12 21:26 - 2013-09-12 21:26 - 00000000 ____D C:\Users\Gaga\AppData\Local\Max Secure Software 2013-09-12 21:25 - 2013-09-12 21:26 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\GetRightToGo 2013-09-12 21:24 - 2013-09-12 21:24 - 00368256 _____ (RegNow.com) C:\Users\Gaga\Downloads\Download_MaxSDDMnew.exe 2013-09-12 21:22 - 2013-09-12 21:22 - 01090200 _____ (AppEnabler) C:\Users\Gaga\Downloads\Setup.exe 2013-09-12 21:13 - 2013-09-13 00:01 - 00001267 _____ C:\DelFix.txt 2013-09-12 20:57 - 2013-09-12 21:13 - 00000000 ____D C:\Windows\ERUNT 2013-09-12 20:33 - 2013-09-12 20:34 - 00002803 _____ C:\Windows\IE9_main.log 2013-09-12 20:29 - 2013-09-12 20:29 - 18991104 _____ C:\Users\Gaga\Downloads\IE9-Setup-Full-vista-32bit.msi 2013-09-12 20:28 - 2013-09-12 20:28 - 30091776 _____ (Microsoft Corporation) C:\Users\Gaga\Downloads\IE10-Windows6.1-x86-de-de_b16521.exe 2013-09-12 20:16 - 2013-09-12 20:16 - 06515112 ____N C:\Users\Gaga\Desktop\PowerISO5.exe 2013-09-12 20:15 - 2013-09-12 20:15 - 00392016 _____ (Softonic ) C:\Users\Gaga\Downloads\SoftonicDownloader_fuer_poweriso.exe 2013-09-12 19:45 - 2013-09-12 19:57 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Windows Net Data 2013-09-12 19:44 - 2013-09-13 08:55 - 00000000 ____D C:\Program Files\HomeTab 2013-09-12 19:44 - 2013-09-12 21:02 - 00000000 ____D C:\SoloApp 2013-09-12 19:44 - 2013-09-12 19:44 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\HomeTab 2013-09-12 19:44 - 2013-09-12 19:44 - 00000000 ____D C:\Program Files\FoxyDeal 2013-09-12 19:44 - 2013-08-13 08:38 - 00032328 _____ C:\Windows\Launcher.exe 2013-09-12 19:43 - 2013-09-12 19:43 - 00000207 _____ C:\Users\Gaga\Desktop\Amazon.url 2013-09-12 19:41 - 2013-09-12 19:41 - 00478552 _____ C:\Users\Gaga\Downloads\gvd3-Downloader.exe 2013-09-12 19:27 - 2013-09-12 19:27 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\0D0S1L2Z1P1B0T1P1B2Z 2013-09-12 19:27 - 2013-09-12 19:27 - 00000000 ____D C:\Program Files\Image Converter 2013-09-12 19:25 - 2013-09-12 19:25 - 00745144 _____ C:\Users\Gaga\Downloads\ImageEditorSetup.exe 2013-09-12 18:56 - 2013-09-12 18:56 - 00000000 ____D C:\ProgramData\NFS Underground Demo 2013-09-12 18:55 - 2013-09-12 18:55 - 00002029 _____ C:\Users\Public\Desktop\Need For Speed Underground Demo.lnk 2013-09-12 18:55 - 2013-09-12 18:55 - 00000000 ____D C:\Program Files\EA GAMES 2013-09-12 18:54 - 2013-09-12 18:54 - 00000000 ____D C:\Users\Gaga\Downloads\NFSU_Demo_Install 2013-09-12 18:48 - 2013-09-12 18:48 - 00001734 _____ C:\Users\Public\Desktop\EZDownloader.lnk 2013-09-12 18:48 - 2013-09-12 18:48 - 00000000 ____D C:\Windows\system32\AMD64 2013-09-12 18:48 - 2013-09-12 18:48 - 00000000 ____D C:\ProgramData\SummerSoft 2013-09-12 18:48 - 2013-09-12 18:48 - 00000000 ____D C:\Program Files\EZDownloader 2013-09-12 18:47 - 2013-09-12 18:48 - 00000000 ____D C:\ProgramData\InstallMate 2013-09-12 18:39 - 2013-09-12 18:51 - 230211072 _____ C:\Users\Gaga\Downloads\nfsudemo_release.exe 2013-09-12 18:28 - 2013-09-12 18:29 - 00138880 _____ C:\Windows\Minidump\Mini091213-01.dmp 2013-09-12 18:28 - 2013-09-12 18:28 - 313142360 _____ C:\Windows\MEMORY.DMP 2013-09-12 18:28 - 2013-09-12 18:28 - 00000000 ____D C:\Windows\Minidump 2013-09-12 18:23 - 2013-09-12 18:25 - 230211072 _____ C:\Users\Gaga\Desktop\nfsudemo_release.exe 2013-09-12 18:16 - 2013-09-12 18:16 - 00392040 _____ (Softonic ) C:\Users\Gaga\Downloads\SoftonicDownloader_for_need-for-speed-underground.exe 2013-09-10 01:34 - 2013-09-10 01:34 - 00022328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsshimx.sys 2013-09-05 01:43 - 2013-09-05 01:43 - 00039224 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx86.sys 2013-09-04 18:41 - 2013-09-12 23:11 - 00001537 _____ C:\Users\Gaga\Downloads\Sudokumat.cfg 2013-09-04 18:41 - 2013-09-04 18:41 - 02035630 _____ C:\Users\Gaga\Downloads\WinSudoku31Installer.zip 2013-09-04 18:41 - 2013-09-04 18:41 - 00001888 _____ C:\Users\Public\Desktop\Windows Sudoku.lnk 2013-09-04 18:41 - 2013-09-04 18:41 - 00000000 ____D C:\Program Files\WinSudoku 2013-09-04 18:34 - 2013-09-04 18:34 - 00653770 _____ C:\Users\Gaga\Downloads\sudokumat.jar 2013-09-04 18:19 - 2013-09-04 18:19 - 00001015 _____ C:\Users\Public\Desktop\AHR Sudoku 4.1.lnk 2013-09-04 18:19 - 2013-09-04 18:19 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\AHR Software 2013-09-04 18:19 - 2013-09-04 18:19 - 00000000 ____D C:\Program Files\AHR Software 2013-09-04 18:18 - 2013-09-04 18:18 - 00753152 _____ C:\Users\Gaga\Downloads\ahr_sudoku_4.1.4.321.msi 2013-09-04 18:14 - 2013-09-12 21:54 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Simple Sudoku 2013-09-04 18:14 - 2013-09-04 18:14 - 00798254 _____ ( ) C:\Users\Gaga\Downloads\sudoku42n_setup.exe 2013-09-04 18:14 - 2013-09-04 18:14 - 00000000 ____D C:\Program Files\Simple Sudoku 2013-09-01 01:09 - 2013-09-12 19:44 - 00001971 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-08-30 15:42 - 2013-08-30 17:20 - 00000000 ____D C:\Users\Gaga\Documents\Calibre-Bibliothek 2013-08-30 15:42 - 2013-08-30 15:49 - 00000000 ____D C:\Users\Gaga\AppData\Local\calibre-cache 2013-08-30 15:41 - 2013-08-30 15:52 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\calibre 2013-08-30 15:41 - 2013-08-30 15:41 - 00000841 _____ C:\Users\Public\Desktop\calibre - E-book management.lnk 2013-08-30 15:41 - 2013-08-30 15:41 - 00000000 ____D C:\Program Files\Calibre2 2013-08-30 15:39 - 2013-08-30 15:40 - 52439552 _____ C:\Users\Gaga\Downloads\calibre-1.1.0.msi 2013-08-30 11:07 - 2013-09-12 19:44 - 00000846 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-08-30 10:59 - 2013-08-30 11:00 - 22240760 _____ (Mozilla) C:\Users\Gaga\Downloads\Firefox Setup 23.0.1.exe 2013-08-29 21:26 - 2013-08-29 21:26 - 00000000 ____D C:\found.004 2013-08-18 18:20 - 2013-08-30 11:07 - 00000000 ____D C:\Program Files\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2013-09-13 09:37 - 2013-09-13 09:37 - 00000000 ____D C:\FRST 2013-09-13 09:36 - 2013-09-13 09:36 - 01082459 _____ (Farbar) C:\Users\Gaga\Downloads\FRST.exe 2013-09-13 09:35 - 2008-10-24 00:26 - 00000416 ____H C:\Windows\Tasks\User_Feed_Synchronization-{E8AD1811-0EAF-4D14-8074-7AD7053A5BCD}.job 2013-09-13 09:35 - 2008-10-06 04:42 - 01399103 _____ C:\Windows\WindowsUpdate.log 2013-09-13 09:34 - 2008-12-01 18:45 - 00000416 ____H C:\Windows\Tasks\SupBackGroundTask.job 2013-09-13 09:17 - 2012-10-08 11:33 - 00000430 _____ C:\Windows\system32\Drivers\etc\hosts.ics 2013-09-13 09:17 - 2010-02-16 13:50 - 00238168 _____ C:\ProgramData\nvModes.001 2013-09-13 09:17 - 2010-01-02 20:29 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-09-13 09:17 - 2006-11-02 14:47 - 00004784 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-13 09:17 - 2006-11-02 14:47 - 00004784 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-13 09:16 - 2006-11-02 15:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-13 09:15 - 2008-06-25 23:08 - 00000836 _____ C:\Windows\bthservsdp.dat 2013-09-13 09:15 - 2006-11-02 15:01 - 00032514 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-09-13 09:08 - 2012-09-26 00:02 - 00000858 _____ C:\Users\Public\Desktop\AVG 2013.lnk 2013-09-13 09:08 - 2011-11-03 23:14 - 00000000 ____D C:\ProgramData\MFAData 2013-09-13 09:02 - 2013-09-13 09:02 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys 2013-09-13 08:57 - 2008-01-21 04:47 - 00107054 _____ C:\Windows\PFRO.log 2013-09-13 08:55 - 2013-09-12 19:44 - 00000000 ____D C:\Program Files\HomeTab 2013-09-13 07:57 - 2010-01-02 20:29 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-09-13 00:29 - 2013-09-13 00:29 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Gaga\Downloads\mbam-setup-1.75.0.1300.exe 2013-09-13 00:29 - 2013-09-13 00:29 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Malwarebytes 2013-09-13 00:29 - 2013-09-13 00:29 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-13 00:29 - 2013-09-13 00:29 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-09-13 00:01 - 2013-09-12 21:13 - 00001267 _____ C:\DelFix.txt 2013-09-12 23:53 - 2013-09-12 23:41 - 00000000 ____D C:\ComboFix 2013-09-12 23:51 - 2006-11-02 12:23 - 00000215 _____ C:\Windows\system.ini 2013-09-12 23:34 - 2006-11-02 14:47 - 00392384 _____ C:\Windows\system32\FNTCACHE.DAT 2013-09-12 23:19 - 2006-11-02 12:33 - 01613470 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-12 23:13 - 2008-10-24 00:05 - 00105992 _____ C:\Users\Gaga\AppData\Local\GDIPFONTCACHEV1.DAT 2013-09-12 23:11 - 2013-09-04 18:41 - 00001537 _____ C:\Users\Gaga\Downloads\Sudokumat.cfg 2013-09-12 22:03 - 2006-11-02 13:18 - 00000000 __RHD C:\Users\Default 2013-09-12 22:03 - 2006-11-02 13:18 - 00000000 ___RD C:\Users\Public 2013-09-12 22:01 - 2013-09-12 21:45 - 00000000 ____D C:\Windows\erdnt 2013-09-12 22:00 - 2008-10-24 00:03 - 00000000 ____D C:\Users\Gaga 2013-09-12 21:54 - 2013-09-04 18:14 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Simple Sudoku 2013-09-12 21:44 - 2013-09-12 21:44 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\TeamViewer 2013-09-12 21:43 - 2013-09-12 21:43 - 00000000 ____D C:\MaxAVLiveUpdate 2013-09-12 21:29 - 2013-09-12 21:27 - 00000000 ____D C:\ProgramData\Max Secure 2013-09-12 21:27 - 2013-09-12 21:26 - 68987384 _____ (Max Secure Software ) C:\Users\Gaga\Desktop\MaxSpywaredetector.exe 2013-09-12 21:26 - 2013-09-12 21:26 - 00000000 ____D C:\Users\Gaga\AppData\Local\Max Secure Software 2013-09-12 21:26 - 2013-09-12 21:25 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\GetRightToGo 2013-09-12 21:24 - 2013-09-12 21:24 - 00368256 _____ (RegNow.com) C:\Users\Gaga\Downloads\Download_MaxSDDMnew.exe 2013-09-12 21:23 - 2009-01-05 08:00 - 00000000 ____D C:\Program Files\7-Zip 2013-09-12 21:22 - 2013-09-12 21:22 - 01090200 _____ (AppEnabler) C:\Users\Gaga\Downloads\Setup.exe 2013-09-12 21:13 - 2013-09-12 20:57 - 00000000 ____D C:\Windows\ERUNT 2013-09-12 21:02 - 2013-09-12 19:44 - 00000000 ____D C:\SoloApp 2013-09-12 20:34 - 2013-09-12 20:33 - 00002803 _____ C:\Windows\IE9_main.log 2013-09-12 20:29 - 2013-09-12 20:29 - 18991104 _____ C:\Users\Gaga\Downloads\IE9-Setup-Full-vista-32bit.msi 2013-09-12 20:28 - 2013-09-12 20:28 - 30091776 _____ (Microsoft Corporation) C:\Users\Gaga\Downloads\IE10-Windows6.1-x86-de-de_b16521.exe 2013-09-12 20:26 - 2008-10-24 00:05 - 00000905 _____ C:\Users\Gaga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-09-12 20:16 - 2013-09-12 20:16 - 06515112 ____N C:\Users\Gaga\Desktop\PowerISO5.exe 2013-09-12 20:15 - 2013-09-12 20:15 - 00392016 _____ (Softonic ) C:\Users\Gaga\Downloads\SoftonicDownloader_fuer_poweriso.exe 2013-09-12 20:06 - 2010-02-16 13:50 - 00238168 _____ C:\ProgramData\nvModes.dat 2013-09-12 19:57 - 2013-09-12 19:45 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Windows Net Data 2013-09-12 19:44 - 2013-09-12 19:44 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\HomeTab 2013-09-12 19:44 - 2013-09-12 19:44 - 00000000 ____D C:\Program Files\FoxyDeal 2013-09-12 19:44 - 2013-09-01 01:09 - 00001971 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-09-12 19:44 - 2013-08-30 11:07 - 00000846 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-09-12 19:44 - 2008-12-18 19:44 - 00001724 _____ C:\Users\Gaga\Desktop\Mozilla Firefox.lnk 2013-09-12 19:43 - 2013-09-12 19:43 - 00000207 _____ C:\Users\Gaga\Desktop\Amazon.url 2013-09-12 19:41 - 2013-09-12 19:41 - 00478552 _____ C:\Users\Gaga\Downloads\gvd3-Downloader.exe 2013-09-12 19:31 - 2008-06-25 07:38 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-09-12 19:27 - 2013-09-12 19:27 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\0D0S1L2Z1P1B0T1P1B2Z 2013-09-12 19:27 - 2013-09-12 19:27 - 00000000 ____D C:\Program Files\Image Converter 2013-09-12 19:25 - 2013-09-12 19:25 - 00745144 _____ C:\Users\Gaga\Downloads\ImageEditorSetup.exe 2013-09-12 18:56 - 2013-09-12 18:56 - 00000000 ____D C:\ProgramData\NFS Underground Demo 2013-09-12 18:55 - 2013-09-12 18:55 - 00002029 _____ C:\Users\Public\Desktop\Need For Speed Underground Demo.lnk 2013-09-12 18:55 - 2013-09-12 18:55 - 00000000 ____D C:\Program Files\EA GAMES 2013-09-12 18:54 - 2013-09-12 18:54 - 00000000 ____D C:\Users\Gaga\Downloads\NFSU_Demo_Install 2013-09-12 18:51 - 2013-09-12 18:39 - 230211072 _____ C:\Users\Gaga\Downloads\nfsudemo_release.exe 2013-09-12 18:48 - 2013-09-12 18:48 - 00001734 _____ C:\Users\Public\Desktop\EZDownloader.lnk 2013-09-12 18:48 - 2013-09-12 18:48 - 00000000 ____D C:\Windows\system32\AMD64 2013-09-12 18:48 - 2013-09-12 18:48 - 00000000 ____D C:\ProgramData\SummerSoft 2013-09-12 18:48 - 2013-09-12 18:48 - 00000000 ____D C:\Program Files\EZDownloader 2013-09-12 18:48 - 2013-09-12 18:47 - 00000000 ____D C:\ProgramData\InstallMate 2013-09-12 18:29 - 2013-09-12 18:28 - 00138880 _____ C:\Windows\Minidump\Mini091213-01.dmp 2013-09-12 18:28 - 2013-09-12 18:28 - 313142360 _____ C:\Windows\MEMORY.DMP 2013-09-12 18:28 - 2013-09-12 18:28 - 00000000 ____D C:\Windows\Minidump 2013-09-12 18:25 - 2013-09-12 18:23 - 230211072 _____ C:\Users\Gaga\Desktop\nfsudemo_release.exe 2013-09-12 18:24 - 2012-07-24 13:30 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Spotify 2013-09-12 18:16 - 2013-09-12 18:16 - 00392040 _____ (Softonic ) C:\Users\Gaga\Downloads\SoftonicDownloader_for_need-for-speed-underground.exe 2013-09-11 23:45 - 2013-08-05 00:11 - 00000000 ____D C:\Windows\system32\MRT 2013-09-11 23:41 - 2006-11-02 12:24 - 76725432 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2013-09-11 17:56 - 2012-07-24 13:30 - 00000000 ____D C:\Users\Gaga\AppData\Local\Spotify 2013-09-11 14:38 - 2012-04-09 14:53 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Skype 2013-09-11 12:01 - 2008-12-29 15:05 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\ICQ 2013-09-10 01:34 - 2013-09-10 01:34 - 00022328 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsshimx.sys 2013-09-09 19:33 - 2012-12-22 13:10 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\vlc 2013-09-09 11:06 - 2010-06-05 13:32 - 00000000 ___RD C:\Users\Gaga\Documents\My Dropbox 2013-09-09 11:06 - 2010-06-05 13:31 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\Dropbox 2013-09-05 01:43 - 2013-09-05 01:43 - 00039224 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgrkx86.sys 2013-09-04 18:41 - 2013-09-04 18:41 - 02035630 _____ C:\Users\Gaga\Downloads\WinSudoku31Installer.zip 2013-09-04 18:41 - 2013-09-04 18:41 - 00001888 _____ C:\Users\Public\Desktop\Windows Sudoku.lnk 2013-09-04 18:41 - 2013-09-04 18:41 - 00000000 ____D C:\Program Files\WinSudoku 2013-09-04 18:34 - 2013-09-04 18:34 - 00653770 _____ C:\Users\Gaga\Downloads\sudokumat.jar 2013-09-04 18:19 - 2013-09-04 18:19 - 00001015 _____ C:\Users\Public\Desktop\AHR Sudoku 4.1.lnk 2013-09-04 18:19 - 2013-09-04 18:19 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\AHR Software 2013-09-04 18:19 - 2013-09-04 18:19 - 00000000 ____D C:\Program Files\AHR Software 2013-09-04 18:18 - 2013-09-04 18:18 - 00753152 _____ C:\Users\Gaga\Downloads\ahr_sudoku_4.1.4.321.msi 2013-09-04 18:14 - 2013-09-04 18:14 - 00798254 _____ ( ) C:\Users\Gaga\Downloads\sudoku42n_setup.exe 2013-09-04 18:14 - 2013-09-04 18:14 - 00000000 ____D C:\Program Files\Simple Sudoku 2013-09-03 07:06 - 2012-05-08 10:02 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-09-01 13:01 - 2008-12-22 18:19 - 00001052 _____ C:\Windows\Tasks\Google Software Updater.job 2013-09-01 01:09 - 2008-12-22 18:20 - 00000000 ____D C:\Users\Gaga\AppData\Local\Google 2013-09-01 01:09 - 2008-12-22 18:19 - 00000000 ____D C:\Program Files\Google 2013-08-30 17:20 - 2013-08-30 15:42 - 00000000 ____D C:\Users\Gaga\Documents\Calibre-Bibliothek 2013-08-30 15:52 - 2013-08-30 15:41 - 00000000 ____D C:\Users\Gaga\AppData\Roaming\calibre 2013-08-30 15:49 - 2013-08-30 15:42 - 00000000 ____D C:\Users\Gaga\AppData\Local\calibre-cache 2013-08-30 15:41 - 2013-08-30 15:41 - 00000841 _____ C:\Users\Public\Desktop\calibre - E-book management.lnk 2013-08-30 15:41 - 2013-08-30 15:41 - 00000000 ____D C:\Program Files\Calibre2 2013-08-30 15:40 - 2013-08-30 15:39 - 52439552 _____ C:\Users\Gaga\Downloads\calibre-1.1.0.msi 2013-08-30 11:07 - 2013-08-18 18:20 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-08-30 11:00 - 2013-08-30 10:59 - 22240760 _____ (Mozilla) C:\Users\Gaga\Downloads\Firefox Setup 23.0.1.exe 2013-08-29 21:26 - 2013-08-29 21:26 - 00000000 ____D C:\found.004 2013-08-18 14:47 - 2013-06-27 08:40 - 00003715 _____ C:\Program Files\Mozilla Firefoxavg-secure-search.xml 2013-08-18 14:47 - 2012-09-26 00:02 - 00000000 ____D C:\Program Files\AVG Secure Search 2013-08-18 14:46 - 2012-09-26 00:02 - 00037664 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx86.sys ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-13 09:23 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 13-09-2013 Ran by Gaga at 2013-09-13 09:40:44 Running from C:\Users\Gaga\Downloads Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Update for Microsoft Office 2007 (KB2508958) 2007 Microsoft Office system (Version: 12.0.6612.1000) 7-Zip 4.64 7-Zip 9.21 (Version: 9.21.00.0) AAC Decoder (Version: 7.1.0) Activation Assistant for the 2007 Microsoft Office suites Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0) Activision(R) (Version: 1.00.0000) Adobe AIR (Version: 2.7.1.19610) Adobe Flash Player 11 Plugin (Version: 11.8.800.94) Adobe Reader 8.3.1 - Deutsch (Version: 8.3.1) Adobe Shockwave Player 12.0 (Version: 12.0.2.122) AGEIA PhysX v7.09.13 (Version: 7.09.13) Agere Systems HDA Modem AHR Sudoku 4.1 (Version: 4.1.4.321) Amazon MP3-Downloader 1.0.9 Any Video Converter 3.0.3 AP Tuner 3.08 Apple Application Support (Version: 1.0.1) Apple Mobile Device Support (Version: 2.6.0.32) Apple Software Update (Version: 2.1.1.116) Assassin's Creed (Version: 1.00) Atheros WLAN Client (Version: 1.00.000) Audacity 1.2.6 AutoUpdate (Version: 1.1) AVG 2013 (Version: 13.0.3222) AVG 2013 (Version: 13.0.3408) AVG 2013 (Version: 2013.0.3408) AVG Security Toolbar (Version: 15.5.0.2) Blobby Volley 2 Version 1.0RC1 Blur(TM) (Version: 1.00.0000) Business Contact Manager für Outlook 2007 SP2 (Version: 3.0.8619.1) CABAReT Stage 4.1 (Version: 4.1) calibre (Version: 1.1.0) Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch (Version: 1.6) Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch (Version: 1.7) CANON iMAGE GATEWAY Task for ZoomBrowser EX (Version: 1.5.0.3) Canon Internet Library for ZoomBrowser EX (Version: 1.6.1.6) Canon RAW Image Task for ZoomBrowser EX (Version: 3.3.0.5) Canon Utilities CameraWindow (Version: 7.1.0.2) Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX (Version: 6.4.2.16) Canon Utilities Digital Photo Professional 3.4 (Version: 3.4.0.0) Canon Utilities EOS Utility (Version: 2.4.0.1) Canon Utilities MyCamera (Version: 6.4.0.5) Canon Utilities PhotoStitch (Version: 3.1.21.45) Canon Utilities Picture Style Editor (Version: 1.3.0.0) Canon Utilities RemoteCapture Task for ZoomBrowser EX (Version: 1.7.1.9) Canon Utilities ZoomBrowser EX (Version: 6.1.1.21) Canon ZoomBrowser EX Memory Card Utility (Version: 1.1.0.8) Carom3D Cisco AnyConnect Secure Mobility Client (Version: 3.0.10057) Cisco AnyConnect Secure Mobility Client (Version: 3.0.10057) CloneCD CloneDVD2 (Version: 2.9.2.8) Data Lifeguard Diagnostic for Windows (Version: 1.13) Deluxe Ski Jump 4 Beta-2 (Version: 0.9.1) DivX Codec (Version: 6.8.5) DivX Converter (Version: 7.1.0) DivX Player (Version: 7.2.0) DivX Plus DirectShow Filters DivX Version Checker (Version: 7.1.0.2) DivX Web Player (Version: 1.5.0) Dropbox (HKCU Version: 2.0.22) EA Download Manager (Version: 4.0.0.462) Easy Battery Manager (Version: 3.2.1.7) Easy Display Manager (Version: 2.0.0.0) Easy Network Manager 3.0 (Version: 3.0.0.0) Easy SpeedUp Manager (Version: 2.0.1.0) EOS USB WIA Driver (Version: 6.0.1.5) EZDownloader (Version: 1.0) Fallout 3 (Version: 1.00.0000) Far Cry 2 (Version: 1.00.00) FLOCK! Demo (Version: 1.00.0000) FluidSIM 4.2l Pneumatik MecLab GIMP 2.6.11 (Version: 2.6.11) Google Chrome (Version: 29.0.1547.66) Google Earth (Version: 7.1.1.1888) Google Update Helper (Version: 1.3.21.153) Google Updater (Version: 2.4.2432.1652) Grand Theft Auto IV (Version: 1.00.0000) H.264 Decoder (Version: 1.1.0) Herrnhuter Losungen (Version: 3.2.0) HomeTab 4.4 (Version: 4.4) HP Deskjet 1000 J110 series - Grundlegende Software für das Gerät (Version: 22.0.334.0) HP Deskjet 1000 J110 series Hilfe (Version: 140.0.65.65) ICQ7.5 (Version: 7.5) Image Editor Packages imagine digital freedom - Samsung (Version: 1.0.2.0) INCEPTION SCREENSAVER Intel PROSet Wireless Intel(R) PROSet/Wireless WiFi-Software (Version: 12.04.4000) Intel® Matrix Storage Manager Internet Explorer (Version: 9) iTunes (Version: 9.0.2.25) Java 7 Update 25 (Version: 7.0.250) Java Auto Updater (Version: 2.1.9.5) Java(TM) 6 Update 37 (Version: 6.0.370) K-Lite Mega Codec Pack 1.57 (Version: 1.57) Kransimulator 2009 Demo (Version: 0.5.0) LibUSB-Win32-0.1.10.1 (Version: 0.1.10.1) Logitech Gaming Software (Version: 4.60) Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300) Maple 9.5 (Version: 1.0.0.0) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729) Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft Games for Windows - LIVE Redistributable (Version: 3.5.88.0) Microsoft Games for Windows Marketplace (Version: 3.5.50.0) Microsoft Office 2003 Web Components (Version: 11.0.8003.0) Microsoft Office 2007 Primary Interop Assemblies (Version: 12.0.4518.1014) Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Access MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office File Validation Add-In (Version: 14.0.5130.5003) Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1) Microsoft Office Outlook MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Professional Hybrid 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000) Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014) Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Publisher MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Small Business Connectivity Components (Version: 2.0.7024.0) Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft PowerPoint Viewer (Version: 14.0.7015.1000) Microsoft Silverlight (Version: 5.1.20513.0) Microsoft SOAP Toolkit 2.0 SP2 (Version: 623.1) Microsoft SQL Server 2005 Microsoft SQL Server 2005 Express Edition (MSSMLBIZ) (Version: 9.4.5000.00) Microsoft SQL Server Native Client (Version: 9.00.5000.00) Microsoft SQL Server VSS Writer (Version: 9.00.5000.00) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219) MiKTeX 2.9 (Version: 2.9) MKV Splitter (Version: 1.0.1) Mobile Partner (Version: 16.002.03.02.511) Mozilla Firefox 23.0.1 (x86 de) (Version: 23.0.1) Mozilla Maintenance Service (Version: 23.0.1) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0) Need For Speed Underground Demo Need For Speed™ World (Version: 1.0.0.68) neroxml (Version: 1.0.0) NVIDIA Drivers (Version: 1.3) NVIDIA GAME System Software 2.8.1 (Version: 2.8.1) NVIDIA HD-Audiotreiber 1.3.18.0 (Version: 1.3.18.0) NVIDIA Install Application (Version: 2.1002.109.718) oneworld Flugplan und Reiseplaner OpenLP 2.0 OpenOffice.org 3.0 (Version: 3.0.9358) PDF Editor 2 PDFCreator (Version: 1.5.1) phonostar-Player Version 3.02.8 Picasa 3 (Version: 3.8) Play AVStation (Version: 4.1.20.50) Play Camera (Version: 2.0.0.13) PunkBuster Services (Version: 0.986) QuickTime (Version: 7.64.17.73) Realtek High Definition Audio Driver (Version: 6.0.1.5605) Richard Burns Rally (Version: 1.00.000) Rockstar Games Social Club (Version: 1.00.0000) Samsung Magic Doctor (Version: 5.00) Samsung Recovery Solution III (Version: 3.0.0.5) Samsung Update Plus (Version: 2.0) simfy (Version: 1.5.0) Simple Sudoku 4.2 Skat 8.4 (Version: 8.4.1.40) Skype™ 6.6 (Version: 6.6.106) SopCast 3.2.9 (Version: 3.2.9) Spotify (HKCU Version: 0.9.1.57.ge7405149) SumatraPDF (Version: 2.1.1) Super Mario Flash v1.0 swMSM (Version: 12.0.0.1) Synaptics Pointing Device Driver (Version: 10.1.2.0) System Requirements Lab TeXnicCenter Version 1.0 Stable RC1 (Version: Version 1.0 Stable RC1) TI-Nspire™ CAS Computer Software (Version: 1.7.2741) TI-Nspire™ Computer Link Software (Version: 1.3.11897) Tomb Raider: Underworld 1.0 Ubuntu (Version: 8.10.515) Unity Web Player (HKCU Version: ) Unreal Tournament 3 (LG) (HKCU Version: 1.00.0000) Unreal Tournament 3 (LG) (Version: 1.00.0000) Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch) (Version: 9.00.5000.00) Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2825641) 32-Bit Edition Update für Microsoft Office Excel 2007 Help (KB963678) Update für Microsoft Office Outlook 2007 Help (KB963677) Update für Microsoft Office Powerpoint 2007 Help (KB963669) Update für Microsoft Office Word 2007 Help (KB963665) USB2.0 UVC WebCam (Version: 6.11.706.012) User Guide (Version: 1.0) VC80CRTRedist - 8.0.50727.762 (Version: 1.0.0) Visual C++ 9.0 CRT (x86) WinSXS MSM (Version: 9.0) VLC media player 2.0.6 (Version: 2.0.6) Wartung Samsung ML-1660 Series WIDCOMM Bluetooth Software 6.0.1.6300 (Version: 6.0.1.6300) Winamp (Version: 5.541 ) Windows 7 Upgrade Advisor (Version: 2.0.3001.0) Windows Live ID Sign-in Assistant (Version: 6.500.3165.0) Windows Media Player Firefox Plugin (Version: 1.0.0.8) Windows Utils WinRAR WinSudoku (Version: 1.0.0) Wolfenstein (Version: 1.1) Worms World Party ==================== Restore Points ========================= 12-09-2013 22:01:15 Ende der Bereinigung ==================== Hosts content: ========================== 2006-11-02 12:23 - 2013-09-12 23:51 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {0AA60ADE-1999-4F56-A1B9-EF09CA2714C6} - System32\Tasks\SamsungMagicDoctor => C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe [2007-07-05] (Samsung Electronics Co., Ltd.) Task: {0D2DBBD5-A610-4557-86E3-FC35AA70FBE6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-02] (Google Inc.) Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {3C685C04-F44B-433E-9BB3-E4B6796B5CC9} - System32\Tasks\Browser Updater\Browser Updater => C:\Program Files\HomeTab\TBUpdater.dll [2013-07-08] (Simply Tech Ltd.) Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-21] (Microsoft Corporation) Task: {49F3B6FC-9BEE-4734-82C4-FAA606100F0A} - System32\Tasks\EasyDisplayMgr => C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe [2008-05-22] (SAMSUNG Electronics) Task: {53403752-F29A-45E1-97AD-465D3F834308} - System32\Tasks\EasyBatteryManager => C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe [2008-04-17] (SAMSUNG Electronics co., LTD.) Task: {810EDE5B-A771-41AB-AAFC-E4881CC286F7} - \DealPly No Task File Task: {862247A7-5B9B-49A5-B9DA-0C78927F04EA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-02] (Google Inc.) Task: {941FD8D6-59AD-4980-AC39-88DA8A84FC45} - System32\Tasks\EasySpeedUpManager => C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe [2008-04-25] (Samsung Electronics Co., Ltd.) Task: {A61555D3-7840-45C1-A5A9-0D49851DE37A} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\OptinNotification => C:\Windows\System32\wsqmcons.exe [2008-01-21] (Microsoft Corporation) Task: {AEDB9B78-923B-406D-997D-7B468BCD8A11} - System32\Tasks\SupBackGroundTask => C:\Program Files\Samsung\Samsung Update Plus\SUPBackGround.exe [2010-04-20] () Task: {BA873B36-FCCA-49F6-979A-F86AEC274C60} - System32\Tasks\Google Software Updater => C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-09-28] (Google) Task: {C8F931E0-ED56-46A0-915D-E64BBED594A0} - System32\Tasks\User_Feed_Synchronization-{E8AD1811-0EAF-4D14-8074-7AD7053A5BCD} => C:\Windows\system32\msfeedssync.exe [2011-05-28] (Microsoft Corporation) Task: {D7EC6DD3-C63E-4D8A-9B63-91F1040857DA} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - Gaga => C:\Program Files\Windows Calendar\WinCal.exe [2008-01-21] (Microsoft Corporation) Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] () Task: {EBD845BB-D919-4912-B516-ADC0A99D5B49} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30] (Apple Inc.) Task: {F4C1ED60-9B39-49C5-8CC9-48E3DC0251B3} - System32\Tasks\ProtectedSearch\Protected Search => C:\Program Files\HomeTab\ProtectedSearch.exe [2013-08-13] (Simplygen) Task: {F99D7667-0349-4A84-B7BD-0ADF7C5E9D73} - System32\Tasks\Microsoft\Windows\Defrag\ManualDefrag => C:\Windows\system32\defrag.exe [2008-01-21] (Microsoft Corp.) Task: {FDCE8A69-BAB4-4D61-A394-6E84F9E20D62} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2008-01-21] (Microsoft Corporation) Task: C:\Windows\Tasks\Google Software Updater.job => C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\SupBackGroundTask.job => C:\Program Files\Samsung\Samsung Update Plus\SUPBackGround.exe Task: C:\Windows\Tasks\User_Feed_Synchronization-{E8AD1811-0EAF-4D14-8074-7AD7053A5BCD}.job => C:\Windows\system32\msfeedssync.exe ==================== Loaded Modules (whitelisted) ============= 2009-02-25 06:49 - 2009-02-25 06:49 - 05976064 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dum.dll 2008-02-12 06:19 - 2008-02-12 06:19 - 00208896 _____ (Broadcom Corporation.) C:\Windows\system32\btmmhook.dll 2013-05-25 02:36 - 2013-05-25 02:36 - 00130736 _____ (Dropbox, Inc.) C:\Users\Gaga\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll 2008-02-12 05:36 - 2008-02-12 05:36 - 00184320 _____ (Broadcom Corporation.) C:\Windows\system32\btncopy.dll 2009-12-06 00:24 - 2009-08-16 18:06 - 00141312 _____ () C:\Program Files\WinRAR\rarext.dll 2006-11-02 14:35 - 2006-11-02 14:35 - 00116736 _____ (Microsoft Corporation) C:\Windows\eHome\ehProxy.dll 2008-02-12 05:31 - 2008-02-12 05:31 - 00602112 _____ (Broadcom Corporation.) C:\Windows\system32\btwapi.dll 2008-02-12 05:46 - 2008-02-12 05:46 - 00233472 _____ (Broadcom Corporation.) C:\Windows\system32\btosif.dll 2008-02-12 05:58 - 2008-02-12 05:58 - 00393216 _____ (Broadcom Corporation.) C:\Windows\system32\btwhidcs.DLL 2008-02-12 05:26 - 2008-02-12 05:26 - 05271552 _____ (Broadcom Corporation.) C:\Windows\system32\btrez.dll 2008-06-25 07:30 - 2006-08-12 05:48 - 00049152 _____ () C:\Program Files\Samsung\Samsung Magic Doctor\HookDllPS2.dll 2007-12-12 06:41 - 2007-12-12 06:41 - 01750960 _____ (Codejock Software) C:\Windows\system32\Codejock.CommandBars.v11.2.2.ocx 2007-12-12 06:41 - 2007-12-12 06:41 - 00518064 _____ (Codejock Software) C:\Windows\system32\Codejock.SkinFramework.v11.2.2.ocx 2005-11-08 10:37 - 2005-11-08 10:37 - 00049152 _____ (BasicPro) C:\Windows\system32\ComBibSub32.ocx 2009-02-25 06:49 - 2009-02-25 06:49 - 00520192 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi.dll 2008-06-25 07:30 - 2006-08-12 05:48 - 00049152 _____ () C:\Program Files\Samsung\Easy Display Manager\HookDllPS2.dll 2008-06-25 07:30 - 2006-08-12 05:48 - 00049152 _____ () C:\Program Files\SAMSUNG\EasySpeedUpManager\HookDllPS2.dll 2013-09-12 19:44 - 2013-08-13 08:38 - 00100352 _____ () C:\Program Files\HomeTab\InstallHelper.dll 2013-09-12 19:44 - 2013-08-13 08:38 - 00152136 _____ (Simply Tech Ltd.) C:\Program Files\HomeTab\cinshlpr.dll 2013-08-18 18:21 - 2013-08-14 19:55 - 03551640 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll 2013-07-28 19:01 - 2013-07-28 19:01 - 16166280 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll ==================== Alternate Data Streams (whitelisted) ========== AlternateDataStreams: C:\Users\Gaga\Desktop\ein Tag im Leben.mpg:TOC.WMV ==================== Faulty Device Manager Devices ============= Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Cisco Systems Service: vpnva Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (09/13/2013 09:18:22 AM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabEin erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. Error: (09/13/2013 09:17:41 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/13/2013 08:59:07 AM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabEin erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. Error: (09/13/2013 08:58:53 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (09/13/2013 08:24:24 AM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\GAGA\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\6YFEGQ12.DEFAULT\CACHE\5> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (09/13/2013 08:24:24 AM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\GAGA\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\6YFEGQ12.DEFAULT\CACHE\5> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (09/13/2013 08:24:24 AM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\GAGA\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\6YFEGQ12.DEFAULT\CACHE\4> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (09/13/2013 08:24:24 AM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\GAGA\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\6YFEGQ12.DEFAULT\CACHE\4> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (09/13/2013 08:24:24 AM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\GAGA\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\6YFEGQ12.DEFAULT\CACHE\3> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) Error: (09/13/2013 08:24:24 AM) (Source: Windows Search Service) (User: ) Description: Eintrag <C:\USERS\GAGA\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\6YFEGQ12.DEFAULT\CACHE\3> in der Hash-Zuordnung kann nicht aktualisiert werden. Kontext: Anwendung, SystemIndex Katalog Details: Ein an das System angeschlossenes Gerät funktioniert nicht. (0x8007001f) System errors: ============= Error: (09/13/2013 09:19:32 AM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT) Description: 0x80070032 Error: (09/13/2013 09:17:49 AM) (Source: ipnathlp) (User: ) Description: Die DHCP-Zuweisung wurde für IP-Adresse 192.168.1.2 deaktiviert, da die IP-Adresse außerhalb des Bereichs 192.168.0.0/255.255.255.0 liegt, von der die Adressen DHCP-Clients zu gewiesen werden. Ändern Sie den Bereich, sodass die IP-Adresse mit einbezogen wird, oder ändern Sie die IP-Adresse, sodass sie innerhalb dieses Bereichs liegt, um die DHCP-Zuweisung zu aktivieren. Error: (09/13/2013 09:17:49 AM) (Source: ipnathlp) (User: ) Description: ICS_IPV6 konnte den IPv6-Stapel nicht konfigurieren. Error: (09/13/2013 09:17:41 AM) (Source: Service Control Manager) (User: ) Description: 30000vpnagent Error: (09/13/2013 09:17:41 AM) (Source: Service Control Manager) (User: ) Description: DgiVecp%%2 Error: (09/13/2013 09:17:41 AM) (Source: Service Control Manager) (User: ) Description: Parallel port driver%%1058 Error: (09/13/2013 09:16:52 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: C:\Windows\System32\IWMSSvc.dll126 Error: (09/13/2013 09:16:51 AM) (Source: HTTP) (User: ) Description: \Device\Http\ReqQueueKerberos Error: (09/13/2013 09:15:25 AM) (Source: Service Control Manager) (User: ) Description: ScRegSetValueExWFailureActions%%5 Error: (09/13/2013 09:00:09 AM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT) Description: 0x80070032 Microsoft Office Sessions: ========================= CodeIntegrity Errors: =================================== Date: 2013-09-13 09:39:15.836 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-13 09:39:15.601 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-13 09:39:15.436 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-13 09:39:15.252 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-13 09:39:15.005 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-13 09:39:14.751 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-13 09:39:14.598 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-13 09:39:14.444 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-13 09:38:52.414 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\avgidshx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2013-09-13 09:38:52.219 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\avgidshx.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 65% Total physical RAM: 3065.88 MB Available physical RAM: 1060.72 MB Total Pagefile: 6334.91 MB Available Pagefile: 4571.86 MB Total Virtual: 2047.88 MB Available Virtual: 1900.46 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:144.09 GB) (Free:25.07 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: () (Fixed) (Total:144 GB) (Free:15.59 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 3A21C8C8) Partition 1: (Not Active) - (Size=10 GB) - (Type=27) Partition 2: (Active) - (Size=144 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=144 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |