![]() |
Plagegeister aller Art und deren Bekämpfung: Win7 IP tunnelt mich jede Nacht und kapert Teledat 530 RouterWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
![]() | #16 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Win7 IP tunnelt mich jede Nacht und kapert Teledat 530 Router Auf allen Rechnern: Lade dir bitte Emsisoft MBR Master herunter und speichere es auf den Desktop.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() | #17 |
![]() | ![]() Win7 IP tunnelt mich jede Nacht und kapert Teledat 530 Router Hallo,
__________________Danke für Ihre Hilfe. Hier das Log des "Infizierten" Code:
ATTFilter Detected Windows version: 6.1 Build 7601 Service Pack 1 Installing direct disk access driver ... Driver connection handle: 0x00000114 6 valid drive(s) found. Details for Disk 0 - WDC WD7500AAKS-65RBA0 Rev 30.04G30: Device name : \\.\PhysicalDrive0 Geometry (C/H/S) : 1453521/16/63 Boot loader reputation : Known Good (Windows XP) Cross view comparison : Passed Partition table integrity: Passed Boot loader hashes SHA-1 : DA38B874B7713D1B51CBC449F4EF809B0DEC644A MD5 : 8F558EB6672622401DA993E1E865C861 Details for Disk 1 - WDC WD1002FAEX-00Y9A0 Rev 05.01D05: Device name : \\.\PhysicalDrive1 Geometry (C/H/S) : 121601/255/63 Boot loader reputation : Known Good (Windows 7) Cross view comparison : Passed Partition table integrity: Passed Boot loader hashes SHA-1 : 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79 MD5 : A36C5E4F47E84449FF07ED3517B43A31 Details for Disk 2 - Hitachi HDS721010CLA332 Rev JP4OA39C: Device name : \\.\PhysicalDrive2 Geometry (C/H/S) : 121601/255/63 Boot loader reputation : Known Good (Windows XP) Cross view comparison : Passed Partition table integrity: Passed Boot loader hashes SHA-1 : DA38B874B7713D1B51CBC449F4EF809B0DEC644A MD5 : 8F558EB6672622401DA993E1E865C861 Details for Disk 3 - SAMSUNG HD204UI Rev 1AQ10001: Device name : \\.\PhysicalDrive3 Geometry (C/H/S) : 243201/255/63 Boot loader reputation : Known Good (Windows 7) Cross view comparison : Passed Partition table integrity: Passed Boot loader hashes SHA-1 : 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79 MD5 : A36C5E4F47E84449FF07ED3517B43A31 Details for Disk 4 - WDC WD7500AAKS-22RBA0 Rev 30.04G30: Device name : \\.\PhysicalDrive4 Geometry (C/H/S) : 1453521/16/63 Boot loader reputation : Unknown Cross view comparison : Passed Partition table integrity: Passed Boot loader hashes SHA-1 : ADFE55CD0C6ED2E00B22375835E4C2736CE9AD11 MD5 : 72B8CE41AF0DE751C946802B3ED844B4 Details for Disk 5 - WDC WD7500AAVS-00M4B0 Rev 01.00A01: Device name : \\.\PhysicalDrive5 Geometry (C/H/S) : 91201/255/63 Boot loader reputation : Known Good (Windows XP) Cross view comparison : Passed Partition table integrity: Passed Boot loader hashes SHA-1 : DA38B874B7713D1B51CBC449F4EF809B0DEC644A MD5 : 8F558EB6672622401DA993E1E865C861 Code:
ATTFilter Detected Windows version: 6.1 Build 7601 Service Pack 1 Installing direct disk access driver ... Driver connection handle: 0x00000114 1 valid drive(s) found. Details for Disk 0 - WDC WD20EZRX-00DC0B0 Rev 80.00A80: Device name : \\.\PhysicalDrive0 Geometry (C/H/S) : 258401/240/63 Boot loader reputation : Unknown Cross view comparison : Passed Partition table integrity: Passed Boot loader hashes SHA-1 : ADFE55CD0C6ED2E00B22375835E4C2736CE9AD11 MD5 : 72B8CE41AF0DE751C946802B3ED844B4 Code:
ATTFilter Detected Windows version: 6.1 Build 7601 Service Pack 1 Installing direct disk access driver ... Driver connection handle: 0x00000150 1 valid drive(s) found. Details for Disk 0 - WDC WD25 00BEVT-80A23 Rev 01.0: Device name : \\.\PhysicalDrive0 Geometry (C/H/S) : 30401/255/63 Boot loader reputation : Known Good (Windows 7) Cross view comparison : Passed Partition table integrity: Passed Boot loader hashes SHA-1 : 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79 MD5 : A36C5E4F47E84449FF07ED3517B43A31 Code:
ATTFilter Detected Windows version: 5.1 Build 2600 Service Pack 3 Installing direct disk access driver ... Driver connection handle: 0x0000009C 2 valid drive(s) found. Details for Disk 0 - SAMSUNG SP2514N Rev VF100-33: Device name : \\.\PhysicalDrive0 Geometry (C/H/S) : 30401/255/63 Boot loader reputation : Unknown Cross view comparison : Passed Partition table integrity: Passed Boot loader hashes SHA-1 : ADFE55CD0C6ED2E00B22375835E4C2736CE9AD11 MD5 : 72B8CE41AF0DE751C946802B3ED844B4 Details for Disk 1 - SAMSUNG SP2514N Rev VF100-33: Device name : \\.\PhysicalDrive1 Geometry (C/H/S) : 30401/255/63 Boot loader reputation : Unknown Cross view comparison : Passed Partition table integrity: Passed Boot loader hashes SHA-1 : ADFE55CD0C6ED2E00B22375835E4C2736CE9AD11 MD5 : 72B8CE41AF0DE751C946802B3ED844B4 |
![]() | #18 |
![]() | ![]() Win7 IP tunnelt mich jede Nacht und kapert Teledat 530 Router Hallo,
__________________habe gerade dies im Routerlog entdeckt: 11/01/2013 00:50:03 destroy tunnel sucessfully 11/01/2013 00:49:29 Datagram redirected, if=PPPOE, dst=, src= 11/01/2013 00:49:02 creates tunnel sucessfully Online war nur der "Zweite" |
![]() | #19 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Win7 IP tunnelt mich jede Nacht und kapert Teledat 530 Router So lamgsam bin ich mit meinem Latein am Ende. Merkst Du irgendwas davon oder hast Du das durch Zufall entdeckt?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() | #20 |
![]() | ![]() Win7 IP tunnelt mich jede Nacht und kapert Teledat 530 Router Hallo, ich war längere Zeit auf xhamster.com (Firefox) als die Downloadrate auf <100kbit einbrach und der Seitenaufbau exxtrem langsam vor sich ging (teilweise auch stoppte). Ich öffnete dann noch den IE und die Startseite lud auch extremst langsam. Nach ein,zwei Minuten war alles wieder normal,ich startete den ex"infizierten" und ging in den Router um nachzuschauen. Im Nachhinein ist mir eine erhöhte CPU Temperatur aufgefallen,auch noch eine Stunde später, im Taskmanager wurde jedoch keine CPU Last > ca.30 % angezeigt. Heute ist die Temp. wieder normal. |
![]() | #21 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Win7 IP tunnelt mich jede Nacht und kapert Teledat 530 Router Solche Speed-Probleme kommen schon mal vor. Ich würd mir da jetzt nicht so den Stress machen. Die REchner sind augenscheinlich sauber. Wenn der Router resettet wurde sollte das passen.
__________________ --> Win7 IP tunnelt mich jede Nacht und kapert Teledat 530 Router |
![]() | #22 |
![]() | ![]() Win7 IP tunnelt mich jede Nacht und kapert Teledat 530 Router Hallo und nochmals vielen Dank für Ihre Hilfe. Entschuldigen Sie bitte meine verspätete Antwort,hatte gesundheitliche Probleme und dann hab ich aus Dummheit noch Win7 vom ex"infizierten" gekillt. Daraufhin habe ich C formatiert,ein Image vom Juni aufgespielt,als erste dann Norton Internet Security upgedatet und bei einem Patch hängte sich der PC mehrfach auf. Also nochmals format-Image und jetzt als erstes mbar,welches eine Fehlermeldung brachte (.dll irgendwas mit Root und Reparatur bei Neustart) danach fand es wieder diesen Trojaner,siehe log. Code:
ATTFilter Malwarebytes Anti-Rootkit BETA www.malwarebytes.org Database version: v2013.11.05.03 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16618 ***** ****** :: ***********-PC [limited] 05.11.2013 12:23:07 mbar-log-2013-11-05 (12-23-07).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: Objects scanned: 323747 Time elapsed: 6 minute(s), 55 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 1 HKCU\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{FBEB8A05-BEEE-4442-804E-409D6C4515E9} (Hijack.Trojan.Siredef.C) -> Delete on reboot. Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) Physical Sectors Detected: 0 (No malicious items detected) (end) Ich hab jetzt wo alles installiert und geupdatet ist nochmals die scans ausgeführt:[CODE] Code:
ATTFilter GMER 2.1.19163 - hxxp://www.gmer.net Rootkit scan 2013-11-06 17:12:33 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD1002FAEX-00Y9A0 rev.05.01D05 931,51GB Running: gmer_2.1.19163.exe; Driver: C:\Users\******~1\AppData\Local\Temp\kxlyiaod.sys ---- Kernel code sections - GMER 2.1 ---- INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff80003602000 76 bytes [00, 00, 2E, 02, 55, 4E, 62, ...] INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 607 fffff8000360204f 7 bytes [00, 80, B0, F2, 0B, 80, FA] ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\MAXA Cookie Manager\Cookie.exe[2960] C:\Windows\SysWow64\WSOCK32.dll!setsockopt + 322 0000000070ee1a22 2 bytes [EE, 70] .text C:\Program Files (x86)\MAXA Cookie Manager\Cookie.exe[2960] C:\Windows\SysWow64\WSOCK32.dll!setsockopt + 496 0000000070ee1ad0 2 bytes [EE, 70] .text C:\Program Files (x86)\MAXA Cookie Manager\Cookie.exe[2960] C:\Windows\SysWow64\WSOCK32.dll!setsockopt + 552 0000000070ee1b08 2 bytes [EE, 70] .text C:\Program Files (x86)\MAXA Cookie Manager\Cookie.exe[2960] C:\Windows\SysWow64\WSOCK32.dll!setsockopt + 730 0000000070ee1bba 2 bytes [EE, 70] .text C:\Program Files (x86)\MAXA Cookie Manager\Cookie.exe[2960] C:\Windows\SysWow64\WSOCK32.dll!setsockopt + 762 0000000070ee1bda 2 bytes [EE, 70] .text C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe[3012] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077bc1465 2 bytes [BC, 77] .text C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe[3012] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000077bc14bb 2 bytes [BC, 77] .text ... * 2 .text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2800] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077bc1465 2 bytes [BC, 77] .text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[2800] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000077bc14bb 2 bytes [BC, 77] .text ... * 2 .text C:\Program Files (x86)\DSL-Manager\DslMgr.exe[2700] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077bc1465 2 bytes [BC, 77] .text C:\Program Files (x86)\DSL-Manager\DslMgr.exe[2700] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000077bc14bb 2 bytes [BC, 77] .text ... * 2 .text C:\Program Files (x86)\Secunia\PSI\PSIA.exe[3884] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077bc1465 2 bytes [BC, 77] .text C:\Program Files (x86)\Secunia\PSI\PSIA.exe[3884] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000077bc14bb 2 bytes [BC, 77] .text ... * 2 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[4496] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 0000000077bc1465 2 bytes [BC, 77] .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[4496] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 0000000077bc14bb 2 bytes [BC, 77] .text ... * 2 .text C:\Program Files (x86)\DSL-Manager\DslMgrSvc.exe[4908] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077bc1465 2 bytes [BC, 77] .text C:\Program Files (x86)\DSL-Manager\DslMgrSvc.exe[4908] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000077bc14bb 2 bytes [BC, 77] .text ... * 2 .text C:\Program Files (x86)\Secunia\PSI\sua.exe[5824] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077bc1465 2 bytes [BC, 77] .text C:\Program Files (x86)\Secunia\PSI\sua.exe[5824] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000077bc14bb 2 bytes [BC, 77] .text ... * 2 .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[6208] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077bc1465 2 bytes [BC, 77] .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[6208] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000077bc14bb 2 bytes [BC, 77] .text ... * 2 ---- EOF - GMER 2.1 ---- Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 31-10-2013 Ran by ****** ****** (administrator) on ************-PC on 06-11-2013 17:27:14 Running from C:\Users\****** ******\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Deutsche Telekom AG) C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\\NIS.exe (Sony Corporation) C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe (Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe () C:\Program Files\Rainlendar2\Rainlendar2.exe (MAXA Research Int'l Inc.) C:\Program Files (x86)\MAXA Cookie Manager\Cookie.exe (BillP Studios) C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios) C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (T-Systems Enterprise Services GmbH) C:\Program Files (x86)\DSL-Manager\DslMgr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (cyberlink) C:\Program Files (x86)\CyberLink\Shared files\brs.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe () C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (Sony Corporation) C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\PSIA.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\\NIS.exe (T-Systems Enterprise Services GmbH) C:\Program Files (x86)\DSL-Manager\DslMgrSvc.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe (Diskeeper Corporation) C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil64_11_9_900_117_ActiveX.exe (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [picon] - C:\Program Files (x86)\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe [773656 2008-09-26] (Intel Corporation) HKLM\...\Run: [IntelTBRunOnce] - C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs [4526 2010-11-29] () HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [XboxStat] - C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe [825184 2009-10-01] (Microsoft Corporation) HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6469736 2012-03-06] (Realtek Semiconductor) HKLM\...\Run: [Acronis Scheduler2 Service] - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [395928 2012-05-10] (Acronis) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [Rainlendar2] - C:\Program Files\Rainlendar2\Rainlendar2.exe [3820032 2011-08-12] () HKCU\...\Run: [MSCS] - C:\Program Files (x86)\MAXA Cookie Manager\Cookie.exe [1138688 2012-05-20] (MAXA Research Int'l Inc.) HKCU\...\Run: [WinPatrol] - C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe [456768 2013-10-19] (BillP Studios) HKCU\...\Run: [Sim Aquarium 3 Livewallpaper Autostart] - [x] HKCU\...\Policies\Explorer: [NoRecentDocsNetHood] 1 MountPoints2: {d364454e-f4d8-11e0-a01b-806e6f6e6963} - S:\setup.exe HKLM-x32\...\Run: [JMB36X IDE Setup] - C:\Windows\RaidTool\xInsIDE.exe [43608 2010-09-07] () HKLM-x32\...\Run: [NUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [REGSHAVE] - C:\Program Files (x86)\REGSHAVE\REGSHAVE.EXE [53248 2002-02-04] (FUJI PHOTO FILM CO., LTD.) HKLM-x32\...\Run: [amd_dc_opt] - C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD) HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.) HKLM-x32\...\Run: [BDRegion] - C:\Program Files (x86)\CyberLink\Shared files\brs.exe [78312 2012-05-09] (cyberlink) HKLM-x32\...\Run: [UpdatePPShortCut] - C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe [223096 2012-04-17] (CyberLink Corp.) HKLM-x32\...\Run: [CLMLServer] - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2011-03-09] (CyberLink) HKLM-x32\...\Run: [TrueImageMonitor.exe] - C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [2673640 2012-05-10] () HKLM-x32\...\Run: [PMBVolumeWatcher] - C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe [740888 2013-04-24] (Sony Corporation) HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe [54840 2007-05-08] (Hewlett-Packard) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files (x86)\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files (x86)\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) Startup: C:\Users\****** ******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files (x86)\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) Startup: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files (x86)\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) ==================== Internet (Whitelisted) ==================== ProxyServer: localhost:21320 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.t-online.de SearchScopes: HKCU - DefaultScope {68ADF79E-E403-43EA-8AAB-57DC2C811EA0} URL = hxxp://www.google.de/search?q={searchTerms} SearchScopes: HKCU - {68ADF79E-E403-43EA-8AAB-57DC2C811EA0} URL = hxxp://www.google.de/search?q={searchTerms} BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine64\\CoIEPlg.dll (Symantec Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: DVDVideoSoft IE Extension - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.) BHO-x32: No Name - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO-x32: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll (AOL Inc.) BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\\CoIEPlg.dll (Symantec Corporation) BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\\IPS\ipsbho.dll (Symantec Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Free Download Manager - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll (FreeDownloadManager.ORG) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: DVDVideoSoft IE Extension - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.) Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\\CoIEPlg.dll (Symantec Corporation) Toolbar: HKLM-x32 - Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll (AOL Inc.) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\\CoIEPlg.dll (Symantec Corporation) Toolbar: HKCU - No Name - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - No File Toolbar: HKCU - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\\CoIEPlg.dll (Symantec Corporation) DPF: HKLM-x32 {644E432F-49D3-41A1-8DD5-E099162EEEC5} hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\****** ******\AppData\Roaming\Mozilla\Firefox\Profiles\x270n2xu.default FF Homepage: hxxp://www.t-online.de/ FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.0.6 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.0 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @canon.com/EPPEX - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @logitech.com/HarmonyRemote,version=1.0.0 - C:\Program Files (x86)\Logitech\Harmony Remote Driver\NprtHarmonyPlugin.dll (Logitech Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nullsoft.com/winampDetector;version=1 - C:\Program Files (x86)\Winamp Detect\npwachk.dll (Nullsoft, Inc.) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.0.6 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\****** ******\AppData\Roaming\Mozilla\Firefox\Profiles\x270n2xu.default\searchplugins\aol-search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Winamp Toolbar - C:\Users\****** ******\AppData\Roaming\Mozilla\Firefox\Profiles\x270n2xu.default\Extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f} FF Extension: fdm_ffext - C:\Users\****** ******\AppData\Roaming\Mozilla\Firefox\Profiles\x270n2xu.default\Extensions\fdm_ffext@freedownloadmanager.org FF Extension: bprivacyprefs - C:\Users\****** ******\AppData\Roaming\Mozilla\Firefox\Profiles\x270n2xu.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.0.18\coFFPlgn\ FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.0.18\coFFPlgn\ FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.0.18\IPSFF FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.0.18\IPSFF FF HKLM-x32\...\Firefox\Extensions: [{ACAA314B-EEBA-48e4-AD47-84E31C44796C}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ FF HKCU\...\Firefox\Extensions: [maxacookie@maxatools.com] - C:\Program Files (x86)\MAXA Cookie Manager\extension FF Extension: MAXA Cookie Manager - C:\Program Files (x86)\MAXA Cookie Manager\extension Chrome: ======= CHR HomePage: hxxp://www.t-online.de/ CHR RestoreOnStartup: "hxxp://www.google.com/" CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\gcswf32.dll No File CHR Plugin: (Java Deployment Toolkit - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll No File CHR Plugin: (Java(TM) Platform SE 6 U29) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll No File CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dll () CHR Plugin: (Norton Confidential) - C:\Users\****** ******\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.1.1.10_0\npcoplgn.dll No File CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll No File CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Plugin: (Default Plug-in) - default_plugin No File CHR Extension: (Norton Identity Protection) - C:\Users\******~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2014.6.0.27_0 CHR Extension: (Google Wallet) - C:\Users\******~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\ CHR Extension: (MyHarmony Chrome Plugin) - C:\Users\******~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\omaonpoimgkmbllpdihbnmgphjoipdhf\ CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\\Exts\Chrome.crx CHR HKLM-x32\...\Chrome\Extension: [omaonpoimgkmbllpdihbnmgphjoipdhf] - C:\Program Files (x86)\Logitech\Harmony Remote Driver\harmony_chrome.crx ==================== Services (Whitelisted) ================= S2 CLKMSVC10_38F51D56; C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [242664 2012-05-09] (CyberLink) R2 Diskeeper; C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe [2435960 2012-07-28] (Diskeeper Corporation) R2 Netzmanager Service; C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [2565632 2011-10-24] (Deutsche Telekom AG) R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\\NIS.exe [275696 2013-10-08] (Symantec Corporation) R2 PMBDeviceInfoProvider; C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe [483864 2013-04-24] (Sony Corporation) S3 SandraAgentSrv; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2011.SP5\RpcAgentSrv.exe [93848 2008-09-18] (SiSoftware) R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.) R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia) R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [660184 2013-07-03] (Secunia) R3 TDslMgrService; C:\Program Files (x86)\DSL-Manager\DslMgrSvc.exe [294912 2007-11-26] (T-Systems Enterprise Services GmbH) ==================== Drivers (Whitelisted) ==================== R1 BHDrvx64; C:\Program Files (x86)\Norton Internet Security\NortonData\\Definitions\BASHDefs\20131101.003\BHDrvx64.sys [1524824 2013-10-23] (Symantec Corporation) R1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1501000.012\ccSetx64.sys [162392 2013-09-26] (Symantec Corporation) R2 cpuz135; C:\Windows\system32\drivers\cpuz135_x64.sys [21992 2010-11-09] (CPUID) R3 DKRtWrt; C:\Windows\System32\DRIVERS\DKRtWrt.sys [52144 2010-03-10] (Diskeeper Corporation) R1 DslMNLwf; C:\Windows\System32\DRIVERS\dslmnlwf.sys [19008 2007-08-01] (T-Systems Enterprise Services GmbH) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-11-04] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [140376 2013-11-04] (Symantec Corporation) R1 IDSVia64; C:\Program Files (x86)\Norton Internet Security\NortonData\\Definitions\IPSDefs\20131105.002\IDSvia64.sys [521816 2013-11-01] (Symantec Corporation) R3 NAVENG; C:\Program Files (x86)\Norton Internet Security\NortonData\\Definitions\VirusDefs\20131105.025\ENG64.SYS [126040 2013-11-04] (Symantec Corporation) R3 NAVEX15; C:\Program Files (x86)\Norton Internet Security\NortonData\\Definitions\VirusDefs\20131105.025\EX64.SYS [2099288 2013-11-04] (Symantec Corporation) S3 NTIOLib_1_0_1; C:\Program Files (x86)\MSI\CLICKBIOSII\NTIOLib_X64.sys [14136 2009-10-05] (MSI) R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-07-03] (Secunia) S3 SANDRA; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2011.SP5\WNt500x64\Sandra.sys [23112 2009-08-07] (SiSoftware) R3 SRTSP; C:\Windows\System32\Drivers\NISx64\1501000.012\SRTSP64.SYS [858200 2013-09-27] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1501000.012\SRTSPX64.SYS [36952 2013-09-10] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\NISx64\1501000.012\SYMDS64.SYS [493656 2013-09-10] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\NISx64\1501000.012\SYMEFA64.SYS [1147480 2013-09-27] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2013-11-05] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\NISx64\1501000.012\Ironx64.SYS [264280 2013-09-27] (Symantec Corporation) R1 SymNetS; C:\Windows\System32\Drivers\NISx64\1501000.012\SYMNETS.SYS [590936 2013-09-26] (Symantec Corporation) S3 TelekomNM6; C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM6.sys [45664 2010-09-16] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH) R0 vidsflt53; C:\Windows\System32\DRIVERS\vsflt53.sys [141920 2013-06-22] (Acronis) S3 MSI_MSIBIOS_010507; \??\C:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys [x] S3 NTIOLib_1_0_3; \??\C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [x] S3 NTIOLib_1_0_4; \??\C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-06 17:27 - 2013-11-05 21:50 - 01957098 _____ (Farbar) C:\Users\****** ******\Desktop\FRST64.exe 2013-11-06 17:12 - 2013-11-06 17:19 - 00005866 _____ C:\Users\****** ******\Desktop\gmer.txt 2013-11-06 17:12 - 2013-11-06 17:12 - 00005866 _____ C:\Users\****** ******\Documents\gmer.log 2013-11-06 17:07 - 2013-11-06 17:04 - 00377856 _____ C:\Users\****** ******\Desktop\gmer_2.1.19163.exe 2013-11-06 16:36 - 2013-11-06 16:36 - 00001244 _____ C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk 2013-11-06 16:21 - 2013-11-06 16:21 - 00000000 ____D C:\Users\****** ******\AppData\Local\{DA6A2054-1BF9-40B8-9486-B3EE2667D9C0} 2013-11-06 16:04 - 2013-11-06 16:06 - 00000000 ____D C:\ProgramData\Live Aquarium HD 2013-11-06 16:04 - 2013-11-06 16:04 - 00000000 ____D C:\Program Files (x86)\Live Aquarium HD 2013-11-06 16:04 - 2013-10-04 10:33 - 01216064 _____ (Vojnic Ladislav) C:\Windows\Live Aquarium HD.scr 2013-11-06 16:04 - 2010-05-26 12:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\D3DX9_43.dll 2013-11-06 15:57 - 2013-11-06 15:57 - 00000000 ____D C:\Program Files (x86)\K-Lite Codec Pack 2013-11-06 15:57 - 2013-08-14 19:00 - 00127488 _____ C:\Windows\system32\ff_vfw.dll 2013-11-06 15:57 - 2013-08-14 19:00 - 00112640 _____ C:\Windows\SysWOW64\ff_vfw.dll 2013-11-06 15:57 - 2013-08-02 18:29 - 00256088 _____ C:\Windows\system32\unrar64.dll 2013-11-06 15:57 - 2013-08-02 18:29 - 00217176 _____ C:\Windows\SysWOW64\unrar.dll 2013-11-06 15:57 - 2013-03-17 18:22 - 03554304 _____ (x264vfw project) C:\Windows\system32\x264vfw64.dll 2013-11-06 15:57 - 2013-03-17 17:21 - 03649536 _____ (x264vfw project) C:\Windows\SysWOW64\x264vfw.dll 2013-11-06 15:57 - 2012-07-21 11:55 - 00180736 _____ (fccHandler) C:\Windows\system32\ac3acm.acm 2013-11-06 15:57 - 2012-07-21 11:54 - 00122880 _____ (fccHandler) C:\Windows\SysWOW64\ac3acm.acm 2013-11-06 15:57 - 2011-12-07 18:37 - 00148992 _____ ( ) C:\Windows\system32\lagarith.dll 2013-11-06 15:57 - 2011-12-07 18:32 - 00216064 _____ ( ) C:\Windows\SysWOW64\lagarith.dll 2013-11-06 15:57 - 2011-06-24 15:45 - 00258560 _____ C:\Windows\system32\xvidvfw.dll 2013-11-06 15:57 - 2011-06-24 15:44 - 00243200 _____ C:\Windows\SysWOW64\xvidvfw.dll 2013-11-06 15:57 - 2011-06-24 15:31 - 00703488 _____ C:\Windows\system32\xvidcore.dll 2013-11-06 15:57 - 2011-06-24 15:28 - 00650752 _____ C:\Windows\SysWOW64\xvidcore.dll 2013-11-06 15:54 - 2013-11-06 15:54 - 00001304 _____ C:\Users\Public\Desktop\Ashampoo Burning Studio 12.lnk 2013-11-06 15:53 - 2013-11-06 15:53 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ashampoo 2013-11-06 15:49 - 2013-11-06 15:49 - 00000000 ___HD C:\ProgramData\CanonBJ 2013-11-06 15:49 - 2013-11-06 15:49 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4 2013-11-06 15:47 - 2013-11-06 15:48 - 00000000 ____D C:\Users\****** ******\Desktop\Canon+Hp 2013-11-06 15:47 - 2013-11-06 15:47 - 00000000 ___HD C:\ProgramData\CanonIJEPPEX2 2013-11-06 15:47 - 2013-11-06 15:47 - 00000000 ___HD C:\ProgramData\CanonEPP 2013-11-06 15:47 - 2013-11-06 15:47 - 00000000 ____D C:\Users\****** ******\AppData\Local\Canon Easy-PhotoPrint EX 2013-11-06 15:47 - 2013-11-06 15:47 - 00000000 ____D C:\Program Files\Common Files\Canon 2013-11-06 15:46 - 2013-11-06 15:46 - 00000000 ____D C:\Program Files\Canon 2013-11-06 15:45 - 2013-11-06 15:46 - 00000000 ____D C:\Program Files (x86)\Canon 2013-11-06 15:45 - 2013-11-06 15:45 - 00000000 ____D C:\Program Files (x86)\CD-LabelPrint 2013-11-06 15:43 - 2013-11-06 15:43 - 00000000 ____D C:\Users\****** ******\Documents\Add-in Express 2013-11-06 15:30 - 2013-11-06 15:31 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\HP 2013-11-06 15:30 - 2013-11-06 15:30 - 00000000 ____D C:\ProgramData\WEBREG 2013-11-06 15:29 - 2013-11-06 15:29 - 00003148 _____ C:\Windows\System32\Tasks\SidebarExecute 2013-11-06 15:29 - 2013-11-06 15:29 - 00002786 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2013-11-06 15:29 - 2013-11-06 15:29 - 00000000 ____D C:\Users\****** ******\AppData\Local\HP 2013-11-06 15:29 - 2013-11-06 15:29 - 00000000 ____D C:\Program Files\CCleaner 2013-11-06 15:21 - 2013-11-06 15:41 - 00000000 ____D C:\Program Files (x86)\Yahoo! 2013-11-06 15:21 - 2013-11-06 15:21 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Yahoo! 2013-11-06 15:19 - 2013-11-06 15:19 - 00000000 ____D C:\Windows\SysWOW64\spool 2013-11-06 15:19 - 2013-11-06 15:19 - 00000000 ____D C:\ProgramData\HP Product Assistant 2013-11-06 15:17 - 2013-11-06 15:33 - 00002889 _____ C:\ProgramData\hpzinstall.log 2013-11-06 15:17 - 2013-11-06 15:30 - 00245549 _____ C:\Windows\hpoins19.dat 2013-11-06 15:17 - 2013-11-06 15:30 - 00000000 ____D C:\ProgramData\HP 2013-11-06 15:17 - 2013-11-06 15:20 - 00000000 ____D C:\Program Files (x86)\HP 2013-11-06 15:17 - 2009-10-20 05:30 - 00013898 ____N C:\Windows\hpomdl19.dat 2013-11-06 15:17 - 2009-07-08 11:51 - 00861184 _____ (Hewlett-Packard) C:\Windows\system32\hpowiav1.dll 2013-11-06 15:17 - 2009-07-08 11:51 - 00730624 _____ (Hewlett-Packard Co.) C:\Windows\system32\hpotscl1.dll 2013-11-06 15:17 - 2009-07-08 11:51 - 00642360 _____ (Hewlett-Packard) C:\Windows\system32\hpzids40.dll 2013-11-06 15:17 - 2009-07-08 11:51 - 00498176 _____ (Hewlett-Packard Co.) C:\Windows\system32\hpovst01.dll 2013-11-06 15:16 - 2013-11-06 15:16 - 00000000 ____D C:\Windows\Hewlett-Packard 2013-11-06 01:15 - 2013-11-06 01:15 - 00000000 _____ C:\Users\****** ******\defogger_reenable 2013-11-06 00:31 - 2013-11-06 00:31 - 00000000 ____D C:\Users\****** ******\AppData\Local\{E46C497C-1C0F-4267-9364-EA173BFA1595} 2013-11-06 00:26 - 2013-11-06 00:26 - 00000000 ____D C:\Users\****** ******\AppData\Local\{49829345-3D1A-403A-8672-90605D11A3A5} 2013-11-06 00:14 - 2013-11-06 00:22 - 00000000 ____D C:\Program Files (x86)\Windows Live 2013-11-06 00:14 - 2013-11-06 00:14 - 00000000 ____D C:\Windows\PCHEALTH 2013-11-06 00:14 - 2013-11-06 00:14 - 00000000 ____D C:\Program Files\Windows Live 2013-11-05 23:42 - 2013-11-05 23:42 - 00000000 ____D C:\Users\****** ******\AppData\Local\{6C580F57-6E5A-47DD-A0AB-5AA8DFD00416} 2013-11-05 22:12 - 2013-06-22 20:24 - 00451816 ____R C:\Windows\system32\Drivers\etc\hosts.20131105-221238.backup 2013-11-05 22:06 - 2013-11-05 22:06 - 00001384 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk 2013-11-05 22:06 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe 2013-11-05 21:29 - 2013-11-05 21:29 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Winamp Erkennungs-Plug-in 2013-11-05 21:03 - 2013-11-05 21:03 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-11-05 21:03 - 2013-11-05 21:03 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-11-05 21:03 - 2013-11-05 21:03 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-11-05 21:03 - 2013-11-05 21:03 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-11-05 21:03 - 2013-11-05 21:03 - 00000000 ____D C:\Program Files\Java 2013-11-05 20:57 - 2013-11-05 20:59 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-05 20:49 - 2013-11-05 20:49 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-11-05 20:49 - 2013-11-05 20:49 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-11-05 20:49 - 2013-11-05 20:49 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-11-05 20:49 - 2013-11-05 20:49 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-11-05 20:49 - 2013-11-05 20:49 - 00000000 ____D C:\Program Files (x86)\Java 2013-11-05 16:09 - 2013-09-04 13:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2013-11-05 16:09 - 2013-09-04 13:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2013-11-05 16:09 - 2013-09-04 13:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2013-11-05 16:09 - 2013-09-04 13:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2013-11-05 16:09 - 2013-09-04 13:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2013-11-05 16:09 - 2013-09-04 13:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2013-11-05 16:09 - 2013-09-04 13:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2013-11-05 16:00 - 2013-09-23 00:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-05 16:00 - 2013-09-23 00:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-05 16:00 - 2013-09-23 00:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-05 16:00 - 2013-09-23 00:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-05 16:00 - 2013-09-23 00:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-05 16:00 - 2013-09-23 00:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-05 16:00 - 2013-09-23 00:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-05 16:00 - 2013-09-23 00:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-05 16:00 - 2013-09-23 00:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-05 16:00 - 2013-09-23 00:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-05 16:00 - 2013-09-23 00:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-05 16:00 - 2013-09-23 00:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-05 16:00 - 2013-09-23 00:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-05 16:00 - 2013-09-22 23:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-05 16:00 - 2013-09-22 23:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-05 16:00 - 2013-09-22 23:55 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-05 16:00 - 2013-09-22 23:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-05 16:00 - 2013-09-22 23:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-05 16:00 - 2013-09-22 23:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-05 16:00 - 2013-09-22 23:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-05 16:00 - 2013-09-22 23:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-05 16:00 - 2013-09-22 23:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-05 16:00 - 2013-09-22 23:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-05 16:00 - 2013-09-22 23:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-05 16:00 - 2013-09-22 23:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-05 16:00 - 2013-09-22 23:54 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-05 16:00 - 2013-09-22 23:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-05 16:00 - 2013-09-21 04:38 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-05 16:00 - 2013-09-21 04:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-05 16:00 - 2013-09-21 03:48 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-05 16:00 - 2013-09-21 03:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-05 15:46 - 2013-11-05 15:48 - 00000000 ____D C:\Windows\system32\MRT 2013-11-05 15:24 - 2013-08-02 03:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-11-05 15:24 - 2013-08-02 03:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-11-05 15:24 - 2013-08-02 03:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2013-11-05 15:24 - 2013-08-02 02:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-11-05 15:24 - 2013-08-02 01:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2013-11-05 15:24 - 2013-08-02 01:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 01:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 01:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 01:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2013-11-05 15:20 - 2013-09-14 02:10 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-11-05 15:20 - 2013-09-08 03:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-11-05 15:20 - 2013-09-08 03:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-11-05 15:20 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2013-11-05 15:20 - 2013-08-29 03:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-11-05 15:20 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-11-05 15:20 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2013-11-05 15:20 - 2013-08-29 03:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-11-05 15:20 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-11-05 15:20 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-11-05 15:20 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-11-05 15:20 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-11-05 15:20 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2013-11-05 15:20 - 2013-08-29 02:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-11-05 15:20 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2013-11-05 15:20 - 2013-08-29 01:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-11-05 15:20 - 2013-08-29 01:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-11-05 15:20 - 2013-08-29 01:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-11-05 15:20 - 2013-08-29 01:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-11-05 15:20 - 2013-07-26 03:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-11-05 15:20 - 2013-07-26 03:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-11-05 15:20 - 2013-07-26 02:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-11-05 15:20 - 2013-07-26 02:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-11-05 15:20 - 2013-07-09 06:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-11-05 15:20 - 2013-07-09 06:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-11-05 15:20 - 2013-07-09 06:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-11-05 15:20 - 2013-07-09 06:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-11-05 15:20 - 2013-07-09 05:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-11-05 15:20 - 2013-07-09 05:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-11-05 15:20 - 2013-07-09 05:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-11-05 15:20 - 2013-07-09 05:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-11-05 15:19 - 2013-08-28 02:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-11-05 15:19 - 2013-08-05 03:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2013-11-05 15:19 - 2013-07-25 10:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-11-05 15:19 - 2013-07-25 09:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-11-05 15:19 - 2013-07-20 11:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-11-05 15:19 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2013-11-05 15:19 - 2013-07-19 02:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-11-05 15:19 - 2013-07-19 02:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-11-05 15:19 - 2013-07-12 11:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2013-11-05 15:19 - 2013-07-09 06:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-11-05 15:19 - 2013-07-09 05:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-11-05 15:19 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2013-11-05 15:19 - 2013-07-04 13:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2013-11-05 15:19 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2013-11-05 15:19 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2013-11-05 15:19 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2013-11-05 15:19 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2013-11-05 15:19 - 2013-07-04 11:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2013-11-05 15:19 - 2013-07-03 05:40 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys 2013-11-05 15:19 - 2013-07-03 05:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2013-11-05 15:19 - 2013-07-03 05:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2013-11-05 15:19 - 2013-06-25 23:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2013-11-05 15:19 - 2013-06-15 05:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-11-05 15:19 - 2013-06-06 06:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2013-11-05 15:19 - 2013-06-06 06:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2013-11-05 15:19 - 2013-06-06 06:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2013-11-05 15:19 - 2013-06-06 06:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-11-05 15:19 - 2013-06-06 05:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2013-11-05 15:19 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2013-11-05 15:19 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2013-11-05 15:19 - 2013-06-06 04:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-11-05 15:19 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2013-11-05 15:19 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2013-11-05 15:18 - 2013-06-04 07:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-11-05 15:18 - 2013-06-04 05:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2013-11-05 15:07 - 2013-04-10 00:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-11-05 15:07 - 2013-04-02 23:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-11-05 15:04 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2013-11-05 15:03 - 2013-08-01 13:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-11-05 14:39 - 2013-11-05 14:55 - 00000000 ____D C:\Users\****** ******\AppData\Local\NPE 2013-11-05 14:30 - 2013-11-05 14:30 - 00000000 ____D C:\Windows\System32\Tasks\Norton Internet Security 2013-11-05 14:24 - 2013-11-05 14:26 - 00002506 _____ C:\Users\Public\Desktop\Norton Internet Security.lnk 2013-11-05 13:54 - 2013-11-05 13:54 - 00000000 ____D C:\FRST 2013-11-05 12:37 - 2013-11-05 12:37 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton 2013-11-05 12:28 - 2013-11-05 12:28 - 00000000 ____D C:\trojaner board soft s 2013-11-05 12:23 - 2013-11-06 17:03 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2013-11-05 12:23 - 2013-11-06 16:41 - 00116440 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2013-11-05 12:23 - 2013-11-05 12:23 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-05 12:18 - 2013-11-06 16:41 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2013-11-05 12:17 - 2013-11-06 17:03 - 00000000 ____D C:\Users\****** ******\Desktop\mbar 2013-10-27 09:12 - 2013-10-27 09:12 - 30344480 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 25257248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 22933792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 15855568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 15212336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 12572960 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2013-10-27 09:12 - 2013-10-27 09:12 - 11426568 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 11374520 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 09524088 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 09480328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 03131680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 03124512 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 02946848 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 02747168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433165.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433165.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 01510176 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco64.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 01241376 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00696096 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00655136 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00560416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00196384 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2013-10-27 09:12 - 2013-10-27 09:12 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2013-10-23 03:02 - 2013-10-23 03:02 - 00589600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe ==================== One Month Modified Files and Folders ======= 2013-11-06 17:26 - 2012-03-30 22:46 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-11-06 17:23 - 2009-07-14 05:45 - 00021696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-06 17:23 - 2009-07-14 05:45 - 00021696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-06 17:20 - 2011-10-08 21:28 - 01406331 _____ C:\Windows\WindowsUpdate.log 2013-11-06 17:19 - 2013-11-06 17:12 - 00005866 _____ C:\Users\****** ******\Desktop\gmer.txt 2013-11-06 17:15 - 2013-01-11 21:10 - 00001118 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-11-06 17:15 - 2011-10-09 03:45 - 00000000 ____D C:\Users\****** ******\.rainlendar2 2013-11-06 17:14 - 2011-11-28 18:32 - 00091663 _____ C:\Windows\setupact.log 2013-11-06 17:14 - 2011-10-12 13:13 - 00000000 ____D C:\ProgramData\NVIDIA 2013-11-06 17:14 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-06 17:12 - 2013-11-06 17:12 - 00005866 _____ C:\Users\****** ******\Documents\gmer.log 2013-11-06 17:04 - 2013-11-06 17:07 - 00377856 _____ C:\Users\****** ******\Desktop\gmer_2.1.19163.exe 2013-11-06 17:03 - 2013-11-05 12:23 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2013-11-06 17:03 - 2013-11-05 12:17 - 00000000 ____D C:\Users\****** ******\Desktop\mbar 2013-11-06 16:41 - 2013-11-05 12:23 - 00116440 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2013-11-06 16:41 - 2013-11-05 12:18 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2013-11-06 16:38 - 2010-11-21 04:47 - 00180016 _____ C:\Windows\PFRO.log 2013-11-06 16:36 - 2013-11-06 16:36 - 00001244 _____ C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk 2013-11-06 16:36 - 2011-10-09 01:41 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\DVDVideoSoftIEHelpers 2013-11-06 16:36 - 2011-10-09 01:41 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\DVDVideoSoft 2013-11-06 16:36 - 2011-10-09 01:41 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft 2013-11-06 16:29 - 2013-01-11 21:10 - 00001122 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-11-06 16:21 - 2013-11-06 16:21 - 00000000 ____D C:\Users\****** ******\AppData\Local\{DA6A2054-1BF9-40B8-9486-B3EE2667D9C0} 2013-11-06 16:14 - 2009-07-14 05:45 - 00315320 _____ C:\Windows\system32\FNTCACHE.DAT 2013-11-06 16:06 - 2013-11-06 16:04 - 00000000 ____D C:\ProgramData\Live Aquarium HD 2013-11-06 16:04 - 2013-11-06 16:04 - 00000000 ____D C:\Program Files (x86)\Live Aquarium HD 2013-11-06 16:03 - 2011-10-08 23:47 - 00072232 _____ C:\Users\****** ******\AppData\Local\GDIPFONTCACHEV1.DAT 2013-11-06 15:57 - 2013-11-06 15:57 - 00000000 ____D C:\Program Files (x86)\K-Lite Codec Pack 2013-11-06 15:56 - 2011-11-03 10:24 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Ashampoo 2013-11-06 15:56 - 2011-10-09 01:49 - 00000000 ____D C:\Users\****** ******\AppData\Local\ashampoo 2013-11-06 15:54 - 2013-11-06 15:54 - 00001304 _____ C:\Users\Public\Desktop\Ashampoo Burning Studio 12.lnk 2013-11-06 15:53 - 2013-11-06 15:53 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ashampoo 2013-11-06 15:53 - 2011-10-09 01:49 - 00000000 ____D C:\ProgramData\ashampoo 2013-11-06 15:53 - 2011-10-09 01:49 - 00000000 ____D C:\Program Files (x86)\Ashampoo 2013-11-06 15:49 - 2013-11-06 15:49 - 00000000 ___HD C:\ProgramData\CanonBJ 2013-11-06 15:49 - 2013-11-06 15:49 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4 2013-11-06 15:48 - 2013-11-06 15:47 - 00000000 ____D C:\Users\****** ******\Desktop\Canon+Hp 2013-11-06 15:47 - 2013-11-06 15:47 - 00000000 ___HD C:\ProgramData\CanonIJEPPEX2 2013-11-06 15:47 - 2013-11-06 15:47 - 00000000 ___HD C:\ProgramData\CanonEPP 2013-11-06 15:47 - 2013-11-06 15:47 - 00000000 ____D C:\Users\****** ******\AppData\Local\Canon Easy-PhotoPrint EX 2013-11-06 15:47 - 2013-11-06 15:47 - 00000000 ____D C:\Program Files\Common Files\Canon 2013-11-06 15:47 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\system32\FxsTmp 2013-11-06 15:46 - 2013-11-06 15:46 - 00000000 ____D C:\Program Files\Canon 2013-11-06 15:46 - 2013-11-06 15:45 - 00000000 ____D C:\Program Files (x86)\Canon 2013-11-06 15:45 - 2013-11-06 15:45 - 00000000 ____D C:\Program Files (x86)\CD-LabelPrint 2013-11-06 15:43 - 2013-11-06 15:43 - 00000000 ____D C:\Users\****** ******\Documents\Add-in Express 2013-11-06 15:43 - 2011-12-30 20:41 - 00000000 ____D C:\ProgramData\WinZip 2013-11-06 15:43 - 2011-10-08 21:53 - 00000000 ____D C:\Users\****** ****** 2013-11-06 15:42 - 2011-10-08 22:59 - 00000000 ___RD C:\Users\****** ******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sys-Software 2013-11-06 15:41 - 2013-11-06 15:21 - 00000000 ____D C:\Program Files (x86)\Yahoo! 2013-11-06 15:33 - 2013-11-06 15:17 - 00002889 _____ C:\ProgramData\hpzinstall.log 2013-11-06 15:32 - 2011-10-09 01:18 - 00000000 ____D C:\Users\****** ******\AppData\Local\CrashDumps 2013-11-06 15:31 - 2013-11-06 15:30 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\HP 2013-11-06 15:30 - 2013-11-06 15:30 - 00000000 ____D C:\ProgramData\WEBREG 2013-11-06 15:30 - 2013-11-06 15:17 - 00245549 _____ C:\Windows\hpoins19.dat 2013-11-06 15:30 - 2013-11-06 15:17 - 00000000 ____D C:\ProgramData\HP 2013-11-06 15:29 - 2013-11-06 15:29 - 00003148 _____ C:\Windows\System32\Tasks\SidebarExecute 2013-11-06 15:29 - 2013-11-06 15:29 - 00002786 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2013-11-06 15:29 - 2013-11-06 15:29 - 00000000 ____D C:\Users\****** ******\AppData\Local\HP 2013-11-06 15:29 - 2013-11-06 15:29 - 00000000 ____D C:\Program Files\CCleaner 2013-11-06 15:29 - 2009-07-14 03:34 - 00000499 _____ C:\Windows\win.ini 2013-11-06 15:21 - 2013-11-06 15:21 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Yahoo! 2013-11-06 15:20 - 2013-11-06 15:17 - 00000000 ____D C:\Program Files (x86)\HP 2013-11-06 15:19 - 2013-11-06 15:19 - 00000000 ____D C:\Windows\SysWOW64\spool 2013-11-06 15:19 - 2013-11-06 15:19 - 00000000 ____D C:\ProgramData\HP Product Assistant 2013-11-06 15:18 - 2012-06-29 12:36 - 00003982 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{1C6C1C2F-D891-4AC6-B935-A56BE995074F} 2013-11-06 15:16 - 2013-11-06 15:16 - 00000000 ____D C:\Windows\Hewlett-Packard 2013-11-06 01:15 - 2013-11-06 01:15 - 00000000 _____ C:\Users\****** ******\defogger_reenable 2013-11-06 00:37 - 2011-10-09 01:57 - 00000000 ____D C:\Users\****** ******\AppData\Local\Windows Live 2013-11-06 00:31 - 2013-11-06 00:31 - 00000000 ____D C:\Users\****** ******\AppData\Local\{E46C497C-1C0F-4267-9364-EA173BFA1595} 2013-11-06 00:26 - 2013-11-06 00:26 - 00000000 ____D C:\Users\****** ******\AppData\Local\{49829345-3D1A-403A-8672-90605D11A3A5} 2013-11-06 00:22 - 2013-11-06 00:14 - 00000000 ____D C:\Program Files (x86)\Windows Live 2013-11-06 00:14 - 2013-11-06 00:14 - 00000000 ____D C:\Windows\PCHEALTH 2013-11-06 00:14 - 2013-11-06 00:14 - 00000000 ____D C:\Program Files\Windows Live 2013-11-06 00:14 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2013-11-06 00:08 - 2011-10-09 01:39 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Macromedia 2013-11-05 23:47 - 2011-04-12 08:43 - 00696620 _____ C:\Windows\system32\perfh007.dat 2013-11-05 23:47 - 2011-04-12 08:43 - 00147916 _____ C:\Windows\system32\perfc007.dat 2013-11-05 23:47 - 2009-07-14 06:13 - 01612484 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-05 23:42 - 2013-11-05 23:42 - 00000000 ____D C:\Users\****** ******\AppData\Local\{6C580F57-6E5A-47DD-A0AB-5AA8DFD00416} 2013-11-05 23:27 - 2012-04-26 22:32 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-05 23:04 - 2011-10-12 13:12 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2013-11-05 23:03 - 2011-10-12 13:13 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-11-05 22:37 - 2011-10-09 01:25 - 00000000 ____D C:\Program Files (x86)\DSL-Manager 2013-11-05 22:07 - 2013-06-22 20:13 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2 2013-11-05 22:06 - 2013-11-05 22:06 - 00001384 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk 2013-11-05 22:06 - 2013-06-22 20:14 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-11-05 21:50 - 2013-11-06 17:27 - 01957098 _____ (Farbar) C:\Users\****** ******\Desktop\FRST64.exe 2013-11-05 21:29 - 2013-11-05 21:29 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Winamp Erkennungs-Plug-in 2013-11-05 21:29 - 2011-10-09 03:25 - 00000984 _____ C:\Users\Public\Desktop\Winamp.lnk 2013-11-05 21:29 - 2011-10-09 03:25 - 00000000 ____D C:\Program Files (x86)\Winamp Detect 2013-11-05 21:29 - 2011-10-09 03:25 - 00000000 ____D C:\Program Files (x86)\Winamp 2013-11-05 21:16 - 2011-10-09 02:03 - 00000000 ____D C:\Program Files (x86)\Opera 2013-11-05 21:09 - 2013-01-11 21:14 - 00002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-11-05 21:08 - 2011-10-08 23:00 - 00000000 ___RD C:\Users\****** ******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sicherheit 2013-11-05 21:06 - 2011-11-03 21:08 - 00000000 ____D C:\Program Files (x86)\XP antispy 2013-11-05 21:03 - 2013-11-05 21:03 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-11-05 21:03 - 2013-11-05 21:03 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-11-05 21:03 - 2013-11-05 21:03 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-11-05 21:03 - 2013-11-05 21:03 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-11-05 21:03 - 2013-11-05 21:03 - 00000000 ____D C:\Program Files\Java 2013-11-05 20:59 - 2013-11-05 20:57 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-05 20:59 - 2012-06-02 19:53 - 00001080 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-11-05 20:58 - 2011-10-09 02:06 - 00000000 ____D C:\Users\****** ******\AppData\Local\Mozilla 2013-11-05 20:49 - 2013-11-05 20:49 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-11-05 20:49 - 2013-11-05 20:49 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-11-05 20:49 - 2013-11-05 20:49 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-11-05 20:49 - 2013-11-05 20:49 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-11-05 20:49 - 2013-11-05 20:49 - 00000000 ____D C:\Program Files (x86)\Java 2013-11-05 20:48 - 2011-10-09 06:08 - 00000000 ____D C:\ProgramData\InstallMate 2013-11-05 16:33 - 2012-03-30 22:46 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-11-05 16:33 - 2012-03-30 22:46 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-11-05 16:33 - 2011-10-09 03:32 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-11-05 16:06 - 2011-10-09 06:30 - 00000000 ___RD C:\Users\****** ******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-11-05 16:06 - 2011-10-08 21:53 - 00000000 ___RD C:\Users\****** ******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-11-05 16:05 - 2012-05-09 23:57 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-11-05 16:05 - 2012-05-09 23:57 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-11-05 16:03 - 2011-04-12 08:55 - 00000000 ____D C:\Program Files\Windows Journal 2013-11-05 16:03 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Defender 2013-11-05 16:03 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2013-11-05 15:55 - 2011-10-09 13:54 - 01589442 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-11-05 15:48 - 2013-11-05 15:46 - 00000000 ____D C:\Windows\system32\MRT 2013-11-05 14:55 - 2013-11-05 14:39 - 00000000 ____D C:\Users\****** ******\AppData\Local\NPE 2013-11-05 14:40 - 2011-10-09 00:30 - 00000000 ____D C:\ProgramData\Norton 2013-11-05 14:36 - 2011-10-09 06:03 - 00000000 ____D C:\Program Files (x86)\MAXA Cookie Manager 2013-11-05 14:30 - 2013-11-05 14:30 - 00000000 ____D C:\Windows\System32\Tasks\Norton Internet Security 2013-11-05 14:26 - 2013-11-05 14:24 - 00002506 _____ C:\Users\Public\Desktop\Norton Internet Security.lnk 2013-11-05 14:26 - 2012-03-07 13:04 - 00000000 ____D C:\Windows\system32\Drivers\NISx64 2013-11-05 14:26 - 2011-10-09 00:55 - 00003234 _____ C:\Windows\System32\Tasks\Norton WSC Integration 2013-11-05 14:24 - 2013-01-11 21:10 - 00004118 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-11-05 14:24 - 2013-01-11 21:10 - 00003866 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-11-05 14:24 - 2011-10-09 00:33 - 00177752 _____ (Symantec Corporation) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS 2013-11-05 14:24 - 2011-10-09 00:33 - 00008222 _____ C:\Windows\system32\Drivers\SYMEVENT64x86.CAT 2013-11-05 14:23 - 2012-03-07 13:04 - 00000000 ____D C:\Program Files (x86)\Norton Internet Security 2013-11-05 13:54 - 2013-11-05 13:54 - 00000000 ____D C:\FRST 2013-11-05 13:53 - 2011-10-09 01:08 - 00000000 ____D C:\Program Files (x86)\Deutsche Telekom 2013-11-05 13:52 - 2013-06-22 23:32 - 00000442 _____ C:\Windows\wininit.ini 2013-11-05 12:37 - 2013-11-05 12:37 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton 2013-11-05 12:37 - 2011-10-09 03:29 - 00000000 ____D C:\Program Files (x86)\OpenOffice.org 3 2013-11-05 12:28 - 2013-11-05 12:28 - 00000000 ____D C:\trojaner board soft s 2013-11-05 12:23 - 2013-11-05 12:23 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-05 12:19 - 2011-10-09 00:35 - 00000000 ____D C:\Users\Public\Downloads\Norton 2013-11-05 12:14 - 2011-04-12 08:55 - 00000000 ____D C:\Windows\CSC 2013-10-27 09:12 - 2013-10-27 09:12 - 30344480 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 25257248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 22933792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 15855568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 15212336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 12572960 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2013-10-27 09:12 - 2013-10-27 09:12 - 11426568 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 11374520 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 09524088 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 09480328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 03131680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 03124512 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 02946848 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 02747168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433165.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433165.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 01510176 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco64.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 01241376 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00696096 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00655136 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00560416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00196384 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2013-10-27 09:12 - 2013-10-27 09:12 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2013-10-27 09:12 - 2013-02-25 23:32 - 02695200 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2013-10-27 09:12 - 2012-10-10 20:23 - 18199872 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2013-10-27 09:12 - 2012-02-24 02:38 - 01435504 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2013-10-27 09:12 - 2011-10-12 13:09 - 18286416 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2013-10-27 09:12 - 2011-10-12 13:09 - 03067560 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2013-10-27 09:12 - 2011-10-12 13:09 - 00023287 _____ C:\Windows\system32\nvinfo.pb 2013-10-23 09:20 - 2012-02-24 02:39 - 03426956 _____ C:\Windows\system32\nvcoproc.bin 2013-10-23 09:20 - 2011-10-12 13:12 - 06669600 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2013-10-23 09:20 - 2011-10-12 13:12 - 03489568 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2013-10-23 09:20 - 2011-10-12 13:12 - 02559776 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2013-10-23 09:20 - 2011-10-12 13:12 - 00922912 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2013-10-23 09:20 - 2011-10-12 13:12 - 00219424 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2013-10-23 09:20 - 2011-10-12 13:12 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2013-10-23 03:02 - 2013-10-23 03:02 - 00589600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe Some content of TEMP: ==================== C:\Users\****** ******\AppData\Local\Temp\_is21A2.exe C:\Users\****** ******\AppData\Local\Temp\_is2D56.exe C:\Users\****** ******\AppData\Local\Temp\_is433.exe C:\Users\****** ******\AppData\Local\Temp\_is9DB5.exe C:\Users\****** ******\AppData\Local\Temp\_isC189.exe C:\Users\****** ******\AppData\Local\Temp\_isD72C.exe C:\Users\****** ******\AppData\Local\Temp\_isDA85.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-06-22 23:09 ==================== End Of Log ============================ |
![]() | #23 |
![]() | ![]() Win7 IP tunnelt mich jede Nacht und kapert Teledat 530 Router Und noch dies: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 31-10-2013 Ran by ****** ****** at 2013-11-06 17:27:58 Running from C:\Users\****** ******\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Norton Internet Security (Enabled - Up to date) {63DF5164-9100-186D-2187-8DC619EFD8BF} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} AS: Norton Internet Security (Enabled - Up to date) {D8BEB080-B73A-17E3-1B37-B6B462689202} FW: Norton Internet Security (Enabled) {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} ==================== Installed Programs ====================== 3DMark 11 (x32 Version: 1.0.2) 3GX (x32 Version: 3.03.2101) 64 Bit HP CIO Components Installer (Version: 7.2.8) 7-Zip 4.57 (x32) Acronis True Image WD Edition (x32 Version: 13.0.14189) Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117) Adobe Reader X (10.1.8) - Deutsch (x32 Version: 10.1.8) aerosoft's - Im Koeblitzer Bergland (x32 Version: 1.10) AIO_CDB_ProductContext (x32 Version: 130.0.365.000) AIO_CDB_Software (x32 Version: 130.0.365.000) AIO_Scan (x32 Version: 130.0.421.000) Apache: Air Assault (x32 Version: Ashampoo Burning Studio 10 v.10.0.15 (x32 Version: 10.0.15) Ashampoo Burning Studio 12 v.12.0.5 (x32 Version: 12.0.5) Assets Lgine du Nord version V1.00 (x32 Version: V1.00) Assets Ligne du Nord version V1.01 (x32 Version: V1.01) AudioGenie (x32) Batman: Arkham City GOTY (x32) Blur (x32) BOSS (x32 Version: 2.0.0) BufferChm (x32 Version: 130.0.331.000) Call of Juarez: Bound in Blood (x32) Canon Easy-PhotoPrint EX (x32 Version: 4.1.6) Canon Inkjet Printer Driver Add-On Module Canon My Printer (x32 Version: 3.1.0) CCleaner (Version: 4.07) CD-LabelPrint (x32) Choplifter HD (x32) CLICKBIOSII (x32 Version: 1.0.021) Colin McRae Rally 2005 (x32 Version: 1.00.000) ControlCenter (x32 Version: 2.2.036) Copy (x32 Version: 130.0.428.000) CPUID CPU-Z 1.58 Creation Kit (x32) CrystalDiskInfo 5.3.1 (x32 Version: 5.3.1) CyberLink BD_3D Advisor 2.0 (x32 Version: 2.0.5425) CyberLink LabelPrint 2.5 (x32 Version: 2.5.5311) CyberLink Media Suite 10 (x32 Version: 10.0) CyberLink Media Suite 10 (x32 Version: 10.2021) CyberLink MediaEspresso 6.5 (x32 Version: 6.5.3019_44673) CyberLink MediaShow 6 (x32 Version: 6.0.4312) CyberLink Power2Go 7 (x32 Version: CyberLink PowerDVD 10 (x32 Version: 10.0.4125.52) CyberLink PowerProducer 5.5 (x32 Version: D3DX10 (x32 Version: 15.4.2368.0902) Daniusoft Media Converter(Build (x32) Destinations (x32 Version: DeviceDiscovery (x32 Version: 130.0.465.000) DHTML Editing Component (x32 Version: 6.02.0001) DiRT 3 (x32 Version: 1.0.0000.130) DiRT 3 (x32 Version: 1.0.0003.130) Diskeeper 2010 (Version: 14.0.915.64) Disktrix UltimateDefrag (x32) DocProc (x32 Version: Download Updater (AOL Inc.) (x32) DSL-Manager (x32) Dual-Core Optimizer (x32 Version: dutchpack 2.00 (x32) EPSON Attach To Email (x32 Version: 1.01.0000) Epson Easy Photo Print 2 (x32 Version: Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) (x32 Version: 1.00.0000) EPSON File Manager (x32 Version: EPSON Scan Assistant (x32 Version: 1.10.00) EVGA Precision X 3.0.4 (x32 Version: 3.0.4) F300 (x32 Version: 130.0.365.000) F300_Help (x32 Version: F300Trb (x32 Version: Fax (x32 Version: 130.0.418.000) Free Download Manager 3.9.2 (x32) Free Studio version 2013 (x32 Version: Freightliner Heavy Haul Class 66 (x32) Freightliner Heavy Haul Class 66V2.0 (x32) FUJIFILM USB Driver (x32) Futuremark SystemInfo (x32 Version: 4.2.0) GameShadow (x32 Version: 2.03.0000) GIMP 2.8.4 (Version: 2.8.4) Google Chrome (x32 Version: 30.0.1599.101) Google Update Helper (x32 Version: GPBaseService2 (x32 Version: 130.0.371.000) GRID (x32 Version: 1.30.0000) HP Customer Participation Program 13.0 (Version: 13.0) HP Imaging Device Functions 13.0 (Version: 13.0) HP Photosmart Officejet and Deskjet All-In-One Driver Software 13.0 Rel. B (Version: 13.0) HP Solution Center 13.0 (Version: 13.0) HP Update (x32 Version: HPPhotoGadget (x32 Version: HPProductAssistant (x32 Version: 130.0.371.000) HPSSupply (x32 Version: 130.0.371.000) Intel(R) Control Center (x32 Version: Intel(R) Management Engine Components (x32 Version: Intel(R) Processor Graphics (x32 Version: IrfanView (remove only) (x32 Version: 4.36) IsoBuster 2.8.5 (x32 Version: 2.8.5) Java 7 Update 45 (64-bit) (Version: 7.0.450) Java 7 Update 45 (x32 Version: 7.0.450) JMicron JMB36X Driver (x32 Version: Junk Mail filter update (x32 Version: 15.4.3502.0922) Just Trains - Class 67 Advanced & Car Carriers (x32 Version: 1.00.0000) Just Trains - Rail Simulator Official Expansion Pack: Isle of Wight & Class 66 (x32 Version: 1.00.0000) Just Trains - Rebuilt Bulleid Light Pacific (x32 Version: 1.00.0000) Just Trains - Scottish East Coast Main Line (x32 Version: 1.00.0000) Just Trains - Streamlined Princess Coronation Class for RailWorks (x32 Version: 1.00.0000) Just Trains - Streamlined Princess Coronation Class for TRS 2013 (x32 Version: 1.00.0000) Just Trains - Voyager (x32 Version: 1.00.0000) Just Trains A4 Pacific Class British Rail Add-on Pack for RailWorks (x32 Version: 1.00.0000) Just Trains A4 Pacific Class British Rail Add-on Pack for Train Simulator 2013 (x32 Version: 1.00.0000) Just Trains A4 Pacific Class for RailWorks (x32 Version: 1.00.0000) Just Trains A4 Pacific Class for Train Simulator 2013 (x32 Version: 1.00.0000) Just Trains A4 Pacific Class LNER Add-on Pack for RailWorks (x32 Version: 1.00.0000) Just Trains Class 20 Collection for RailWorks (x32 Version: 1.00.0000) Just Trains Class 67 Free Livery (x32 Version: 1.00.0000) Just Trains JJA Autoballaster for RailWorks (x32 Version: 1.00.0000) Just Trains Seacow for RailWorks (x32 Version: 1.00.0000) K-Lite Mega Codec Pack 10.0.0 (x32 Version: 10.0.0) KRS pak Delete (x32) Link Shell Extension Live Aquarium HD (x32 Version: 3) Logitech Harmony Remote Software (x86) (x32 Version: 2.0) MarketResearch (x32 Version: 130.0.374.000) marvell 91xx driver (x32 Version: MAXA Cookie Manager Pro 5.3 (x32) MegaStore Game Controller (Ver. 3.0) (x32 Version: 3.0) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Baseline Security Analyzer 2.2 (Version: 2.2.2170) Microsoft Games for Windows - LIVE Redistributable (x32 Version: Microsoft Games for Windows Marketplace (x32 Version: Microsoft Silverlight (Version: 5.1.20913.0) Microsoft Train Simulator (x32) Microsoft VC9 runtime libraries (x32 Version: 2.0.0) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (x32 Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (x32 Version: 9.0.30411) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0) Microsoft Xbox 360 Accessories 1.2 (Version: Microsoft XNA Framework Redistributable 4.0 Refresh (x32 Version: 4.0.30901.0) Mozilla Firefox 25.0 (x86 de) (x32 Version: 25.0) Mozilla Maintenance Service (x32 Version: 25.0) MSVCRT (x32 Version: 15.4.2862.0708) MSVCRT_amd64 (x32 Version: 15.4.2862.0708) MSXML 4.0 SP3 Parser (KB2721691) (x32 Version: 4.30.2114.0) MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0) MSXML 4.0 SP3 Parser (KB973685) (x32 Version: 4.30.2107.0) MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0) NAVIGON Fresh 3.4.1 (x32 Version: 3.4.1) Need for Speed™ Most Wanted (x32) Network64 (Version: 130.0.572.000) Network64 (Version: Netzmanager (Version: 1.07) Netzmanager (x32 Version: 1.07) Nexus Mod Manager (Version: 0.44.12) Norton Internet Security (x32 Version: NVIDIA 3D Vision Controller-Treiber 296.10 (Version: 296.10) NVIDIA 3D Vision Treiber 331.65 (Version: 331.65) NVIDIA Alien vs. Triangles demo (x32 Version: 1.0) NVIDIA Endless City demo (x32 Version: 1.0) NVIDIA Grafiktreiber 331.65 (Version: 331.65) NVIDIA Install Application (Version: 2.1002.133.889) NVIDIA PhysX (x32 Version: 9.12.0213) NVIDIA PhysX-Systemsoftware 9.12.0213 (Version: 9.12.0213) NVIDIA Stereoscopic 3D Driver (x32 Version: NVIDIA Systemsteuerung 331.65 (Version: 331.65) NVIDIA Update 1.15.2 (Version: 1.15.2) NVIDIA Update Components (Version: 1.15.2) OCR Software by I.R.I.S. 13.0 (Version: 13.0) OpenAL (x32) OpenOffice 4.0.1 (x32 Version: 4.01.9714) Opera 12.16 (x32 Version: 12.16.1860) Paint.NET v3.5.10 (Version: 3.60.0) Personal Backup 5.4 (x32 Version: 5.3) PhoenixRC (x32 Version: 2.00.10) PlayMemories Home (x32 Version: Primo (x32 Version: 1.00.0000) Python 2.7.3 (64-bit) (Version: 2.7.3150) RAGE (x32) Railworks Community Asset Project (x32 Version: v1.12.24.12) Rainlendar2 (remove only) (x32) Rapture3D 2.4.8 Game (x32) Realtek Ethernet Controller Driver (x32 Version: Realtek High Definition Audio Driver (x32 Version: Recuva (Version: 1.43) REFLEX Modellflugsimulator (x32 Version: 5.04.2) Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: Ridge Racer™ Unbounded (x32) Roadkil's Unstoppable Copier Version 5.2 (x32) Runtime (x32 Version: 1.00.0000) Rural Landscapes (x32 Version: - Freeware Edition) Rural Landscapes (x32 Version: v1.06.22.09 HR Edition) RW_Tools V2 (HKCU) RW_Tools V3 (HKCU) RW_Tools V4 (HKCU) Scan (x32 Version: Secunia PSI ( (x32 Version: Shop for HP Supplies (Version: 13.0) Silent Hunter 4 Wolves of the Pacific (x32 Version: 1.04.0000) Silent Hunter III (x32 Version: 1.00.0000) SimpleScreenshot 1.40 (x32) Simtrain's - SBB Route 1 (x32 Version: 1.00) SiSoftware Sandra Lite 2011.SP5 (Version: 17.80.2011.10) Skyrim NPC Editor (x32 Version: 0.75.1) SL-6640 Black Widow Flightstick (x32 Version: 3.1) SolutionCenter (x32 Version: 130.0.373.000) Spelling Dictionaries Support For Adobe Reader 9 (x32 Version: 9.0.0) Spybot - Search & Destroy (x32 Version: 2.2.25) Status (x32 Version: 130.0.469.000) Steam (x32 Version: Suoni Italiani per RailWorks v 1.0 (x32) Take On Helicopters (x32) Test Drive Unlimited (x32 Version: 1.00.0000) The Donner Pass freeware scenario set by TaD (HKCU) The Elder Scrolls V: Skyrim (x32) the Mother of Tears - Cleaner Part 1 (x32) The Walking Dead (x32) T-Online 6.0 (x32) T-Online WLAN-Access Finder (x32) Toolbox (x32 Version: 130.0.648.000) Torino Genova Rel. 1.0 per RailWorks (x32) Torino Genova Rel. 3.0 per RailWorks (x32) Train Simulator 2013 (x32) Train Store (German Language Pack) (x32) Train Store V3.2 (x32) TrayApp (x32 Version: 130.0.422.000) TreeSize Free V2.5 (x32 Version: 2.5) Überwachungstool für die Intel® Turbo-Boost-Technik 2.0 (Version: UKTS Freeware Pack - Blocks-Lofts-Bridges #1 (x32 Version: 1.0.9) UKTS Freeware Pack - Clutter #1 (x32 Version: 1.0.6) UKTS Freeware Pack - CN Rolling Stock Pack #1 (x32 Version: 1.0.1) UKTS Freeware Pack - Commercial #1 (x32 Version: 1.0.3) UKTS Freeware Pack - Foliage #1 (x32 Version: 1.0.2) UKTS Freeware Pack - Great Central Railway Loco Pack (x32 Version: 1.0.3) UKTS Freeware Pack - Great Scenario Challenge #1 (x32 Version: 1.0.5) UKTS Freeware Pack - Housing #1 (x32 Version: 1.1.1) UKTS Freeware Pack - Industrial #1 (x32 Version: 1.0.3) UKTS Freeware Pack - Railway Buildings #1 (x32 Version: 1.0.4) UKTS Freeware Pack - Terrain Textures #1 (x32 Version: 1.0.1) UKTS Freeware Pack - UK Carriages #1 (x32 Version: 1.1.2) UKTS Freeware Pack - UK Classic Diesel and Electric #1 (x32 Version: 1.1.2) UKTS Freeware Pack - UK DMUs-EMUs-Trams #1 (x32 Version: 1.1.5) UKTS Freeware Pack - UK Modern Diesel and Electric #1 (x32 Version: 1.1.1) UKTS Freeware Pack - UK Steam #1 (x32 Version: 1.1.1) UKTS Freeware Pack - UK Wagons #1 (x32 Version: 1.1.3) UKTS Freeware Route Pack - Candlewick (x32 Version: 1.0.3) UKTS Freeware Route Pack - Coniston Branch (x32 Version: 1.0.7) UKTS Freeware Route Pack - Lavender Line (x32 Version: 1.0.2) UKTS Freeware Route Pack - QiLian Mountain Line (x32 Version: 1.0.3) UKTS Freeware Route Pack - The Mayflower Line (x32 Version: 2.0.0) UnloadSupport (x32 Version: 11.0.0) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (x32 Version: 3) USB game controller (x32 Version: 1.00.0000) USBFast (x32 Version: VLC media player 2.1.0 (Version: 2.1.0) VLC media player 2.1.0 (x32 Version: 2.1.0) WebReg (x32 Version: Winamp (x32 Version: 5.65 ) Winamp Erkennungs-Plug-in (HKCU Version: Winamp Toolbar (HKCU) Winamp Toolbar (x32) Windows 7 USB/DVD Download Tool (x32 Version: 1.0.30) Windows Live Communications Platform (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3555.0308) Windows Live ID Sign-in Assistant (Version: 7.250.4232.0) Windows Live Installer (x32 Version: 15.4.3502.0922) Windows Live Language Selector (Version: 15.4.3555.0308) Windows Live Mail (x32 Version: 15.4.3502.0922) Windows Live MIME IFilter (Version: 15.4.3502.0922) Windows Live Photo Common (x32 Version: 15.4.3502.0922) Windows Live PIMT Platform (x32 Version: 15.4.3508.1109) Windows Live SOXE (x32 Version: 15.4.3502.0922) Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922) Windows Live UX Platform (x32 Version: 15.4.3502.0922) Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109) Windows Live Writer (x32 Version: 15.4.3502.0922) Windows Live Writer Resources (x32 Version: 15.4.3502.0922) Windows-Treiberpaket - FTDI CDM Driver Package (10/22/2009 2.06.00) (Version: 10/22/2009 2.06.00) WinMend File Copy 1.4.2 (x32) WinPatrol (Version: 28.1.2013.0) WinPatrol (Version: 29.0.2013) Wrye Bash (x32 Version: wxPython (unicode) for Python 2.7 (x32 Version: xp-AntiSpy 3.98-2 (x32) yuPlay client 0.7.24 (x32) ==================== Restore Points ========================= ==================== Hosts content: ========================== 2013-11-06 16:24 - 2013-11-06 16:24 - 00453207 ____A C:\Windows\system32\Drivers\etc\hosts www.007guard.com 007guard.com 008i.com www.008k.com 008k.com www.00hq.com 00hq.com 010402.com www.032439.com 032439.com www.0scan.com 0scan.com 1000gratisproben.com www.1000gratisproben.com 1001namen.com www.1001namen.com 100888290cs.com www.100888290cs.com www.100sexlinks.com 100sexlinks.com 10sek.com www.10sek.com www.1-2005-search.com 1-2005-search.com 123fporn.info www.123fporn.info 123haustiereundmehr.com www.123haustiereundmehr.com 123moviedownload.com There are 1000 more lines. ==================== Scheduled Tasks (whitelisted) ============= Task: {36686732-A32A-4190-8EFB-4904368BB8E5} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-10-22] (Piriform Ltd) Task: {651DBF99-F2E7-45FC-BA71-AE6F96C0B93B} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe Task: {682EEDCE-6BD4-424F-BD2B-1FE4F2E6E144} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-11] (Google Inc.) Task: {7C9B285F-E884-4566-B5AF-4DD3B23C1E04} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation) Task: {81A1039B-E733-4F55-8CBC-E33DC0AC9916} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-11-05] (Adobe Systems Incorporated) Task: {8B39AB58-7907-4DF9-A431-B8C180D7FFB6} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe Task: {93D43514-93E4-4D85-84A5-AF8BEB4F0707} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-11] (Google Inc.) Task: {ABAB7124-18A5-407D-B28E-93AA42767C1D} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\\symerr.exe [2013-08-01] (Symantec Corporation) Task: {CDD0EE2E-4D31-40BC-9B7F-B5F0D92A5F6E} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\\symerr.exe [2013-08-01] (Symantec Corporation) Task: {F75AA70F-4590-4164-BFEB-0702B51C0835} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\\WSCStub.exe [2013-10-08] (Symantec Corporation) Task: {FCC9D927-0EA2-44CB-BD1A-FFEB5A69EA5B} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2004-09-30 19:15 - 2004-09-30 19:15 - 00192000 _____ () C:\Program Files\LinkShellExtension\RockallDLL.dll 2010-05-23 18:30 - 2010-05-23 18:30 - 00160768 _____ () C:\Program Files\Rainlendar2\lua51.dll 2011-08-12 06:47 - 2011-08-12 06:47 - 00312832 _____ () C:\Program Files\Rainlendar2\plugins\iCalendarPlugin.dll 2010-05-23 18:30 - 2010-05-23 18:30 - 00013824 _____ () C:\Program Files\Rainlendar2\lfs.dll 2011-10-09 06:03 - 2010-12-19 20:16 - 00338944 _____ () C:\Program Files (x86)\MAXA Cookie Manager\sqlite36_engine.dll 2011-10-09 06:03 - 2010-12-19 20:19 - 00023552 _____ () C:\Program Files (x86)\MAXA Cookie Manager\DirectCOM.dll 2011-10-09 06:08 - 2013-07-15 18:29 - 00620718 ____N () C:\Program Files (x86)\BillP Studios\WinPatrol\sqlite3.dll 2011-03-09 13:21 - 2011-03-09 13:21 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll 2011-03-09 13:21 - 2011-03-09 13:21 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll 2012-05-10 15:16 - 2012-05-10 15:16 - 00071008 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\Common\rpc_client.dll 2013-11-05 22:06 - 2013-05-16 10:55 - 00113496 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl 2013-11-05 22:06 - 2013-05-16 10:55 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl 2013-11-05 22:06 - 2013-05-16 10:55 - 00161112 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl 2013-11-05 22:06 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll 2013-11-05 22:06 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\****** ******\Documents\Der erhaltene Artikel entspricht nicht der Beschreibung_ ****** ***** hat eine Nachricht zu Fleischmann piccolo 8599 Artikelnummer 230842947883 gesendet_.eml:OECustomProperty ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (11/06/2013 05:15:56 PM) (Source: Microsoft-Windows-WMI) (User: NT-AUTORITÄT) Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden. Error: (11/06/2013 04:40:15 PM) (Source: Microsoft-Windows-WMI) (User: NT-AUTORITÄT) Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden. Error: (11/06/2013 04:15:12 PM) (Source: Microsoft-Windows-WMI) (User: NT-AUTORITÄT) Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden. Error: (11/06/2013 03:41:05 PM) (Source: MsiInstaller) (User: ************-PC) Description: Produkt: WinZip 17.0 - Fehler 1730. Sie müssen über Administratorrechte verfügen, um diese Anwendung entfernen zu können. Melden Sie sich als Administrator an oder wenden Sie sich an den technischen Support, um Unterstützung zu erhalten. Error: (11/06/2013 03:36:51 PM) (Source: Microsoft-Windows-WMI) (User: NT-AUTORITÄT) Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden. Error: (11/06/2013 03:32:49 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: hpqtra08.exe, Version: 130.0.422.0, Zeitstempel: 0x4ab683ef Name des fehlerhaften Moduls: unknown, Version:, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000 ID des fehlerhaften Prozesses: 0x1008 Startzeit der fehlerhaften Anwendung: 0xhpqtra08.exe0 Pfad der fehlerhaften Anwendung: hpqtra08.exe1 Pfad des fehlerhaften Moduls: hpqtra08.exe2 Berichtskennung: hpqtra08.exe3 Error: (11/06/2013 03:29:10 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521eaf24 Ausnahmecode: 0xc015000f Fehleroffset: 0x000000000006f7ba ID des fehlerhaften Prozesses: 0xf94 Startzeit der fehlerhaften Anwendung: 0xexplorer.exe0 Pfad der fehlerhaften Anwendung: explorer.exe1 Pfad des fehlerhaften Moduls: explorer.exe2 Berichtskennung: explorer.exe3 Error: (11/06/2013 03:29:06 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4 Name des fehlerhaften Moduls: SHELL32.dll, Version: 6.1.7601.18222, Zeitstempel: 0x51f1ddfa Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000005055a ID des fehlerhaften Prozesses: 0xf94 Startzeit der fehlerhaften Anwendung: 0xexplorer.exe0 Pfad der fehlerhaften Anwendung: explorer.exe1 Pfad des fehlerhaften Moduls: explorer.exe2 Berichtskennung: explorer.exe3 Error: (11/06/2013 03:15:18 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521eaf24 Ausnahmecode: 0xc015000f Fehleroffset: 0x000000000006f7ba ID des fehlerhaften Prozesses: 0x6f8 Startzeit der fehlerhaften Anwendung: 0xexplorer.exe0 Pfad der fehlerhaften Anwendung: explorer.exe1 Pfad des fehlerhaften Moduls: explorer.exe2 Berichtskennung: explorer.exe3 Error: (11/06/2013 03:15:15 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4 Name des fehlerhaften Moduls: SHELL32.dll, Version: 6.1.7601.18222, Zeitstempel: 0x51f1ddfa Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000005055a ID des fehlerhaften Prozesses: 0x6f8 Startzeit der fehlerhaften Anwendung: 0xexplorer.exe0 Pfad der fehlerhaften Anwendung: explorer.exe1 Pfad des fehlerhaften Moduls: explorer.exe2 Berichtskennung: explorer.exe3 System errors: ============= Error: (11/06/2013 05:18:18 PM) (Source: NetBT) (User: ) Description: Der Name "************-PC :20" konnte nicht auf der Schnittstelle mit IP-Adresse registriert werden. Der Computer mit IP-Adresse hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (11/06/2013 05:18:18 PM) (Source: NetBT) (User: ) Description: Der Name "************-PC :0" konnte nicht auf der Schnittstelle mit IP-Adresse registriert werden. Der Computer mit IP-Adresse hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (11/06/2013 05:18:18 PM) (Source: Server) (User: ) Description: Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{6326D19A-C8CD-4791-847B-F4AD6E293BB9} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden. Error: (11/06/2013 05:15:40 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Spybot-S&D 2 Scanner Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (11/06/2013 05:15:40 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Scanner Service erreicht. Error: (11/06/2013 05:03:34 PM) (Source: mbamchameleon) (User: ) Description: \Device\HarddiskVolume2\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\\NIS.EXE Error: (11/06/2013 05:03:34 PM) (Source: mbamchameleon) (User: ) Description: \Device\HarddiskVolume2\PROGRAM FILES (X86)\SPYBOT - SEARCH & DESTROY 2\SDWSCSVC.EXE Error: (11/06/2013 05:03:34 PM) (Source: mbamchameleon) (User: ) Description: \Device\HarddiskVolume2\PROGRAM FILES (X86)\SPYBOT - SEARCH & DESTROY 2\SDUPDSVC.EXE Error: (11/06/2013 05:03:34 PM) (Source: mbamchameleon) (User: ) Description: \Device\HarddiskVolume2\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\\NIS.EXE Error: (11/06/2013 04:59:36 PM) (Source: mbamchameleon) (User: ) Description: Device\HarddiskVolume2\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\\WSCSTUB.EXE Microsoft Office Sessions: ========================= Error: (11/06/2013 05:15:56 PM) (Source: Microsoft-Windows-WMI)(User: NT-AUTORITÄT) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/06/2013 04:40:15 PM) (Source: Microsoft-Windows-WMI)(User: NT-AUTORITÄT) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/06/2013 04:15:12 PM) (Source: Microsoft-Windows-WMI)(User: NT-AUTORITÄT) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/06/2013 03:41:05 PM) (Source: MsiInstaller)(User: ************-PC) Description: Produkt: WinZip 17.0 - Fehler 1730. Sie müssen über Administratorrechte verfügen, um diese Anwendung entfernen zu können. Melden Sie sich als Administrator an oder wenden Sie sich an den technischen Support, um Unterstützung zu erhalten.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (11/06/2013 03:36:51 PM) (Source: Microsoft-Windows-WMI)(User: NT-AUTORITÄT) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/06/2013 03:32:49 PM) (Source: Application Error)(User: ) Description: hpqtra08.exe130.0.422.04ab683efunknown0.0.0.000000000c000000500000000100801cedafca11637a9C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exeunknown4f03778c-46f0-11e3-a94c-8c89a55a2bc5 Error: (11/06/2013 03:29:10 PM) (Source: Application Error)(User: ) Description: explorer.exe6.1.7601.175674d672ee4ntdll.dll6.1.7601.18247521eaf24c015000f000000000006f7baf9401cedafaa0541a74C:\Windows\explorer.exeC:\Windows\SYSTEM32\ntdll.dllcc73cd0e-46ef-11e3-a94c-8c89a55a2bc5 Error: (11/06/2013 03:29:06 PM) (Source: Application Error)(User: ) Description: explorer.exe6.1.7601.175674d672ee4SHELL32.dll6.1.7601.1822251f1ddfac0000005000000000005055af9401cedafaa0541a74C:\Windows\explorer.exeC:\Windows\system32\SHELL32.dllca740533-46ef-11e3-a94c-8c89a55a2bc5 Error: (11/06/2013 03:15:18 PM) (Source: Application Error)(User: ) Description: explorer.exe6.1.7601.175674d672ee4ntdll.dll6.1.7601.18247521eaf24c015000f000000000006f7ba6f801cedafa99691aa8C:\Windows\explorer.exeC:\Windows\SYSTEM32\ntdll.dlldc7ca507-46ed-11e3-a94c-8c89a55a2bc5 Error: (11/06/2013 03:15:15 PM) (Source: Application Error)(User: ) Description: explorer.exe6.1.7601.175674d672ee4SHELL32.dll6.1.7601.1822251f1ddfac0000005000000000005055a6f801cedafa99691aa8C:\Windows\explorer.exeC:\Windows\system32\SHELL32.dlldacdcbf6-46ed-11e3-a94c-8c89a55a2bc5 ==================== Memory info =========================== Percentage of memory in use: 25% Total physical RAM: 12267.6 MB Available physical RAM: 9141.63 MB Total Pagefile: 24533.38 MB Available Pagefile: 21474.34 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: (Win 7) (Fixed) (Total:209.86 GB) (Free:116.29 GB) NTFS Drive d: (Eisenbahn) (Fixed) (Total:93.75 GB) (Free:74.22 GB) NTFS Drive e: (Data) (Fixed) (Total:224.61 GB) (Free:144.34 GB) NTFS Drive f: (Big Data) (Fixed) (Total:372.46 GB) (Free:222.57 GB) NTFS Drive g: (klein bei c) (Fixed) (Total:4.88 GB) (Free:4.8 GB) NTFS Drive h: (Traini+Data) (Fixed) (Total:698.64 GB) (Free:173.94 GB) NTFS Drive i: (Mini 1) (Fixed) (Total:3.91 GB) (Free:3.79 GB) NTFS Drive j: (Cache+temp) (Fixed) (Total:107.42 GB) (Free:92.36 GB) NTFS Drive k: (Mini 2) (Fixed) (Total:3.91 GB) (Free:3.81 GB) NTFS Drive l: (L Backups) (Fixed) (Total:716.67 GB) (Free:509.35 GB) NTFS Drive m: (100g) (Fixed) (Total:107.42 GB) (Free:107.12 GB) NTFS Drive n: (Emulatoren + Steam) (Fixed) (Total:1648.17 GB) (Free:697.96 GB) NTFS Drive o: (Big Data 2) (Fixed) (Total:698.64 GB) (Free:79.61 GB) NTFS Drive p: (BiigFäädData) (Fixed) (Total:931.51 GB) (Free:123.78 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 4E6B547D) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=210 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=5 GB) - (Type=OF Extended) Partition 4: (Not Active) - (Size=717 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows XP) (Size: 932 GB) (Disk ID: 0E6DB056) Partition 1: (Active) - (Size=932 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (MBR Code: Windows XP) (Size: 699 GB) (Disk ID: E9DE3773) Partition 1: (Not Active) - (Size=699 GB) - (Type=07 NTFS) ======================================================== Disk: 3 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 53F586F0) Partition 1: (Not Active) - (Size=107 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=107 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=-429314277376) - (Type=07 NTFS) ======================================================== Disk: 4 (Size: 699 GB) (Disk ID: 09376CBC) Partition 1: (Not Active) - (Size=4 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=94 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=225 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=376 GB) - (Type=OF Extended) ======================================================== Disk: 5 (MBR Code: Windows XP) (Size: 699 GB) (Disk ID: 7B8D17E8) Partition 1: (Not Active) - (Size=699 GB) - (Type=07 NTFS) ==================== End Of Log ============================ bevor ich wieder Banking usw mache (PayPal spende). Das Tunneln geht munter weiter. Würde hier ein modernerer Router besser standhalten ? Und eine letzte Frage hätte ich noch: Da Spybot S+D nicht so gut sein soll, suche ich eine Alternative,ist die mbar Kaufvariante besser? Was würden Sie empfehlen ? Nochmals danke |
![]() | #24 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Win7 IP tunnelt mich jede Nacht und kapert Teledat 530 Router Nicht MBAr, sondern MBAM, das Antimalwaretool von Malwarebytes. Freeware version reciht als Zusatz zum normalen AV Programm. Nur würd ich Norton weg lassen und was anständiges holen. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter ProxyServer: localhost:21320 Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() | #25 |
![]() | ![]() Win7 IP tunnelt mich jede Nacht und kapert Teledat 530 Router Hallo, Danke für den Tip,hier das Log: Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 31-10-2013 Ran by ****** ***** at 2013-11-07 10:30:25 Run:1 Running from C:\Users\****** *****\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** ProxyServer: localhost:21320 ***************** HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => Value deleted successfully. ==== End of Fixlog ==== Habe aber das Häkchen vor Proxyserver entfernt,hat evtl Spybot S+d diesen Eintrag gemacht ? Dieser Eintrag ist aber immernoch unter Lan Einstellungen vorhanden Nochmals Hallo, Beim neu installierten war der Localhost Eintrag nach dem Neustart immernoch vorhanden,nochmals frst-fixlist,dann war er entfernt,beim "zweiten" PC gings beim ersten Versuch MBAM hat im Quickscan auch was gefunden Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Datenbank Version: v2013.11.07.03 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16721 ****** ***** :: ***********-PC [Administrator] 07.11.2013 10:58:34 MBAM-log-2013-11-07 (11-02-59).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 250137 Laufzeit: 3 Minute(n), 45 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 C:\Users\****** *****\AppData\Local\Temp\OCS\ocs_v71.exe (PUP.Optional.DownloadSponsor.A) -> Keine Aktion durchgeführt. (Ende) Auf dem "Zweiten" war auch was; Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Datenbank Version: v2013.11.07.03 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16721 ****** ***** :: ***********-PC [Administrator] 07.11.2013 11:16:11 mbam-log-2013-11-07 (11-16-11).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 206748 Laufzeit: 3 Minute(n), 56 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 1 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{31AD400D-1B06-4E33-A59A-90C2C140CBA0} (PUP.Optional.QuickShare.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 4 HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Search Page (PUP.Optional.Snapdo) -> Bösartig: (hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=514347bc-b91d-4a28-b463-2e529db901ce&searchtype=ds&q={searchTerms}&installDate=17/06/2013) Gut: (hxxp://www.google.com) -> Erfolgreich ersetzt und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Search Bar (PUP.Optional.Snapdo) -> Bösartig: (hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=514347bc-b91d-4a28-b463-2e529db901ce&searchtype=ds&q={searchTerms}&installDate=17/06/2013) Gut: (hxxp://www.google.com) -> Erfolgreich ersetzt und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Internet Explorer\Search|Default_Search_URL (PUP.Optional.Snapdo) -> Bösartig: (hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=514347bc-b91d-4a28-b463-2e529db901ce&searchtype=ds&q={searchTerms}&installDate=17/06/2013) Gut: (hxxp://www.google.com) -> Erfolgreich ersetzt und in Quarantäne gestellt. HKCU\SOFTWARE\Microsoft\Internet Explorer\Search|SearchAssistant (PUP.Optional.Snapdo) -> Bösartig: (hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=514347bc-b91d-4a28-b463-2e529db901ce&searchtype=ds&q={searchTerms}&installDate=17/06/2013) Gut: (hxxp://www.google.com) -> Erfolgreich ersetzt und in Quarantäne gestellt. Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 C:\Windows\Installer\104b22.msi (PUP.Optional.SmartBar.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) |
![]() | #26 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Win7 IP tunnelt mich jede Nacht und kapert Teledat 530 Router dann frische FRST logs bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() | #27 |
![]() | ![]() Win7 IP tunnelt mich jede Nacht und kapert Teledat 530 Router Hallo,der Localhost war auf drei Rechnern: Der grosse "ex infizierte" FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 31-10-2013 Ran by ****** ****** (administrator) on ************-PC on 08-11-2013 02:44:13 Running from C:\Users\****** ******\Desktop Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Deutsche Telekom AG) C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\\NIS.exe (Sony Corporation) C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\PSIA.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe () C:\Program Files\Rainlendar2\Rainlendar2.exe (MAXA Research Int'l Inc.) C:\Program Files (x86)\MAXA Cookie Manager\Cookie.exe (BillP Studios) C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (cyberlink) C:\Program Files (x86)\CyberLink\Shared files\brs.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (Sony Corporation) C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (T-Systems Enterprise Services GmbH) C:\Program Files (x86)\DSL-Manager\DslMgr.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\\NIS.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (T-Systems Enterprise Services GmbH) C:\Program Files (x86)\DSL-Manager\DslMgrSvc.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe (Diskeeper Corporation) C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe (Valve Corporation) N:\! Steam-Arbeitsordner !\Steam.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\IELowutil.exe () C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [picon] - C:\Program Files (x86)\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe [773656 2008-09-26] (Intel Corporation) HKLM\...\Run: [IntelTBRunOnce] - C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs [4526 2010-11-29] () HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [XboxStat] - C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe [825184 2009-10-01] (Microsoft Corporation) HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6469736 2012-03-06] (Realtek Semiconductor) HKLM\...\Run: [Acronis Scheduler2 Service] - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [395928 2012-05-10] (Acronis) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [Rainlendar2] - C:\Program Files\Rainlendar2\Rainlendar2.exe [3820032 2011-08-12] () HKCU\...\Run: [MSCS] - C:\Program Files (x86)\MAXA Cookie Manager\Cookie.exe [1138688 2012-05-20] (MAXA Research Int'l Inc.) HKCU\...\Run: [Sim Aquarium 3 Livewallpaper Autostart] - [x] HKCU\...\Run: [WinPatrol] - C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe [456768 2013-10-19] (BillP Studios) HKCU\...\Policies\Explorer: [NoRecentDocsNetHood] 1 MountPoints2: {d364454e-f4d8-11e0-a01b-806e6f6e6963} - S:\setup.exe HKLM-x32\...\Run: [JMB36X IDE Setup] - C:\Windows\RaidTool\xInsIDE.exe [43608 2010-09-07] () HKLM-x32\...\Run: [NUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [REGSHAVE] - C:\Program Files (x86)\REGSHAVE\REGSHAVE.EXE [53248 2002-02-04] (FUJI PHOTO FILM CO., LTD.) HKLM-x32\...\Run: [amd_dc_opt] - C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD) HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.) HKLM-x32\...\Run: [BDRegion] - C:\Program Files (x86)\CyberLink\Shared files\brs.exe [78312 2012-05-09] (cyberlink) HKLM-x32\...\Run: [UpdatePPShortCut] - C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe [223096 2012-04-17] (CyberLink Corp.) HKLM-x32\...\Run: [CLMLServer] - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2011-03-09] (CyberLink) HKLM-x32\...\Run: [PMBVolumeWatcher] - C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe [740888 2013-04-24] (Sony Corporation) HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe [49208 2011-10-28] (Hewlett-Packard) HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [TrueImageMonitor.exe] - C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [2673640 2012-05-10] () Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files (x86)\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files (x86)\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) Startup: C:\Users\****** ******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files (x86)\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) Startup: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files (x86)\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.t-online.de SearchScopes: HKCU - DefaultScope {68ADF79E-E403-43EA-8AAB-57DC2C811EA0} URL = hxxp://www.google.de/search?q={searchTerms} SearchScopes: HKCU - {68ADF79E-E403-43EA-8AAB-57DC2C811EA0} URL = hxxp://www.google.de/search?q={searchTerms} BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine64\\CoIEPlg.dll (Symantec Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: DVDVideoSoft IE Extension - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.) BHO-x32: No Name - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO-x32: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll (AOL Inc.) BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\\CoIEPlg.dll (Symantec Corporation) BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\\IPS\ipsbho.dll (Symantec Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Free Download Manager - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll (FreeDownloadManager.ORG) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: DVDVideoSoft IE Extension - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.) Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\\CoIEPlg.dll (Symantec Corporation) Toolbar: HKLM-x32 - Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll (AOL Inc.) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\\CoIEPlg.dll (Symantec Corporation) Toolbar: HKCU - No Name - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - No File Toolbar: HKCU - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\\CoIEPlg.dll (Symantec Corporation) DPF: HKLM-x32 {644E432F-49D3-41A1-8DD5-E099162EEEC5} hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\****** ******\AppData\Roaming\Mozilla\Firefox\Profiles\x270n2xu.default FF Homepage: hxxp://www.t-online.de/ FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.0.6 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.0 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @canon.com/EPPEX - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @logitech.com/HarmonyRemote,version=1.0.0 - C:\Program Files (x86)\Logitech\Harmony Remote Driver\NprtHarmonyPlugin.dll (Logitech Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nullsoft.com/winampDetector;version=1 - C:\Program Files (x86)\Winamp Detect\npwachk.dll (Nullsoft, Inc.) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.0.6 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\****** ******\AppData\Roaming\Mozilla\Firefox\Profiles\x270n2xu.default\searchplugins\aol-search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Winamp Toolbar - C:\Users\****** ******\AppData\Roaming\Mozilla\Firefox\Profiles\x270n2xu.default\Extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f} FF Extension: fdm_ffext - C:\Users\****** ******\AppData\Roaming\Mozilla\Firefox\Profiles\x270n2xu.default\Extensions\fdm_ffext@freedownloadmanager.org FF Extension: bprivacyprefs - C:\Users\****** ******\AppData\Roaming\Mozilla\Firefox\Profiles\x270n2xu.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.0.18\coFFPlgn\ FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.0.18\coFFPlgn\ FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.0.18\IPSFF FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.0.18\IPSFF FF HKLM-x32\...\Firefox\Extensions: [{ACAA314B-EEBA-48e4-AD47-84E31C44796C}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ FF HKCU\...\Firefox\Extensions: [maxacookie@maxatools.com] - C:\Program Files (x86)\MAXA Cookie Manager\extension FF Extension: MAXA Cookie Manager - C:\Program Files (x86)\MAXA Cookie Manager\extension Chrome: ======= CHR HomePage: hxxp://www.t-online.de/ CHR RestoreOnStartup: "hxxp://www.google.com/" CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\gcswf32.dll No File CHR Plugin: (Java Deployment Toolkit - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll No File CHR Plugin: (Java(TM) Platform SE 6 U29) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll No File CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dll () CHR Plugin: (Norton Confidential) - C:\Users\****** ******\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.1.1.10_0\npcoplgn.dll No File CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll No File CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Plugin: (Default Plug-in) - default_plugin No File CHR Extension: (Norton Identity Protection) - C:\Users\******~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2014.6.0.27_0 CHR Extension: (DVDVideoSoft) - C:\Users\******~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\ CHR Extension: (Google Wallet) - C:\Users\******~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\ CHR Extension: (MyHarmony Chrome Plugin) - C:\Users\******~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\omaonpoimgkmbllpdihbnmgphjoipdhf\ CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\\Exts\Chrome.crx CHR HKLM-x32\...\Chrome\Extension: [omaonpoimgkmbllpdihbnmgphjoipdhf] - C:\Program Files (x86)\Logitech\Harmony Remote Driver\harmony_chrome.crx ==================== Services (Whitelisted) ================= S2 CLKMSVC10_38F51D56; C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [242664 2012-05-09] (CyberLink) R2 Diskeeper; C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe [2435960 2012-07-28] (Diskeeper Corporation) R2 Netzmanager Service; C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [2565632 2011-10-24] (Deutsche Telekom AG) R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\\NIS.exe [275696 2013-10-08] (Symantec Corporation) R2 PMBDeviceInfoProvider; C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe [483864 2013-04-24] (Sony Corporation) S3 SandraAgentSrv; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2011.SP5\RpcAgentSrv.exe [93848 2008-09-18] (SiSoftware) R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.) R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia) S2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [660184 2013-07-03] (Secunia) R3 TDslMgrService; C:\Program Files (x86)\DSL-Manager\DslMgrSvc.exe [294912 2007-11-26] (T-Systems Enterprise Services GmbH) ==================== Drivers (Whitelisted) ==================== R1 BHDrvx64; C:\Program Files (x86)\Norton Internet Security\NortonData\\Definitions\BASHDefs\20131101.003\BHDrvx64.sys [1524824 2013-10-23] (Symantec Corporation) R1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1501000.012\ccSetx64.sys [162392 2013-09-26] (Symantec Corporation) R2 cpuz135; C:\Windows\system32\drivers\cpuz135_x64.sys [21992 2010-11-09] (CPUID) R3 DKRtWrt; C:\Windows\System32\DRIVERS\DKRtWrt.sys [52144 2010-03-10] (Diskeeper Corporation) R1 DslMNLwf; C:\Windows\System32\DRIVERS\dslmnlwf.sys [19008 2007-08-01] (T-Systems Enterprise Services GmbH) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-11-04] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [140376 2013-11-04] (Symantec Corporation) R1 IDSVia64; C:\Program Files (x86)\Norton Internet Security\NortonData\\Definitions\IPSDefs\20131106.001\IDSvia64.sys [521816 2013-11-01] (Symantec Corporation) R3 NAVENG; C:\Program Files (x86)\Norton Internet Security\NortonData\\Definitions\VirusDefs\20131107.003\ENG64.SYS [126040 2013-11-04] (Symantec Corporation) R3 NAVEX15; C:\Program Files (x86)\Norton Internet Security\NortonData\\Definitions\VirusDefs\20131107.003\EX64.SYS [2099288 2013-11-04] (Symantec Corporation) S3 NTIOLib_1_0_1; C:\Program Files (x86)\MSI\CLICKBIOSII\NTIOLib_X64.sys [14136 2009-10-05] (MSI) R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-07-03] (Secunia) S3 SANDRA; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2011.SP5\WNt500x64\Sandra.sys [23112 2009-08-07] (SiSoftware) R3 SRTSP; C:\Windows\System32\Drivers\NISx64\1501000.012\SRTSP64.SYS [858200 2013-09-27] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1501000.012\SRTSPX64.SYS [36952 2013-09-10] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\NISx64\1501000.012\SYMDS64.SYS [493656 2013-09-10] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\NISx64\1501000.012\SYMEFA64.SYS [1147480 2013-09-27] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2013-11-05] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\NISx64\1501000.012\Ironx64.SYS [264280 2013-09-27] (Symantec Corporation) R1 SymNetS; C:\Windows\System32\Drivers\NISx64\1501000.012\SYMNETS.SYS [590936 2013-09-26] (Symantec Corporation) S3 TelekomNM6; C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM6.sys [45664 2010-09-16] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH) R0 vidsflt53; C:\Windows\System32\DRIVERS\vsflt53.sys [141920 2013-11-07] (Acronis) S3 MSI_MSIBIOS_010507; \??\C:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys [x] S3 NTIOLib_1_0_3; \??\C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [x] S3 NTIOLib_1_0_4; \??\C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-08 02:43 - 2013-11-07 10:41 - 01957098 _____ (Farbar) C:\Users\****** ******\Desktop\FRST64.exe 2013-11-08 01:35 - 2013-11-08 01:35 - 00000000 ____D C:\Users\****** ******\AppData\Local\{E7C0278F-3574-4E9E-9139-B41F42B1D1B4} 2013-11-08 00:02 - 2013-11-08 00:04 - 00000000 ___SH C:\DkHyperbootSync 2013-11-07 22:01 - 2013-11-07 22:01 - 00971360 _____ (Acronis) C:\Windows\system32\Drivers\timntr.sys 2013-11-07 22:01 - 2013-11-07 22:01 - 00000000 ____D C:\ProgramData\Acronis 2013-11-07 22:00 - 2013-11-07 22:00 - 00275552 _____ (Acronis) C:\Windows\system32\Drivers\snapman.sys 2013-11-07 22:00 - 2013-11-07 22:00 - 00141920 _____ (Acronis) C:\Windows\system32\Drivers\vsflt53.sys 2013-11-07 22:00 - 2013-11-07 22:00 - 00000000 ____D C:\Program Files (x86)\Acronis 2013-11-07 20:57 - 2013-11-07 20:57 - 00000000 ___HD C:\Program Files (x86)\Zero G Registry 2013-11-07 20:57 - 2013-11-07 20:57 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ErosLink 2013-11-07 20:57 - 2013-11-07 20:57 - 00000000 ____D C:\Program Files (x86)\ErosLink 2013-11-07 12:04 - 2013-11-07 12:04 - 00000000 ____D C:\Users\****** ******\Documents\Witcher 2 2013-11-07 12:04 - 2013-10-14 01:07 - 00000122 _____ C:\Users\****** ******\Documents\hacking.txt 2013-11-07 12:04 - 2013-09-29 00:26 - 00000824 _____ C:\Users\****** ******\Documents\hosts.txt 2013-11-07 12:04 - 2013-08-16 00:28 - 00001581 _____ C:\Users\****** ******\Documents\TombRaider.log 2013-11-07 10:56 - 2013-11-07 10:56 - 00001114 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-11-07 10:56 - 2013-11-07 10:56 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Malwarebytes 2013-11-07 10:56 - 2013-11-07 10:56 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-11-07 10:56 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-11-07 10:43 - 2013-11-07 11:05 - 00000704 _____ C:\Windows\PFRO.log 2013-11-07 08:37 - 2013-11-07 08:37 - 00000000 ____D C:\Users\****** ******\AppData\Local\{650AFD04-1DE3-4A30-9ACD-22254994D0A6} 2013-11-07 02:48 - 2013-11-07 02:48 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Media Player Classic 2013-11-07 02:24 - 2013-11-07 02:24 - 00000000 ____D C:\Users\****** ******\AppData\Local\Rekenwonder_Software 2013-11-07 01:41 - 2013-11-07 01:41 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Junction Link Magic 2013-11-07 01:41 - 2013-11-07 01:41 - 00000000 ____D C:\Program Files\Rekenwonder Software 2013-11-07 00:51 - 2013-11-08 01:39 - 00000248 _____ C:\Users\****** ******\Documents\tunnel.txt 2013-11-07 00:32 - 2013-11-07 11:05 - 00000168 _____ C:\Windows\setupact.log 2013-11-07 00:32 - 2013-11-07 00:32 - 00000000 _____ C:\Windows\setuperr.log 2013-11-06 23:48 - 2013-11-06 23:48 - 00000000 ____D C:\Program Files (x86)\JAM Software 2013-11-06 22:05 - 2013-11-06 22:05 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Acronis 2013-11-06 21:14 - 2013-11-06 21:14 - 00000000 ____D C:\LÖSCH ZEUGS 2013-11-06 18:29 - 2013-11-06 18:29 - 00000000 ____D C:\Users\****** ******\AppData\Local\WarThunder 2013-11-06 18:29 - 2013-11-06 18:29 - 00000000 ____D C:\ProgramData\WarThunder 2013-11-06 18:17 - 2013-11-06 18:17 - 00000000 ____D C:\Users\****** ******\AppData\Local\WOP 2013-11-06 18:15 - 2013-11-06 18:17 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\HpUpdate 2013-11-06 18:14 - 2013-11-06 18:15 - 03607616 _____ (Igor Pavlov) C:\Users\****** ******\Downloads\GmdClientSetup.exe 2013-11-06 18:14 - 2013-11-06 18:15 - 03111104 _____ (Hewlett-Packard ) C:\Users\****** ******\Downloads\hpusetup.exe 2013-11-06 17:12 - 2013-11-06 17:12 - 00005866 _____ C:\Users\****** ******\Documents\gmer.log 2013-11-06 16:36 - 2013-11-06 16:36 - 00001244 _____ C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk 2013-11-06 16:21 - 2013-11-06 16:21 - 00000000 ____D C:\Users\****** ******\AppData\Local\{DA6A2054-1BF9-40B8-9486-B3EE2667D9C0} 2013-11-06 16:04 - 2013-11-06 16:06 - 00000000 ____D C:\ProgramData\Live Aquarium HD 2013-11-06 16:04 - 2013-11-06 16:04 - 00000000 ____D C:\Program Files (x86)\Live Aquarium HD 2013-11-06 16:04 - 2013-10-04 10:33 - 01216064 _____ (Vojnic Ladislav) C:\Windows\Live Aquarium HD.scr 2013-11-06 16:04 - 2010-05-26 12:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\D3DX9_43.dll 2013-11-06 15:57 - 2013-11-06 15:57 - 00000000 ____D C:\Program Files (x86)\K-Lite Codec Pack 2013-11-06 15:57 - 2013-08-14 19:00 - 00127488 _____ C:\Windows\system32\ff_vfw.dll 2013-11-06 15:57 - 2013-08-14 19:00 - 00112640 _____ C:\Windows\SysWOW64\ff_vfw.dll 2013-11-06 15:57 - 2013-08-02 18:29 - 00256088 _____ C:\Windows\system32\unrar64.dll 2013-11-06 15:57 - 2013-08-02 18:29 - 00217176 _____ C:\Windows\SysWOW64\unrar.dll 2013-11-06 15:57 - 2013-03-17 18:22 - 03554304 _____ (x264vfw project) C:\Windows\system32\x264vfw64.dll 2013-11-06 15:57 - 2013-03-17 17:21 - 03649536 _____ (x264vfw project) C:\Windows\SysWOW64\x264vfw.dll 2013-11-06 15:57 - 2012-07-21 11:55 - 00180736 _____ (fccHandler) C:\Windows\system32\ac3acm.acm 2013-11-06 15:57 - 2012-07-21 11:54 - 00122880 _____ (fccHandler) C:\Windows\SysWOW64\ac3acm.acm 2013-11-06 15:57 - 2011-12-07 18:37 - 00148992 _____ ( ) C:\Windows\system32\lagarith.dll 2013-11-06 15:57 - 2011-12-07 18:32 - 00216064 _____ ( ) C:\Windows\SysWOW64\lagarith.dll 2013-11-06 15:57 - 2011-06-24 15:45 - 00258560 _____ C:\Windows\system32\xvidvfw.dll 2013-11-06 15:57 - 2011-06-24 15:44 - 00243200 _____ C:\Windows\SysWOW64\xvidvfw.dll 2013-11-06 15:57 - 2011-06-24 15:31 - 00703488 _____ C:\Windows\system32\xvidcore.dll 2013-11-06 15:57 - 2011-06-24 15:28 - 00650752 _____ C:\Windows\SysWOW64\xvidcore.dll 2013-11-06 15:54 - 2013-11-06 15:54 - 00001304 _____ C:\Users\Public\Desktop\Ashampoo Burning Studio 12.lnk 2013-11-06 15:53 - 2013-11-06 15:53 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ashampoo 2013-11-06 15:49 - 2013-11-06 15:49 - 00000000 ___HD C:\ProgramData\CanonBJ 2013-11-06 15:49 - 2013-11-06 15:49 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4 2013-11-06 15:47 - 2013-11-06 15:48 - 00000000 ____D C:\Users\****** ******\Desktop\Canon+Hp 2013-11-06 15:47 - 2013-11-06 15:47 - 00000000 ___HD C:\ProgramData\CanonIJEPPEX2 2013-11-06 15:47 - 2013-11-06 15:47 - 00000000 ___HD C:\ProgramData\CanonEPP 2013-11-06 15:47 - 2013-11-06 15:47 - 00000000 ____D C:\Users\****** ******\AppData\Local\Canon Easy-PhotoPrint EX 2013-11-06 15:47 - 2013-11-06 15:47 - 00000000 ____D C:\Program Files\Common Files\Canon 2013-11-06 15:46 - 2013-11-06 15:46 - 00000000 ____D C:\Program Files\Canon 2013-11-06 15:45 - 2013-11-06 15:46 - 00000000 ____D C:\Program Files (x86)\Canon 2013-11-06 15:45 - 2013-11-06 15:45 - 00000000 ____D C:\Program Files (x86)\CD-LabelPrint 2013-11-06 15:43 - 2013-11-06 15:43 - 00000000 ____D C:\Users\****** ******\Documents\Add-in Express 2013-11-06 15:30 - 2013-11-06 15:31 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\HP 2013-11-06 15:30 - 2013-11-06 15:30 - 00000000 ____D C:\ProgramData\WEBREG 2013-11-06 15:29 - 2013-11-06 15:29 - 00003148 _____ C:\Windows\System32\Tasks\SidebarExecute 2013-11-06 15:29 - 2013-11-06 15:29 - 00002786 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2013-11-06 15:29 - 2013-11-06 15:29 - 00000000 ____D C:\Users\****** ******\AppData\Local\HP 2013-11-06 15:29 - 2013-11-06 15:29 - 00000000 ____D C:\Program Files\CCleaner 2013-11-06 15:21 - 2013-11-06 15:41 - 00000000 ____D C:\Program Files (x86)\Yahoo! 2013-11-06 15:21 - 2013-11-06 15:21 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Yahoo! 2013-11-06 15:19 - 2013-11-06 15:19 - 00000000 ____D C:\Windows\SysWOW64\spool 2013-11-06 15:19 - 2013-11-06 15:19 - 00000000 ____D C:\ProgramData\HP Product Assistant 2013-11-06 15:17 - 2013-11-06 23:15 - 00003881 _____ C:\ProgramData\hpzinstall.log 2013-11-06 15:17 - 2013-11-06 23:14 - 00000000 ____D C:\Program Files (x86)\HP 2013-11-06 15:17 - 2013-11-06 15:30 - 00245549 _____ C:\Windows\hpoins19.dat 2013-11-06 15:17 - 2013-11-06 15:30 - 00000000 ____D C:\ProgramData\HP 2013-11-06 15:17 - 2009-10-20 05:30 - 00013898 ____N C:\Windows\hpomdl19.dat 2013-11-06 15:17 - 2009-07-08 11:51 - 00861184 _____ (Hewlett-Packard) C:\Windows\system32\hpowiav1.dll 2013-11-06 15:17 - 2009-07-08 11:51 - 00730624 _____ (Hewlett-Packard Co.) C:\Windows\system32\hpotscl1.dll 2013-11-06 15:17 - 2009-07-08 11:51 - 00642360 _____ (Hewlett-Packard) C:\Windows\system32\hpzids40.dll 2013-11-06 15:17 - 2009-07-08 11:51 - 00498176 _____ (Hewlett-Packard Co.) C:\Windows\system32\hpovst01.dll 2013-11-06 15:16 - 2013-11-06 15:16 - 00000000 ____D C:\Windows\Hewlett-Packard 2013-11-06 01:15 - 2013-11-06 01:15 - 00000000 _____ C:\Users\****** ******\defogger_reenable 2013-11-06 00:31 - 2013-11-06 00:31 - 00000000 ____D C:\Users\****** ******\AppData\Local\{E46C497C-1C0F-4267-9364-EA173BFA1595} 2013-11-06 00:26 - 2013-11-06 00:26 - 00000000 ____D C:\Users\****** ******\AppData\Local\{49829345-3D1A-403A-8672-90605D11A3A5} 2013-11-06 00:14 - 2013-11-06 00:22 - 00000000 ____D C:\Program Files (x86)\Windows Live 2013-11-06 00:14 - 2013-11-06 00:14 - 00000000 ____D C:\Windows\PCHEALTH 2013-11-06 00:14 - 2013-11-06 00:14 - 00000000 ____D C:\Program Files\Windows Live 2013-11-05 23:42 - 2013-11-05 23:42 - 00000000 ____D C:\Users\****** ******\AppData\Local\{6C580F57-6E5A-47DD-A0AB-5AA8DFD00416} 2013-11-05 22:12 - 2013-06-22 20:24 - 00451816 ____R C:\Windows\system32\Drivers\etc\hosts.20131105-221238.backup 2013-11-05 22:06 - 2013-11-05 22:06 - 00001384 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk 2013-11-05 22:06 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe 2013-11-05 21:29 - 2013-11-05 21:29 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Winamp Erkennungs-Plug-in 2013-11-05 21:03 - 2013-11-05 21:03 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-11-05 21:03 - 2013-11-05 21:03 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-11-05 21:03 - 2013-11-05 21:03 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-11-05 21:03 - 2013-11-05 21:03 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-11-05 21:03 - 2013-11-05 21:03 - 00000000 ____D C:\Program Files\Java 2013-11-05 20:57 - 2013-11-05 20:59 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-05 20:49 - 2013-11-05 20:49 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-11-05 20:49 - 2013-11-05 20:49 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-11-05 20:49 - 2013-11-05 20:49 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-11-05 20:49 - 2013-11-05 20:49 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-11-05 20:49 - 2013-11-05 20:49 - 00000000 ____D C:\Program Files (x86)\Java 2013-11-05 16:09 - 2013-09-04 13:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2013-11-05 16:09 - 2013-09-04 13:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2013-11-05 16:09 - 2013-09-04 13:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2013-11-05 16:09 - 2013-09-04 13:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2013-11-05 16:09 - 2013-09-04 13:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2013-11-05 16:09 - 2013-09-04 13:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2013-11-05 16:09 - 2013-09-04 13:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2013-11-05 16:00 - 2013-09-23 00:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-05 16:00 - 2013-09-23 00:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-05 16:00 - 2013-09-23 00:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-05 16:00 - 2013-09-23 00:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-05 16:00 - 2013-09-23 00:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-05 16:00 - 2013-09-23 00:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-05 16:00 - 2013-09-23 00:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-05 16:00 - 2013-09-23 00:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-05 16:00 - 2013-09-23 00:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-05 16:00 - 2013-09-23 00:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-05 16:00 - 2013-09-23 00:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-05 16:00 - 2013-09-23 00:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-05 16:00 - 2013-09-23 00:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-05 16:00 - 2013-09-22 23:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-05 16:00 - 2013-09-22 23:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-05 16:00 - 2013-09-22 23:55 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-05 16:00 - 2013-09-22 23:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-05 16:00 - 2013-09-22 23:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-05 16:00 - 2013-09-22 23:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-05 16:00 - 2013-09-22 23:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-05 16:00 - 2013-09-22 23:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-05 16:00 - 2013-09-22 23:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-05 16:00 - 2013-09-22 23:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-05 16:00 - 2013-09-22 23:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-05 16:00 - 2013-09-22 23:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-05 16:00 - 2013-09-22 23:54 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-05 16:00 - 2013-09-22 23:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-05 16:00 - 2013-09-21 04:38 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-05 16:00 - 2013-09-21 04:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-05 16:00 - 2013-09-21 03:48 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-05 16:00 - 2013-09-21 03:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-05 15:46 - 2013-11-05 15:48 - 00000000 ____D C:\Windows\system32\MRT 2013-11-05 15:24 - 2013-08-02 03:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-11-05 15:24 - 2013-08-02 03:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-11-05 15:24 - 2013-08-02 03:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2013-11-05 15:24 - 2013-08-02 02:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 02:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-11-05 15:24 - 2013-08-02 01:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2013-11-05 15:24 - 2013-08-02 01:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 01:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 01:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2013-11-05 15:24 - 2013-08-02 01:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2013-11-05 15:20 - 2013-09-14 02:10 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-11-05 15:20 - 2013-09-08 03:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-11-05 15:20 - 2013-09-08 03:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-11-05 15:20 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2013-11-05 15:20 - 2013-08-29 03:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-11-05 15:20 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-11-05 15:20 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2013-11-05 15:20 - 2013-08-29 03:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-11-05 15:20 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-11-05 15:20 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-11-05 15:20 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-11-05 15:20 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-11-05 15:20 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2013-11-05 15:20 - 2013-08-29 02:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-11-05 15:20 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2013-11-05 15:20 - 2013-08-29 01:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-11-05 15:20 - 2013-08-29 01:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-11-05 15:20 - 2013-08-29 01:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-11-05 15:20 - 2013-08-29 01:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-11-05 15:20 - 2013-07-26 03:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-11-05 15:20 - 2013-07-26 03:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-11-05 15:20 - 2013-07-26 02:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-11-05 15:20 - 2013-07-26 02:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-11-05 15:20 - 2013-07-09 06:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-11-05 15:20 - 2013-07-09 06:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-11-05 15:20 - 2013-07-09 06:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-11-05 15:20 - 2013-07-09 06:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-11-05 15:20 - 2013-07-09 05:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-11-05 15:20 - 2013-07-09 05:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-11-05 15:20 - 2013-07-09 05:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-11-05 15:20 - 2013-07-09 05:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-11-05 15:19 - 2013-08-28 02:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-11-05 15:19 - 2013-08-05 03:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2013-11-05 15:19 - 2013-07-25 10:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-11-05 15:19 - 2013-07-25 09:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-11-05 15:19 - 2013-07-20 11:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-11-05 15:19 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2013-11-05 15:19 - 2013-07-19 02:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-11-05 15:19 - 2013-07-19 02:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-11-05 15:19 - 2013-07-12 11:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2013-11-05 15:19 - 2013-07-09 06:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-11-05 15:19 - 2013-07-09 05:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-11-05 15:19 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2013-11-05 15:19 - 2013-07-04 13:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2013-11-05 15:19 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2013-11-05 15:19 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2013-11-05 15:19 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2013-11-05 15:19 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2013-11-05 15:19 - 2013-07-04 11:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2013-11-05 15:19 - 2013-07-03 05:40 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys 2013-11-05 15:19 - 2013-07-03 05:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2013-11-05 15:19 - 2013-07-03 05:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2013-11-05 15:19 - 2013-06-25 23:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2013-11-05 15:19 - 2013-06-15 05:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-11-05 15:19 - 2013-06-06 06:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2013-11-05 15:19 - 2013-06-06 06:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2013-11-05 15:19 - 2013-06-06 06:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2013-11-05 15:19 - 2013-06-06 06:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-11-05 15:19 - 2013-06-06 05:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2013-11-05 15:19 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2013-11-05 15:19 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2013-11-05 15:19 - 2013-06-06 04:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-11-05 15:19 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2013-11-05 15:19 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2013-11-05 15:18 - 2013-06-04 07:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-11-05 15:18 - 2013-06-04 05:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2013-11-05 15:07 - 2013-04-10 00:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-11-05 15:07 - 2013-04-02 23:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-11-05 15:04 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2013-11-05 15:03 - 2013-08-01 13:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-11-05 14:39 - 2013-11-05 14:55 - 00000000 ____D C:\Users\****** ******\AppData\Local\NPE 2013-11-05 14:30 - 2013-11-05 14:30 - 00000000 ____D C:\Windows\System32\Tasks\Norton Internet Security 2013-11-05 14:24 - 2013-11-05 14:26 - 00002506 _____ C:\Users\Public\Desktop\Norton Internet Security.lnk 2013-11-05 13:54 - 2013-11-05 13:54 - 00000000 ____D C:\FRST 2013-11-05 12:37 - 2013-11-05 12:37 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton 2013-11-05 12:28 - 2013-11-05 12:28 - 00000000 ____D C:\trojaner board soft s 2013-11-05 12:23 - 2013-11-06 17:03 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2013-11-05 12:23 - 2013-11-05 12:23 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-05 12:18 - 2013-11-06 16:41 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2013-10-27 09:12 - 2013-10-27 09:12 - 30344480 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 25257248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 22933792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 15855568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 15212336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 12572960 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2013-10-27 09:12 - 2013-10-27 09:12 - 11426568 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 11374520 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 09524088 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 09480328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 03131680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 03124512 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 02946848 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 02747168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433165.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433165.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 01510176 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco64.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 01241376 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00696096 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00655136 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00560416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00196384 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2013-10-27 09:12 - 2013-10-27 09:12 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2013-10-23 03:02 - 2013-10-23 03:02 - 00589600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe ==================== One Month Modified Files and Folders ======= 2013-11-08 02:29 - 2013-01-11 21:10 - 00001122 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-11-08 02:26 - 2012-03-30 22:46 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-11-08 01:39 - 2013-11-07 00:51 - 00000248 _____ C:\Users\****** ******\Documents\tunnel.txt 2013-11-08 01:35 - 2013-11-08 01:35 - 00000000 ____D C:\Users\****** ******\AppData\Local\{E7C0278F-3574-4E9E-9139-B41F42B1D1B4} 2013-11-08 01:35 - 2011-10-09 01:57 - 00000000 ____D C:\Users\****** ******\AppData\Local\Windows Live 2013-11-08 01:33 - 2011-10-08 21:28 - 01492233 _____ C:\Windows\WindowsUpdate.log 2013-11-08 00:04 - 2013-11-08 00:02 - 00000000 ___SH C:\DkHyperbootSync 2013-11-07 22:01 - 2013-11-07 22:01 - 00971360 _____ (Acronis) C:\Windows\system32\Drivers\timntr.sys 2013-11-07 22:01 - 2013-11-07 22:01 - 00000000 ____D C:\ProgramData\Acronis 2013-11-07 22:00 - 2013-11-07 22:00 - 00275552 _____ (Acronis) C:\Windows\system32\Drivers\snapman.sys 2013-11-07 22:00 - 2013-11-07 22:00 - 00141920 _____ (Acronis) C:\Windows\system32\Drivers\vsflt53.sys 2013-11-07 22:00 - 2013-11-07 22:00 - 00000000 ____D C:\Program Files (x86)\Acronis 2013-11-07 21:03 - 2011-04-12 08:43 - 00696620 _____ C:\Windows\system32\perfh007.dat 2013-11-07 21:03 - 2011-04-12 08:43 - 00147916 _____ C:\Windows\system32\perfc007.dat 2013-11-07 21:03 - 2009-07-14 06:13 - 01612484 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-07 20:57 - 2013-11-07 20:57 - 00000000 ___HD C:\Program Files (x86)\Zero G Registry 2013-11-07 20:57 - 2013-11-07 20:57 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ErosLink 2013-11-07 20:57 - 2013-11-07 20:57 - 00000000 ____D C:\Program Files (x86)\ErosLink 2013-11-07 19:15 - 2011-10-09 01:25 - 00000000 ____D C:\Program Files (x86)\DSL-Manager 2013-11-07 16:22 - 2012-06-29 12:36 - 00003982 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{1C6C1C2F-D891-4AC6-B935-A56BE995074F} 2013-11-07 14:29 - 2013-01-11 21:10 - 00001118 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-11-07 12:36 - 2012-10-04 13:00 - 00023817 _____ C:\Users\****** ******\Documents\Der erhaltene Artikel entspricht nicht der Beschreibung_ ************ hat eine Nachricht zu Fleischmann piccolo 8599 Artikelnummer 230842947883 gesendet_.eml 2013-11-07 12:25 - 2012-05-14 00:27 - 00000000 ____D C:\Users\****** ******\Documents\Nexus Mod Manager 2013-11-07 12:25 - 2009-02-22 03:16 - 00000000 ____D C:\Users\****** ******\Documents\PersBackup 2013-11-07 12:04 - 2013-11-07 12:04 - 00000000 ____D C:\Users\****** ******\Documents\Witcher 2 2013-11-07 12:04 - 2011-10-09 14:01 - 00000000 ____D C:\Users\****** ******\Documents\My Games 2013-11-07 12:04 - 2008-02-23 22:54 - 00000000 ____D C:\Users\****** ******\Documents\Eigene Dokumente+wichtiges 2013-11-07 11:18 - 2011-10-09 01:18 - 00000000 ____D C:\Users\****** ******\AppData\Local\CrashDumps 2013-11-07 11:12 - 2009-07-14 05:45 - 00021696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-07 11:12 - 2009-07-14 05:45 - 00021696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-07 11:05 - 2013-11-07 10:43 - 00000704 _____ C:\Windows\PFRO.log 2013-11-07 11:05 - 2013-11-07 00:32 - 00000168 _____ C:\Windows\setupact.log 2013-11-07 11:05 - 2011-10-12 13:13 - 00000000 ____D C:\ProgramData\NVIDIA 2013-11-07 11:05 - 2011-10-09 03:45 - 00000000 ____D C:\Users\****** ******\.rainlendar2 2013-11-07 11:05 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-07 10:56 - 2013-11-07 10:56 - 00001114 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-11-07 10:56 - 2013-11-07 10:56 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Malwarebytes 2013-11-07 10:56 - 2013-11-07 10:56 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-11-07 10:41 - 2013-11-08 02:43 - 01957098 _____ (Farbar) C:\Users\****** ******\Desktop\FRST64.exe 2013-11-07 08:37 - 2013-11-07 08:37 - 00000000 ____D C:\Users\****** ******\AppData\Local\{650AFD04-1DE3-4A30-9ACD-22254994D0A6} 2013-11-07 02:48 - 2013-11-07 02:48 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Media Player Classic 2013-11-07 02:24 - 2013-11-07 02:24 - 00000000 ____D C:\Users\****** ******\AppData\Local\Rekenwonder_Software 2013-11-07 01:41 - 2013-11-07 01:41 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Junction Link Magic 2013-11-07 01:41 - 2013-11-07 01:41 - 00000000 ____D C:\Program Files\Rekenwonder Software 2013-11-07 01:40 - 2011-10-09 06:08 - 00000000 ____D C:\ProgramData\InstallMate 2013-11-07 00:32 - 2013-11-07 00:32 - 00000000 _____ C:\Windows\setuperr.log 2013-11-06 23:57 - 2011-10-09 03:25 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Winamp 2013-11-06 23:57 - 2011-10-09 01:40 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Free Download Manager 2013-11-06 23:54 - 2011-10-09 00:08 - 00000000 ___DC C:\Users\****** ******\AppData\Local\MigWiz 2013-11-06 23:54 - 2011-10-08 22:23 - 00000000 ____D C:\Windows\Panther 2013-11-06 23:48 - 2013-11-06 23:48 - 00000000 ____D C:\Program Files (x86)\JAM Software 2013-11-06 23:33 - 2011-10-09 06:08 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\WinPatrol 2013-11-06 23:19 - 2011-10-08 22:59 - 00000000 ___RD C:\Users\****** ******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sys-Software 2013-11-06 23:19 - 2011-10-08 22:59 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sys-Tuning+Bench 2013-11-06 23:17 - 2011-10-08 23:00 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Backup 2013-11-06 23:15 - 2013-11-06 15:17 - 00003881 _____ C:\ProgramData\hpzinstall.log 2013-11-06 23:14 - 2013-11-06 15:17 - 00000000 ____D C:\Program Files (x86)\HP 2013-11-06 22:20 - 2011-10-09 01:43 - 00000000 ____D C:\Program Files\LinkShellExtension 2013-11-06 22:05 - 2013-11-06 22:05 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Acronis 2013-11-06 21:14 - 2013-11-06 21:14 - 00000000 ____D C:\LÖSCH ZEUGS 2013-11-06 18:29 - 2013-11-06 18:29 - 00000000 ____D C:\Users\****** ******\AppData\Local\WarThunder 2013-11-06 18:29 - 2013-11-06 18:29 - 00000000 ____D C:\ProgramData\WarThunder 2013-11-06 18:24 - 2011-10-08 22:59 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Simulationen 2013-11-06 18:21 - 2011-10-09 14:06 - 00000000 ____D C:\Users\****** ******\AppData\Local\Wings of Prey 2013-11-06 18:17 - 2013-11-06 18:17 - 00000000 ____D C:\Users\****** ******\AppData\Local\WOP 2013-11-06 18:17 - 2013-11-06 18:15 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\HpUpdate 2013-11-06 18:15 - 2013-11-06 18:14 - 03607616 _____ (Igor Pavlov) C:\Users\****** ******\Downloads\GmdClientSetup.exe 2013-11-06 18:15 - 2013-11-06 18:14 - 03111104 _____ (Hewlett-Packard ) C:\Users\****** ******\Downloads\hpusetup.exe 2013-11-06 17:12 - 2013-11-06 17:12 - 00005866 _____ C:\Users\****** ******\Documents\gmer.log 2013-11-06 17:03 - 2013-11-05 12:23 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2013-11-06 16:41 - 2013-11-05 12:18 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2013-11-06 16:36 - 2013-11-06 16:36 - 00001244 _____ C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk 2013-11-06 16:36 - 2011-10-09 01:41 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\DVDVideoSoftIEHelpers 2013-11-06 16:36 - 2011-10-09 01:41 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\DVDVideoSoft 2013-11-06 16:36 - 2011-10-09 01:41 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft 2013-11-06 16:21 - 2013-11-06 16:21 - 00000000 ____D C:\Users\****** ******\AppData\Local\{DA6A2054-1BF9-40B8-9486-B3EE2667D9C0} 2013-11-06 16:14 - 2009-07-14 05:45 - 00315320 _____ C:\Windows\system32\FNTCACHE.DAT 2013-11-06 16:06 - 2013-11-06 16:04 - 00000000 ____D C:\ProgramData\Live Aquarium HD 2013-11-06 16:04 - 2013-11-06 16:04 - 00000000 ____D C:\Program Files (x86)\Live Aquarium HD 2013-11-06 16:03 - 2011-10-08 23:47 - 00072232 _____ C:\Users\****** ******\AppData\Local\GDIPFONTCACHEV1.DAT 2013-11-06 15:57 - 2013-11-06 15:57 - 00000000 ____D C:\Program Files (x86)\K-Lite Codec Pack 2013-11-06 15:56 - 2011-11-03 10:24 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Ashampoo 2013-11-06 15:56 - 2011-10-09 01:49 - 00000000 ____D C:\Users\****** ******\AppData\Local\ashampoo 2013-11-06 15:54 - 2013-11-06 15:54 - 00001304 _____ C:\Users\Public\Desktop\Ashampoo Burning Studio 12.lnk 2013-11-06 15:53 - 2013-11-06 15:53 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ashampoo 2013-11-06 15:53 - 2011-10-09 01:49 - 00000000 ____D C:\ProgramData\ashampoo 2013-11-06 15:53 - 2011-10-09 01:49 - 00000000 ____D C:\Program Files (x86)\Ashampoo 2013-11-06 15:49 - 2013-11-06 15:49 - 00000000 ___HD C:\ProgramData\CanonBJ 2013-11-06 15:49 - 2013-11-06 15:49 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4 2013-11-06 15:48 - 2013-11-06 15:47 - 00000000 ____D C:\Users\****** ******\Desktop\Canon+Hp 2013-11-06 15:47 - 2013-11-06 15:47 - 00000000 ___HD C:\ProgramData\CanonIJEPPEX2 2013-11-06 15:47 - 2013-11-06 15:47 - 00000000 ___HD C:\ProgramData\CanonEPP 2013-11-06 15:47 - 2013-11-06 15:47 - 00000000 ____D C:\Users\****** ******\AppData\Local\Canon Easy-PhotoPrint EX 2013-11-06 15:47 - 2013-11-06 15:47 - 00000000 ____D C:\Program Files\Common Files\Canon 2013-11-06 15:47 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\system32\FxsTmp 2013-11-06 15:46 - 2013-11-06 15:46 - 00000000 ____D C:\Program Files\Canon 2013-11-06 15:46 - 2013-11-06 15:45 - 00000000 ____D C:\Program Files (x86)\Canon 2013-11-06 15:45 - 2013-11-06 15:45 - 00000000 ____D C:\Program Files (x86)\CD-LabelPrint 2013-11-06 15:43 - 2013-11-06 15:43 - 00000000 ____D C:\Users\****** ******\Documents\Add-in Express 2013-11-06 15:43 - 2011-12-30 20:41 - 00000000 ____D C:\ProgramData\WinZip 2013-11-06 15:43 - 2011-10-08 21:53 - 00000000 ____D C:\Users\****** ****** 2013-11-06 15:41 - 2013-11-06 15:21 - 00000000 ____D C:\Program Files (x86)\Yahoo! 2013-11-06 15:31 - 2013-11-06 15:30 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\HP 2013-11-06 15:30 - 2013-11-06 15:30 - 00000000 ____D C:\ProgramData\WEBREG 2013-11-06 15:30 - 2013-11-06 15:17 - 00245549 _____ C:\Windows\hpoins19.dat 2013-11-06 15:30 - 2013-11-06 15:17 - 00000000 ____D C:\ProgramData\HP 2013-11-06 15:29 - 2013-11-06 15:29 - 00003148 _____ C:\Windows\System32\Tasks\SidebarExecute 2013-11-06 15:29 - 2013-11-06 15:29 - 00002786 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2013-11-06 15:29 - 2013-11-06 15:29 - 00000000 ____D C:\Users\****** ******\AppData\Local\HP 2013-11-06 15:29 - 2013-11-06 15:29 - 00000000 ____D C:\Program Files\CCleaner 2013-11-06 15:29 - 2009-07-14 03:34 - 00000499 _____ C:\Windows\win.ini 2013-11-06 15:21 - 2013-11-06 15:21 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Yahoo! 2013-11-06 15:19 - 2013-11-06 15:19 - 00000000 ____D C:\Windows\SysWOW64\spool 2013-11-06 15:19 - 2013-11-06 15:19 - 00000000 ____D C:\ProgramData\HP Product Assistant 2013-11-06 15:16 - 2013-11-06 15:16 - 00000000 ____D C:\Windows\Hewlett-Packard 2013-11-06 01:15 - 2013-11-06 01:15 - 00000000 _____ C:\Users\****** ******\defogger_reenable 2013-11-06 00:31 - 2013-11-06 00:31 - 00000000 ____D C:\Users\****** ******\AppData\Local\{E46C497C-1C0F-4267-9364-EA173BFA1595} 2013-11-06 00:26 - 2013-11-06 00:26 - 00000000 ____D C:\Users\****** ******\AppData\Local\{49829345-3D1A-403A-8672-90605D11A3A5} 2013-11-06 00:22 - 2013-11-06 00:14 - 00000000 ____D C:\Program Files (x86)\Windows Live 2013-11-06 00:14 - 2013-11-06 00:14 - 00000000 ____D C:\Windows\PCHEALTH 2013-11-06 00:14 - 2013-11-06 00:14 - 00000000 ____D C:\Program Files\Windows Live 2013-11-06 00:14 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2013-11-06 00:08 - 2011-10-09 01:39 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Macromedia 2013-11-05 23:42 - 2013-11-05 23:42 - 00000000 ____D C:\Users\****** ******\AppData\Local\{6C580F57-6E5A-47DD-A0AB-5AA8DFD00416} 2013-11-05 23:27 - 2012-04-26 22:32 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-05 23:04 - 2011-10-12 13:12 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2013-11-05 23:03 - 2011-10-12 13:13 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-11-05 22:07 - 2013-06-22 20:13 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2 2013-11-05 22:06 - 2013-11-05 22:06 - 00001384 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk 2013-11-05 22:06 - 2013-06-22 20:14 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-11-05 21:29 - 2013-11-05 21:29 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Winamp Erkennungs-Plug-in 2013-11-05 21:29 - 2011-10-09 03:25 - 00000984 _____ C:\Users\Public\Desktop\Winamp.lnk 2013-11-05 21:29 - 2011-10-09 03:25 - 00000000 ____D C:\Program Files (x86)\Winamp Detect 2013-11-05 21:29 - 2011-10-09 03:25 - 00000000 ____D C:\Program Files (x86)\Winamp 2013-11-05 21:16 - 2011-10-09 02:03 - 00000000 ____D C:\Program Files (x86)\Opera 2013-11-05 21:09 - 2013-01-11 21:14 - 00002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-11-05 21:08 - 2011-10-08 23:00 - 00000000 ___RD C:\Users\****** ******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sicherheit 2013-11-05 21:06 - 2011-11-03 21:08 - 00000000 ____D C:\Program Files (x86)\XP antispy 2013-11-05 21:03 - 2013-11-05 21:03 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-11-05 21:03 - 2013-11-05 21:03 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-11-05 21:03 - 2013-11-05 21:03 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-11-05 21:03 - 2013-11-05 21:03 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-11-05 21:03 - 2013-11-05 21:03 - 00000000 ____D C:\Program Files\Java 2013-11-05 20:59 - 2013-11-05 20:57 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-05 20:59 - 2012-06-02 19:53 - 00001080 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-11-05 20:58 - 2011-10-09 02:06 - 00000000 ____D C:\Users\****** ******\AppData\Local\Mozilla 2013-11-05 20:49 - 2013-11-05 20:49 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-11-05 20:49 - 2013-11-05 20:49 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-11-05 20:49 - 2013-11-05 20:49 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-11-05 20:49 - 2013-11-05 20:49 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-11-05 20:49 - 2013-11-05 20:49 - 00000000 ____D C:\Program Files (x86)\Java 2013-11-05 16:33 - 2012-03-30 22:46 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-11-05 16:33 - 2012-03-30 22:46 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-11-05 16:33 - 2011-10-09 03:32 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-11-05 16:06 - 2011-10-09 06:30 - 00000000 ___RD C:\Users\****** ******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-11-05 16:06 - 2011-10-08 21:53 - 00000000 ___RD C:\Users\****** ******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-11-05 16:05 - 2012-05-09 23:57 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-11-05 16:05 - 2012-05-09 23:57 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-11-05 16:03 - 2011-04-12 08:55 - 00000000 ____D C:\Program Files\Windows Journal 2013-11-05 16:03 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Defender 2013-11-05 16:03 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2013-11-05 15:55 - 2011-10-09 13:54 - 01589442 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-11-05 15:48 - 2013-11-05 15:46 - 00000000 ____D C:\Windows\system32\MRT 2013-11-05 14:55 - 2013-11-05 14:39 - 00000000 ____D C:\Users\****** ******\AppData\Local\NPE 2013-11-05 14:40 - 2011-10-09 00:30 - 00000000 ____D C:\ProgramData\Norton 2013-11-05 14:36 - 2011-10-09 06:03 - 00000000 ____D C:\Program Files (x86)\MAXA Cookie Manager 2013-11-05 14:30 - 2013-11-05 14:30 - 00000000 ____D C:\Windows\System32\Tasks\Norton Internet Security 2013-11-05 14:26 - 2013-11-05 14:24 - 00002506 _____ C:\Users\Public\Desktop\Norton Internet Security.lnk 2013-11-05 14:26 - 2012-03-07 13:04 - 00000000 ____D C:\Windows\system32\Drivers\NISx64 2013-11-05 14:26 - 2011-10-09 00:55 - 00003234 _____ C:\Windows\System32\Tasks\Norton WSC Integration 2013-11-05 14:24 - 2013-01-11 21:10 - 00004118 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-11-05 14:24 - 2013-01-11 21:10 - 00003866 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-11-05 14:24 - 2011-10-09 00:33 - 00177752 _____ (Symantec Corporation) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS 2013-11-05 14:24 - 2011-10-09 00:33 - 00008222 _____ C:\Windows\system32\Drivers\SYMEVENT64x86.CAT 2013-11-05 14:23 - 2012-03-07 13:04 - 00000000 ____D C:\Program Files (x86)\Norton Internet Security 2013-11-05 13:54 - 2013-11-05 13:54 - 00000000 ____D C:\FRST 2013-11-05 13:53 - 2011-10-09 01:08 - 00000000 ____D C:\Program Files (x86)\Deutsche Telekom 2013-11-05 13:52 - 2013-06-22 23:32 - 00000442 _____ C:\Windows\wininit.ini 2013-11-05 12:37 - 2013-11-05 12:37 - 00000000 ____D C:\Users\****** ******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton 2013-11-05 12:37 - 2011-10-09 03:29 - 00000000 ____D C:\Program Files (x86)\OpenOffice.org 3 2013-11-05 12:28 - 2013-11-05 12:28 - 00000000 ____D C:\trojaner board soft s 2013-11-05 12:23 - 2013-11-05 12:23 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-05 12:19 - 2011-10-09 00:35 - 00000000 ____D C:\Users\Public\Downloads\Norton 2013-11-05 12:14 - 2011-04-12 08:55 - 00000000 ____D C:\Windows\CSC 2013-10-27 09:12 - 2013-10-27 09:12 - 30344480 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 25257248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 22933792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 15855568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 15212336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 12572960 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2013-10-27 09:12 - 2013-10-27 09:12 - 11426568 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 11374520 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 09524088 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 09480328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 03131680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 03124512 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 02946848 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 02747168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433165.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433165.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 01510176 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco64.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 01241376 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00696096 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00655136 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00560416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00196384 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2013-10-27 09:12 - 2013-10-27 09:12 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2013-10-27 09:12 - 2013-10-27 09:12 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2013-10-27 09:12 - 2013-02-25 23:32 - 02695200 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2013-10-27 09:12 - 2012-10-10 20:23 - 18199872 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2013-10-27 09:12 - 2012-02-24 02:38 - 01435504 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2013-10-27 09:12 - 2011-10-12 13:09 - 18286416 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2013-10-27 09:12 - 2011-10-12 13:09 - 03067560 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2013-10-27 09:12 - 2011-10-12 13:09 - 00023287 _____ C:\Windows\system32\nvinfo.pb 2013-10-23 09:20 - 2012-02-24 02:39 - 03426956 _____ C:\Windows\system32\nvcoproc.bin 2013-10-23 09:20 - 2011-10-12 13:12 - 06669600 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2013-10-23 09:20 - 2011-10-12 13:12 - 03489568 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2013-10-23 09:20 - 2011-10-12 13:12 - 02559776 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2013-10-23 09:20 - 2011-10-12 13:12 - 00922912 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2013-10-23 09:20 - 2011-10-12 13:12 - 00219424 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2013-10-23 09:20 - 2011-10-12 13:12 - 00063776 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2013-10-23 03:02 - 2013-10-23 03:02 - 00589600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2013-10-14 01:07 - 2013-11-07 12:04 - 00000122 _____ C:\Users\****** ******\Documents\hacking.txt Some content of TEMP: ==================== C:\Users\****** ******\AppData\Local\Temp\yupdate0.7.36.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-06-22 23:09 ==================== End Of Log ============================ |
![]() | #28 |
![]() | ![]() Win7 IP tunnelt mich jede Nacht und kapert Teledat 530 RouterCode:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 31-10-2013 Ran by ****** ****** at 2013-11-08 02:44:51 Running from C:\Users\****** ******\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Norton Internet Security (Enabled - Up to date) {63DF5164-9100-186D-2187-8DC619EFD8BF} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} AS: Norton Internet Security (Enabled - Up to date) {D8BEB080-B73A-17E3-1B37-B6B462689202} FW: Norton Internet Security (Enabled) {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} ==================== Installed Programs ====================== 3DMark 11 (x32 Version: 1.0.2) 3GX (x32 Version: 3.03.2101) 64 Bit HP CIO Components Installer (Version: 7.2.8) 7-Zip 4.57 (x32) Acronis True Image WD Edition (x32 Version: 13.0.14189) Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117) Adobe Reader X (10.1.8) - Deutsch (x32 Version: 10.1.8) aerosoft's - Im Koeblitzer Bergland (x32 Version: 1.10) AIO_CDB_ProductContext (x32 Version: 130.0.365.000) AIO_CDB_Software (x32 Version: 130.0.365.000) AIO_Scan (x32 Version: 130.0.421.000) Apache: Air Assault (x32 Version: Ashampoo Burning Studio 10 v.10.0.15 (x32 Version: 10.0.15) Ashampoo Burning Studio 12 v.12.0.5 (x32 Version: 12.0.5) Assets Lgine du Nord version V1.00 (x32 Version: V1.00) Assets Ligne du Nord version V1.01 (x32 Version: V1.01) AudioGenie (x32) Batman: Arkham City GOTY (x32) Blur (x32) BOSS (x32 Version: 2.0.0) BufferChm (x32 Version: 130.0.331.000) Call of Juarez: Bound in Blood (x32) Canon Easy-PhotoPrint EX (x32 Version: 4.1.6) Canon Inkjet Printer Driver Add-On Module Canon My Printer (x32 Version: 3.1.0) CCleaner (Version: 4.07) CD-LabelPrint (x32) Choplifter HD (x32) CLICKBIOSII (x32 Version: 1.0.021) Colin McRae Rally 2005 (x32 Version: 1.00.000) ControlCenter (x32 Version: 2.2.036) Copy (x32 Version: 130.0.428.000) CPUID CPU-Z 1.58 Creation Kit (x32) CrystalDiskInfo 5.3.1 (x32 Version: 5.3.1) CyberLink BD_3D Advisor 2.0 (x32 Version: 2.0.5425) CyberLink LabelPrint 2.5 (x32 Version: 2.5.5311) CyberLink Media Suite 10 (x32 Version: 10.0) CyberLink Media Suite 10 (x32 Version: 10.2021) CyberLink MediaEspresso 6.5 (x32 Version: 6.5.3019_44673) CyberLink MediaShow 6 (x32 Version: 6.0.4312) CyberLink Power2Go 7 (x32 Version: CyberLink PowerDVD 10 (x32 Version: 10.0.4125.52) CyberLink PowerProducer 5.5 (x32 Version: D3DX10 (x32 Version: 15.4.2368.0902) Daniusoft Media Converter(Build (x32) Destinations (x32 Version: DeviceDiscovery (x32 Version: 130.0.465.000) DHTML Editing Component (x32 Version: 6.02.0001) DiRT 3 (x32 Version: 1.0.0000.130) DiRT 3 (x32 Version: 1.0.0003.130) Diskeeper 2010 (Version: 14.0.915.64) Disktrix UltimateDefrag (x32) DocProc (x32 Version: Download Updater (AOL Inc.) (x32) DSL-Manager (x32) Dual-Core Optimizer (x32 Version: dutchpack 2.00 (x32) EPSON Attach To Email (x32 Version: 1.01.0000) Epson Easy Photo Print 2 (x32 Version: Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) (x32 Version: 1.00.0000) EPSON File Manager (x32 Version: EPSON Scan Assistant (x32 Version: 1.10.00) ErosLink (x32 Version: EVGA Precision X 3.0.4 (x32 Version: 3.0.4) F300 (x32 Version: 130.0.365.000) F300_Help (x32 Version: F300Trb (x32 Version: Fax (x32 Version: 130.0.418.000) Free Download Manager 3.9.2 (x32) Free Studio version 2013 (x32 Version: Freightliner Heavy Haul Class 66 (x32) Freightliner Heavy Haul Class 66V2.0 (x32) FUJIFILM USB Driver (x32) Futuremark SystemInfo (x32 Version: 4.2.0) GameShadow (x32 Version: 2.03.0000) GIMP 2.8.4 (Version: 2.8.4) Google Chrome (x32 Version: 30.0.1599.101) Google Update Helper (x32 Version: GPBaseService2 (x32 Version: 130.0.371.000) GRID (x32 Version: 1.30.0000) HP Customer Participation Program 13.0 (Version: 13.0) HP Imaging Device Functions 13.0 (Version: 13.0) HP Photosmart Officejet and Deskjet All-In-One Driver Software 13.0 Rel. B (Version: 13.0) HP Solution Center 13.0 (Version: 13.0) HP Update (x32 Version: HPPhotoGadget (x32 Version: HPProductAssistant (x32 Version: 130.0.371.000) Intel(R) Control Center (x32 Version: Intel(R) Management Engine Components (x32 Version: Intel(R) Processor Graphics (x32 Version: IrfanView (remove only) (x32 Version: 4.36) IsoBuster 2.8.5 (x32 Version: 2.8.5) Java 7 Update 45 (64-bit) (Version: 7.0.450) Java 7 Update 45 (x32 Version: 7.0.450) JMicron JMB36X Driver (x32 Version: Junction Link Magic 2.0 Junk Mail filter update (x32 Version: 15.4.3502.0922) Just Trains - Class 67 Advanced & Car Carriers (x32 Version: 1.00.0000) Just Trains - Rail Simulator Official Expansion Pack: Isle of Wight & Class 66 (x32 Version: 1.00.0000) Just Trains - Rebuilt Bulleid Light Pacific (x32 Version: 1.00.0000) Just Trains - Scottish East Coast Main Line (x32 Version: 1.00.0000) Just Trains - Streamlined Princess Coronation Class for RailWorks (x32 Version: 1.00.0000) Just Trains - Streamlined Princess Coronation Class for TRS 2013 (x32 Version: 1.00.0000) Just Trains - Voyager (x32 Version: 1.00.0000) Just Trains A4 Pacific Class British Rail Add-on Pack for RailWorks (x32 Version: 1.00.0000) Just Trains A4 Pacific Class British Rail Add-on Pack for Train Simulator 2013 (x32 Version: 1.00.0000) Just Trains A4 Pacific Class for RailWorks (x32 Version: 1.00.0000) Just Trains A4 Pacific Class for Train Simulator 2013 (x32 Version: 1.00.0000) Just Trains A4 Pacific Class LNER Add-on Pack for RailWorks (x32 Version: 1.00.0000) Just Trains Class 20 Collection for RailWorks (x32 Version: 1.00.0000) Just Trains Class 67 Free Livery (x32 Version: 1.00.0000) Just Trains JJA Autoballaster for RailWorks (x32 Version: 1.00.0000) Just Trains Seacow for RailWorks (x32 Version: 1.00.0000) K-Lite Mega Codec Pack 10.0.0 (x32 Version: 10.0.0) KRS pak Delete (x32) Live Aquarium HD (x32 Version: 3) Logitech Harmony Remote Software (x86) (x32 Version: 2.0) Malwarebytes Anti-Malware Version (x32 Version: MarketResearch (x32 Version: 130.0.374.000) marvell 91xx driver (x32 Version: MAXA Cookie Manager Pro 5.3 (x32) MegaStore Game Controller (Ver. 3.0) (x32 Version: 3.0) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Games for Windows - LIVE Redistributable (x32 Version: Microsoft Games for Windows Marketplace (x32 Version: Microsoft Silverlight (Version: 5.1.20913.0) Microsoft Train Simulator (x32) Microsoft VC9 runtime libraries (x32 Version: 2.0.0) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (x32 Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (x32 Version: 9.0.30411) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0) Microsoft Xbox 360 Accessories 1.2 (Version: Microsoft XNA Framework Redistributable 4.0 Refresh (x32 Version: 4.0.30901.0) Mozilla Firefox 25.0 (x86 de) (x32 Version: 25.0) Mozilla Maintenance Service (x32 Version: 25.0) MSVCRT (x32 Version: 15.4.2862.0708) MSVCRT_amd64 (x32 Version: 15.4.2862.0708) MSXML 4.0 SP3 Parser (KB2721691) (x32 Version: 4.30.2114.0) MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0) MSXML 4.0 SP3 Parser (KB973685) (x32 Version: 4.30.2107.0) MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0) NAVIGON Fresh 3.4.1 (x32 Version: 3.4.1) Need for Speed™ Most Wanted (x32) Network64 (Version: 130.0.572.000) Network64 (Version: Netzmanager (Version: 1.07) Netzmanager (x32 Version: 1.07) Nexus Mod Manager (Version: 0.44.12) Norton Internet Security (x32 Version: NVIDIA 3D Vision Controller-Treiber 296.10 (Version: 296.10) NVIDIA 3D Vision Treiber 331.65 (Version: 331.65) NVIDIA Alien vs. Triangles demo (x32 Version: 1.0) NVIDIA Endless City demo (x32 Version: 1.0) NVIDIA Grafiktreiber 331.65 (Version: 331.65) NVIDIA Install Application (Version: 2.1002.133.889) NVIDIA PhysX (x32 Version: 9.12.0213) NVIDIA PhysX-Systemsoftware 9.12.0213 (Version: 9.12.0213) NVIDIA Stereoscopic 3D Driver (x32 Version: NVIDIA Systemsteuerung 331.65 (Version: 331.65) NVIDIA Update 1.15.2 (Version: 1.15.2) NVIDIA Update Components (Version: 1.15.2) OCR Software by I.R.I.S. 13.0 (Version: 13.0) OpenAL (x32) OpenOffice 4.0.1 (x32 Version: 4.01.9714) Opera 12.16 (x32 Version: 12.16.1860) Paint.NET v3.5.10 (Version: 3.60.0) Personal Backup 5.4 (x32 Version: 5.3) PhoenixRC (x32 Version: 2.00.10) PlayMemories Home (x32 Version: Primo (x32 Version: 1.00.0000) Python 2.7.3 (64-bit) (Version: 2.7.3150) RAGE (x32) Railworks Community Asset Project (x32 Version: v1.12.24.12) Rainlendar2 (remove only) (x32) Rapture3D 2.4.8 Game (x32) Realtek Ethernet Controller Driver (x32 Version: Realtek High Definition Audio Driver (x32 Version: REFLEX Modellflugsimulator (x32 Version: 5.04.2) Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: Ridge Racer™ Unbounded (x32) Runtime (x32 Version: 1.00.0000) Rural Landscapes (x32 Version: - Freeware Edition) Rural Landscapes (x32 Version: v1.06.22.09 HR Edition) Scan (x32 Version: Secunia PSI ( (x32 Version: Silent Hunter 4 Wolves of the Pacific (x32 Version: 1.04.0000) Silent Hunter III (x32 Version: 1.00.0000) SimpleScreenshot 1.40 (x32) Simtrain's - SBB Route 1 (x32 Version: 1.00) SiSoftware Sandra Lite 2011.SP5 (Version: 17.80.2011.10) Skyrim NPC Editor (x32 Version: 0.75.1) SL-6640 Black Widow Flightstick (x32 Version: 3.1) SolutionCenter (x32 Version: 130.0.373.000) Spelling Dictionaries Support For Adobe Reader 9 (x32 Version: 9.0.0) Spybot - Search & Destroy (x32 Version: 2.2.25) Status (x32 Version: 130.0.469.000) Steam (x32 Version: Suoni Italiani per RailWorks v 1.0 (x32) Take On Helicopters (x32) Test Drive Unlimited (x32 Version: 1.00.0000) The Donner Pass freeware scenario set by TaD (HKCU) The Elder Scrolls V: Skyrim (x32) the Mother of Tears - Cleaner Part 1 (x32) The Walking Dead (x32) T-Online 6.0 (x32) T-Online WLAN-Access Finder (x32) Toolbox (x32 Version: 130.0.648.000) Torino Genova Rel. 1.0 per RailWorks (x32) Torino Genova Rel. 3.0 per RailWorks (x32) Train Simulator 2013 (x32) Train Store (German Language Pack) (x32) Train Store V3.2 (x32) TrayApp (x32 Version: 130.0.422.000) TreeSize Free V2.7 (x32 Version: 2.7) Überwachungstool für die Intel® Turbo-Boost-Technik 2.0 (Version: UKTS Freeware Pack - Blocks-Lofts-Bridges #1 (x32 Version: 1.0.9) UKTS Freeware Pack - Clutter #1 (x32 Version: 1.0.6) UKTS Freeware Pack - CN Rolling Stock Pack #1 (x32 Version: 1.0.1) UKTS Freeware Pack - Commercial #1 (x32 Version: 1.0.3) UKTS Freeware Pack - Foliage #1 (x32 Version: 1.0.2) UKTS Freeware Pack - Great Central Railway Loco Pack (x32 Version: 1.0.3) UKTS Freeware Pack - Great Scenario Challenge #1 (x32 Version: 1.0.5) UKTS Freeware Pack - Housing #1 (x32 Version: 1.1.1) UKTS Freeware Pack - Industrial #1 (x32 Version: 1.0.3) UKTS Freeware Pack - Railway Buildings #1 (x32 Version: 1.0.4) UKTS Freeware Pack - Terrain Textures #1 (x32 Version: 1.0.1) UKTS Freeware Pack - UK Carriages #1 (x32 Version: 1.1.2) UKTS Freeware Pack - UK Classic Diesel and Electric #1 (x32 Version: 1.1.2) UKTS Freeware Pack - UK DMUs-EMUs-Trams #1 (x32 Version: 1.1.5) UKTS Freeware Pack - UK Modern Diesel and Electric #1 (x32 Version: 1.1.1) UKTS Freeware Pack - UK Steam #1 (x32 Version: 1.1.1) UKTS Freeware Pack - UK Wagons #1 (x32 Version: 1.1.3) UKTS Freeware Route Pack - Candlewick (x32 Version: 1.0.3) UKTS Freeware Route Pack - Coniston Branch (x32 Version: 1.0.7) UKTS Freeware Route Pack - Lavender Line (x32 Version: 1.0.2) UKTS Freeware Route Pack - QiLian Mountain Line (x32 Version: 1.0.3) UKTS Freeware Route Pack - The Mayflower Line (x32 Version: 2.0.0) UnloadSupport (x32 Version: 11.0.0) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (x32 Version: 3) USB game controller (x32 Version: 1.00.0000) USBFast (x32 Version: VLC media player 2.1.0 (Version: 2.1.0) VLC media player 2.1.0 (x32 Version: 2.1.0) War Thunder (x32) WebReg (x32 Version: Winamp (x32 Version: 5.65 ) Winamp Erkennungs-Plug-in (HKCU Version: Winamp Toolbar (HKCU) Winamp Toolbar (x32) Windows 7 USB/DVD Download Tool (x32 Version: 1.0.30) Windows Live Communications Platform (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3555.0308) Windows Live ID Sign-in Assistant (Version: 7.250.4232.0) Windows Live Installer (x32 Version: 15.4.3502.0922) Windows Live Language Selector (Version: 15.4.3555.0308) Windows Live Mail (x32 Version: 15.4.3502.0922) Windows Live MIME IFilter (Version: 15.4.3502.0922) Windows Live Photo Common (x32 Version: 15.4.3502.0922) Windows Live PIMT Platform (x32 Version: 15.4.3508.1109) Windows Live SOXE (x32 Version: 15.4.3502.0922) Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922) Windows Live UX Platform (x32 Version: 15.4.3502.0922) Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109) Windows Live Writer (x32 Version: 15.4.3502.0922) Windows Live Writer Resources (x32 Version: 15.4.3502.0922) Windows-Treiberpaket - FTDI CDM Driver Package (10/22/2009 2.06.00) (Version: 10/22/2009 2.06.00) WinPatrol (Version: 29.0.2013) Wrye Bash (x32 Version: wxPython (unicode) for Python 2.7 (x32 Version: xp-AntiSpy 3.98-2 (x32) yuPlay client 0.7.24 (x32) ==================== Restore Points ========================= 07-11-2013 21:00:13 Acronis True Image wird installiert ==================== Hosts content: ========================== 2013-11-06 16:24 - 2013-11-06 16:24 - 00453207 ____A C:\Windows\system32\Drivers\etc\hosts www.007guard.com 007guard.com 008i.com www.008k.com 008k.com www.00hq.com 00hq.com 010402.com www.032439.com 032439.com www.0scan.com 0scan.com 1000gratisproben.com www.1000gratisproben.com 1001namen.com www.1001namen.com 100888290cs.com www.100888290cs.com www.100sexlinks.com 100sexlinks.com 10sek.com www.10sek.com www.1-2005-search.com 1-2005-search.com 123fporn.info www.123fporn.info 123haustiereundmehr.com www.123haustiereundmehr.com 123moviedownload.com There are 1000 more lines. ==================== Scheduled Tasks (whitelisted) ============= Task: {36686732-A32A-4190-8EFB-4904368BB8E5} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-10-22] (Piriform Ltd) Task: {651DBF99-F2E7-45FC-BA71-AE6F96C0B93B} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe Task: {682EEDCE-6BD4-424F-BD2B-1FE4F2E6E144} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-11] (Google Inc.) Task: {7C9B285F-E884-4566-B5AF-4DD3B23C1E04} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation) Task: {81A1039B-E733-4F55-8CBC-E33DC0AC9916} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-11-05] (Adobe Systems Incorporated) Task: {8B39AB58-7907-4DF9-A431-B8C180D7FFB6} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe Task: {93D43514-93E4-4D85-84A5-AF8BEB4F0707} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-11] (Google Inc.) Task: {ABAB7124-18A5-407D-B28E-93AA42767C1D} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\\symerr.exe [2013-08-01] (Symantec Corporation) Task: {CDD0EE2E-4D31-40BC-9B7F-B5F0D92A5F6E} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\\symerr.exe [2013-08-01] (Symantec Corporation) Task: {F75AA70F-4590-4164-BFEB-0702B51C0835} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\\WSCStub.exe [2013-10-08] (Symantec Corporation) Task: {FCC9D927-0EA2-44CB-BD1A-FFEB5A69EA5B} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2010-05-23 18:30 - 2010-05-23 18:30 - 00160768 _____ () C:\Program Files\Rainlendar2\lua51.dll 2011-08-12 06:47 - 2011-08-12 06:47 - 00312832 _____ () C:\Program Files\Rainlendar2\plugins\iCalendarPlugin.dll 2010-05-23 18:30 - 2010-05-23 18:30 - 00013824 _____ () C:\Program Files\Rainlendar2\lfs.dll 2004-09-30 19:15 - 2004-09-30 19:15 - 00192000 _____ () C:\Program Files\LinkShellExtension\RockallDLL.dll 2012-05-10 16:23 - 2012-05-10 16:23 - 01233528 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll 2013-11-05 22:06 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll 2013-11-05 22:06 - 2013-05-16 10:55 - 00113496 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl 2013-11-05 22:06 - 2013-05-16 10:55 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl 2013-11-05 22:06 - 2013-05-16 10:55 - 00161112 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl 2013-11-05 22:06 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll 2011-10-09 06:03 - 2010-12-19 20:16 - 00338944 _____ () C:\Program Files (x86)\MAXA Cookie Manager\sqlite36_engine.dll 2011-10-09 06:03 - 2010-12-19 20:19 - 00023552 _____ () C:\Program Files (x86)\MAXA Cookie Manager\DirectCOM.dll 2013-11-07 01:40 - 2013-07-15 18:29 - 00620718 ____N () C:\Program Files (x86)\BillP Studios\WinPatrol\sqlite3.dll 2011-03-09 13:21 - 2011-03-09 13:21 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll 2011-03-09 13:21 - 2011-03-09 13:21 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll 2013-03-12 17:10 - 2013-10-24 18:45 - 00691200 _____ () N:\! Steam-Arbeitsordner !\SDL2.dll 2011-10-27 13:35 - 2013-10-30 20:25 - 01123240 _____ () N:\! Steam-Arbeitsordner !\bin\chromehtml.DLL 2011-10-27 13:35 - 2013-10-23 21:07 - 20625832 _____ () N:\! Steam-Arbeitsordner !\bin\libcef.dll 2012-03-15 04:04 - 2013-06-15 00:49 - 01100800 _____ () N:\! Steam-Arbeitsordner !\bin\avcodec-53.dll 2012-03-15 04:04 - 2013-06-15 00:49 - 00124416 _____ () N:\! Steam-Arbeitsordner !\bin\avutil-51.dll 2012-03-15 04:04 - 2013-06-15 00:49 - 00192000 _____ () N:\! Steam-Arbeitsordner !\bin\avformat-53.dll 2012-12-12 21:13 - 2013-10-30 20:25 - 00121256 _____ () N:\! Steam-Arbeitsordner !\bin\audio.dll 2011-10-27 13:35 - 2013-06-15 00:49 - 00071680 _____ () N:\! Steam-Arbeitsordner !\bin\mssmp3.asi 2011-10-27 13:35 - 2013-06-15 00:49 - 00153088 _____ () N:\! Steam-Arbeitsordner !\bin\mssvoice.asi 2012-05-10 16:16 - 2012-05-10 16:16 - 00071008 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\Common\rpc_client.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\****** ******\Documents\Der erhaltene Artikel entspricht nicht der Beschreibung_ ****** ****** hat eine Nachricht zu Fleischmann piccolo 8599 Artikelnummer 230842947883 gesendet_.eml:OECustomProperty ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (11/07/2013 11:17:59 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521eaf24 Ausnahmecode: 0xc015000f Fehleroffset: 0x000000000006f7ba ID des fehlerhaften Prozesses: 0xf20 Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Error: (11/07/2013 11:17:52 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4 Name des fehlerhaften Moduls: SHELL32.dll, Version: 6.1.7601.18222, Zeitstempel: 0x51f1ddfa Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000005055a ID des fehlerhaften Prozesses: 0xf20 Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Error: (11/07/2013 11:07:22 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 10.0.9200.16720, Zeitstempel: 0x523cf127 Name des fehlerhaften Moduls: MSHTML.dll, Version: 10.0.9200.16721, Zeitstempel: 0x523f7a70 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0010f2bf ID des fehlerhaften Prozesses: 0x121c Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0 Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1 Pfad des fehlerhaften Moduls: IEXPLORE.EXE2 Berichtskennung: IEXPLORE.EXE3 Error: (11/07/2013 11:06:00 AM) (Source: Microsoft-Windows-WMI) (User: NT-AUTORITÄT) Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden. Error: (11/07/2013 10:44:07 AM) (Source: Microsoft-Windows-WMI) (User: NT-AUTORITÄT) Description: Der Ereignisfilter mit der Abfrage "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" konnte im Namespace "//./root/CIMV2" aufgrund des Fehlers "0x80041003" nicht reaktiviert werden. Solange dieses Problem besteht, können mit diesem Filter keine Ereignisse übermittelt werden. Error: (11/07/2013 00:35:25 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521eaf24 Ausnahmecode: 0xc015000f Fehleroffset: 0x000000000006f7ba ID des fehlerhaften Prozesses: 0xdf4 Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Error: (11/07/2013 00:35:16 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4 Name des fehlerhaften Moduls: SHELL32.dll, Version: 6.1.7601.18222, Zeitstempel: 0x51f1ddfa Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000005055a ID des fehlerhaften Prozesses: 0xdf4 Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Error: (11/07/2013 00:34:19 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521eaf24 Ausnahmecode: 0xc015000f Fehleroffset: 0x000000000006f7ba ID des fehlerhaften Prozesses: 0xa24 Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Error: (11/07/2013 00:34:16 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4 Name des fehlerhaften Moduls: SHELL32.dll, Version: 6.1.7601.18222, Zeitstempel: 0x51f1ddfa Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000005055a ID des fehlerhaften Prozesses: 0xa24 Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Error: (11/07/2013 00:33:57 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521eaf24 Ausnahmecode: 0xc015000f Fehleroffset: 0x000000000006f7ba ID des fehlerhaften Prozesses: 0x790 Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 System errors: ============= Error: (11/07/2013 02:38:08 AM) (Source: volsnap) (User: ) Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte. Error: (11/07/2013 00:33:15 AM) (Source: NetBT) (User: ) Description: Der Name "************-PC :20" konnte nicht auf der Schnittstelle mit IP-Adresse registriert werden. Der Computer mit IP-Adresse hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (11/07/2013 00:33:15 AM) (Source: Server) (User: ) Description: Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{6326D19A-C8CD-4791-847B-F4AD6E293BB9} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden. Error: (11/07/2013 00:32:49 AM) (Source: NetBT) (User: ) Description: Der Name "************-PC :0" konnte nicht auf der Schnittstelle mit IP-Adresse registriert werden. Der Computer mit IP-Adresse hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (11/07/2013 00:05:14 AM) (Source: NetBT) (User: ) Description: Der Name "************-PC :0" konnte nicht auf der Schnittstelle mit IP-Adresse registriert werden. Der Computer mit IP-Adresse hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (11/06/2013 11:35:09 PM) (Source: NetBT) (User: ) Description: Der Name "************-PC :20" konnte nicht auf der Schnittstelle mit IP-Adresse registriert werden. Der Computer mit IP-Adresse hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (11/06/2013 11:35:09 PM) (Source: Server) (User: ) Description: Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{6326D19A-C8CD-4791-847B-F4AD6E293BB9} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden. Error: (11/06/2013 11:34:57 PM) (Source: NetBT) (User: ) Description: Der Name "************-PC :0" konnte nicht auf der Schnittstelle mit IP-Adresse registriert werden. Der Computer mit IP-Adresse hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (11/06/2013 11:32:00 PM) (Source: NetBT) (User: ) Description: Der Name "************-PC :20" konnte nicht auf der Schnittstelle mit IP-Adresse registriert werden. Der Computer mit IP-Adresse hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (11/06/2013 11:32:00 PM) (Source: Server) (User: ) Description: Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{6326D19A-C8CD-4791-847B-F4AD6E293BB9} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden. Microsoft Office Sessions: ========================= Error: (11/07/2013 11:17:59 AM) (Source: Application Error)(User: ) Description: Explorer.EXE6.1.7601.175674d672ee4ntdll.dll6.1.7601.18247521eaf24c015000f000000000006f7baf2001cedba0e9cdb972C:\Windows\Explorer.EXEC:\Windows\SYSTEM32\ntdll.dlldfeaf7ff-4795-11e3-81fc-8c89a55a2bc5 Error: (11/07/2013 11:17:52 AM) (Source: Application Error)(User: ) Description: Explorer.EXE6.1.7601.175674d672ee4SHELL32.dll6.1.7601.1822251f1ddfac0000005000000000005055af2001cedba0e9cdb972C:\Windows\Explorer.EXEC:\Windows\system32\SHELL32.dlldbafe5e2-4795-11e3-81fc-8c89a55a2bc5 Error: (11/07/2013 11:07:22 AM) (Source: Application Error)(User: ) Description: IEXPLORE.EXE10.0.9200.16720523cf127MSHTML.dll10.0.9200.16721523f7a70c00000050010f2bf121c01cedba110d6be5bC:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\system32\MSHTML.dll64517998-4794-11e3-81fc-8c89a55a2bc5 Error: (11/07/2013 11:06:00 AM) (Source: Microsoft-Windows-WMI)(User: NT-AUTORITÄT) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/07/2013 10:44:07 AM) (Source: Microsoft-Windows-WMI)(User: NT-AUTORITÄT) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/07/2013 00:35:25 AM) (Source: Application Error)(User: ) Description: Explorer.EXE6.1.7601.175674d672ee4ntdll.dll6.1.7601.18247521eaf24c015000f000000000006f7badf401cedb48bf9dea76C:\Windows\Explorer.EXEC:\Windows\SYSTEM32\ntdll.dll1c08586a-473c-11e3-b10d-8c89a55a2bc5 Error: (11/07/2013 00:35:16 AM) (Source: Application Error)(User: ) Description: Explorer.EXE6.1.7601.175674d672ee4SHELL32.dll6.1.7601.1822251f1ddfac0000005000000000005055adf401cedb48bf9dea76C:\Windows\Explorer.EXEC:\Windows\system32\SHELL32.dll16efe654-473c-11e3-b10d-8c89a55a2bc5 Error: (11/07/2013 00:34:19 AM) (Source: Application Error)(User: ) Description: Explorer.EXE6.1.7601.175674d672ee4ntdll.dll6.1.7601.18247521eaf24c015000f000000000006f7baa2401cedb48ac543957C:\Windows\Explorer.EXEC:\Windows\SYSTEM32\ntdll.dllf4751a12-473b-11e3-b10d-8c89a55a2bc5 Error: (11/07/2013 00:34:16 AM) (Source: Application Error)(User: ) Description: Explorer.EXE6.1.7601.175674d672ee4SHELL32.dll6.1.7601.1822251f1ddfac0000005000000000005055aa2401cedb48ac543957C:\Windows\Explorer.EXEC:\Windows\system32\SHELL32.dllf2cd6522-473b-11e3-b10d-8c89a55a2bc5 Error: (11/07/2013 00:33:57 AM) (Source: Application Error)(User: ) Description: Explorer.EXE6.1.7601.175674d672ee4ntdll.dll6.1.7601.18247521eaf24c015000f000000000006f7ba79001cedb4882b8692fC:\Windows\Explorer.EXEC:\Windows\SYSTEM32\ntdll.dlle74c13c8-473b-11e3-b10d-8c89a55a2bc5 ==================== Memory info =========================== Percentage of memory in use: 53% Total physical RAM: 12267.6 MB Available physical RAM: 5759.83 MB Total Pagefile: 24533.38 MB Available Pagefile: 19853.43 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: (Win 7) (Fixed) (Total:209.86 GB) (Free:113.03 GB) NTFS Drive d: (Eisenbahn) (Fixed) (Total:93.75 GB) (Free:74.22 GB) NTFS Drive e: (Data) (Fixed) (Total:224.61 GB) (Free:144.41 GB) NTFS Drive f: (Big Data) (Fixed) (Total:372.46 GB) (Free:222.57 GB) NTFS Drive g: (klein bei c) (Fixed) (Total:4.88 GB) (Free:4.8 GB) NTFS Drive h: (Traini+Data) (Fixed) (Total:698.64 GB) (Free:173.94 GB) NTFS Drive i: (Mini 1) (Fixed) (Total:3.91 GB) (Free:3.79 GB) NTFS Drive j: (Cache+temp) (Fixed) (Total:107.42 GB) (Free:95.3 GB) NTFS Drive k: (Mini 2) (Fixed) (Total:3.91 GB) (Free:3.81 GB) NTFS Drive l: (L Backups) (Fixed) (Total:716.67 GB) (Free:509.35 GB) NTFS Drive m: (100g) (Fixed) (Total:107.42 GB) (Free:107.12 GB) NTFS Drive n: (Emulatoren + Steam) (Fixed) (Total:1648.17 GB) (Free:690.81 GB) NTFS Drive o: (Big Data 2) (Fixed) (Total:698.64 GB) (Free:258.92 GB) NTFS Drive p: (BiigFäädData) (Fixed) (Total:931.51 GB) (Free:375.31 GB) NTFS Drive r: (INTENSO 16G) (Removable) (Total:14.83 GB) (Free:14.63 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 4E6B547D) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=210 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=5 GB) - (Type=OF Extended) Partition 4: (Not Active) - (Size=717 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows XP) (Size: 932 GB) (Disk ID: 0E6DB056) Partition 1: (Active) - (Size=932 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 53F586F0) Partition 1: (Not Active) - (Size=107 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=107 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=-429314277376) - (Type=07 NTFS) ======================================================== Disk: 3 (Size: 699 GB) (Disk ID: 09376CBC) Partition 1: (Not Active) - (Size=4 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=94 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=225 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=376 GB) - (Type=OF Extended) ======================================================== Disk: 4 (MBR Code: Windows XP) (Size: 699 GB) (Disk ID: E9DE3773) Partition 1: (Not Active) - (Size=699 GB) - (Type=07 NTFS) ======================================================== Disk: 5 (MBR Code: Windows XP) (Size: 699 GB) (Disk ID: 7B8D17E8) Partition 1: (Not Active) - (Size=699 GB) - (Type=07 NTFS) ======================================================== Disk: 6 (MBR Code: Windows XP) (Size: 15 GB) (Disk ID: BEF1B6FF) Partition 1: (Active) - (Size=15 GB) - (Type=0C) ==================== End Of Log ============================ |
![]() | #29 |
![]() | ![]() Win7 IP tunnelt mich jede Nacht und kapert Teledat 530 Router Der " zweite " FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 31-10-2013 Ran by ****** ***** (administrator) on ***********-PC on 07-11-2013 21:49:48 Running from C:\Users\****** *****\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\\NIS.exe () C:\Users\******~1\AppData\Local\Temp\7zO6D34.tmp\Core Temp.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe () C:\Program Files\Rainlendar2\Rainlendar2.exe (MAXA Research Int'l Inc.) C:\Program Files (x86)\MAXA Cookie Manager\Cookie.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (BillP Studios) C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (EIZO NANAO CORPORATION) C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD\Lcdctrl.exe (Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winampa.exe () C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (cyberlink) C:\Program Files (x86)\CyberLink\Shared files\brs.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\PSIA.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\\NIS.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe (T-Systems Enterprise Services GmbH) C:\Program Files (x86)\DSL-Manager\DslMgrSvc.exe (AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe (AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\SeaPort.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Acronis Scheduler2 Service] - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [395928 2012-05-10] (Acronis) HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13192848 2012-08-30] (Realtek Semiconductor) HKCU\...\Run: [Rainlendar2] - C:\Program Files\Rainlendar2\Rainlendar2.exe [3820032 2011-08-12] () HKCU\...\Run: [Google Update] - C:\Users\****** *****\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-06-16] (Google Inc.) HKCU\...\Run: [MSCS] - C:\Program Files (x86)\MAXA Cookie Manager\Cookie.exe [1138688 2012-05-20] (MAXA Research Int'l Inc.) HKCU\...\Run: [WinPatrol] - C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe [441408 2013-09-24] (BillP Studios) HKCU\...\Run: [HydraVisionDesktopManager] - C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [393216 2012-11-16] (AMD) HKCU\...\Policies\Explorer: [NoRecentDocsNetHood] 1 HKLM-x32\...\Run: [ScreenManager Pro for LCD] - C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD\Lcdctrl.exe [9365032 2007-01-16] (EIZO NANAO CORPORATION) HKLM-x32\...\Run: [WinampAgent] - C:\Program Files (x86)\Winamp\winampa.exe [84576 2013-07-23] (Nullsoft, Inc.) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [641704 2012-11-16] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [AMD AVT] - C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [20992 2012-03-19] () HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) HKLM-x32\...\Run: [TrueImageMonitor.exe] - C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [2673640 2012-05-10] () HKLM-x32\...\Run: [EaseUS EPM tray] - C:\Program Files (x86)\EaseUS\EaseUS Partition Master 9.2.2\bin\EpmNews.exe HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.) HKLM-x32\...\Run: [BDRegion] - C:\Program Files (x86)\CyberLink\Shared files\brs.exe [78312 2012-05-09] (cyberlink) HKLM-x32\...\Run: [UpdatePPShortCut] - C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe [223096 2012-04-17] (CyberLink Corp.) HKLM-x32\...\Run: [CLMLServer] - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2011-03-09] (CyberLink) HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.) HKLM-x32\...\Run: [TkBellExe] - C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe [295512 2013-10-14] (RealNetworks, Inc.) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe [49208 2011-10-28] (Hewlett-Packard) HKLM-x32\...\Run: [] - [x] Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files (x86)\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files (x86)\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) Startup: C:\Users\****** *****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> (No File) BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.t-online.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xF522DFC3846ACE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=514347bc-b91d-4a28-b463-2e529db901ce&searchtype=ds&q={searchTerms}&installDate=17/06/2013 SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=514347bc-b91d-4a28-b463-2e529db901ce&searchtype=ds&q={searchTerms}&installDate=17/06/2013 SearchScopes: HKCU - {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://nortonsafe.search.ask.com/web?q={SEARCHTERMS}&o=APN10506&l=dis&prt=NIS&chn=retail&geo=DE&ver=20&locale=de_DE&gct=kwd&qsrc=2869 BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine64\\coieplg.dll (Symantec Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: DVDVideoSoft WebPageAdjuster Class - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.) BHO-x32: No Name - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader) BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\\coieplg.dll (Symantec Corporation) BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\\ips\ipsbho.dll (Symantec Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Free Download Manager - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll (FreeDownloadManager.ORG) BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll (Microsoft Corporation.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: DVDVideoSoft WebPageAdjuster Class - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.) Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\\coieplg.dll (Symantec Corporation) Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\\coieplg.dll (Symantec Corporation) Toolbar: HKCU - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\\coieplg.dll (Symantec Corporation) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\****** *****\AppData\Roaming\Mozilla\Firefox\Profiles\si9amjky.default FF NewTab: hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=514347bc-b91d-4a28-b463-2e529db901ce&searchtype=nt&installDate=17/06/2013&q= FF Homepage: hxxp://www.t-online.de/ FF Keyword.URL: hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=514347bc-b91d-4a28-b463-2e529db901ce&searchtype=ds&installDate=17/06/2013&q= FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.0 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @nullsoft.com/winampDetector;version=1 - C:\Program Files (x86)\Winamp Detect\npwachk.dll (Nullsoft, Inc.) FF Plugin-x32: @real.com/nppl3260;version= - c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprpplugin;version= - c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer) FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\****** *****\AppData\Local\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\****** *****\AppData\Local\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: DownloadHelper - C:\Users\****** *****\AppData\Roaming\Mozilla\Firefox\Profiles\si9amjky.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} FF Extension: fdm_ffext - C:\Users\****** *****\AppData\Roaming\Mozilla\Firefox\Profiles\si9amjky.default\Extensions\fdm_ffext@freedownloadmanager.org FF Extension: bprivacyprefs - C:\Users\****** *****\AppData\Roaming\Mozilla\Firefox\Profiles\si9amjky.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.0.2.1\coFFPlgn\ FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.0.2.1\coFFPlgn\ FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF HKLM-x32\...\Firefox\Extensions: [{ACAA314B-EEBA-48e4-AD47-84E31C44796C}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ FF HKLM-x32\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.0.2.1\IPSFF FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.0.2.1\IPSFF FF HKCU\...\Firefox\Extensions: [maxacookie@maxatools.com] - C:\Program Files (x86)\MAXA Cookie Manager\extension FF Extension: MAXA Cookie Manager - C:\Program Files (x86)\MAXA Cookie Manager\extension Chrome: ======= CHR HomePage: hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=514347bc-b91d-4a28-b463-2e529db901ce&searchtype=hp&installDate=17/06/2013 CHR RestoreOnStartup: "hxxp://www.t-online.de/" CHR Plugin: (Shockwave Flash) - C:\Users\****** *****\AppData\Local\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\****** *****\AppData\Local\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\****** *****\AppData\Local\Google\Chrome\Application\30.0.1599.101\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll No File CHR Plugin: (Free Download Manager Click Catcher Plug-In for Netscape, Opera, Mozilla) - C:\Users\****** *****\AppData\Local\Google\Chrome\Application\plugins\npfdm.dll (FreeDownloadManager.org) CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) CHR Plugin: (RealPlayer Download Plugin) - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer) CHR Plugin: (RealNetworks(tm) RealDownloader Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.) CHR Plugin: (RealNetworks(tm) RealDownloader HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.) CHR Plugin: (RealNetworks(tm) RealDownloader PepperFlashVideoShim Plug-In (32-bit) ) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.) CHR Plugin: (RealDownloader Plugin) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader) CHR Plugin: (Google Update) - C:\Users\****** *****\AppData\Local\Google\Update\\npGoogleUpdate3.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll No File CHR Plugin: (Java Deployment Toolkit - C:\Windows\SysWOW64\npDeployJava1.dll No File CHR Extension: (Snap.Do ) - C:\Users\******~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0 CHR Extension: (Google Docs) - C:\Users\******~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (RealDownloader) - C:\Users\******~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.3_0 CHR Extension: (Norton Identity Protection) - C:\Users\******~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2014.5.1.4_0 CHR Extension: (DVDVideoSoft) - C:\Users\******~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\ CHR Extension: (Chrome In-App Payments service) - C:\Users\******~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\ CHR HKLM-x32\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\\Exts\Chrome.crx ==================== Services (Whitelisted) ================= R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-11-16] (Advanced Micro Devices, Inc.) S2 CLKMSVC10_38F51D56; C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [242664 2012-05-09] (CyberLink) S3 IEEtwCollectorService; C:\Windows\system32\IEEtwCollector.exe [111616 2013-11-07] (Microsoft Corporation) R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\\NIS.exe [275696 2013-10-08] (Symantec Corporation) R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] () S3 SandraAgentSrv; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2013.SP4\RpcAgentSrv.exe [71832 2009-06-15] (SiSoftware) R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1817560 2013-05-16] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1033688 2013-05-16] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2013-05-15] (Safer-Networking Ltd.) R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia) S2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [660184 2013-07-03] (Secunia) R3 TDslMgrService; C:\Program Files (x86)\DSL-Manager\DslMgrSvc.exe [294912 2007-11-26] (T-Systems Enterprise Services GmbH) ==================== Drivers (Whitelisted) ==================== R1 BHDrvx64; C:\Program Files (x86)\Norton Internet Security\NortonData\\Definitions\BASHDefs\20131101.003\BHDrvx64.sys [1524824 2013-10-23] (Symantec Corporation) R1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1501000.012\ccSetx64.sys [162392 2013-09-26] (Symantec Corporation) R1 DslMNLwf; C:\Windows\System32\DRIVERS\dslmnlwf.sys [19008 2007-08-01] (T-Systems Enterprise Services GmbH) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-10-12] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [140376 2013-10-12] (Symantec Corporation) R1 IDSVia64; C:\Program Files (x86)\Norton Internet Security\NortonData\\Definitions\IPSDefs\20131106.001\IDSvia64.sys [521816 2013-10-28] (Symantec Corporation) R3 NAVENG; C:\Program Files (x86)\Norton Internet Security\NortonData\\Definitions\VirusDefs\20131107.003\ENG64.SYS [126040 2013-10-12] (Symantec Corporation) R3 NAVEX15; C:\Program Files (x86)\Norton Internet Security\NortonData\\Definitions\VirusDefs\20131107.003\EX64.SYS [2099288 2013-10-12] (Symantec Corporation) R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-07-03] (Secunia) S3 SANDRA; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2013.SP4\WNt500x64\Sandra.sys [23112 2009-08-07] (SiSoftware) R3 SRTSP; C:\Windows\System32\Drivers\NISx64\1501000.012\SRTSP64.SYS [858200 2013-09-27] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1501000.012\SRTSPX64.SYS [36952 2013-07-31] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\NISx64\1501000.012\SYMDS64.SYS [493656 2013-08-01] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\NISx64\1501000.012\SYMEFA64.SYS [1147480 2013-09-27] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2013-10-13] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\NISx64\1501000.012\Ironx64.SYS [264280 2013-07-31] (Symantec Corporation) R1 SymNetS; C:\Windows\System32\Drivers\NISx64\1501000.012\SYMNETS.SYS [590936 2013-09-26] (Symantec Corporation) R0 vidsflt53; C:\Windows\System32\DRIVERS\vsflt53.sys [141920 2013-06-20] (Acronis) R3 ALSysIO; \??\C:\Users\******~1\AppData\Local\Temp\ALSysIO64.sys [x] S3 MSICDSetup; \??\H:\CDriver64.sys [x] S3 S12345; \??\H:\s1234564.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-07 21:49 - 2013-11-07 10:41 - 01957098 _____ (Farbar) C:\Users\****** *****\Desktop\FRST64.exe 2013-11-07 20:48 - 2013-11-07 21:20 - 00003388 _____ C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-4189605395-1850867417-3092745277-1000 2013-11-07 20:48 - 2013-11-07 21:20 - 00003268 _____ C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-4189605395-1850867417-3092745277-1000 2013-11-07 20:44 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2013-11-07 20:30 - 2013-11-07 20:30 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-07 20:30 - 2013-11-07 20:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-07 20:30 - 2013-11-07 20:30 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-11-07 20:30 - 2013-11-07 20:30 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-11-07 20:30 - 2013-11-07 20:30 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-11-07 20:30 - 2013-11-07 20:30 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-11-07 20:30 - 2013-11-07 20:30 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-11-07 20:30 - 2013-11-07 20:30 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-11-07 20:30 - 2013-11-07 20:30 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-11-07 20:30 - 2013-11-07 20:30 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-11-07 20:30 - 2013-11-07 20:30 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-11-07 20:28 - 2013-11-07 20:44 - 00009206 _____ C:\Windows\IE11_main.log 2013-11-07 11:12 - 2013-11-07 11:12 - 00001130 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-11-07 11:12 - 2013-11-07 11:12 - 00000000 ____D C:\Users\****** *****\AppData\Roaming\Malwarebytes 2013-11-07 11:12 - 2013-11-07 11:12 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-11-07 11:12 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-11-04 10:59 - 2013-11-04 10:59 - 00004608 _____ C:\Users\****** *****\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-11-02 03:20 - 2013-11-02 03:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-01 03:00 - 2013-11-01 03:00 - 00003408 _____ C:\Windows\System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-4189605395-1850867417-3092745277-1000 2013-10-28 17:03 - 2013-10-28 17:03 - 00000000 ____D C:\Users\****** *****\Desktop\SysInfo.{ED7BA470-8E54-465E-825C-99712043E01C} 2013-10-27 20:55 - 2013-10-27 20:55 - 02474341 _____ C:\Users\****** *****\Documents\cheyenne 150x55.epp 2013-10-27 19:38 - 2013-10-27 19:38 - 00002665 _____ C:\Users\Public\Desktop\Easy Poster Printer.lnk 2013-10-27 19:38 - 2013-10-27 19:38 - 00000000 ____D C:\Program Files (x86)\GD Software 2013-10-27 19:32 - 2013-10-27 19:32 - 00000000 ___HD C:\ProgramData\CanonBJ 2013-10-27 19:31 - 2013-10-27 19:31 - 00000000 ____D C:\Program Files\Common Files\Canon 2013-10-27 19:26 - 2013-10-27 19:31 - 00000000 ____D C:\Program Files (x86)\Canon 2013-10-27 19:26 - 2013-10-27 19:26 - 00002305 _____ C:\Users\Public\Desktop\iP5200 Handbuchausgabe für den Bildschirm.lnk 2013-10-27 14:05 - 2013-10-27 13:57 - 00452879 _____ C:\Windows\system32\Drivers\etc\hosts.20131027-140515.backup 2013-10-26 22:50 - 2013-10-26 22:50 - 00000000 ____D C:\ProgramData\HPSSUPPLY 2013-10-20 15:13 - 2013-10-20 15:13 - 00000000 ____D C:\Users\****** *****\dwhelper 2013-10-20 12:24 - 2013-11-07 02:40 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2013-10-20 12:24 - 2013-10-20 12:24 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-20 12:21 - 2013-11-07 01:57 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2013-10-17 22:17 - 2013-10-17 22:17 - 00000000 ____D C:\Windows\System32\Tasks\Norton Internet Security 2013-10-17 04:10 - 2013-10-17 04:10 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-10-17 04:10 - 2013-10-17 04:10 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-10-17 04:10 - 2013-10-17 04:10 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-10-17 04:10 - 2013-10-17 04:10 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-10-17 04:10 - 2013-10-17 04:10 - 00000000 ____D C:\Program Files\Java 2013-10-17 04:00 - 2013-10-17 04:10 - 00000000 ____D C:\ProgramData\Oracle 2013-10-17 04:00 - 2013-10-17 04:00 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-10-17 04:00 - 2013-10-17 04:00 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-10-17 04:00 - 2013-10-17 04:00 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-10-17 04:00 - 2013-10-17 04:00 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-10-17 04:00 - 2013-10-17 04:00 - 00000000 ____D C:\Program Files (x86)\Java 2013-10-17 03:23 - 2013-10-17 03:23 - 00000038 _____ C:\Users\****** *****\AppData\Local\census.cache 2013-10-17 03:23 - 2013-10-17 03:23 - 00000000 _____ C:\Users\****** *****\AppData\Local\ars.cache 2013-10-16 16:13 - 2013-10-16 16:13 - 00000036 _____ C:\Users\****** *****\AppData\Local\housecall.guid.cache 2013-10-16 02:35 - 2013-10-16 02:35 - 00000000 ____D C:\FRST 2013-10-16 02:35 - 2013-10-16 02:35 - 00000000 _____ C:\Users\****** *****\defogger_reenable 2013-10-15 21:07 - 2013-10-15 21:14 - 00259396 _____ C:\Windows\msxml4-KB2758694-enu.LOG 2013-10-15 09:54 - 2013-10-15 09:55 - 02434048 _____ C:\Users\****** *****\Downloads\msxml.msi 2013-10-15 00:32 - 2013-11-05 01:35 - 00000000 ____D C:\Users\****** *****\AppData\Roaming\HpUpdate 2013-10-15 00:32 - 2013-10-15 00:32 - 00000000 ____D C:\Windows\Hewlett-Packard 2013-10-15 00:29 - 2013-10-15 09:56 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0 2013-10-15 00:29 - 2013-10-15 00:29 - 00286566 _____ C:\Windows\msxml4-KB954430-enu.LOG 2013-10-14 22:46 - 2013-10-14 22:46 - 00000000 ____D C:\ProgramData\WEBREG 2013-10-14 22:45 - 2013-10-18 22:09 - 00000000 ____D C:\Users\****** *****\AppData\Roaming\HP 2013-10-14 21:17 - 2013-10-14 21:17 - 00003148 _____ C:\Windows\System32\Tasks\SidebarExecute 2013-10-14 21:17 - 2013-10-14 21:17 - 00000000 ____D C:\Users\****** *****\AppData\Local\HP 2013-10-14 21:16 - 2013-10-15 00:10 - 00000000 ____D C:\Program Files (x86)\Yahoo! 2013-10-14 21:16 - 2013-10-14 21:16 - 00000000 ____D C:\Users\****** *****\AppData\Roaming\Yahoo! 2013-10-14 21:15 - 2013-10-14 21:15 - 00000000 ____D C:\ProgramData\HP Product Assistant 2013-10-14 21:14 - 2013-10-14 21:14 - 00000000 ____D C:\Windows\SysWOW64\spool 2013-10-14 21:12 - 2013-10-15 00:33 - 00000000 ____D C:\Program Files (x86)\HP 2013-10-14 21:11 - 2013-10-14 23:32 - 00003874 _____ C:\ProgramData\hpzinstall.log 2013-10-14 21:11 - 2013-10-14 22:45 - 00245587 _____ C:\Windows\hpoins19.dat 2013-10-14 21:11 - 2013-10-14 22:45 - 00000000 ____D C:\ProgramData\HP 2013-10-14 21:11 - 2009-10-20 05:30 - 00013898 ____N C:\Windows\hpomdl19.dat 2013-10-14 21:11 - 2009-07-08 11:51 - 00861184 _____ (Hewlett-Packard) C:\Windows\system32\hpowiav1.dll 2013-10-14 21:11 - 2009-07-08 11:51 - 00730624 _____ (Hewlett-Packard Co.) C:\Windows\system32\hpotscl1.dll 2013-10-14 21:11 - 2009-07-08 11:51 - 00642360 _____ (Hewlett-Packard) C:\Windows\system32\hpzids40.dll 2013-10-14 21:11 - 2009-07-08 11:51 - 00498176 _____ (Hewlett-Packard Co.) C:\Windows\system32\hpovst01.dll 2013-10-14 15:10 - 2013-10-14 15:10 - 00000000 ____D C:\Users\****** *****\AppData\Roaming\RealNetworks 2013-10-14 15:09 - 2013-10-14 15:09 - 00000000 ____D C:\ProgramData\RealNetworks 2013-10-14 15:09 - 2013-10-14 15:09 - 00000000 ____D C:\Program Files (x86)\RealNetworks 2013-10-14 15:05 - 2013-10-14 15:05 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4 2013-10-14 15:04 - 2013-10-14 15:04 - 00000000 ____D C:\Users\****** *****\Documents\DVDVideoSoft 2013-10-14 15:01 - 2013-10-14 15:01 - 00000000 ____D C:\Users\****** *****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Winamp Erkennungs-Plug-in 2013-10-14 14:25 - 2013-09-04 13:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2013-10-14 14:25 - 2013-09-04 13:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2013-10-14 14:25 - 2013-09-04 13:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2013-10-14 14:25 - 2013-09-04 13:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2013-10-14 14:25 - 2013-09-04 13:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2013-10-14 14:25 - 2013-09-04 13:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2013-10-14 14:25 - 2013-09-04 13:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2013-10-14 14:25 - 2013-07-09 06:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-10-14 14:25 - 2013-07-09 06:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-10-14 14:25 - 2013-07-09 06:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-10-14 14:25 - 2013-07-09 06:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-10-14 14:25 - 2013-07-09 05:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-10-14 14:25 - 2013-07-09 05:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-10-14 14:25 - 2013-07-09 05:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-10-14 14:25 - 2013-07-09 05:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-10-14 14:24 - 2013-07-19 02:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-10-14 14:24 - 2013-07-19 02:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-10-14 14:24 - 2013-07-04 13:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2013-10-14 14:24 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2013-10-14 14:22 - 2013-08-05 03:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys 2013-10-14 14:21 - 2013-07-25 10:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-10-14 14:21 - 2013-07-25 09:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-10-14 14:21 - 2013-07-12 11:41 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys 2013-10-14 14:21 - 2013-07-12 11:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2013-10-14 14:21 - 2013-07-12 11:40 - 00109824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBAUDIO.sys 2013-10-14 14:21 - 2013-07-09 06:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-10-14 14:21 - 2013-07-09 05:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-10-14 14:21 - 2013-07-03 05:40 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys 2013-10-14 14:21 - 2013-07-03 05:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2013-10-14 14:21 - 2013-07-03 05:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2013-10-14 14:21 - 2013-06-25 23:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2013-10-14 14:21 - 2013-06-06 06:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2013-10-14 14:21 - 2013-06-06 06:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2013-10-14 14:21 - 2013-06-06 06:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2013-10-14 14:21 - 2013-06-06 06:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-10-14 14:21 - 2013-06-06 05:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2013-10-14 14:21 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2013-10-14 14:21 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2013-10-14 14:21 - 2013-06-06 04:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-10-14 14:21 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2013-10-14 14:21 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2013-10-14 14:14 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2013-10-14 14:14 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2013-10-14 14:14 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2013-10-14 14:14 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2013-10-14 14:14 - 2013-07-04 11:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2013-10-14 14:14 - 2013-06-04 07:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-10-14 14:14 - 2013-06-04 05:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2013-10-14 14:12 - 2013-09-14 02:10 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-10-14 14:12 - 2013-09-08 03:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-10-14 14:12 - 2013-09-08 03:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-10-14 14:12 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2013-10-14 14:12 - 2013-08-28 02:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-10-14 14:12 - 2013-06-15 05:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-10-14 12:58 - 2013-10-14 13:00 - 00000000 ____D C:\Windows\system32\MRT 2013-10-14 11:43 - 2013-07-26 03:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2013-10-14 11:43 - 2013-07-26 02:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2013-10-14 11:42 - 2013-07-26 03:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll 2013-10-14 11:42 - 2013-07-26 02:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll 2013-10-14 11:41 - 2013-04-10 00:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-10-14 11:41 - 2013-04-02 23:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-10-14 11:30 - 2013-08-29 03:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-10-14 11:30 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-10-14 11:30 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2013-10-14 11:30 - 2013-08-29 03:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-10-14 11:30 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-10-14 11:30 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-10-14 11:30 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-10-14 11:30 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-10-14 11:30 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2013-10-14 11:30 - 2013-08-29 02:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-10-14 11:30 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2013-10-14 11:30 - 2013-08-29 01:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-10-14 11:30 - 2013-08-29 01:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-10-14 11:30 - 2013-08-29 01:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-10-14 11:30 - 2013-08-29 01:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-10-14 11:30 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2013-10-14 11:30 - 2013-08-02 03:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2013-10-14 11:30 - 2013-08-02 03:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2013-10-14 11:30 - 2013-08-02 03:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2013-10-14 11:30 - 2013-08-02 03:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2013-10-14 11:30 - 2013-08-02 03:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2013-10-14 11:30 - 2013-08-02 03:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 03:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 03:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 03:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 03:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 03:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 02:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2013-10-14 11:30 - 2013-08-02 02:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2013-10-14 11:30 - 2013-08-02 02:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2013-10-14 11:30 - 2013-08-02 02:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 02:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 02:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 02:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 02:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 02:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2013-10-14 11:30 - 2013-08-02 01:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2013-10-14 11:30 - 2013-08-02 01:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 01:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 01:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2013-10-14 11:30 - 2013-08-02 01:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2013-10-14 11:29 - 2013-08-01 13:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-10-14 11:29 - 2013-07-20 11:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-10-14 11:29 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2013-10-14 06:59 - 2013-10-14 06:59 - 00000000 ____D C:\Windows\Microsoft Antimalware 2013-10-14 02:56 - 2013-10-14 02:55 - 00450619 ____R C:\Windows\system32\Drivers\etc\hosts.20131014-035617.backup 2013-10-14 02:55 - 2013-10-14 12:26 - 00000822 _____ C:\Windows\system32\Drivers\etc\hosts.20131014-035517.backup 2013-10-14 02:40 - 2013-10-14 11:15 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-10-14 02:40 - 2013-10-14 02:48 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2 2013-10-14 02:40 - 2013-10-14 02:40 - 17813896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2013-10-14 02:40 - 2013-10-14 02:40 - 00001400 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk 2013-10-14 02:40 - 2013-10-14 02:40 - 00000000 ____D C:\Users\****** *****\AppData\Local\Secunia PSI 2013-10-14 02:40 - 2009-01-25 12:14 - 00017272 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe 2013-10-14 02:39 - 2013-10-14 02:39 - 00000000 ____D C:\Program Files (x86)\Secunia 2013-10-13 17:52 - 2013-10-13 17:52 - 00000000 ____D C:\Users\****** *****\AppData\Roaming\DVDVideoSoftIEHelpers 2013-10-13 17:50 - 2013-10-13 17:52 - 00000000 ____D C:\Users\****** *****\AppData\Roaming\DVDVideoSoft 2013-10-13 17:50 - 2013-10-13 17:52 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft 2013-10-13 17:50 - 2013-10-13 17:51 - 00000000 ___RD C:\Users\Public\Desktop\DVDVideoSoft 2013-10-13 16:56 - 2013-10-13 16:56 - 00000000 ____D C:\Program Files (x86)\MPC-HC 2013-10-13 16:54 - 2013-10-13 18:03 - 00000000 ____D C:\Users\****** *****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton ==================== One Month Modified Files and Folders ======= 2013-11-07 21:36 - 2013-06-17 02:04 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-11-07 21:27 - 2013-06-16 23:17 - 00001148 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4189605395-1850867417-3092745277-1000UA.job 2013-11-07 21:27 - 2009-07-14 18:58 - 00653928 _____ C:\Windows\system32\perfh007.dat 2013-11-07 21:27 - 2009-07-14 18:58 - 00129800 _____ C:\Windows\system32\perfc007.dat 2013-11-07 21:27 - 2009-07-14 06:13 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-07 21:27 - 2009-07-14 05:45 - 00015600 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-07 21:27 - 2009-07-14 05:45 - 00015600 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-07 21:24 - 2013-06-22 20:47 - 00001122 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-11-07 21:23 - 2013-06-16 11:39 - 01908996 _____ C:\Windows\WindowsUpdate.log 2013-11-07 21:20 - 2013-11-07 20:48 - 00003388 _____ C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-4189605395-1850867417-3092745277-1000 2013-11-07 21:20 - 2013-11-07 20:48 - 00003268 _____ C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-4189605395-1850867417-3092745277-1000 2013-11-07 21:20 - 2013-06-16 20:43 - 00000000 ____D C:\Users\****** *****\.rainlendar2 2013-11-07 21:19 - 2013-06-22 20:47 - 00001118 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-11-07 21:19 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-07 21:19 - 2009-07-14 05:51 - 00034203 _____ C:\Windows\setupact.log 2013-11-07 20:51 - 2013-06-17 02:12 - 00003982 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{0D79F6DA-AEA2-46A2-A301-EB255122D466} 2013-11-07 20:47 - 2013-06-17 18:07 - 00001442 _____ C:\Users\****** *****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-11-07 20:44 - 2013-11-07 20:28 - 00009206 _____ C:\Windows\IE11_main.log 2013-11-07 20:44 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-11-07 20:38 - 2013-06-17 11:48 - 00000000 ____D C:\Program Files (x86)\MAXA Cookie Manager 2013-11-07 20:30 - 2013-11-07 20:30 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-07 20:30 - 2013-11-07 20:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-07 20:30 - 2013-11-07 20:30 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-11-07 20:30 - 2013-11-07 20:30 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-11-07 20:30 - 2013-11-07 20:30 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-11-07 20:30 - 2013-11-07 20:30 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-11-07 20:30 - 2013-11-07 20:30 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-11-07 20:30 - 2013-11-07 20:30 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-11-07 20:30 - 2013-11-07 20:30 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-11-07 20:30 - 2013-11-07 20:30 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-11-07 20:30 - 2013-11-07 20:30 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-11-07 20:30 - 2013-11-07 20:30 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-11-07 20:30 - 2013-11-07 20:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-11-07 20:04 - 2013-06-17 02:19 - 00003366 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-4189605395-1850867417-3092745277-1000 2013-11-07 20:04 - 2013-06-17 02:19 - 00003246 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-4189605395-1850867417-3092745277-1000 2013-11-07 20:04 - 2013-06-16 15:53 - 00060050 _____ C:\Windows\PFRO.log 2013-11-07 11:12 - 2013-11-07 11:12 - 00001130 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-11-07 11:12 - 2013-11-07 11:12 - 00000000 ____D C:\Users\****** *****\AppData\Roaming\Malwarebytes 2013-11-07 11:12 - 2013-11-07 11:12 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-11-07 10:41 - 2013-11-07 21:49 - 01957098 _____ (Farbar) C:\Users\****** *****\Desktop\FRST64.exe 2013-11-07 03:36 - 2013-06-17 12:59 - 00000000 ____D C:\Users\****** *****\AppData\Roaming\vlc 2013-11-07 02:40 - 2013-10-20 12:24 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2013-11-07 01:57 - 2013-10-20 12:21 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2013-11-07 00:27 - 2013-06-16 23:17 - 00001096 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4189605395-1850867417-3092745277-1000Core.job 2013-11-05 23:34 - 2013-06-16 19:14 - 00000000 ____D C:\Users\****** *****\AppData\Roaming\Macromedia 2013-11-05 01:35 - 2013-10-15 00:32 - 00000000 ____D C:\Users\****** *****\AppData\Roaming\HpUpdate 2013-11-04 16:36 - 2013-06-16 19:19 - 00000000 ____D C:\Users\****** *****\AppData\Local\CrashDumps 2013-11-04 10:59 - 2013-11-04 10:59 - 00004608 _____ C:\Users\****** *****\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-11-02 19:31 - 2013-06-16 22:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-02 03:20 - 2013-11-02 03:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-01 03:00 - 2013-11-01 03:00 - 00003408 _____ C:\Windows\System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-4189605395-1850867417-3092745277-1000 2013-10-28 17:03 - 2013-10-28 17:03 - 00000000 ____D C:\Users\****** *****\Desktop\SysInfo.{ED7BA470-8E54-465E-825C-99712043E01C} 2013-10-27 20:55 - 2013-10-27 20:55 - 02474341 _____ C:\Users\****** *****\Documents\cheyenne 150x55.epp 2013-10-27 19:38 - 2013-10-27 19:38 - 00002665 _____ C:\Users\Public\Desktop\Easy Poster Printer.lnk 2013-10-27 19:38 - 2013-10-27 19:38 - 00000000 ____D C:\Program Files (x86)\GD Software 2013-10-27 19:32 - 2013-10-27 19:32 - 00000000 ___HD C:\ProgramData\CanonBJ 2013-10-27 19:31 - 2013-10-27 19:31 - 00000000 ____D C:\Program Files\Common Files\Canon 2013-10-27 19:31 - 2013-10-27 19:26 - 00000000 ____D C:\Program Files (x86)\Canon 2013-10-27 19:28 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\system32\FxsTmp 2013-10-27 19:26 - 2013-10-27 19:26 - 00002305 _____ C:\Users\Public\Desktop\iP5200 Handbuchausgabe für den Bildschirm.lnk 2013-10-27 13:57 - 2013-10-27 14:05 - 00452879 _____ C:\Windows\system32\Drivers\etc\hosts.20131027-140515.backup 2013-10-26 22:50 - 2013-10-26 22:50 - 00000000 ____D C:\ProgramData\HPSSUPPLY 2013-10-22 00:14 - 2009-07-14 06:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-10-20 15:13 - 2013-10-20 15:13 - 00000000 ____D C:\Users\****** *****\dwhelper 2013-10-20 15:13 - 2013-06-16 12:25 - 00000000 ____D C:\Users\****** ***** 2013-10-20 12:24 - 2013-10-20 12:24 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-18 22:09 - 2013-10-14 22:45 - 00000000 ____D C:\Users\****** *****\AppData\Roaming\HP 2013-10-17 23:22 - 2013-06-16 23:17 - 00004132 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4189605395-1850867417-3092745277-1000UA 2013-10-17 23:22 - 2013-06-16 23:17 - 00003736 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4189605395-1850867417-3092745277-1000Core 2013-10-17 22:17 - 2013-10-17 22:17 - 00000000 ____D C:\Windows\System32\Tasks\Norton Internet Security 2013-10-17 22:12 - 2013-06-16 13:04 - 00000000 ____D C:\Windows\system32\Drivers\NISx64 2013-10-17 22:11 - 2013-06-16 13:05 - 00003234 _____ C:\Windows\System32\Tasks\Norton WSC Integration 2013-10-17 22:11 - 2013-06-16 13:05 - 00002518 _____ C:\Users\Public\Desktop\Norton Internet Security.lnk 2013-10-17 20:19 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-10-17 12:02 - 2013-06-16 14:11 - 00000000 ____D C:\Program Files (x86)\DSL-Manager 2013-10-17 04:10 - 2013-10-17 04:10 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-10-17 04:10 - 2013-10-17 04:10 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-10-17 04:10 - 2013-10-17 04:10 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-10-17 04:10 - 2013-10-17 04:10 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-10-17 04:10 - 2013-10-17 04:10 - 00000000 ____D C:\Program Files\Java 2013-10-17 04:10 - 2013-10-17 04:00 - 00000000 ____D C:\ProgramData\Oracle 2013-10-17 04:00 - 2013-10-17 04:00 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-10-17 04:00 - 2013-10-17 04:00 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-10-17 04:00 - 2013-10-17 04:00 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-10-17 04:00 - 2013-10-17 04:00 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-10-17 04:00 - 2013-10-17 04:00 - 00000000 ____D C:\Program Files (x86)\Java 2013-10-17 03:23 - 2013-10-17 03:23 - 00000038 _____ C:\Users\****** *****\AppData\Local\census.cache 2013-10-17 03:23 - 2013-10-17 03:23 - 00000000 _____ C:\Users\****** *****\AppData\Local\ars.cache 2013-10-16 16:13 - 2013-10-16 16:13 - 00000036 _____ C:\Users\****** *****\AppData\Local\housecall.guid.cache 2013-10-16 02:35 - 2013-10-16 02:35 - 00000000 ____D C:\FRST 2013-10-16 02:35 - 2013-10-16 02:35 - 00000000 _____ C:\Users\****** *****\defogger_reenable 2013-10-16 01:26 - 2013-06-16 23:24 - 00002425 _____ C:\Users\****** *****\Desktop\Google Chrome.lnk 2013-10-15 21:14 - 2013-10-15 21:07 - 00259396 _____ C:\Windows\msxml4-KB2758694-enu.LOG 2013-10-15 13:28 - 2013-06-19 15:25 - 00000000 ____D C:\Users\****** *****\Documents\PhoenixRC 2013-10-15 10:19 - 2013-06-22 20:47 - 00004118 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-10-15 10:19 - 2013-06-22 20:47 - 00003866 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-10-15 09:56 - 2013-10-15 00:29 - 00000000 ____D C:\Program Files (x86)\MSXML 4.0 2013-10-15 09:55 - 2013-10-15 09:54 - 02434048 _____ C:\Users\****** *****\Downloads\msxml.msi 2013-10-15 00:33 - 2013-10-14 21:12 - 00000000 ____D C:\Program Files (x86)\HP 2013-10-15 00:32 - 2013-10-15 00:32 - 00000000 ____D C:\Windows\Hewlett-Packard 2013-10-15 00:29 - 2013-10-15 00:29 - 00286566 _____ C:\Windows\msxml4-KB954430-enu.LOG 2013-10-15 00:10 - 2013-10-14 21:16 - 00000000 ____D C:\Program Files (x86)\Yahoo! 2013-10-14 23:32 - 2013-10-14 21:11 - 00003874 _____ C:\ProgramData\hpzinstall.log 2013-10-14 22:46 - 2013-10-14 22:46 - 00000000 ____D C:\ProgramData\WEBREG 2013-10-14 22:45 - 2013-10-14 21:11 - 00245587 _____ C:\Windows\hpoins19.dat 2013-10-14 22:45 - 2013-10-14 21:11 - 00000000 ____D C:\ProgramData\HP 2013-10-14 22:45 - 2009-07-14 03:34 - 00000470 _____ C:\Windows\win.ini 2013-10-14 22:36 - 2013-06-16 14:12 - 00069496 _____ C:\Users\****** *****\AppData\Local\GDIPFONTCACHEV1.DAT 2013-10-14 22:36 - 2009-07-14 05:45 - 00304856 _____ C:\Windows\system32\FNTCACHE.DAT 2013-10-14 21:17 - 2013-10-14 21:17 - 00003148 _____ C:\Windows\System32\Tasks\SidebarExecute 2013-10-14 21:17 - 2013-10-14 21:17 - 00000000 ____D C:\Users\****** *****\AppData\Local\HP 2013-10-14 21:16 - 2013-10-14 21:16 - 00000000 ____D C:\Users\****** *****\AppData\Roaming\Yahoo! 2013-10-14 21:15 - 2013-10-14 21:15 - 00000000 ____D C:\ProgramData\HP Product Assistant 2013-10-14 21:14 - 2013-10-14 21:14 - 00000000 ____D C:\Windows\SysWOW64\spool 2013-10-14 18:00 - 2013-11-07 20:44 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2013-10-14 15:10 - 2013-10-14 15:10 - 00000000 ____D C:\Users\****** *****\AppData\Roaming\RealNetworks 2013-10-14 15:09 - 2013-10-14 15:09 - 00000000 ____D C:\ProgramData\RealNetworks 2013-10-14 15:09 - 2013-10-14 15:09 - 00000000 ____D C:\Program Files (x86)\RealNetworks 2013-10-14 15:08 - 2013-06-17 02:18 - 00499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll 2013-10-14 15:08 - 2013-06-17 02:18 - 00272896 _____ (Progressive Networks) C:\Windows\SysWOW64\pncrt.dll 2013-10-14 15:08 - 2013-06-17 02:18 - 00201872 _____ (RealNetworks, Inc.) C:\Windows\SysWOW64\rmoc3260.dll 2013-10-14 15:08 - 2013-06-17 02:18 - 00006656 _____ (RealNetworks, Inc.) C:\Windows\SysWOW64\pndx5016.dll 2013-10-14 15:08 - 2013-06-17 02:18 - 00005632 _____ (RealNetworks, Inc.) C:\Windows\SysWOW64\pndx5032.dll 2013-10-14 15:08 - 2013-06-17 02:18 - 00000000 ____D C:\Program Files (x86)\Real 2013-10-14 15:08 - 2013-06-17 02:06 - 00000000 ____D C:\ProgramData\Real 2013-10-14 15:05 - 2013-10-14 15:05 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4 2013-10-14 15:04 - 2013-10-14 15:04 - 00000000 ____D C:\Users\****** *****\Documents\DVDVideoSoft 2013-10-14 15:02 - 2013-06-17 18:37 - 00001000 _____ C:\Users\Public\Desktop\Winamp.lnk 2013-10-14 15:02 - 2013-06-17 18:37 - 00000000 ____D C:\Users\****** *****\AppData\Roaming\Winamp 2013-10-14 15:02 - 2013-06-17 18:37 - 00000000 ____D C:\Program Files (x86)\Winamp 2013-10-14 15:01 - 2013-10-14 15:01 - 00000000 ____D C:\Users\****** *****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Winamp Erkennungs-Plug-in 2013-10-14 15:01 - 2013-06-17 18:37 - 00000000 ____D C:\Program Files (x86)\Winamp Detect 2013-10-14 14:58 - 2013-06-16 22:35 - 00000000 ____D C:\Users\****** *****\AppData\Local\Mozilla 2013-10-14 14:51 - 2013-06-16 19:40 - 00001092 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-10-14 14:30 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Windows Defender 2013-10-14 14:30 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2013-10-14 13:17 - 2013-06-16 12:25 - 00000000 ___RD C:\Users\****** *****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-10-14 13:17 - 2013-06-16 12:25 - 00000000 ___RD C:\Users\****** *****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-10-14 13:00 - 2013-10-14 12:58 - 00000000 ____D C:\Windows\system32\MRT 2013-10-14 12:26 - 2013-10-14 02:55 - 00000822 _____ C:\Windows\system32\Drivers\etc\hosts.20131014-035517.backup 2013-10-14 12:26 - 2013-06-17 12:07 - 00000000 ____D C:\Users\****** *****\AppData\Roaming\WinPatrol 2013-10-14 12:20 - 2009-07-14 19:18 - 00000000 ____D C:\Program Files\Windows Journal 2013-10-14 11:15 - 2013-10-14 02:40 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-10-14 06:59 - 2013-10-14 06:59 - 00000000 ____D C:\Windows\Microsoft Antimalware 2013-10-14 02:55 - 2013-10-14 02:56 - 00450619 ____R C:\Windows\system32\Drivers\etc\hosts.20131014-035617.backup 2013-10-14 02:48 - 2013-10-14 02:40 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2 2013-10-14 02:40 - 2013-10-14 02:40 - 17813896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2013-10-14 02:40 - 2013-10-14 02:40 - 00001400 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk 2013-10-14 02:40 - 2013-10-14 02:40 - 00000000 ____D C:\Users\****** *****\AppData\Local\Secunia PSI 2013-10-14 02:40 - 2013-06-17 02:04 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-10-14 02:40 - 2013-06-17 02:04 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-10-14 02:40 - 2013-06-17 02:04 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-10-14 02:39 - 2013-10-14 02:39 - 00000000 ____D C:\Program Files (x86)\Secunia 2013-10-13 18:03 - 2013-10-13 16:54 - 00000000 ____D C:\Users\****** *****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton 2013-10-13 18:03 - 2013-06-16 12:36 - 00000000 ____D C:\ProgramData\Norton 2013-10-13 18:01 - 2013-06-16 13:05 - 00177752 _____ (Symantec Corporation) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS 2013-10-13 18:01 - 2013-06-16 13:05 - 00008222 _____ C:\Windows\system32\Drivers\SYMEVENT64x86.CAT 2013-10-13 18:01 - 2013-06-16 13:04 - 00000000 ____D C:\Program Files (x86)\Norton Internet Security 2013-10-13 17:53 - 2013-06-16 22:48 - 00000000 ____D C:\Users\****** *****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sicherheit 2013-10-13 17:52 - 2013-10-13 17:52 - 00000000 ____D C:\Users\****** *****\AppData\Roaming\DVDVideoSoftIEHelpers 2013-10-13 17:52 - 2013-10-13 17:50 - 00000000 ____D C:\Users\****** *****\AppData\Roaming\DVDVideoSoft 2013-10-13 17:52 - 2013-10-13 17:50 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft 2013-10-13 17:51 - 2013-10-13 17:50 - 00000000 ___RD C:\Users\Public\Desktop\DVDVideoSoft 2013-10-13 17:49 - 2013-06-25 12:58 - 00000000 ____D C:\Windows\Minidump 2013-10-13 17:35 - 2013-06-17 12:07 - 00000000 ____D C:\ProgramData\InstallMate 2013-10-13 17:04 - 2013-06-16 23:13 - 00000000 ____D C:\Program Files (x86)\OpenOffice.org 3 2013-10-13 17:00 - 2013-06-17 20:36 - 00007901 _____ C:\Windows\wininit.ini 2013-10-13 16:56 - 2013-10-13 16:56 - 00000000 ____D C:\Program Files (x86)\MPC-HC 2013-10-13 16:54 - 2013-06-16 12:36 - 00000000 ____D C:\Users\Public\Downloads\Norton 2013-10-13 16:52 - 2013-06-17 02:17 - 00000000 ____D C:\Users\****** *****\AppData\Roaming\Real ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-01 18:15 ==================== End Of Log ============================ |
![]() | #30 |
![]() | ![]() Win7 IP tunnelt mich jede Nacht und kapert Teledat 530 RouterCode:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 31-10-2013 Ran by ******* ******* at 2013-11-07 21:51:03 Running from C:\Users\******* *******\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Norton Internet Security (Enabled - Up to date) {63DF5164-9100-186D-2187-8DC619EFD8BF} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Enabled - Out of date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} AS: Norton Internet Security (Enabled - Up to date) {D8BEB080-B73A-17E3-1B37-B6B462689202} FW: Norton Internet Security (Enabled) {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} ==================== Installed Programs ====================== 64 Bit HP CIO Components Installer (Version: 7.2.8) 7-Zip 9.20 (x64 edition) (Version: Acronis True Image WD*Edition (x32 Version: 13.0.14189) Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117) Adobe Reader XI (11.0.05) - Deutsch (x32 Version: 11.0.05) AIO_CDB_ProductContext (x32 Version: 130.0.365.000) AIO_CDB_Software (x32 Version: 130.0.365.000) AIO_Scan (x32 Version: 130.0.421.000) AMD Accelerated Video Transcoding (Version: AMD APP SDK Runtime (Version: 10.0.937.2) AMD AVIVO64 Codecs (Version: AMD Catalyst Install Manager (Version: 8.0.911.0) AMD Drag and Drop Transcoding (Version: 2.00.0000) AMD Fuel (Version: 2012.1116.1515.27190) AMD Media Foundation Decoders (Version: 1.0.71116.1554) AMD VISION Engine Control Center (x32 Version: 2012.1116.1515.27190) Apple Application Support (x32 Version: 2.3.4) Apple Software Update (x32 Version: Bing Bar (x32 Version: 7.1.362.0) BufferChm (x32 Version: 130.0.331.000) Canon Inkjet Printer Driver Add-On Module Catalyst Control Center - Branding (x32 Version: 1.00.0000) Catalyst Control Center Graphics Previews Common (x32 Version: 2012.1116.1515.27190) Catalyst Control Center Localization All (x32 Version: 2012.1116.1515.27190) CCC Help Chinese Standard (x32 Version: 2012.1116.1514.27190) CCC Help Chinese Traditional (x32 Version: 2012.1116.1514.27190) CCC Help Czech (x32 Version: 2012.1116.1514.27190) CCC Help Danish (x32 Version: 2012.1116.1514.27190) CCC Help Dutch (x32 Version: 2012.1116.1514.27190) CCC Help English (x32 Version: 2012.1116.1514.27190) CCC Help Finnish (x32 Version: 2012.1116.1514.27190) CCC Help French (x32 Version: 2012.1116.1514.27190) CCC Help German (x32 Version: 2012.1116.1514.27190) CCC Help Greek (x32 Version: 2012.1116.1514.27190) CCC Help Hungarian (x32 Version: 2012.1116.1514.27190) CCC Help Italian (x32 Version: 2012.1116.1514.27190) CCC Help Japanese (x32 Version: 2012.1116.1514.27190) CCC Help Korean (x32 Version: 2012.1116.1514.27190) CCC Help Norwegian (x32 Version: 2012.1116.1514.27190) CCC Help Polish (x32 Version: 2012.1116.1514.27190) CCC Help Portuguese (x32 Version: 2012.1116.1514.27190) CCC Help Russian (x32 Version: 2012.1116.1514.27190) CCC Help Spanish (x32 Version: 2012.1116.1514.27190) CCC Help Swedish (x32 Version: 2012.1116.1514.27190) CCC Help Thai (x32 Version: 2012.1116.1514.27190) CCC Help Turkish (x32 Version: 2012.1116.1514.27190) ccc-utility64 (Version: 2012.1116.1515.27190) Copy (x32 Version: 130.0.428.000) CPUID CPU-Z 1.64.0 CrystalDiskInfo 5.6.2 (x32 Version: 5.6.2) CyberLink BD_3D Advisor 2.0 (x32 Version: 2.0.5425) CyberLink LabelPrint 2.5 (x32 Version: 2.5.5311) CyberLink Media Suite 10 (x32 Version: 10.0) CyberLink Media Suite 10 (x32 Version: 10.2021) CyberLink MediaEspresso 6.5 (x32 Version: 6.5.3019_44673) CyberLink MediaShow 6 (x32 Version: 6.0.4312) CyberLink Power2Go 7 (x32 Version: CyberLink PowerDVD 10 (x32 Version: 10.0.4125.52) CyberLink PowerProducer 5.5 (x32 Version: Defraggler (Version: 2.14) Destinations (x32 Version: DeviceDiscovery (x32 Version: 130.0.465.000) DHTML Editing Component (x32 Version: 6.02.0001) Disktrix UltimateDefrag (x32) DocProc (x32 Version: DriveImage XML (Private Edition) (x32 Version: 2.44.000) DSL-Manager (x32) Easy Poster Printer (x32 Version: 6.0.0) F300 (x32 Version: 130.0.365.000) F300_Help (x32 Version: F300Trb (x32 Version: Fax (x32 Version: 130.0.418.000) Free Download Manager 3.9.2 (x32) Free Studio version 2013 (x32 Version: Google Chrome (HKCU Version: 30.0.1599.101) Google Earth (x32 Version: Google Update Helper (x32 Version: GPBaseService2 (x32 Version: 130.0.371.000) HP Customer Participation Program 13.0 (Version: 13.0) HP Imaging Device Functions 13.0 (Version: 13.0) HP Photosmart Officejet and Deskjet All-In-One Driver Software 13.0 Rel. B (Version: 13.0) HP Solution Center 13.0 (Version: 13.0) HP Update (x32 Version: HPPhotoGadget (x32 Version: HPProductAssistant (x32 Version: 130.0.371.000) HPSSupply (x32 Version: 130.0.371.000) HydraVision (x32 Version: IrfanView (remove only) (x32 Version: 4.36) Java 7 Update 45 (64-bit) (Version: 7.0.450) Java 7 Update 45 (x32 Version: 7.0.450) Java Auto Updater (x32 Version: K-Lite Codec Pack 9.9.0 (64-bit) (Version: 9.9.0) K-Lite Codec Pack 9.9.0 (Full) (x32 Version: 9.9.0) Malwarebytes Anti-Malware Version (x32 Version: MarketResearch (x32 Version: 130.0.374.000) MAXA Cookie Manager Pro 5.3 (x32) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Rechner-Plus (x32 Version: 1.0.0) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319) Mozilla Firefox 25.0 (x86 de) (x32 Version: 25.0) Mozilla Maintenance Service (x32 Version: 25.0) MPC-HC 1.7.0 (x32 Version: MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0) MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0) MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0) Network64 (Version: 130.0.572.000) Network64 (Version: Norton Internet Security (x32 Version: OCR Software by I.R.I.S. 13.0 (Version: 13.0) OpenOffice 4.0.1 (x32 Version: 4.01.9714) Opera 12.15 (Version: 12.15.1748) Paint.NET v3.5.10 (Version: 3.60.0) Phoenix R/C 2.5.v to 3.0.a BETA Update (x32 Version: 3.0.0) PhoenixRC (x32 Version: 2.00.10) QuickTime (x32 Version: Rainlendar2 (remove only) (x32) RealDownloader (x32 Version: 1.3.3) RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0) RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0) RealPlayer (x32 Version: 16.0.3) Realtek Ethernet Controller Driver (x32 Version: 7.58.411.2012) Realtek High Definition Audio Driver (x32 Version: RealUpgrade 1.1 (x32 Version: 1.1.0) Scan (x32 Version: ScreenManager Pro for LCD (x32 Version: Secunia PSI ( (x32 Version: Shop for HP Supplies (Version: 13.0) SimpleScreenshot 1.20 (x32) SiSoftware Sandra Lite 2013.SP4 (Version: 19.50.2013.7) SolutionCenter (x32 Version: 130.0.373.000) Spybot - Search & Destroy (x32 Version: 2.1.21) Status (x32 Version: 130.0.469.000) Streamripper (Remove only) (x32) TechPowerUp GPU-Z (x32) T-Online 6.0 (x32) T-Online WLAN-Access Finder (x32) Toolbox (x32 Version: 130.0.648.000) TrayApp (x32 Version: 130.0.422.000) TreeSize Free V2.5 (x32 Version: 2.5) UnloadSupport (x32 Version: 11.0.0) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3) USBFast (x32 Version: VLC media player 2.1.0 (Version: 2.1.0) WebReg (x32 Version: Winamp (x32 Version: 5.65 ) Winamp Erkennungs-Plug-in (HKCU Version: WinPatrol (Version: 28.9.2013.1) WinRAR (x32) WinRAR 4.20 (64-Bit) (Version: 4.20.0) xp-AntiSpy 3.98-2 (x32) ==================== Restore Points ========================= 26-10-2013 22:55:50 Geplanter Prüfpunkt 27-10-2013 18:38:00 Installed Easy Poster Printer 29-10-2013 00:42:19 Installed Network64 05-11-2013 12:12:53 Geplanter Prüfpunkt 07-11-2013 19:28:32 Windows Modules Installer ==================== Hosts content: ========================== 2013-11-07 00:59 - 2013-11-07 00:59 - 00452990 ____A C:\Windows\system32\Drivers\etc\hosts localhost www.007guard.com 007guard.com 008i.com www.008k.com 008k.com www.00hq.com 00hq.com 010402.com www.032439.com 032439.com www.0scan.com 0scan.com 1000gratisproben.com www.1000gratisproben.com 1001namen.com www.1001namen.com 100888290cs.com www.100888290cs.com www.100sexlinks.com 100sexlinks.com 10sek.com www.10sek.com www.1-2005-search.com 1-2005-search.com 123fporn.info www.123fporn.info 123haustiereundmehr.com www.123haustiereundmehr.com There are 1000 more lines. ==================== Scheduled Tasks (whitelisted) ============= Task: {060199AE-A5E9-49AE-B19E-5AA2E385D79A} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe Task: {110B3263-6995-4315-9EAB-FE4983D72A43} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4189605395-1850867417-3092745277-1000Core => C:\Users\******* *******\AppData\Local\Google\Update\GoogleUpdate.exe [2013-06-16] (Google Inc.) Task: {1597C513-772A-4951-894D-2C45C0D19C77} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-4189605395-1850867417-3092745277-1000 => C:\Program Files (x86)\Real\RealUpgrade\realupgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {2E616398-C2B6-44A6-8F49-D79A1F3D77C7} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-4189605395-1850867417-3092745277-1000 => C:\Program Files (x86)\Real\RealUpgrade\realupgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {32717702-D861-4B3E-B64E-EF6981B35A0E} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe Task: {33263AC0-2CFA-4097-93DC-CE1920AB8E17} - System32\Tasks\{B30D24F3-16CC-4A2E-B9F5-5379BCCC8C45} => E:\aaaa-Programme-downloads\Hard Disk Sleeper HDDScan 3.3\HDDScan.exe Task: {3D9FDEBB-1044-452B-B8D9-EDA656E2729E} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\\symerr.exe [2013-08-01] (Symantec Corporation) Task: {447FC619-6652-4075-9B1C-F9C775028CB2} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-4189605395-1850867417-3092745277-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe [2013-08-14] (RealNetworks, Inc.) Task: {53BCCDC7-2FD1-4331-A60A-7CBE48E132A9} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation) Task: {6B77E853-4DC9-4558-92CC-56CE5B129513} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\\symerr.exe [2013-08-01] (Symantec Corporation) Task: {8779788B-4FA4-4009-8A0F-00B0268DEC65} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-06-22] (Google Inc.) Task: {9023D63A-5AE7-4D12-8C3D-F282A170F3B1} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4189605395-1850867417-3092745277-1000UA => C:\Users\******* *******\AppData\Local\Google\Update\GoogleUpdate.exe [2013-06-16] (Google Inc.) Task: {92457C33-0CC0-41C8-A52A-80A350585CF0} - System32\Tasks\{5D6595C2-3643-4491-98BF-9C795E81C012} => E:\aaaa-Programme-downloads\Hard Disk Sleeper HDDScan 3.3\HDDScan.exe Task: {96A5E441-F229-4D68-9FE7-A8E5CFE64A71} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-4189605395-1850867417-3092745277-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {9A6AFDAB-F2AA-427A-B1F4-57C7953D8ECA} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-4189605395-1850867417-3092745277-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {AA2A9180-CBED-43E7-A53F-E7CD406B3ABF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-06-22] (Google Inc.) Task: {ABEEBB48-23FE-4257-BBBD-B493BAD1F375} - System32\Tasks\Core Temp Autostart ******* ******* => C:\Users\******* *******\AppData\Local\Temp\7zO6D34.tmp\Core Temp.exe [2013-03-01] () Task: {ACC7B2BB-C098-4995-A046-271A66F4ADE3} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe Task: {B211FAD8-F608-4E2C-B200-5E15A21EADC9} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {B8E0F68F-1C91-4F83-9B22-7FA5F558CB04} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\\wscstub.exe [2013-10-08] (Symantec Corporation) Task: {CBA0D212-87F4-4EBF-813D-B5AB3B5EC060} - System32\Tasks\{028722A3-A1D9-458B-A4EC-63090063E2CD} => C:\Program Files (x86)\revoSleep\revoSleep.exe Task: {E1F18F10-25F4-4C98-BB78-BC8E00CCF02B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-14] (Adobe Systems Incorporated) Task: {E4AAF512-2236-45B7-BA68-ADAAEBB98E6F} - System32\Tasks\{1B55A9D2-4AEF-404A-A21E-F75A623287B5} => E:\aaaa-Programme-downloads\Hard Disk Sleeper HDDScan 3.3\HDDScan.exe Task: {EB77126A-A921-4E37-AE91-FD29AFEFFB0B} - System32\Tasks\{032203FC-348D-4183-8022-0E08D43736CD} => H:\Setup.exe Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4189605395-1850867417-3092745277-1000Core.job => C:\Users\******* *******\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4189605395-1850867417-3092745277-1000UA.job => C:\Users\******* *******\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2012-05-10 15:23 - 2012-05-10 15:23 - 01233528 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll 2013-06-16 20:46 - 2010-05-23 18:30 - 00160768 _____ () C:\Program Files\Rainlendar2\lua51.dll 2013-03-10 19:00 - 2011-08-12 06:47 - 00312832 _____ () C:\Program Files\Rainlendar2\plugins\iCalendarPlugin.dll 2012-06-17 14:21 - 2010-05-23 18:30 - 00013824 _____ () C:\Program Files\Rainlendar2\lfs.dll 2012-11-16 14:27 - 2012-11-16 14:27 - 00103424 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll 2012-11-16 14:09 - 2012-11-16 14:09 - 00369152 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2013-06-17 11:48 - 2010-12-19 19:16 - 00338944 _____ () C:\Program Files (x86)\MAXA Cookie Manager\sqlite36_engine.dll 2013-06-17 11:48 - 2010-12-19 19:19 - 00023552 _____ () C:\Program Files (x86)\MAXA Cookie Manager\DirectCOM.dll 2013-06-17 12:07 - 2013-07-15 18:29 - 00620718 ____N () C:\Program Files (x86)\BillP Studios\WinPatrol\sqlite3.dll 2012-05-10 15:16 - 2012-05-10 15:16 - 00071008 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\Common\rpc_client.dll 2011-03-09 13:21 - 2011-03-09 13:21 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll 2011-03-09 13:21 - 2011-03-09 13:21 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll 2013-10-14 02:40 - 2013-05-16 09:55 - 00113496 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl 2013-10-14 02:40 - 2013-05-16 09:55 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl 2013-10-14 02:40 - 2013-05-16 09:55 - 00161112 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl 2013-10-14 02:40 - 2012-08-23 09:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll 2013-10-14 02:40 - 2012-04-03 16:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (11/07/2013 01:42:16 AM) (Source: Application Hang) (User: ) Description: Programm Mail.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1008 Startzeit: 01cedb514bb6d845 Endzeit: 16 Anwendungspfad: C:\Program Files (x86)\T-Online\T-Online_Software_6\eMail\Mail.exe Berichts-ID: 6fbecdb9-4745-11e3-b1ed-003018af12c2 Error: (11/05/2013 09:55:13 PM) (Source: Application Hang) (User: ) Description: Programm IEXPLORE.EXE, Version 10.0.9200.16720 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1f0 Startzeit: 01ceda6721c8ba27 Endzeit: 16 Anwendungspfad: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Berichts-ID: Error: (11/04/2013 04:36:22 PM) (Source: Application Error) (User: ) Description: Aus einem der folgenden Gründe kann nicht auf die Datei "" zugegriffen werden: Es besteht ein Problem mit der Netzwerkverbindung, dem Datenträger mit der gespeicherten Datei bzw. den auf dem Computer installierten Speichertreibern, oder der Datenträger fehlt. Das Programm ScreenManager Pro for LCD wurde wegen dieses Fehlers geschlossen. Programm: ScreenManager Pro for LCD Datei: Der Fehlerwert ist im Abschnitt "Zusätzliche Dateien" aufgelistet. Benutzeraktion 1. Öffnen Sie die Datei erneut. Diese Situation ist eventuell ein temporäres Problem, das selbstständig behoben wird, wenn das Programm erneut ausgeführt wird. 2. Wenn Sie weiterhin nicht auf die Datei zugreifen können und - diese sich im Netzwerk befindet, dann sollte der Netzwerkadministrator überprüfen, dass kein Netzwerkproblem besteht und dass eine Verbindung mit dem Server hergestellt werden kann. - diese sich auf einem Wechseldatenträger, wie z. B. einer Diskette oder einer CD, befindet, überprüfen Sie, ob der Datenträger richtig in den Computer eingelegt ist. 3. Überprüfen und reparieren Sie das Dateisystem, indem Sie CHKDSK ausführen. Klicken Sie dazu im Menü "Start" auf "Ausführen", geben Sie CMD ein, und klicken Sie auf "OK". Geben Sie an der Eingabeaufforderung CHKDSK /F ein, und drücken Sie die EINGABETASTE. 4. Stellen Sie die Datei von einer Sicherungskopie wieder her, wenn das Problem weiterhin besteht. 5. Überprüfen Sie, ob andere Dateien auf demselben Datenträger geöffnet werden können. Falls dies nicht möglich ist, ist der Datenträger eventuell beschädigt. Wenden Sie sich an den Administrator oder den Hersteller der Computerhardware, um weitere Unterstützung zu erhalten, wenn es sich um eine Festplatte handelt. Zusätzliche Daten Fehlerwert: 00000000 Datenträgertyp: 0 Error: (11/04/2013 04:36:22 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Lcdctrl.exe, Version:, Zeitstempel: 0x45ac9cbc Name des fehlerhaften Moduls: Lcdctrl.exe, Version:, Zeitstempel: 0x45ac9cbc Ausnahmecode: 0xc000001d Fehleroffset: 0x00073965 ID des fehlerhaften Prozesses: 0xb7c Startzeit der fehlerhaften Anwendung: 0xLcdctrl.exe0 Pfad der fehlerhaften Anwendung: Lcdctrl.exe1 Pfad des fehlerhaften Moduls: Lcdctrl.exe2 Berichtskennung: Lcdctrl.exe3 Error: (11/01/2013 03:51:20 AM) (Source: .NET Runtime) (User: ) Description: .NET Runtime version 4.0.30319.1008 - Fehler beim Initialisieren der Profilerstellungs-API-Anfügeinfrastruktur. Dieser Prozess ermöglicht einem Profiler das Anfügen nicht. HRESULT: 0x80004005. Prozess-ID (dezimal): 9956. Meldungs-ID: [0x2509]. Error: (11/01/2013 01:34:36 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: phoenixRC.exe, Version:, Zeitstempel: 0x51406972 Name des fehlerhaften Moduls: phoenixRC.exe, Version:, Zeitstempel: 0x51406972 Ausnahmecode: 0xc0000005 Fehleroffset: 0x002cc014 ID des fehlerhaften Prozesses: 0x1274 Startzeit der fehlerhaften Anwendung: 0xphoenixRC.exe0 Pfad der fehlerhaften Anwendung: phoenixRC.exe1 Pfad des fehlerhaften Moduls: phoenixRC.exe2 Berichtskennung: phoenixRC.exe3 Error: (10/30/2013 00:04:02 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Mail.exe, Version:, Zeitstempel: 0x4faba5f4 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea8e7 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000343e6 ID des fehlerhaften Prozesses: 0x1c6c Startzeit der fehlerhaften Anwendung: 0xMail.exe0 Pfad der fehlerhaften Anwendung: Mail.exe1 Pfad des fehlerhaften Moduls: Mail.exe2 Berichtskennung: Mail.exe3 Error: (10/30/2013 00:03:59 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Mail.exe, Version:, Zeitstempel: 0x4faba5f4 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea8e7 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0002e3be ID des fehlerhaften Prozesses: 0x1c6c Startzeit der fehlerhaften Anwendung: 0xMail.exe0 Pfad der fehlerhaften Anwendung: Mail.exe1 Pfad des fehlerhaften Moduls: Mail.exe2 Berichtskennung: Mail.exe3 Error: (10/29/2013 07:31:03 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Mail.exe, Version:, Zeitstempel: 0x4faba5f4 Name des fehlerhaften Moduls: dao360.dll, Version: 3.60.9756.0, Zeitstempel: 0x49246e49 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0006a113 ID des fehlerhaften Prozesses: 0x1514 Startzeit der fehlerhaften Anwendung: 0xMail.exe0 Pfad der fehlerhaften Anwendung: Mail.exe1 Pfad des fehlerhaften Moduls: Mail.exe2 Berichtskennung: Mail.exe3 Error: (10/29/2013 07:30:58 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Mail.exe, Version:, Zeitstempel: 0x4faba5f4 Name des fehlerhaften Moduls: dao360.dll, Version: 3.60.9756.0, Zeitstempel: 0x49246e49 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0006a113 ID des fehlerhaften Prozesses: 0x1514 Startzeit der fehlerhaften Anwendung: 0xMail.exe0 Pfad der fehlerhaften Anwendung: Mail.exe1 Pfad des fehlerhaften Moduls: Mail.exe2 Berichtskennung: Mail.exe3 System errors: ============= Error: (11/07/2013 09:22:34 PM) (Source: WMPNetworkSvc) (User: ) Description: WMPNetworkSvc Error: (11/07/2013 09:20:30 PM) (Source: NetBT) (User: ) Description: Der Name "**************-PC :20" konnte nicht auf der Schnittstelle mit IP-Adresse registriert werden. Der Computer mit IP-Adresse hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (11/07/2013 09:20:30 PM) (Source: Server) (User: ) Description: Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{8B1AC5F0-DCFA-4FD5-95DA-7E370B6D6D18} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden. Error: (11/07/2013 09:20:24 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Spybot-S&D 2 Scanner Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (11/07/2013 09:20:24 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Scanner Service erreicht. Error: (11/07/2013 09:19:46 PM) (Source: NetBT) (User: ) Description: Der Name "**************-PC :0" konnte nicht auf der Schnittstelle mit IP-Adresse registriert werden. Der Computer mit IP-Adresse hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (11/07/2013 09:18:33 PM) (Source: DCOM) (User: ) Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Error: (11/07/2013 08:49:20 PM) (Source: WMPNetworkSvc) (User: ) Description: WMPNetworkSvc Error: (11/07/2013 08:47:05 PM) (Source: NetBT) (User: ) Description: Der Name "**************-PC :20" konnte nicht auf der Schnittstelle mit IP-Adresse registriert werden. Der Computer mit IP-Adresse hat nicht zugelassen, dass dieser Computer diesen Namen verwendet. Error: (11/07/2013 08:47:05 PM) (Source: Server) (User: ) Description: Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{8B1AC5F0-DCFA-4FD5-95DA-7E370B6D6D18} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden. Microsoft Office Sessions: ========================= Error: (11/07/2013 01:42:16 AM) (Source: Application Hang)(User: ) Description: Mail.exe6.10.0.5100801cedb514bb6d84516C:\Program Files (x86)\T-Online\T-Online_Software_6\eMail\Mail.exe6fbecdb9-4745-11e3-b1ed-003018af12c2 Error: (11/05/2013 09:55:13 PM) (Source: Application Hang)(User: ) Description: IEXPLORE.EXE10.0.9200.167201f001ceda6721c8ba2716C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Error: (11/04/2013 04:36:22 PM) (Source: Application Error)(User: ) Description: ScreenManager Pro for LCD000000000 Error: (11/04/2013 04:36:22 PM) (Source: Application Error)(User: ) Description: Lcdctrl.exe2.3.0.145ac9cbcLcdctrl.exe2.3.0.145ac9cbcc000001d00073965b7c01ced973698c5efeC:\Program Files (x86)\EIZO\ScreenManager Pro for LCD\Lcdctrl.exeC:\Program Files (x86)\EIZO\ScreenManager Pro for LCD\Lcdctrl.exedb52bb30-4566-11e3-9253-003018af12c2 Error: (11/01/2013 03:51:20 AM) (Source: .NET Runtime)(User: ) Description: .NET Runtime version 4.0.30319.1008 - Fehler beim Initialisieren der Profilerstellungs-API-Anfügeinfrastruktur. Dieser Prozess ermöglicht einem Profiler das Anfügen nicht. HRESULT: 0x80004005. Prozess-ID (dezimal): 9956. Meldungs-ID: [0x2509]. Error: (11/01/2013 01:34:36 AM) (Source: Application Error)(User: ) Description: phoenixRC.exe0.0.0.051406972phoenixRC.exe0.0.0.051406972c0000005002cc014127401ced699694c3f0cE:\Simulatoren\PhoenixRC\phoenixRC.exeE:\Simulatoren\PhoenixRC\phoenixRC.exe623d0061-428d-11e3-b6dd-003018af12c2 Error: (10/30/2013 00:04:02 PM) (Source: Application Error)(User: ) Description: Mail.exe6.10.0.54faba5f4ntdll.dll6.1.7601.18247521ea8e7c0000005000343e61c6c01ced55f907d6a9dC:\Program Files (x86)\T-Online\T-Online_Software_6\eMail\Mail.exeC:\Windows\SysWOW64\ntdll.dllfbb50972-4152-11e3-b718-003018af12c2 Error: (10/30/2013 00:03:59 PM) (Source: Application Error)(User: ) Description: Mail.exe6.10.0.54faba5f4ntdll.dll6.1.7601.18247521ea8e7c00000050002e3be1c6c01ced55f907d6a9dC:\Program Files (x86)\T-Online\T-Online_Software_6\eMail\Mail.exeC:\Windows\SysWOW64\ntdll.dllf9d8f63b-4152-11e3-b718-003018af12c2 Error: (10/29/2013 07:31:03 PM) (Source: Application Error)(User: ) Description: Mail.exe6.10.0.54faba5f4dao360.dll3.60.9756.049246e49c00000050006a113151401ced4d4d208a310C:\Program Files (x86)\T-Online\T-Online_Software_6\eMail\Mail.exeC:\Program Files (x86)\Common Files\Microsoft Shared\DAO\dao360.dll439b998e-40c8-11e3-b95c-003018af12c2 Error: (10/29/2013 07:30:58 PM) (Source: Application Error)(User: ) Description: Mail.exe6.10.0.54faba5f4dao360.dll3.60.9756.049246e49c00000050006a113151401ced4d4d208a310C:\Program Files (x86)\T-Online\T-Online_Software_6\eMail\Mail.exeC:\Program Files (x86)\Common Files\Microsoft Shared\DAO\dao360.dll40c3347b-40c8-11e3-b95c-003018af12c2 CodeIntegrity Errors: =================================== Date: 2013-06-18 12:08:35.913 Description: Windows konnte die Abbildintegrität der Datei "\Device\CdRom0\S1234564.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-06-18 12:08:35.772 Description: Windows konnte die Abbildintegrität der Datei "\Device\CdRom0\S1234564.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-06-18 12:07:33.407 Description: Windows konnte die Abbildintegrität der Datei "\Device\CdRom0\S1234564.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-06-18 12:07:33.266 Description: Windows konnte die Abbildintegrität der Datei "\Device\CdRom0\S1234564.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-06-18 12:06:08.260 Description: Windows konnte die Abbildintegrität der Datei "\Device\CdRom0\S1234564.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-06-18 12:06:08.120 Description: Windows konnte die Abbildintegrität der Datei "\Device\CdRom0\S1234564.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-06-18 12:02:21.217 Description: Windows konnte die Abbildintegrität der Datei "\Device\CdRom0\S1234564.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-06-18 12:02:21.076 Description: Windows konnte die Abbildintegrität der Datei "\Device\CdRom0\S1234564.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 38% Total physical RAM: 4094.49 MB Available physical RAM: 2522.87 MB Total Pagefile: 10592.67 MB Available Pagefile: 8760.32 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: (Win 7 HomePremium) (Fixed) (Total:146.48 GB) (Free:101.5 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (Eisenbahn ) (Fixed) (Total:244.14 GB) (Free:184.08 GB) NTFS Drive e: (Daten ) (Fixed) (Total:488.28 GB) (Free:354.02 GB) NTFS Drive f: (Big Data ) (Fixed) (Total:984.11 GB) (Free:762.72 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 1863 GB) (Disk ID: 5077DC26) Partition 1: (Active) - (Size=146 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=244 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=488 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=984 GB) - (Type=05) ==================== End Of Log ============================ FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 31-10-2013 Ran by Asus Eee Pc (administrator) on ASUSEEEPC-PC on 07-11-2013 22:14:00 Running from C:\Users\Asus Eee Pc\Desktop Microsoft Windows 7 Starter Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (NVIDIA Corporation) C:\windows\system32\nvvsvc.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (Microsoft Corporation) C:\windows\system32\WLANExt.exe () C:\Windows\System32\AsusService.exe (Microsoft Corporation.) C:\Program Files\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation) C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Deutsche Telekom AG) C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe (Secunia) C:\Program Files\Secunia\PSI\PSIA.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe () C:\ExpressGateUtil\VAWinService.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe (NVIDIA Corporation) C:\windows\system32\nvvsvc.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (ASUS) C:\Windows\AsScrPro.exe (ASUSTeK Computer Inc.) C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe () C:\Program Files\ASUS\Eee Docking\Eee Docking.exe (ASUSTeK Computer Inc.) C:\Program Files\EeePC\HotkeyService\HotkeyService.exe (AsusTek Computer Inc.) C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe (ASUS) C:\Program Files\EeePC\CapsHook\CapsHook.exe (ASUSTeK Computer Inc.) C:\Program Files\ASUS\SHE\SuperHybridEngine.exe (Boingo Wireless, Inc.) C:\Program Files\Boingo\Boingo Wi-Fi\Boingo Wi-Fi.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cistray.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe () C:\ExpressGateUtil\VAWinAgent.exe (Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Nullsoft, Inc.) C:\Program Files\Winamp\winampa.exe (CyberLink Corp.) C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe (cyberlink) C:\Program Files\CyberLink\Shared files\brs.exe (CyberLink) C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe (RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (BillP Studios) C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Secunia) C:\Program Files\Secunia\PSI\psi_tray.exe (Rainy) C:\Program Files\Rainlendar\Rainlendar.exe (Intel Corporation) C:\windows\system32\igfxsrvc.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ETDWare] - C:\Program Files\Elantech\ETDCtrl.exe [1813800 2011-04-13] (ELAN Microelectronics Corp.) HKLM\...\Run: [EeeSplendidAgent] - C:\Program Files\ASUS\EPC\EeeSplendid\AsAgent.exe HKLM\...\Run: [ASUS Screen Saver Protector] - C:\Windows\AsScrPro.exe [3058304 2010-09-02] (ASUS) HKLM\...\Run: [HotkeyMon] - C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe [95744 2010-09-02] (ASUSTeK Computer Inc.) HKLM\...\Run: [HotkeyService] - C:\Program Files\EeePC\HotkeyService\HotkeyService.exe [1245104 2010-09-03] (ASUSTeK Computer Inc.) HKLM\...\Run: [SuperHybridEngine] - C:\Program Files\ASUS\SHE\SuperHybridEngine.exe [425400 2011-08-01] (ASUSTeK Computer Inc.) HKLM\...\Run: [LiveUpdate] - C:\Program Files\ASUS\LiveUpdate\LiveUpdate.exe [1095080 2011-07-13] (AsusTek Computer Inc.) HKLM\...\Run: [CapsHook] - C:\Program Files\EeePC\CapsHook\CapsHook.exe [445344 2010-05-29] (ASUS) HKLM\...\Run: [Eee Docking] - C:\Program Files\ASUS\Eee Docking\Eee Docking.exe [414384 2010-06-10] () HKLM\...\Run: [GraphicsSwitch] - C:\Program Files\ASUS\GraphicsSwitch\GPUStatusMonitor.exe [205304 2010-08-19] (AsusTek Computer Inc.) HKLM\...\Run: [HotKeysCmds] - C:\windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [OOBESetup] - C:\Program Files\ASUS\OOBERegBackup\OOBERegBackup.exe [334848 2009-12-11] (ASUSTeK Computer Inc.) HKLM\...\Run: [UCam_Menu] - C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.) HKLM\...\Run: [Boingo Wi-Fi] - C:\Program Files\Boingo\Boingo Wi-Fi\Boingo.lnk [2429 2013-06-01] () HKLM\...\Run: [ASUSPRP] - C:\Program Files\ASUS\APRP\aprp.exe [2018032 2010-09-02] (ASUSTek Computer Inc.) HKLM\...\Run: [COMODO Internet Security] - C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1576152 2013-10-20] (COMODO) HKLM\...\Run: [ASUSWebStorage] - C:\Program Files\ASUS\ASUS WebStorage\\AsusWSPanel.exe [737104 2011-07-29] (ecareme) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [10082920 2011-05-23] (Realtek Semiconductor) HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe [186904 2009-06-04] (Intel Corporation) HKLM\...\Run: [VAWinAgent] - C:\ExpressGateUtil\VAWinAgent.exe [45448 2012-01-12] () HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [1813800 2011-04-13] (ELAN Microelectronics Corp.) HKLM\...\Run: [SDTray] - C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [3830224 2013-05-16] (Safer-Networking Ltd.) HKLM\...\Run: [WinampAgent] - C:\Program Files\Winamp\winampa.exe [74752 2012-06-20] (Nullsoft, Inc.) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM\...\Run: [RemoteControl10] - C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.) HKLM\...\Run: [BDRegion] - C:\Program Files\CyberLink\Shared files\brs.exe [78312 2012-05-09] (cyberlink) HKLM\...\Run: [CLMLServer] - C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe [107816 2011-03-09] (CyberLink) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) HKLM\...\Run: [TkBellExe] - C:\Program Files\Real\RealPlayer\Update\realsched.exe [295512 2013-09-06] (RealNetworks, Inc.) Winlogon\Notify\SDWinLogon: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [Spybot-S&D Cleaning] - C:\Program Files\Spybot - Search & Destroy 2\SDCleaner.exe [3642312 2013-05-16] (Safer-Networking Ltd.) HKCU\...\Run: [WinPatrol] - C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe [436800 2013-07-15] (BillP Studios) HKCU\...\Policies\Explorer: [NoRecentDocsHistory] 1 HKCU\...\Policies\Explorer: [NoRecentDocsMenu] 1 HKCU\...\Policies\Explorer: [NoRecentDocsNetHood] 1 HKU\Default\...\RunOnce: [Reboot] - C:\Windows\Reboot.exe [ 2010-08-11] (AsusTek Computer Inc.) HKU\Default\...\RunOnce: [AskScreensaver] - C:\Program Files\ASUS\AsusScreensaver\AsusScreensaver.exe [ 2010-08-23] (AsusTek Computer Inc.) HKU\Default User\...\RunOnce: [Reboot] - C:\Windows\Reboot.exe [ 2010-08-11] (AsusTek Computer Inc.) HKU\Default User\...\RunOnce: [AskScreensaver] - C:\Program Files\ASUS\AsusScreensaver\AsusScreensaver.exe [ 2010-08-23] (AsusTek Computer Inc.) Startup: C:\Users\Asus Eee Pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainlendar.lnk ShortcutTarget: Rainlendar.lnk -> C:\Program Files\Rainlendar\Rainlendar.exe (Rainy) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\DSL-Manager\DslMgr.exe (T-Systems Enterprise Services GmbH) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.t-online.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://eeepc.asus.com SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=MAAU&src=IE-SearchBox BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader) BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: DVDVideoSoft WebPageAdjuster Class - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.) Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} hxxp://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\Asus Eee Pc\AppData\Roaming\Mozilla\Firefox\Profiles\kbyk0wnp.default FF Homepage: hxxp://www.t-online.de/ FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin: @real.com/nppl3260;version= - c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpplugin;version= - c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer) FF Plugin: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.6 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.0.8 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.0 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: fdm_ffext - C:\Users\Asus Eee Pc\AppData\Roaming\Mozilla\Firefox\Profiles\kbyk0wnp.default\Extensions\fdm_ffext@freedownloadmanager.org FF HKLM\...\Firefox\Extensions: [{ACAA314B-EEBA-48e4-AD47-84E31C44796C}] - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff\ FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff\ FF HKLM\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ Chrome: ======= CHR HomePage: hxxp://www.t-online.de/ CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\30.0.1599.101\pdf.dll () CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll (RealNetworks, Inc.) CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (RealPlayer Download Plugin) - C:\Program Files\Mozilla Firefox\plugins\nprpplugin.dll (RealPlayer) CHR Plugin: (Winamp Application Detector) - C:\Program Files\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.) CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files\Google\Update\\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U21) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Plugin: (VLC Web Plugin) - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Plugin: (Windows Live\u00AE Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (RealNetworks(tm) RealDownloader Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.) CHR Plugin: (RealNetworks(tm) RealDownloader HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.) CHR Plugin: (RealNetworks(tm) RealDownloader PepperFlashVideoShim Plug-In (32-bit) ) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.) CHR Plugin: (RealDownloader Plugin) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader) CHR Plugin: (Java Deployment Toolkit - C:\windows\system32\npDeployJava1.dll No File CHR Extension: (Google Docs) - C:\Users\ASUSEE~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\ASUSEE~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\ASUSEE~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\ASUSEE~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\ CHR Extension: (RealDownloader) - C:\Users\ASUSEE~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.3_0 CHR Extension: (DVDVideoSoft Browser Extension) - C:\Users\ASUSEE~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\ CHR Extension: (Chrome In-App Payments service) - C:\Users\ASUSEE~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\ CHR Extension: (Gmail) - C:\Users\ASUSEE~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx ========================== Services (Whitelisted) ================= R2 AsusService; C:\Windows\System32\AsusService.exe [219136 2009-08-19] () S2 CLKMSVC10_B91CB6D3; C:\Program Files\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [242664 2012-05-09] (CyberLink) R2 cmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [4832192 2013-10-20] (COMODO) S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [131288 2013-09-24] (COMODO) S3 IEEtwCollectorService; C:\Windows\system32\IEEtwCollector.exe [108032 2013-11-07] (Microsoft Corporation) R2 Netzmanager Service; C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [2635776 2012-07-20] (Deutsche Telekom AG) R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] () R2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [1817560 2013-05-16] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [1033688 2013-05-16] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2013-05-15] (Safer-Networking Ltd.) R2 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [1227800 2013-04-18] (Secunia) S2 Secunia Update Agent; C:\Program Files\Secunia\PSI\sua.exe [659992 2013-04-18] (Secunia) S3 TDslMgrService; C:\Program Files\DSL-Manager\DslMgrSvc.exe [307200 2008-10-23] (T-Systems Enterprise Services GmbH) R2 VideAceWindowsService; C:\ExpressGateUtil\VAWinService.exe [91464 2011-03-25] () ==================== Drivers (Whitelisted) ==================== R1 AsUpIO; C:\Windows\System32\drivers\AsUpIO.sys [11832 2011-02-09] () S3 btwampfl; C:\Windows\System32\drivers\btwampfl.sys [293928 2010-05-21] (Broadcom Corporation.) R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [20072 2013-09-24] (COMODO) R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [582936 2013-09-24] (COMODO) R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [44752 2013-09-24] (COMODO) R1 DslMNLwf; C:\Windows\System32\DRIVERS\dslmnlwf.sys [16448 2007-08-01] (T-Systems Enterprise Services GmbH) R3 ETD; C:\Windows\System32\DRIVERS\ETD.sys [119592 2011-04-13] (ELAN Microelectronics Corp.) S3 FTDIBUS; C:\Windows\System32\drivers\ftdibus.sys [65896 2013-07-25] (FTDI Ltd.) R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [85464 2013-09-24] (COMODO) R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [13880 2009-07-20] ( ) S3 mbamchameleon; C:\windows\system32\drivers\mbamchameleon.sys [75992 2013-10-31] (Malwarebytes Corporation) R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_x86.sys [16024 2013-04-18] (Secunia) S3 silabenm; C:\Windows\System32\DRIVERS\silabenm.sys [47176 2011-02-08] (Silicon Laboratories) S3 silabser; C:\Windows\System32\DRIVERS\silabser.sys [58496 2011-02-08] (Silicon Laboratories) S3 TelekomNM3; C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM3.sys [35040 2010-09-16] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-07 22:12 - 2013-11-07 22:12 - 00000000 ____D C:\FRST 2013-11-07 22:11 - 2013-11-07 22:10 - 01089445 _____ (Farbar) C:\Users\Asus Eee Pc\Desktop\FRST.exe 2013-11-07 21:51 - 2013-11-07 21:51 - 17142784 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 11220992 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 04240384 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2013-11-07 21:51 - 2013-11-07 21:51 - 02166272 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 01926656 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2013-11-07 21:51 - 2013-11-07 21:51 - 01818112 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 01156608 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 01051136 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00703488 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00646144 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe 2013-11-07 21:51 - 2013-11-07 21:51 - 00645120 _____ (Microsoft Corporation) C:\windows\system32\jsIntl.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00616104 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dat 2013-11-07 21:51 - 2013-11-07 21:51 - 00610304 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00553472 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00523776 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00454656 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00440832 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00367104 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00337408 _____ (Microsoft Corporation) C:\windows\system32\html.iec 2013-11-07 21:51 - 2013-11-07 21:51 - 00244736 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00238288 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00233472 _____ (Microsoft Corporation) C:\windows\system32\url.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00208896 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2013-11-07 21:51 - 2013-11-07 21:51 - 00208384 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00194048 _____ (Microsoft Corporation) C:\windows\system32\elshyph.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00182272 _____ (Microsoft Corporation) C:\windows\system32\msls31.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00164864 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00151552 _____ (Microsoft Corporation) C:\windows\system32\iexpress.exe 2013-11-07 21:51 - 2013-11-07 21:51 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\wextract.exe 2013-11-07 21:51 - 2013-11-07 21:51 - 00127488 _____ (Microsoft Corporation) C:\windows\system32\occache.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00116736 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00112128 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2013-11-07 21:51 - 2013-11-07 21:51 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\IEAdvpack.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00108032 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2013-11-07 21:51 - 2013-11-07 21:51 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00083456 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00074240 _____ (Microsoft Corporation) C:\windows\system32\SetIEInstalledDate.exe 2013-11-07 21:51 - 2013-11-07 21:51 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe 2013-11-07 21:51 - 2013-11-07 21:51 - 00069632 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00069120 _____ (Microsoft Corporation) C:\windows\system32\icardie.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx 2013-11-07 21:51 - 2013-11-07 21:51 - 00061952 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00061952 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\pngfilt.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\mshtmler.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\msfeedsbs.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00036352 _____ (Microsoft Corporation) C:\windows\system32\imgutil.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00034816 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00032768 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\licmgr10.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\mshta.exe 2013-11-07 21:51 - 2013-11-07 21:51 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\msfeedssync.exe 2013-11-07 21:51 - 2013-11-07 21:51 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2013-11-07 21:48 - 2013-11-07 22:00 - 00010155 _____ C:\windows\IE11_main.log 2013-11-07 21:01 - 2013-11-07 21:01 - 00001067 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-11-07 21:01 - 2013-11-07 21:01 - 00000000 ____D C:\Users\Asus Eee Pc\AppData\Roaming\Malwarebytes 2013-11-07 21:01 - 2013-11-07 21:01 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-11-07 21:01 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2013-10-30 18:43 - 2013-10-30 22:16 - 00000000 ____D C:\Users\Asus Eee Pc\Documents\Anwalt 2013-10-29 20:50 - 2013-10-29 20:50 - 00002569 _____ C:\Users\Public\Desktop\3GX V3.1.lnk 2013-10-29 20:50 - 2013-10-29 20:50 - 00000000 ____D C:\Program Files\ALIGN 2013-10-20 13:34 - 2013-10-31 11:21 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2013-10-20 13:34 - 2013-10-20 13:34 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-20 13:30 - 2013-10-31 11:06 - 00075992 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys 2013-10-16 16:35 - 2013-10-16 16:35 - 00000000 ____D C:\Program Files\Java 2013-10-13 03:34 - 2008-10-15 05:22 - 04379984 _____ (Microsoft Corporation) C:\windows\system32\D3DX9_40.dll 2013-10-13 03:34 - 2008-10-15 05:22 - 02036576 _____ (Microsoft Corporation) C:\windows\system32\D3DCompiler_40.dll 2013-10-13 03:34 - 2008-10-15 05:22 - 00452440 _____ (Microsoft Corporation) C:\windows\system32\d3dx10_40.dll 2013-10-13 01:00 - 2013-10-13 01:00 - 00001859 _____ C:\Users\Public\Desktop\PhoenixRC.lnk 2013-10-13 00:57 - 2013-10-13 03:42 - 00000000 ____D C:\Users\Asus Eee Pc\Documents\PhoenixRC 2013-10-13 00:57 - 2013-10-13 03:27 - 00000000 ____D C:\Program Files\PhoenixRC 2013-10-12 19:36 - 2013-10-13 04:12 - 00000000 ____D C:\Program Files\stinger 2013-10-12 18:39 - 2013-10-12 18:39 - 00000000 ____D C:\Users\Asus Eee Pc\Downloads\Sophos Virus Removal Tool 2.3 Rev.2 2013-10-12 02:44 - 2013-10-12 03:17 - 00000000 ____D C:\cce_linux 2013-10-11 22:44 - 2013-10-11 22:56 - 00000000 ____D C:\Kaspersky Rescue Disk 10.0 2013-10-11 00:55 - 2013-10-11 00:55 - 00059328 _____ C:\Users\Asus Eee Pc\Downloads\backup_config(1).exe 2013-10-09 11:13 - 2013-08-28 01:57 - 00434688 _____ (Microsoft Corporation) C:\windows\system32\scavengeui.dll 2013-10-09 11:12 - 2013-09-14 01:48 - 00338944 _____ (Microsoft Corporation) C:\windows\system32\Drivers\afd.sys 2013-10-09 11:12 - 2013-09-08 03:07 - 01294272 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys 2013-10-09 11:12 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\windows\system32\mswsock.dll 2013-10-09 11:12 - 2013-09-04 02:15 - 00258560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbhub.sys 2013-10-09 11:12 - 2013-09-04 02:14 - 00284672 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbport.sys 2013-10-09 11:12 - 2013-09-04 02:14 - 00076288 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbccgp.sys 2013-10-09 11:12 - 2013-09-04 02:14 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbehci.sys 2013-10-09 11:12 - 2013-09-04 02:14 - 00024064 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbuhci.sys 2013-10-09 11:12 - 2013-09-04 02:14 - 00006016 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbd.sys 2013-10-09 11:12 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\windows\system32\ntkrnlpa.exe 2013-10-09 11:12 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe 2013-10-09 11:12 - 2013-08-29 02:50 - 01289096 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll 2013-10-09 11:12 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\windows\system32\tdh.dll 2013-10-09 11:12 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll 2013-10-09 11:12 - 2013-08-28 02:04 - 02348544 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys 2013-10-09 11:12 - 2013-08-01 12:03 - 00729024 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgkrnl.sys 2013-10-09 11:12 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-10-09 11:12 - 2013-07-12 11:08 - 00146816 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbvideo.sys 2013-10-09 11:12 - 2013-07-12 11:07 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbcir.sys 2013-10-09 11:12 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\windows\system32\WebClnt.dll 2013-10-09 11:12 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\windows\system32\davclnt.dll 2013-10-09 11:12 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\windows\system32\comctl32.dll 2013-10-09 11:12 - 2013-07-04 10:48 - 00115712 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxdav.sys 2013-10-09 11:12 - 2013-06-25 23:56 - 00527064 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Wdf01000.sys 2013-10-09 11:12 - 2013-06-06 05:52 - 00026112 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll 2013-10-09 11:12 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll 2013-10-09 11:12 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll 2013-10-09 11:12 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll 2013-10-09 11:12 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\windows\system32\atmlib.dll ==================== One Month Modified Files and Folders ======= 2013-11-07 22:12 - 2013-11-07 22:12 - 00000000 ____D C:\FRST 2013-11-07 22:11 - 2013-06-01 02:23 - 01474832 _____ C:\windows\system32\Drivers\sfi.dat 2013-11-07 22:10 - 2013-11-07 22:11 - 01089445 _____ (Farbar) C:\Users\Asus Eee Pc\Desktop\FRST.exe 2013-11-07 22:10 - 2013-06-01 10:49 - 01474418 _____ C:\windows\WindowsUpdate.log 2013-11-07 22:09 - 2009-07-25 08:50 - 01498506 _____ C:\windows\system32\PerfStringBackup.INI 2013-11-07 22:08 - 2009-07-14 05:34 - 00009696 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-07 22:08 - 2009-07-14 05:34 - 00009696 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-07 22:03 - 2013-06-01 12:14 - 00001104 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-11-07 22:02 - 2010-09-03 01:28 - 00000000 ____D C:\ProgramData\NVIDIA 2013-11-07 22:02 - 2009-07-14 05:53 - 00000006 ____H C:\windows\Tasks\SA.DAT 2013-11-07 22:02 - 2009-07-14 05:39 - 00064587 _____ C:\windows\setupact.log 2013-11-07 22:00 - 2013-11-07 21:48 - 00010155 _____ C:\windows\IE11_main.log 2013-11-07 22:00 - 2009-07-14 03:37 - 00000000 ____D C:\windows\system32\de-DE 2013-11-07 21:51 - 2013-11-07 21:51 - 17142784 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 11220992 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 04240384 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2013-11-07 21:51 - 2013-11-07 21:51 - 02166272 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 01926656 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2013-11-07 21:51 - 2013-11-07 21:51 - 01818112 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 01156608 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 01051136 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00703488 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00646144 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe 2013-11-07 21:51 - 2013-11-07 21:51 - 00645120 _____ (Microsoft Corporation) C:\windows\system32\jsIntl.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00616104 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dat 2013-11-07 21:51 - 2013-11-07 21:51 - 00610304 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00553472 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00523776 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00454656 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00440832 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00367104 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00337408 _____ (Microsoft Corporation) C:\windows\system32\html.iec 2013-11-07 21:51 - 2013-11-07 21:51 - 00244736 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00238288 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00233472 _____ (Microsoft Corporation) C:\windows\system32\url.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00208896 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2013-11-07 21:51 - 2013-11-07 21:51 - 00208384 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00194048 _____ (Microsoft Corporation) C:\windows\system32\elshyph.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00182272 _____ (Microsoft Corporation) C:\windows\system32\msls31.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00164864 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00151552 _____ (Microsoft Corporation) C:\windows\system32\iexpress.exe 2013-11-07 21:51 - 2013-11-07 21:51 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\wextract.exe 2013-11-07 21:51 - 2013-11-07 21:51 - 00127488 _____ (Microsoft Corporation) C:\windows\system32\occache.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00116736 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00112128 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2013-11-07 21:51 - 2013-11-07 21:51 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\IEAdvpack.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00108032 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2013-11-07 21:51 - 2013-11-07 21:51 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00083456 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00074240 _____ (Microsoft Corporation) C:\windows\system32\SetIEInstalledDate.exe 2013-11-07 21:51 - 2013-11-07 21:51 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe 2013-11-07 21:51 - 2013-11-07 21:51 - 00069632 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00069120 _____ (Microsoft Corporation) C:\windows\system32\icardie.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx 2013-11-07 21:51 - 2013-11-07 21:51 - 00061952 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00061952 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\pngfilt.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\mshtmler.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\msfeedsbs.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00036352 _____ (Microsoft Corporation) C:\windows\system32\imgutil.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00034816 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00032768 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\licmgr10.dll 2013-11-07 21:51 - 2013-11-07 21:51 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\mshta.exe 2013-11-07 21:51 - 2013-11-07 21:51 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\msfeedssync.exe 2013-11-07 21:51 - 2013-11-07 21:51 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2013-11-07 21:49 - 2013-07-01 22:45 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job 2013-11-07 21:28 - 2013-08-03 00:34 - 00002201 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-11-07 21:24 - 2013-06-01 12:14 - 00001108 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-11-07 21:01 - 2013-11-07 21:01 - 00001067 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-11-07 21:01 - 2013-11-07 21:01 - 00000000 ____D C:\Users\Asus Eee Pc\AppData\Roaming\Malwarebytes 2013-11-07 21:01 - 2013-11-07 21:01 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-10-31 11:21 - 2013-10-20 13:34 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2013-10-31 11:06 - 2013-10-20 13:30 - 00075992 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys 2013-10-30 23:39 - 2013-06-03 20:43 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-10-30 22:16 - 2013-10-30 18:43 - 00000000 ____D C:\Users\Asus Eee Pc\Documents\Anwalt 2013-10-30 19:18 - 2013-09-29 01:23 - 00001033 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-10-30 19:18 - 2013-08-16 22:02 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-10-29 20:52 - 2010-09-02 22:37 - 00032564 _____ C:\windows\DPINST.LOG 2013-10-29 20:50 - 2013-10-29 20:50 - 00002569 _____ C:\Users\Public\Desktop\3GX V3.1.lnk 2013-10-29 20:50 - 2013-10-29 20:50 - 00000000 ____D C:\Program Files\ALIGN 2013-10-25 19:23 - 2013-06-14 12:35 - 00000000 ____D C:\Users\Asus Eee Pc\AppData\Roaming\vlc 2013-10-20 13:34 - 2013-10-20 13:34 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-17 09:19 - 2013-06-01 23:20 - 00239253 _____ C:\Users\Asus Eee Pc\AppData\Local\census.cache 2013-10-17 09:19 - 2013-06-01 23:19 - 00103772 _____ C:\Users\Asus Eee Pc\AppData\Local\ars.cache 2013-10-16 16:35 - 2013-10-16 16:35 - 00000000 ____D C:\Program Files\Java 2013-10-15 00:51 - 2013-06-02 14:38 - 00000000 ____D C:\Program Files\Free Download Manager 2013-10-15 00:50 - 2013-06-02 14:38 - 00000000 ____D C:\Users\Asus Eee Pc\AppData\Roaming\Free Download Manager 2013-10-13 04:12 - 2013-10-12 19:36 - 00000000 ____D C:\Program Files\stinger 2013-10-13 03:42 - 2013-10-13 00:57 - 00000000 ____D C:\Users\Asus Eee Pc\Documents\PhoenixRC 2013-10-13 03:27 - 2013-10-13 00:57 - 00000000 ____D C:\Program Files\PhoenixRC 2013-10-13 03:27 - 2013-06-01 01:58 - 00000000 ____D C:\Users\Asus Eee Pc\AppData\Local\Adobe 2013-10-13 01:00 - 2013-10-13 01:00 - 00001859 _____ C:\Users\Public\Desktop\PhoenixRC.lnk 2013-10-12 18:39 - 2013-10-12 18:39 - 00000000 ____D C:\Users\Asus Eee Pc\Downloads\Sophos Virus Removal Tool 2.3 Rev.2 2013-10-12 03:17 - 2013-10-12 02:44 - 00000000 ____D C:\cce_linux 2013-10-11 22:56 - 2013-10-11 22:44 - 00000000 ____D C:\Kaspersky Rescue Disk 10.0 2013-10-11 00:55 - 2013-10-11 00:55 - 00059328 _____ C:\Users\Asus Eee Pc\Downloads\backup_config(1).exe 2013-10-09 18:57 - 2009-07-14 03:37 - 00000000 ____D C:\windows\rescache 2013-10-09 18:22 - 2009-07-14 03:37 - 00000000 ____D C:\windows\Microsoft.NET 2013-10-09 17:53 - 2013-07-01 22:45 - 00692616 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerApp.exe 2013-10-09 17:53 - 2013-06-03 01:46 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerCPLApp.cpl 2013-10-09 11:50 - 2010-09-02 22:54 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-10-09 11:50 - 2009-07-14 05:33 - 00297440 _____ C:\windows\system32\FNTCACHE.DAT 2013-10-09 11:34 - 2013-07-21 21:08 - 00000000 ____D C:\windows\system32\MRT 2013-10-09 11:27 - 2013-06-01 13:22 - 78106760 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe Some content of TEMP: ==================== C:\Users\Asus Eee Pc\AppData\Local\Temp\lowproc.exe C:\Users\Asus Eee Pc\AppData\Local\Temp\stubhelper.dll ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-13 18:05 ==================== End Of Log ============================ --- --- --- --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 31-10-2013 Ran by Asus Eee Pc at 2013-11-07 22:18:01 Running from C:\Users\Asus Eee Pc\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: COMODO Antivirus (Enabled - Up to date) {B74CC7D2-B407-E1DC-1033-DD315BCDC8C8} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} AS: COMODO Antivirus (Enabled - Up to date) {0C2D2636-923D-EE52-2A83-E643204A8275} FW: COMODO Firewall (Enabled) {8F7746F7-FE68-E084-3B6C-7404A51E8FB3} ==================== Installed Programs ====================== 32 Bit HP CIO Components Installer (Version: 1.1.0) 3GX (Version: 3.03.2101) Acrobat.com (Version: 1.6.65) Adobe AIR (Version: Adobe Flash Player 11 ActiveX (Version: 11.9.900.117) Adobe Flash Player 11 Plugin (Version: 11.9.900.117) Adobe Reader XI (11.0.05) - Deutsch (Version: 11.0.05) Apple Application Support (Version: 2.3.4) Apple Software Update (Version: ASUS WebStorage (Version: AsusScreensaver (Version: 1.03) ASUSUpdate for Eee PC (Version: 1.04.01) AsusVibe2.0 (Version: Atheros Client Installation Program (Version: 7.0) Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (Version: Bing Bar (Version: 7.0.850.0) Boingo Wi-Fi (Version: 1.7.0048) Broadcom Wireless Network Adapter (Version: 1.00.0000) CapsHook (Version: COMODO Internet Security Premium (Version: 6.1.13008.2801) CPUID CPU-Z 1.64.0 CrystalDiskInfo 5.6.2 (Version: 5.6.2) CVE-2013-3893 CyberLink Media Suite 10 (Version: 10.0) CyberLink Media Suite 10 (Version: 10.2021) CyberLink Power2Go 7 (Version: CyberLink PowerDVD 10 (Version: 10.0.4125.52) CyberLink YouCam (Version: 2.0.3718a) Defraggler (Version: 2.14) DHTML Editing Component (Version: 6.02.0001) Disktrix UltimateDefrag DSL-Manager ebi.BookReader3J (Version: 3.75.14) E-Cam (Version: Eee Docking 3.8.1 (Version: 3.8.1) EeeSplendid (Version: ETDWare PS/2-X86 (Version: ExpressGateCloud (Version: FontResizer (Version: 1.01.0011) Free Download Manager 3.9.3 Free YouTube Download version (Version: Google Chrome (Version: 30.0.1599.101) Google Earth (Version: Google Update Helper (Version: GraphicsSwitch (Version: 1.4) Hotkey Service (Version: 1.32) Intel(R) Graphics Media Accelerator Driver (Version: Intel® Matrix Storage Manager IrfanView (remove only) (Version: 4.36) Java 7 Update 45 (Version: 7.0.450) Junk Mail filter update (Version: 14.0.8089.726) Junsi USB to UART Bridge(Windows XP/2003/Vista/7) (Driver Removal) LiveUpdate (Version: 1.29) LocaleMe (Version: 1.3) LogView V2 (Version: LogView V2 2) LogView V2 2 (HKCU Version: 2) Malwarebytes Anti-Malware Version (Version: Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6012.5000) Microsoft Choice Guard (Version: Microsoft Rechner-Plus (Version: 1.0.0) Microsoft Silverlight (Version: 5.1.20913.0) Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000) Microsoft Sync Framework Runtime Native v1.0 (x86) (Version: 1.0.1215.0) Microsoft Sync Framework Services Native v1.0 (x86) (Version: 1.0.1215.0) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (Version: 9.0.30411) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft WSE 3.0 Runtime (Version: 3.0.5305.0) Mozilla Firefox 25.0 (x86 de) (Version: 25.0) Mozilla Maintenance Service (Version: 25.0) MSVCRT (Version: 14.0.1468.721) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0) MSXML 4.0 SP3 Parser (KB2758694) (Version: 4.30.2117.0) MSXML 4.0 SP3 Parser (KB973685) (Version: 4.30.2107.0) Netzmanager (Version: 1.071) NirSoft WirelessNetView NVIDIA Display Control Panel (Version: NVIDIA Drivers (Version: NVIDIA HD-Audiotreiber (Version: NVIDIA Install Application (Version: 2.1002.109.718) NVIDIA Stereoscopic 3D Driver (Version: OOBERegBackup OpenOffice 4.0.0 (Version: 4.00.9702) Opera 12.15 (Version: 12.15.1748) PhoenixRC (Version: 2.00.10) QuickTime (Version: Rainlendar (remove only) Ralink RT2860 Wireless LAN Card (Version: RealDownloader (Version: 1.3.3) RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0) RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0) RealPlayer (Version: 16.0.3) Realtek High Definition Audio Driver (Version: RealUpgrade 1.1 (Version: 1.1.0) ScreenSaverPatch Secunia PSI ( (Version: Spybot - Search & Destroy (Version: 2.1.19) Streamripper (Remove only) Super Hybrid Engine (Version: 2.19) syncables desktop SE (Version: 5.5.746.11492) TechPowerUp GPU-Z T-Online 6.0 Trend Micro Titanium (Version: 1.0) TUGZip 3.5 Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (Version: 3) USBFast (Version: VLC media player 2.1.0 (Version: 2.1.0) WIDCOMM Bluetooth Software (Version: Winamp (Version: 5.63 ) Winamp Erkennungs-Plug-in (HKCU Version: Windows Live Anmelde-Assistent (Version: 5.000.818.5) Windows Live Call (Version: 14.0.8064.0206) Windows Live Communications Platform (Version: 14.0.8064.206) Windows Live Essentials (Version: 14.0.8089.0726) Windows Live Essentials (Version: 14.0.8089.726) Windows Live Family Safety (Version: 14.0.8093.805) Windows Live Fotogalerie (Version: 14.0.8081.709) Windows Live Mail (Version: 14.0.8089.0726) Windows Live Messenger (Version: 14.0.8089.0726) Windows Live Sync (Version: 14.0.8089.726) Windows Live Writer (Version: 14.0.8089.0726) Windows Live-Uploadtool (Version: 14.0.8014.1029) Windows-Treiberpaket - FTDI CDM Driver Package (10/22/2009 2.06.00) (Version: 10/22/2009 2.06.00) WinPatrol (Version: 28.5.2013.0) xp-AntiSpy 3.98-2 ==================== Restore Points ========================= 16-10-2013 15:37:24 Windows Update 17-10-2013 03:00:24 Removed Java 7 Update 45 19-10-2013 17:33:29 Windows Update 24-10-2013 18:07:03 Windows Update 29-10-2013 19:36:01 Removed 3GX 29-10-2013 19:40:23 Removed 3GX 29-10-2013 19:49:55 Installed 3GX 29-10-2013 20:18:09 Windows Update 29-10-2013 20:24:09 Windows Update 07-11-2013 20:00:16 Windows Update 07-11-2013 20:49:21 Windows Modules Installer 07-11-2013 20:50:06 Windows Modules Installer ==================== Hosts content: ========================== 2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {082ECE51-CF95-4EF5-A839-5D5B482688DB} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-673250275-1065294829-2973658958-1000 => C:\Program Files\Real\RealUpgrade\realupgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {23AB4958-B541-43EE-8A37-9F43BC450266} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe Task: {29A7A44F-0816-4AF8-901F-5BDB085F1209} - System32\Tasks\{981B645E-E917-4B70-83C1-4343AD52199D} => D:\A Downloads Asus eee pc 1015pn\Astra2100u\Diese nehmen-vs XP treiber375-ok\vs375u\DISK1\VSSETUP.EXE Task: {2A8002EF-DA46-4587-BAA4-772FC5E7A9E4} - System32\Tasks\{560D8678-843B-4F11-8788-502606510960} => D:\A Downloads Asus eee pc 1015pn\Astra2100u\Diese nehmen-vs XP treiber375-ok\vs375u\DISK1\VSSETUP.EXE Task: {3B104D48-6CB2-4E67-A417-0119F7C86B0D} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe Task: {41BD9CBE-3A89-453D-8CBE-CD7BFD2F7C52} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-06-01] (Google Inc.) Task: {4EEF6488-0779-437F-8361-BC3A32EE79F4} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2013-09-24] (COMODO) Task: {6001D2EA-FD38-4222-A621-F18C164F4358} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-06-01] (Google Inc.) Task: {6BE6240D-1519-4B09-B238-DA0897B7EB7B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-09] (Adobe Systems Incorporated) Task: {786471E3-D8C2-45ED-9CE0-B694148E5FB4} - System32\Tasks\COMODO\COMODO Welcome {CEB54B45-2B5E-4FF5-9223-6735CD80FE69} => C:\Program Files\COMODO\COMODO Internet Security\cis.exe [2013-10-20] (COMODO) Task: {93259AC9-929E-4AE1-B000-D5DA9F014AEE} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-673250275-1065294829-2973658958-1000 => C:\Program Files\Real\RealUpgrade\realupgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {96DD6F41-4FB4-4889-B1D2-C4C933923967} - System32\Tasks\{093B5337-47A9-41EB-9C40-1633EA0FDBE6} => D:\A Downloads Asus eee pc 1015pn\Astra2100u\Diese nehmen-vs XP treiber375-ok\vs375u\DISK1\VSSETUP.EXE Task: {9ECAA39B-2B7C-4282-83D0-D6F70B4AFDF7} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files\Spybot - Search & Destroy 2\SDImmunize.exe Task: {AA9C7A02-18A1-4928-ABD2-868A49B978FB} - System32\Tasks\COMODO\COMODO Scan {F140D794-60B6-4F00-9235-D6457AA25B22} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2013-09-24] (COMODO) Task: {AB714DE1-39D4-4DE5-8362-B29F9F3BF97E} - System32\Tasks\{FB334746-1C96-42F9-A325-A80FBA5BE87D} => D:\A Downloads Asus eee pc 1015pn\Astra2100u\Diese nehmen-vs XP treiber375-ok\vs375u\DISK1\VSSETUP.EXE Task: {B1101B57-8CC8-40FB-AD37-9F80F2898ED6} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2010-11-20] (Microsoft Corporation) Task: {B90B4797-A414-4A55-8A97-D79EB384D62E} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {C314CAEC-AC9D-4AF5-AE4C-712702D39D26} - System32\Tasks\COMODO\COMODO Cache Builder {0FB77674-7905-4F34-A362-C5A9A26F8CF9} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2013-09-24] (COMODO) Task: {C417F11D-93A3-4491-8857-F4AC27D13754} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-11] (Microsoft Corporation) Task: {F49A525D-5772-4ACF-919C-02C82385E8E4} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2013-09-24] (COMODO) Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2010-09-02 12:08 - 2010-09-02 12:08 - 00118784 _____ () C:\Program Files\ASUS\ASUS WebStorage\\AsusWSShellExt.dll 2010-05-21 12:42 - 2010-05-21 12:42 - 00132384 _____ () C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll 2013-06-02 20:48 - 2013-05-16 09:55 - 00113496 _____ () C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl 2013-06-02 20:48 - 2013-05-16 09:55 - 00416600 _____ () C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl 2013-06-02 20:48 - 2013-05-16 09:55 - 00161112 _____ () C:\Program Files\Spybot - Search & Destroy 2\snlFileFormats150.bpl 2011-03-09 13:21 - 2011-03-09 13:21 - 00619816 _____ () C:\Program Files\CyberLink\Power2Go\CLMediaLibrary.dll 2011-03-09 13:21 - 2011-03-09 13:21 - 00013096 _____ () C:\Program Files\CyberLink\Power2Go\CLMLSvcPS.dll 2013-06-02 23:21 - 2013-07-15 18:29 - 00620718 ____N () C:\Program Files\BillP Studios\WinPatrol\sqlite3.dll 2005-07-22 16:14 - 2005-07-22 15:14 - 00557056 _____ () C:\Program Files\Rainlendar\Rainlendar.dll 2005-07-20 16:14 - 2005-07-20 15:14 - 00172032 _____ () C:\Program Files\Rainlendar\Plugins\iCalPlugin.dll 2005-07-20 16:14 - 2005-07-20 15:14 - 00061440 _____ () C:\Program Files\Rainlendar\Plugins\IniFormatPlugin.dll 2005-07-20 16:14 - 2005-07-20 15:14 - 00045056 _____ () C:\Program Files\Rainlendar\Plugins\OutlookPlugin.dll 2005-07-20 16:14 - 2005-07-20 15:14 - 00045056 _____ () C:\Program Files\Rainlendar\Plugins\ServerPlugin.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:AB689DEA ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (10/29/2013 08:40:02 PM) (Source: MsiInstaller) (User: AsusEeePc-PC) Description: Product: 3GX -- Error 1730. You must be an Administrator to remove this application. To remove this application, you can log on as an Administrator, or contact your technical support group for assistance. Error: (10/19/2013 07:09:34 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version=""1". Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version=""" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (10/17/2013 00:37:45 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version=""1". Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version=""" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (10/17/2013 10:07:44 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version=""1". Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version=""" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (10/13/2013 09:10:58 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d6727a7 Name des fehlerhaften Moduls: SHELL32.dll, Version: 6.1.7601.18222, Zeitstempel: 0x51f1d731 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0004b1e8 ID des fehlerhaften Prozesses: 0x%9 Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Error: (10/13/2013 03:30:25 AM) (Source: MsiInstaller) (User: AsusEeePc-PC) Description: Produkt: Adobe Reader 9.3.4 - Update "Adobe Reader 9.3.2 - CPSID_53951" konnte nicht installiert werden. Fehlercode 1603. Weitere Informationen sind in der Protokolldatei C:\Users\ASUSEE~1\AppData\Local\Temp\MSI502d5.LOG enthalten. Error: (10/13/2013 03:30:25 AM) (Source: MsiInstaller) (User: AsusEeePc-PC) Description: Produkt: Adobe Reader 9.3.4 - Update "Adobe Reader 9.3.3 - CPSID_83708" konnte nicht installiert werden. Fehlercode 1603. Weitere Informationen sind in der Protokolldatei C:\Users\ASUSEE~1\AppData\Local\Temp\MSI502d5.LOG enthalten. Error: (10/13/2013 03:30:25 AM) (Source: MsiInstaller) (User: AsusEeePc-PC) Description: Produkt: Adobe Reader 9.3.4 - Update "Adobe Reader 9.3.4 - CPSID_83708" konnte nicht installiert werden. Fehlercode 1603. Weitere Informationen sind in der Protokolldatei C:\Users\ASUSEE~1\AppData\Local\Temp\MSI502d5.LOG enthalten. Error: (10/13/2013 03:30:22 AM) (Source: MsiInstaller) (User: AsusEeePc-PC) Description: Product: Adobe Reader 9.3.4 -- Setup has detected that you already have a more functional product installed. Setup will now terminate. Error: (10/12/2013 08:12:55 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d6727a7 Name des fehlerhaften Moduls: SHELL32.dll, Version: 6.1.7601.18222, Zeitstempel: 0x51f1d731 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0004b1e8 ID des fehlerhaften Prozesses: 0x%9 Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 System errors: ============= Error: (11/07/2013 10:02:25 PM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (11/07/2013 09:07:12 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Definition Update for Windows Defender - KB915597 (Definition 1.161.1423.0) Error: (11/07/2013 08:55:16 PM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (10/31/2013 01:22:54 PM) (Source: DCOM) (User: ) Description: {995C996E-D918-4A8C-A302-45719A6F4EA7} Error: (10/31/2013 01:12:54 PM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (10/31/2013 11:47:57 AM) (Source: mbamchameleon) (User: ) Description: C0000034 Error: (10/31/2013 11:47:56 AM) (Source: mbamchameleon) (User: ) Description: C0000034 Error: (10/31/2013 11:47:56 AM) (Source: mbamchameleon) (User: ) Description: OGRAM FILES\SPYBOT - SEARCH & DESTROY 2\SDWSCSVC.EXE Error: (10/31/2013 11:47:56 AM) (Source: mbamchameleon) (User: ) Description: C0000034 Error: (10/31/2013 11:47:55 AM) (Source: mbamchameleon) (User: ) Description: C0000034 Microsoft Office Sessions: ========================= Error: (10/29/2013 08:40:02 PM) (Source: MsiInstaller)(User: AsusEeePc-PC) Description: Product: 3GX -- Error 1730. You must be an Administrator to remove this application. To remove this application, you can log on as an Administrator, or contact your technical support group for assistance.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (10/19/2013 07:09:34 PM) (Source: SideBySide)(User: ) Description: rpshellextension.1.0,language="*",type="win32",version=""C:\Windows\Installer\{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}\recordingmanager.exe Error: (10/17/2013 00:37:45 PM) (Source: SideBySide)(User: ) Description: rpshellextension.1.0,language="*",type="win32",version=""C:\Windows\Installer\{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}\recordingmanager.exe Error: (10/17/2013 10:07:44 AM) (Source: SideBySide)(User: ) Description: rpshellextension.1.0,language="*",type="win32",version=""C:\Windows\Installer\{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}\recordingmanager.exe Error: (10/13/2013 09:10:58 PM) (Source: Application Error)(User: ) Description: Explorer.EXE6.1.7601.175674d6727a7SHELL32.dll6.1.7601.1822251f1d731c00000050004b1e8 Error: (10/13/2013 03:30:25 AM) (Source: MsiInstaller)(User: AsusEeePc-PC) Description: Adobe Reader 9.3.4Adobe Reader 9.3.2 - CPSID_539511603C:\Users\ASUSEE~1\AppData\Local\Temp\MSI502d5.LOG(NULL)(NULL) Error: (10/13/2013 03:30:25 AM) (Source: MsiInstaller)(User: AsusEeePc-PC) Description: Adobe Reader 9.3.4Adobe Reader 9.3.3 - CPSID_837081603C:\Users\ASUSEE~1\AppData\Local\Temp\MSI502d5.LOG(NULL)(NULL) Error: (10/13/2013 03:30:25 AM) (Source: MsiInstaller)(User: AsusEeePc-PC) Description: Adobe Reader 9.3.4Adobe Reader 9.3.4 - CPSID_837081603C:\Users\ASUSEE~1\AppData\Local\Temp\MSI502d5.LOG(NULL)(NULL) Error: (10/13/2013 03:30:22 AM) (Source: MsiInstaller)(User: AsusEeePc-PC) Description: Product: Adobe Reader 9.3.4 -- Setup has detected that you already have a more functional product installed. Setup will now terminate.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (10/12/2013 08:12:55 PM) (Source: Application Error)(User: ) Description: Explorer.EXE6.1.7601.175674d6727a7SHELL32.dll6.1.7601.1822251f1d731c00000050004b1e8 ==================== Memory info =========================== Percentage of memory in use: 56% Total physical RAM: 2047.12 MB Available physical RAM: 890.29 MB Total Pagefile: 5117.12 MB Available Pagefile: 3668.07 MB Total Virtual: 2047.88 MB Available Virtual: 1924.16 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:100 GB) (Free:64.52 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: () (Fixed) (Total:117.87 GB) (Free:66.75 GB) NTFS Drive f: (SD-ReadyBoost) (Removable) (Total:14.92 GB) (Free:4.86 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: 29133921) Partition 1: (Active) - (Size=100 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=15 GB) - (Type=1B) Partition 3: (Not Active) - (Size=118 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=20 MB) - (Type=EF) ======================================================== Disk: 1 (Size: 15 GB) (Disk ID: 2CDD2CDC) Partition 1: (Not Active) - (Size=15 GB) - (Type=07 NTFS) ==================== End Of Log ============================ P.S.Das Tunneln geht leider immernoch weiter |
![]() |
Themen zu Win7 IP tunnelt mich jede Nacht und kapert Teledat 530 Router |
browser, converter, cpu-z, desktop, dvdvideosoft ltd., error, farbar, farbar recovery scan tool, firefox, flash player, google, help, helper, home, homepage, ie 10, iexplore.exe, installation, nicht möglich, ntdll.dll, officejet, plug-in, refresh, registry, security, software, stick, symantec, trojaner, trojaner board, tunnel, updates, usb, virus, windows, windows xp |