|
Plagegeister aller Art und deren Bekämpfung: Firefox: [JavaScript-Anwendung] TypeError: window.flagCache[curip] is undefinedWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
20.10.2013, 18:31 | #1 |
| Firefox: [JavaScript-Anwendung] TypeError: window.flagCache[curip] is undefined Hallo, seit ein paar Tagen öffnet sich, wenn ich gerade im Internet bin, ein Fenster und ich bekomme folgende Meldung: Code:
ATTFilter [JavaScript-Anwendung] TypeError: window.flagCache[curip] is undefined Die Meldung kommt meistens mehrmals kurz hintereinander. Ich denke nicht, dass es sich dabei um einen Virus handelt. Trotzdem bitte ich um Hilfe, da es ziemlich nervt. Firefox habe ich bereits deinstalliert und neu installiert und ist auf dem neuesten Stand. Heute kam noch ein Update von Java und Adobe Reader. Alles installiert - trotzdem erscheint die Meldung. Während ich diesen Text schrieb war ich nur hier auf Trojaner-Board. Die Meldung erschien nicht. |
25.10.2013, 23:17 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Firefox: [JavaScript-Anwendung] TypeError: window.flagCache[curip] is undefined Hallo und
__________________Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die mal fündig geworden? Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520 Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs in CODE-Tags posten! Relevant sind nur Logs der letzten 7 Tage bzw. seitdem das Problem besteht! Zudem bitte auch ein Log mit Farbars Tool machen: Scan mit Farbar's Recovery Scan Tool (FRST) Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
26.10.2013, 09:50 | #3 |
| Firefox: [JavaScript-Anwendung] TypeError: window.flagCache[curip] is undefined Hi,
__________________ich habe am 20.10. eine Vollständige Untersuchung mit Norton gemacht. Er hat nichts gefunden außer 3 Tracking Cookies (ist aber normal, also stellt keine Gefahr dar). Ich benutze jetzt Google Chrome. Dort ist das Problem nicht. Genauso beim Internet Explorer. Eine Logdatei vom Scan habe ich leider nicht. Hier die 2 Logs: FRST.txt FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-10-2013 Ran by **** (administrator) on ****-PC on 26-10-2013 10:42:51 Running from C:\Users\****\Downloads Windows 8 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe (Microsoft Corporation) C:\WINDOWS\system32\WLANExt.exe (Broadcom Corporation.) C:\WINDOWS\system32\BtwRSupportService.exe (Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Microsoft Corporation) C:\WINDOWS\system32\dashost.exe (MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe ( ) C:\WINDOWS\system32\lxdfcoms.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security CBE\Engine\20.4.0.40\ccSvcHst.exe () C:\WINDOWS\SysWOW64\PnkBstrA.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security CBE\Engine\20.4.0.40\ccSvcHst.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (Synaptics) C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe (Lenovo) C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe (Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe () C:\Program Files\Realtek\Audio\HDA\FMAPP.exe () C:\Program Files (x86)\Lexmark 6500 Series\lxdfmon.exe () C:\Program Files (x86)\Lexmark 6500 Series\lxdfamon.exe (CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe (CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe (Microsoft) C:\Program Files (x86)\Lenovo\Intelligent Touchpad\IntelligentTouchpad.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Microsoft Corporation) C:\WINDOWS\system32\taskmgr.exe (BatBrowse) C:\Program Files (x86)\BatBrowse\updateBatBrowse.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [HotKeysCmds] - C:\WINDOWS\system32\hkcmd.exe [ ] () HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-27] (Synaptics Incorporated) HKLM\...\Run: [SynLenovoGestureMgr] - C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe [665400 2012-08-27] (Synaptics) HKLM\...\Run: [OnekeyStudio] - C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe [4196432 2012-08-10] (Lenovo) HKLM\...\Run: [Energy Management] - C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17080376 2012-11-11] (Lenovo (Beijing) Limited) HKLM\...\Run: [EnergyUtility] - C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [191544 2012-11-11] (Lenovo(beijing) Limited) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12921488 2012-09-14] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1214608 2012-09-14] (Realtek Semiconductor) HKLM\...\Run: [lxdfmon.exe] - C:\Program Files (x86)\Lexmark 6500 Series\lxdfmon.exe [455600 2007-06-11] () HKLM\...\Run: [lxdfamon] - C:\Program Files (x86)\Lexmark 6500 Series\lxdfamon.exe [20480 2007-06-01] () HKLM-x32\...\Runonce: [Del247079921] - cmd.exe /Q /D /c del "C:\Users\****\AppData\Local\Temp\0.del" [x] Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [Steam] - C:\Program Files (x86)\Steam\steam.exe [1813928 2013-10-09] (Valve Corporation) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [277504 2012-08-16] (Intel Corporation) HKLM-x32\...\Run: [YouCam Mirage] - C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2012-07-27] (CyberLink) HKLM-x32\...\Run: [YouCam Tray] - C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [167024 2012-07-27] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateP2GShortCut] - C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [217088 2012-04-18] (CyberLink Corp.) HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.) HKLM-x32\...\Run: [Intel AppUp(SM) center] - C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-12] (Intel Corporation) HKLM-x32\...\Run: [IntellingentTouchpad] - C:\Program Files (x86)\Lenovo\Intelligent Touchpad\IntelligentTouchpad.exe [673336 2012-07-23] (Microsoft) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [TrayServer] - C:\Program Files (x86)\MAGIX\Video_deluxe_16_Premium\Trayserver.exe [90112 2008-08-07] (MAGIX AG) HKLM-x32\...\Run: [Dolby Home Theater v4] - C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [508656 2012-07-25] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [Lexmark 6500 Series] - C:\Program Files (x86)\Lexmark 6500 Series\fm3032.exe [308144 2007-06-11] () AppInit_DLLs: C:\WINDOWS\system32\nvinitx.dll [266448 2013-06-21] (NVIDIA Corporation) AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll [214448 2013-06-21] (NVIDIA Corporation) Startup: C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo13.msn.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com SearchScopes: HKLM - DefaultScope {E94F6640-DF04-4C3A-9ABD-D8246A05E733} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS SearchScopes: HKLM - {E94F6640-DF04-4C3A-9ABD-D8246A05E733} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS SearchScopes: HKLM-x32 - DefaultScope {E94F6640-DF04-4C3A-9ABD-D8246A05E733} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS SearchScopes: HKLM-x32 - {E94F6640-DF04-4C3A-9ABD-D8246A05E733} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS SearchScopes: HKCU - DefaultScope {E94F6640-DF04-4C3A-9ABD-D8246A05E733} URL = SearchScopes: HKCU - {E94F6640-DF04-4C3A-9ABD-D8246A05E733} URL = BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security CBE\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation) BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security CBE\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: BatBrowse - {b67b3dbb-c1c9-49d2-b016-2748b0b5017e} - C:\Program Files (x86)\BatBrowse\BatBrowsebho.dll (BatBrowse) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security CBE\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation) DPF: HKLM-x32 {22E5D91F-89E6-4405-AD9C-0AF27BA6F06B} file:///C:/Users/****/Videos/Mario_Abiball/components/hidinputmonitorx.ocx DPF: HKLM-x32 {4F63D44B-6274-4D60-8AB1-CAA7116B8AF3} file:///C:/Users/****/Videos/Mario_Abiball/components/A9.ocx DPF: HKLM-x32 {7030CC6C-1A88-4591-BB5A-651B9F7F0C30} file:///C:/Users/****/Videos/Mario_Abiball/components/wmvhdrating.ocx Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\2zjds9a1.default FF DefaultSearchEngine: Wikipedia (de) FF SelectedSearchEngine: Wikipedia (de) FF Homepage: hxxp://www.google.de/ FF NetworkProxy: "http", "proxy-1.cojobo.net" FF NetworkProxy: "http_port", 3128 FF NetworkProxy: "share_proxy_settings", true FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1203133.dll (Adobe Systems, Inc.) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\WINDOWS\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\****\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: ProxTube - Gesperrte YouTube Videos entsperren - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\2zjds9a1.default\Extensions\ich@maltegoetz.de FF Extension: Flagfox - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\2zjds9a1.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b} FF Extension: Domain Details - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\2zjds9a1.default\Extensions\{152455DE-7B40-4bcf-B5B4-C68A1BE85A91} FF Extension: WOT - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\2zjds9a1.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} FF Extension: firebug - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\2zjds9a1.default\Extensions\firebug@software.joehewitt.com.xpi FF Extension: firefox - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\2zjds9a1.default\Extensions\firefox@batbrowse.com.xpi FF Extension: noscript - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\2zjds9a1.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi FF Extension: Adblock Plus - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\2zjds9a1.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.1.2\coFFPlgn\ FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.1.2\coFFPlgn\ FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.1.2\IPSFF FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.1.2\IPSFF FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK Chrome: ======= CHR RestoreOnStartup: "hxxp://www.google.de/" CHR Extension: (Docs) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0 CHR Extension: (Google Drive) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0 CHR Extension: (YouTube) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0 CHR Extension: (Adblock Plus) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.6.1_0 CHR Extension: (Google Search) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0 CHR Extension: (uDomainFlag) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\eklbfdpploakpkdakoielobggbhemlnm\0.0.1.5_0 CHR Extension: (Black metallic theme) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbhhihkiaeeioepkklgfpdohnemkjcoi\5_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0 CHR Extension: (Gmail) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKLM\...\Chrome\Extension: [dchmpbaclbiioedakpcldenooikekokm] - C:\Users\****\AppData\Local\foxtab_speeddial.crx CHR HKLM-x32\...\Chrome\Extension: [ccncljhbalbbkkfgopogabimepmfkmff] - C:\Program Files (x86)\BatBrowse\ccncljhbalbbkkfgopogabimepmfkmff.crx CHR HKLM-x32\...\Chrome\Extension: [dchmpbaclbiioedakpcldenooikekokm] - C:\Users\****\AppData\Local\foxtab_speeddial.crx CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security CBE\Engine\20.4.0.40\Exts\Chrome.crx ==================== Services (Whitelisted) ================= R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2252088 2012-08-25] (Broadcom Corporation.) R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [957304 2012-09-06] (Broadcom Corporation.) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation) S2 lxdfCATSCustConnectService; C:\WINDOWS\system32\spool\DRIVERS\x64\3\\lxdfserv.exe [33712 2007-05-29] (Lexmark International, Inc.) R2 lxdf_device; C:\WINDOWS\system32\lxdfcoms.exe [1053104 2007-05-29] ( ) R2 lxdf_device; C:\WINDOWS\SysWow64\lxdfcoms.exe [598960 2007-05-29] ( ) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [272176 2012-07-18] () R2 NIS; C:\Program Files (x86)\Norton Internet Security CBE\Engine\20.4.0.40\ccSvcHst.exe [144368 2013-05-21] (Symantec Corporation) R2 PnkBstrA; C:\WINDOWS\SysWow64\PnkBstrA.exe [76888 2013-09-12] () R2 Update BatBrowse; C:\Program Files (x86)\BatBrowse\updateBatBrowse.exe [65824 2013-10-22] (BatBrowse) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation) S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2699568 2012-07-18] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== S3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [165688 2012-08-25] (Broadcom Corporation.) R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.1.2\Definitions\BASHDefs\20131022.001\BHDrvx64.sys [1524824 2013-10-23] (Symantec Corporation) S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation) R1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1404000.028\ccSetx64.sys [169048 2013-04-16] (Symantec Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-08-27] (Symantec Corporation) U3 EraserUtilDrv11311; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11311.sys [140376 2013-10-23] (Symantec Corporation) S3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [140376 2013-08-27] (Symantec Corporation) R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.1.2\Definitions\IPSDefs\20131025.001\IDSvia64.sys [521816 2013-10-18] (Symantec Corporation) R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.1.2\Definitions\VirusDefs\20131025.009\ENG64.SYS [126040 2013-10-23] (Symantec Corporation) R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.1.2\Definitions\VirusDefs\20131025.009\EX64.SYS [2099288 2013-10-23] (Symantec Corporation) R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [4273192 2012-08-19] (Intel Corporation) R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [8222736 2012-06-15] (Realtek Semiconductor Corp.) R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [43832 2012-08-27] (Synaptics Incorporated) R3 SRTSP; C:\Windows\System32\Drivers\NISx64\1404000.028\SRTSP64.SYS [796760 2013-05-16] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1404000.028\SRTSPX64.SYS [36952 2013-03-05] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\NISx64\1404000.028\SYMDS64.SYS [493656 2013-05-21] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\NISx64\1404000.028\SYMEFA64.SYS [1139800 2013-05-23] (Symantec Corporation) S0 SymELAM; C:\Windows\System32\drivers\NISx64\1404000.028\SymELAM.sys [23448 2012-06-20] (Symantec Corporation) R3 SymEvent; C:\WINDOWS\system32\Drivers\SYMEVENT64x86.SYS [177312 2013-07-25] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\NISx64\1404000.028\Ironx64.SYS [224416 2013-03-05] (Symantec Corporation) R1 SymNetS; C:\Windows\System32\Drivers\NISx64\1404000.028\SYMNETS.SYS [433752 2013-04-25] (Symantec Corporation) S3 usb3Hub; C:\Windows\System32\drivers\usb3Hub.sys [48096 2012-08-09] (Windows (R) Win 7 DDK provider) S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink) S3 XHCIPort; C:\Windows\System32\drivers\XHCIPort.sys [188384 2012-08-09] (Windows (R) Win 7 DDK provider) S3 xusb22; C:\Windows\System32\drivers\xusb22.sys [89088 2012-07-26] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-26 10:42 - 2013-10-26 10:42 - 00000000 ____D C:\FRST 2013-10-26 10:36 - 2013-10-26 10:36 - 01956086 _____ (Farbar) C:\Users\****\Downloads\FRST64.exe 2013-10-26 10:35 - 2013-10-26 10:40 - 00000000 ____D C:\Program Files (x86)\MyPC Backup 2013-10-26 10:31 - 2013-10-26 10:37 - 00000000 ____D C:\Users\****\AppData\Roaming\Systweak 2013-10-26 10:31 - 2013-10-26 10:33 - 00000000 ____D C:\Program Files (x86)\BatBrowse 2013-10-26 10:31 - 2013-10-26 10:31 - 00002644 _____ C:\WINDOWS\System32\Tasks\FoxTab 2013-10-26 10:31 - 2013-10-26 10:31 - 00002644 _____ C:\WINDOWS\System32\Tasks\DigitalSite 2013-10-26 10:31 - 2013-10-26 10:31 - 00000306 _____ C:\WINDOWS\Tasks\FoxTab.job 2013-10-26 10:31 - 2013-10-26 10:31 - 00000306 _____ C:\WINDOWS\Tasks\DigitalSite.job 2013-10-26 10:31 - 2013-10-26 10:31 - 00000000 ____D C:\Users\****\AppData\Roaming\FoxTab 2013-10-26 10:31 - 2013-10-26 10:31 - 00000000 ____D C:\Users\****\AppData\Roaming\DigitalSite 2013-10-26 10:31 - 2013-10-26 10:31 - 00000000 ____D C:\Users\****\AppData\Roaming\0D0S1L2Z1P1B 2013-10-26 10:31 - 2013-07-22 16:07 - 00020312 _____ (Systweak Inc., (www.systweak.com)) C:\WINDOWS\system32\roboot64.exe 2013-10-26 10:30 - 2013-10-26 10:30 - 00364318 _____ C:\Users\****\AppData\Local\foxtab_speeddial.crx 2013-10-26 10:30 - 2013-10-26 10:30 - 00000000 ____D C:\Program Files (x86)\Foxtab 2013-10-23 16:28 - 2013-10-23 16:28 - 00002266 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-10-23 16:18 - 2013-10-26 10:24 - 00001126 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2013-10-23 16:18 - 2013-10-26 10:23 - 00001122 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-23 16:18 - 2013-10-23 16:18 - 00004098 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2013-10-23 16:18 - 2013-10-23 16:18 - 00003862 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2013-10-23 16:16 - 2013-10-23 16:16 - 00819192 _____ (Google Inc.) C:\Users\****\Downloads\ChromeSetup.exe 2013-10-23 16:10 - 2013-10-23 16:19 - 00000000 ____D C:\Users\****\AppData\Roaming\Opera Software 2013-10-23 16:10 - 2013-10-23 16:19 - 00000000 ____D C:\Users\****\AppData\Local\Opera Software 2013-10-23 16:10 - 2013-10-23 16:19 - 00000000 ____D C:\Program Files (x86)\Opera 2013-10-23 15:59 - 2013-10-23 16:03 - 33727472 _____ (Opera Software ASA) C:\Users\****\Downloads\Opera_17.0.1241.53_Setup.exe 2013-10-23 12:59 - 2013-10-23 12:59 - 00000000 ____D C:\WINDOWS\System32\Tasks\Aufgaben der Ereignisanzeige 2013-10-22 19:10 - 2013-10-22 19:10 - 00052194 _____ C:\Users\****\Downloads\Flamed Maple 1.1.gpx 2013-10-22 18:56 - 2013-10-22 18:56 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies 2013-10-21 15:05 - 2013-10-21 15:06 - 00000000 ____D C:\Users\****\AppData\Local\Google 2013-10-21 15:05 - 2013-10-21 15:06 - 00000000 ____D C:\Program Files (x86)\Google 2013-10-20 21:46 - 2013-10-20 21:46 - 00011792 _____ C:\Users\****\AppData\Local\recently-used.xbel 2013-10-20 16:52 - 2013-10-20 16:52 - 00004886 _____ C:\WINDOWS\SysWOW64\jupdate-1.7.0_45-b18.log 2013-10-20 16:52 - 2013-10-20 16:52 - 00000000 ____D C:\ProgramData\Oracle 2013-10-20 15:17 - 2013-10-23 13:50 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-10-13 18:33 - 2013-08-03 08:40 - 01374208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wdc.dll 2013-10-13 18:33 - 2013-08-03 08:40 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wvc.dll 2013-10-13 18:33 - 2013-08-03 08:40 - 00462336 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmon.ocx 2013-10-13 18:33 - 2013-08-03 07:14 - 00399360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sysmon.ocx 2013-10-13 18:33 - 2013-08-03 07:13 - 01245696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wdc.dll 2013-10-13 18:33 - 2013-08-03 07:13 - 00437248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wvc.dll 2013-10-13 18:33 - 2013-08-02 08:28 - 19758080 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2013-10-13 18:33 - 2013-08-02 08:28 - 10116608 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2013-10-13 18:33 - 2013-08-02 07:08 - 17561088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2013-10-13 18:33 - 2013-08-02 07:08 - 08858112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2013-10-13 18:32 - 2013-08-10 07:21 - 00448512 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll 2013-10-13 18:32 - 2013-08-10 07:21 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncInfo.dll 2013-10-13 18:32 - 2013-08-10 05:58 - 00356352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll 2013-10-13 18:32 - 2013-08-02 08:28 - 00222208 _____ (Microsoft Corporation) C:\WINDOWS\system32\shdocvw.dll 2013-10-13 18:32 - 2013-08-02 08:26 - 02304512 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll 2013-10-13 18:32 - 2013-08-02 07:08 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shdocvw.dll 2013-10-13 18:32 - 2013-08-02 07:06 - 02035712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll 2013-10-13 18:32 - 2013-08-01 12:41 - 02233688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 2013-10-13 18:32 - 2013-07-31 01:30 - 00386923 _____ C:\WINDOWS\system32\ApnDatabase.xml 2013-10-13 18:32 - 2013-07-25 01:10 - 00158208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mbsmsapi.dll 2013-10-13 18:32 - 2013-07-25 01:06 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\system32\mbsmsapi.dll 2013-10-13 18:32 - 2013-04-10 01:17 - 01125888 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2013-10-13 18:32 - 2013-04-10 00:29 - 00893952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2013-10-13 16:30 - 2013-10-13 16:30 - 00000000 ____D C:\WINDOWS\System32\Tasks\Norton Internet Security 2013-10-12 14:39 - 2013-10-12 14:40 - 00434712 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2013-10-10 18:49 - 2013-10-10 18:49 - 00000000 ____D C:\Users\****\AppData\Roaming\Unity 2013-10-10 18:45 - 2013-10-10 18:45 - 00000000 ____D C:\Users\****\AppData\Local\Unity 2013-10-10 17:55 - 2013-09-23 01:28 - 01767936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2013-10-10 17:55 - 2013-09-23 01:28 - 01141248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2013-10-10 17:55 - 2013-09-23 01:27 - 14335488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2013-10-10 17:55 - 2013-09-23 01:27 - 13761024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2013-10-10 17:55 - 2013-09-23 01:27 - 02876928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2013-10-10 17:55 - 2013-09-23 01:27 - 02048512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2013-10-10 17:55 - 2013-09-23 01:27 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll 2013-10-10 17:55 - 2013-09-23 01:27 - 00493056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2013-10-10 17:55 - 2013-09-23 00:55 - 02241024 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2013-10-10 17:55 - 2013-09-23 00:55 - 01365504 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2013-10-10 17:55 - 2013-09-23 00:55 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2013-10-10 17:55 - 2013-09-23 00:54 - 19252224 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2013-10-10 17:55 - 2013-09-23 00:54 - 15404544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2013-10-10 17:55 - 2013-09-23 00:54 - 03959296 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2013-10-10 17:55 - 2013-09-23 00:54 - 02647552 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2013-10-10 17:55 - 2013-09-23 00:54 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll 2013-10-10 17:55 - 2013-09-23 00:54 - 00603136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2013-10-10 17:55 - 2013-07-06 02:15 - 00652288 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll 2013-10-10 17:55 - 2013-07-04 04:13 - 00541696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll 2013-10-10 17:55 - 2013-05-16 00:37 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UXInit.dll 2013-10-10 17:55 - 2013-05-16 00:35 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\UXInit.dll 2013-10-10 17:55 - 2013-05-14 15:14 - 02706432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb 2013-10-10 17:55 - 2013-05-14 11:23 - 02706432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb 2013-10-10 17:55 - 2013-04-29 00:28 - 00915968 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxtheme.dll 2013-10-10 17:55 - 2013-02-21 12:29 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesysprep.dll 2013-10-10 17:55 - 2013-02-21 12:29 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll 2013-10-10 17:55 - 2013-02-21 12:29 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll 2013-10-10 17:55 - 2013-02-21 12:29 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll 2013-10-10 17:55 - 2013-02-21 12:14 - 00136704 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesysprep.dll 2013-10-10 17:55 - 2013-02-21 12:14 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll 2013-10-10 17:55 - 2013-02-19 11:53 - 00534528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uxtheme.dll 2013-10-10 17:55 - 2012-11-08 06:20 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll 2013-10-10 17:55 - 2012-11-08 06:20 - 00039936 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll 2013-10-10 17:54 - 2013-08-23 07:11 - 04040192 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2013-10-10 17:54 - 2013-07-06 00:02 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbcir.sys 2013-10-10 17:54 - 2013-07-06 00:01 - 00210560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbvideo.sys 2013-10-10 17:54 - 2013-07-02 00:14 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbprint.sys 2013-10-10 17:54 - 2013-06-29 05:08 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidparse.sys 2013-10-10 17:54 - 2013-06-29 05:07 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidclass.sys 2013-10-10 17:54 - 2013-06-22 07:45 - 00785624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Wdf01000.sys 2013-10-10 17:54 - 2013-06-22 07:45 - 00054488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdfLdr.sys 2013-10-10 17:54 - 2013-05-27 01:17 - 00035328 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll 2013-10-10 17:54 - 2013-05-27 00:59 - 00046080 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2013-10-10 17:54 - 2013-05-25 05:15 - 00362496 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll 2013-10-10 17:54 - 2013-05-25 04:32 - 00300032 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll 2013-10-10 17:53 - 2013-07-20 00:13 - 00124112 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll 2013-10-10 17:53 - 2013-07-20 00:13 - 00102608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2013-10-10 17:53 - 2013-07-02 03:41 - 00447320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS 2013-10-10 17:53 - 2013-07-02 03:41 - 00337752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS 2013-10-10 17:53 - 2013-07-02 03:41 - 00213336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UCX01000.SYS 2013-10-10 17:53 - 2013-07-01 03:42 - 00623448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbhub.sys 2013-10-10 17:53 - 2013-07-01 03:42 - 00498008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbport.sys 2013-10-10 17:53 - 2013-07-01 03:42 - 00079192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbehci.sys 2013-10-10 17:53 - 2013-07-01 03:42 - 00021848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbd.sys 2013-10-10 17:53 - 2013-06-29 05:07 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbuhci.sys 2013-10-10 17:53 - 2013-06-29 05:06 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbccgp.sys 2013-10-05 21:00 - 2013-10-05 21:00 - 00000000 ____D C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2013-10-04 15:52 - 2007-05-01 03:14 - 00420352 _____ C:\WINDOWS\system32\lxdfcoin.dll 2013-10-04 15:52 - 2006-10-30 14:38 - 01462272 _____ (Microsoft Corporation) C:\WINDOWS\system32\lxdfg.dll 2013-10-04 15:51 - 2007-05-24 13:44 - 00045568 _____ C:\WINDOWS\system32\LXDFPMON.DLL 2013-10-04 15:51 - 2007-05-24 13:44 - 00014336 _____ C:\WINDOWS\system32\LXDFFXPU.DLL 2013-10-04 15:50 - 2013-10-04 15:50 - 00001076 _____ C:\Users\Public\Desktop\Lexmark Productivity Studio - 6500 Series.LNK 2013-10-04 15:50 - 2013-10-04 15:50 - 00000000 ____D C:\ProgramData\6500 Series 2013-10-04 15:50 - 2007-05-24 13:45 - 00003584 _____ () C:\WINDOWS\system32\LXDFPMRC.DLL 2013-10-04 15:49 - 2013-10-04 15:51 - 00000000 ____D C:\Program Files (x86)\Lexmark 6500 Series 2013-10-04 15:49 - 2007-05-28 13:10 - 00147456 _____ (Lexmark International, Inc.) C:\WINDOWS\SysWOW64\lxdfjswr.dll 2013-10-04 15:49 - 2007-05-28 13:10 - 00114688 _____ (Lexmark International, Inc.) C:\WINDOWS\SysWOW64\lxdfinsr.dll 2013-10-04 15:49 - 2007-05-28 13:10 - 00036864 _____ (Lexmark International, Inc.) C:\WINDOWS\SysWOW64\lxdfcur.dll 2013-10-04 15:49 - 2007-05-28 04:14 - 00208896 _____ (Lexmark International, Inc.) C:\WINDOWS\SysWOW64\lxdfinsb.dll 2013-10-04 15:49 - 2007-05-28 04:14 - 00090112 _____ (Lexmark International, Inc.) C:\WINDOWS\SysWOW64\lxdfcub.dll 2013-10-04 15:49 - 2007-05-28 04:07 - 00176128 _____ (Lexmark International, Inc.) C:\WINDOWS\SysWOW64\lxdfins.dll 2013-10-04 15:49 - 2007-05-28 04:07 - 00077824 _____ (Lexmark International, Inc.) C:\WINDOWS\SysWOW64\lxdfcu.dll 2013-10-04 15:49 - 2007-05-28 04:03 - 00503808 _____ (Lexmark International, Inc.) C:\WINDOWS\SysWOW64\lxdfutil.dll 2013-10-04 15:49 - 2007-05-23 21:39 - 01512613 _____ C:\WINDOWS\SysWOW64\LXDFhelp.chm 2013-10-04 15:49 - 2007-05-23 06:34 - 00385024 _____ () C:\WINDOWS\SysWOW64\lxdfcomx.dll 2013-10-04 15:49 - 2007-05-17 20:08 - 00647168 _____ ( ) C:\WINDOWS\SysWOW64\lxdfpmui.dll 2013-10-04 15:49 - 2007-05-17 20:06 - 01200128 _____ ( ) C:\WINDOWS\SysWOW64\lxdfserv.dll 2013-10-04 15:49 - 2007-05-17 20:00 - 00356352 _____ ( ) C:\WINDOWS\SysWOW64\lxdfinpa.dll 2013-10-04 15:49 - 2007-05-17 19:57 - 00950272 _____ ( ) C:\WINDOWS\SysWOW64\lxdfusb1.dll 2013-10-04 15:49 - 2007-05-17 19:52 - 00348160 _____ C:\WINDOWS\SysWOW64\lxdfinst.dll 2013-10-04 15:49 - 2007-05-17 19:52 - 00339968 _____ ( ) C:\WINDOWS\SysWOW64\lxdfiesc.dll 2013-10-04 15:49 - 2007-01-22 11:53 - 00126976 _____ (Lexmark International Inc.) C:\WINDOWS\SysWOW64\lxdflnks.dll 2013-10-04 15:49 - 2007-01-22 11:53 - 00000060 ____H C:\WINDOWS\system32\lxdfrwrd.ini 2013-10-04 15:49 - 2006-10-24 11:16 - 00983121 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lxdfgf.dll 2013-10-04 15:48 - 2013-10-04 15:54 - 00101925 _____ C:\WINDOWS\system32\LexFiles.ulf 2013-10-04 15:48 - 2013-10-04 15:51 - 00000000 ____D C:\Program Files\Lexmark 6500 Series 2013-10-04 15:48 - 2007-05-29 12:06 - 01053104 _____ ( ) C:\WINDOWS\system32\lxdfcoms.exe 2013-10-04 15:48 - 2007-05-29 12:06 - 00598960 _____ ( ) C:\WINDOWS\SysWOW64\lxdfcoms.exe 2013-10-04 15:48 - 2007-05-29 12:06 - 00598960 _____ ( ) C:\WINDOWS\system32\lxdfcfg.exe 2013-10-04 15:48 - 2007-05-29 12:06 - 00515504 _____ ( ) C:\WINDOWS\system32\lxdfih.exe 2013-10-04 15:48 - 2007-05-29 12:06 - 00365488 _____ ( ) C:\WINDOWS\SysWOW64\lxdfcfg.exe 2013-10-04 15:48 - 2007-05-29 12:06 - 00320432 _____ ( ) C:\WINDOWS\SysWOW64\lxdfih.exe 2013-10-04 15:48 - 2007-05-29 11:49 - 00002003 _____ C:\WINDOWS\SysWOW64\lxdf.loc 2013-10-04 15:48 - 2007-05-29 11:49 - 00002003 _____ C:\WINDOWS\system32\lxdf.loc 2013-10-04 15:48 - 2007-05-28 14:08 - 00130560 _____ (Lexmark International, Inc.) C:\WINDOWS\system32\lxdfjswr.dll 2013-10-04 15:48 - 2007-05-28 14:08 - 00097280 _____ (Lexmark International, Inc.) C:\WINDOWS\system32\lxdfinsr.dll 2013-10-04 15:48 - 2007-05-28 14:08 - 00023552 _____ (Lexmark International, Inc.) C:\WINDOWS\system32\lxdfcur.dll 2013-10-04 15:48 - 2007-05-28 13:39 - 00299520 _____ () C:\WINDOWS\system32\lxdfgrd.dll 2013-10-04 15:48 - 2007-05-28 05:14 - 00189952 _____ (Lexmark International, Inc.) C:\WINDOWS\system32\lxdfinsb.dll 2013-10-04 15:48 - 2007-05-28 05:14 - 00073216 _____ (Lexmark International, Inc.) C:\WINDOWS\system32\lxdfcub.dll 2013-10-04 15:48 - 2007-05-28 05:10 - 00235520 _____ (Lexmark International, Inc.) C:\WINDOWS\system32\lxdfins.dll 2013-10-04 15:48 - 2007-05-28 05:10 - 00100864 _____ (Lexmark International, Inc.) C:\WINDOWS\system32\lxdfcu.dll 2013-10-04 15:48 - 2007-05-28 05:08 - 00715264 _____ (Lexmark International, Inc.) C:\WINDOWS\system32\lxdfutil.dll 2013-10-04 15:48 - 2007-05-23 21:39 - 01512613 _____ C:\WINDOWS\system32\LXDFhelp.chm 2013-10-04 15:48 - 2007-05-17 20:31 - 00980992 _____ ( ) C:\WINDOWS\system32\lxdfpmui.dll 2013-10-04 15:48 - 2007-05-17 20:28 - 01895936 _____ ( ) C:\WINDOWS\system32\lxdfserv.dll 2013-10-04 15:48 - 2007-05-17 20:22 - 00879104 _____ ( ) C:\WINDOWS\system32\lxdflmpm.dll 2013-10-04 15:48 - 2007-05-17 20:22 - 00563200 _____ ( ) C:\WINDOWS\system32\lxdfcomm.dll 2013-10-04 15:48 - 2007-05-17 20:22 - 00541184 _____ ( ) C:\WINDOWS\system32\lxdfinpa.dll 2013-10-04 15:48 - 2007-05-17 20:20 - 01065984 _____ ( ) C:\WINDOWS\system32\lxdfhbn3.dll 2013-10-04 15:48 - 2007-05-17 20:19 - 01501696 _____ ( ) C:\WINDOWS\system32\lxdfusb1.dll 2013-10-04 15:48 - 2007-05-17 20:19 - 01489408 _____ ( ) C:\WINDOWS\system32\lxdfcomc.dll 2013-10-04 15:48 - 2007-05-17 20:15 - 00668672 _____ ( ) C:\WINDOWS\system32\lxdfhcp.dll 2013-10-04 15:48 - 2007-05-17 20:15 - 00509440 _____ ( ) C:\WINDOWS\system32\lxdfiesc.dll 2013-10-04 15:48 - 2007-05-17 20:14 - 00524288 _____ C:\WINDOWS\system32\lxdfinst.dll 2013-10-04 15:48 - 2007-05-17 20:13 - 00047104 _____ ( ) C:\WINDOWS\system32\lxdfprox.dll 2013-10-04 15:48 - 2007-05-17 20:00 - 00565248 _____ ( ) C:\WINDOWS\SysWOW64\lxdflmpm.dll 2013-10-04 15:48 - 2007-05-17 20:00 - 00364544 _____ ( ) C:\WINDOWS\SysWOW64\lxdfcomm.dll 2013-10-04 15:48 - 2007-05-17 19:59 - 00663552 _____ ( ) C:\WINDOWS\SysWOW64\lxdfhbn3.dll 2013-10-04 15:48 - 2007-05-17 19:56 - 00860160 _____ ( ) C:\WINDOWS\SysWOW64\lxdfcomc.dll 2013-10-04 15:48 - 2007-05-17 19:51 - 00053248 _____ ( ) C:\WINDOWS\SysWOW64\lxdfprox.dll 2013-10-04 15:48 - 2007-05-11 03:56 - 00065536 _____ (Lexmark International) C:\WINDOWS\system32\lxdfcfg.dll 2013-10-04 15:48 - 2007-05-11 03:52 - 00077906 _____ (Lexmark International) C:\WINDOWS\SysWOW64\lxdfcfg.dll 2013-10-04 15:48 - 2006-10-24 11:16 - 00983121 _____ (Microsoft Corporation) C:\WINDOWS\system32\lxdfgf.dll 2013-10-04 15:42 - 2013-10-04 15:42 - 00000178 _____ C:\lxdf.log 2013-10-04 15:42 - 2013-10-04 15:42 - 00000047 _____ C:\WINDOWS\WinInit.Ini 2013-10-04 15:22 - 2013-10-04 15:22 - 00003128 _____ C:\WINDOWS\System32\Tasks\{E2DB31D0-6EAC-4C42-B453-4B647AF08E2B} 2013-10-03 22:18 - 2013-10-03 22:18 - 05238341 _____ C:\ProgramData\SPLA1B2.tmp ==================== One Month Modified Files and Folders ======= 2013-10-26 10:42 - 2013-10-26 10:42 - 00000000 ____D C:\FRST 2013-10-26 10:41 - 2013-07-27 13:02 - 00000000 ____D C:\Program Files (x86)\Steam 2013-10-26 10:40 - 2013-10-26 10:35 - 00000000 ____D C:\Program Files (x86)\MyPC Backup 2013-10-26 10:40 - 2013-07-25 02:15 - 00000000 ___RD C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-10-26 10:37 - 2013-10-26 10:31 - 00000000 ____D C:\Users\****\AppData\Roaming\Systweak 2013-10-26 10:36 - 2013-10-26 10:36 - 01956086 _____ (Farbar) C:\Users\****\Downloads\FRST64.exe 2013-10-26 10:33 - 2013-10-26 10:31 - 00000000 ____D C:\Program Files (x86)\BatBrowse 2013-10-26 10:31 - 2013-10-26 10:31 - 00002644 _____ C:\WINDOWS\System32\Tasks\FoxTab 2013-10-26 10:31 - 2013-10-26 10:31 - 00002644 _____ C:\WINDOWS\System32\Tasks\DigitalSite 2013-10-26 10:31 - 2013-10-26 10:31 - 00000306 _____ C:\WINDOWS\Tasks\FoxTab.job 2013-10-26 10:31 - 2013-10-26 10:31 - 00000306 _____ C:\WINDOWS\Tasks\DigitalSite.job 2013-10-26 10:31 - 2013-10-26 10:31 - 00000000 ____D C:\Users\****\AppData\Roaming\FoxTab 2013-10-26 10:31 - 2013-10-26 10:31 - 00000000 ____D C:\Users\****\AppData\Roaming\DigitalSite 2013-10-26 10:31 - 2013-10-26 10:31 - 00000000 ____D C:\Users\****\AppData\Roaming\0D0S1L2Z1P1B 2013-10-26 10:30 - 2013-10-26 10:30 - 00364318 _____ C:\Users\****\AppData\Local\foxtab_speeddial.crx 2013-10-26 10:30 - 2013-10-26 10:30 - 00000000 ____D C:\Program Files (x86)\Foxtab 2013-10-26 10:24 - 2013-10-23 16:18 - 00001126 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2013-10-26 10:23 - 2013-10-23 16:18 - 00001122 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-25 23:54 - 2013-07-24 21:46 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2013-10-25 23:31 - 2013-07-25 15:53 - 00000000 ____D C:\Users\****\Documents\MAGIX_Video_deluxe_16_Premium 2013-10-25 23:00 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\system32\sru 2013-10-24 17:53 - 2013-07-24 23:51 - 00000000 ____D C:\Users\****\.gimp-2.8 2013-10-23 20:51 - 2013-07-24 23:12 - 00000000 ____D C:\Users\****\AppData\Local\CrashDumps 2013-10-23 20:04 - 2013-08-31 14:33 - 00000000 ____D C:\Users\****\AppData\Roaming\Audacity 2013-10-23 18:05 - 2013-07-25 02:21 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3713764075-1403762093-349256513-1002 2013-10-23 16:52 - 2013-07-30 20:29 - 00000000 ____D C:\Program Files\OblyTile 2013-10-23 16:52 - 2013-07-30 17:38 - 00000000 ____D C:\Users\****\icons 2013-10-23 16:28 - 2013-10-23 16:28 - 00002266 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-10-23 16:19 - 2013-10-23 16:10 - 00000000 ____D C:\Users\****\AppData\Roaming\Opera Software 2013-10-23 16:19 - 2013-10-23 16:10 - 00000000 ____D C:\Users\****\AppData\Local\Opera Software 2013-10-23 16:19 - 2013-10-23 16:10 - 00000000 ____D C:\Program Files (x86)\Opera 2013-10-23 16:18 - 2013-10-23 16:18 - 00004098 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2013-10-23 16:18 - 2013-10-23 16:18 - 00003862 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2013-10-23 16:16 - 2013-10-23 16:16 - 00819192 _____ (Google Inc.) C:\Users\****\Downloads\ChromeSetup.exe 2013-10-23 16:03 - 2013-10-23 15:59 - 33727472 _____ (Opera Software ASA) C:\Users\****\Downloads\Opera_17.0.1241.53_Setup.exe 2013-10-23 13:54 - 2013-07-25 02:13 - 00000000 ____D C:\Users\**** 2013-10-23 13:53 - 2012-07-26 09:22 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2013-10-23 13:51 - 2013-08-02 14:28 - 00000000 ____D C:\Users\****\AppData\Local\gtk-2.0 2013-10-23 13:51 - 2013-07-26 13:13 - 00000000 ____D C:\WINDOWS\SysWOW64\NV 2013-10-23 13:51 - 2013-07-26 13:13 - 00000000 ____D C:\WINDOWS\system32\NV 2013-10-23 13:51 - 2013-07-24 20:28 - 00000000 ____D C:\ProgramData\Norton 2013-10-23 13:50 - 2013-10-20 15:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-10-23 13:50 - 2013-07-24 21:21 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-10-23 13:50 - 2012-11-11 18:54 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2013-10-23 13:50 - 2012-11-11 18:54 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-10-23 13:48 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\registration 2013-10-23 13:46 - 2012-11-11 18:55 - 00000000 ____D C:\ProgramData\NVIDIA 2013-10-23 13:45 - 2013-07-24 22:32 - 00000000 ____D C:\Program Files (x86)\Java 2013-10-23 12:59 - 2013-10-23 12:59 - 00000000 ____D C:\WINDOWS\System32\Tasks\Aufgaben der Ereignisanzeige 2013-10-23 12:48 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\AUInstallAgent 2013-10-22 20:48 - 2012-11-11 18:54 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2013-10-22 19:10 - 2013-10-22 19:10 - 00052194 _____ C:\Users\****\Downloads\Flamed Maple 1.1.gpx 2013-10-22 18:56 - 2013-10-22 18:56 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies 2013-10-21 15:06 - 2013-10-21 15:05 - 00000000 ____D C:\Users\****\AppData\Local\Google 2013-10-21 15:06 - 2013-10-21 15:05 - 00000000 ____D C:\Program Files (x86)\Google 2013-10-21 15:05 - 2013-07-25 12:38 - 00000000 ____D C:\Users\****\AppData\Local\Deployment 2013-10-20 21:46 - 2013-10-20 21:46 - 00011792 _____ C:\Users\****\AppData\Local\recently-used.xbel 2013-10-20 16:52 - 2013-10-20 16:52 - 00004886 _____ C:\WINDOWS\SysWOW64\jupdate-1.7.0_45-b18.log 2013-10-20 16:52 - 2013-10-20 16:52 - 00000000 ____D C:\ProgramData\Oracle 2013-10-20 15:17 - 2013-07-24 21:22 - 00000000 ____D C:\Users\****\AppData\Local\Mozilla 2013-10-20 15:06 - 2012-07-26 07:26 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM 2013-10-20 15:04 - 2012-07-26 07:26 - 00262144 ___SH C:\WINDOWS\system32\config\BBI 2013-10-18 22:07 - 2013-07-24 23:51 - 00000000 ____D C:\Users\****\AppData\Roaming\vlc 2013-10-18 18:23 - 2012-11-12 03:40 - 00754172 _____ C:\WINDOWS\system32\perfh007.dat 2013-10-18 18:23 - 2012-11-12 03:40 - 00156362 _____ C:\WINDOWS\system32\perfc007.dat 2013-10-18 18:23 - 2012-07-26 09:28 - 01748838 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2013-10-18 16:50 - 2013-07-25 11:10 - 00000000 ____D C:\ProgramData\Lx_cats 2013-10-14 21:09 - 2013-07-25 13:05 - 00000000 ____D C:\Users\****\AppData\Roaming\Mp3tag 2013-10-14 15:27 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\rescache 2013-10-14 12:49 - 2013-07-25 20:58 - 00000000 ____D C:\Users\****\Noten 2013-10-14 12:13 - 2013-07-25 02:15 - 00000000 ___RD C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-10-14 12:00 - 2012-07-26 10:12 - 00000000 ___HD C:\WINDOWS\ELAMBKUP 2013-10-14 11:59 - 2012-07-26 10:12 - 00000000 ___RD C:\WINDOWS\ToastData 2013-10-13 20:05 - 2013-07-24 22:31 - 00000000 ____D C:\Users\****\Documents\Schule 2013-10-13 16:30 - 2013-10-13 16:30 - 00000000 ____D C:\WINDOWS\System32\Tasks\Norton Internet Security 2013-10-12 14:40 - 2013-10-12 14:39 - 00434712 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2013-10-11 16:02 - 2013-07-25 10:44 - 00000000 ____D C:\Users\****\AppData\Roaming\Skype 2013-10-10 19:14 - 2013-07-25 13:42 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-10-10 19:13 - 2013-08-16 13:40 - 00000000 ____D C:\WINDOWS\system32\MRT 2013-10-10 19:12 - 2013-07-24 21:51 - 80541720 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2013-10-10 18:49 - 2013-10-10 18:49 - 00000000 ____D C:\Users\****\AppData\Roaming\Unity 2013-10-10 18:45 - 2013-10-10 18:45 - 00000000 ____D C:\Users\****\AppData\Local\Unity 2013-10-08 21:54 - 2013-07-24 21:46 - 00003772 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2013-10-05 21:00 - 2013-10-05 21:00 - 00000000 ____D C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2013-10-05 21:00 - 2013-07-25 02:14 - 00000000 ____D C:\Users\****\AppData\Local\Packages 2013-10-04 15:54 - 2013-10-04 15:48 - 00101925 _____ C:\WINDOWS\system32\LexFiles.ulf 2013-10-04 15:51 - 2013-10-04 15:49 - 00000000 ____D C:\Program Files (x86)\Lexmark 6500 Series 2013-10-04 15:51 - 2013-10-04 15:48 - 00000000 ____D C:\Program Files\Lexmark 6500 Series 2013-10-04 15:50 - 2013-10-04 15:50 - 00001076 _____ C:\Users\Public\Desktop\Lexmark Productivity Studio - 6500 Series.LNK 2013-10-04 15:50 - 2013-10-04 15:50 - 00000000 ____D C:\ProgramData\6500 Series 2013-10-04 15:42 - 2013-10-04 15:42 - 00000178 _____ C:\lxdf.log 2013-10-04 15:42 - 2013-10-04 15:42 - 00000047 _____ C:\WINDOWS\WinInit.Ini 2013-10-04 15:42 - 2012-11-11 19:03 - 00000000 ____D C:\Program Files\Lenovo 2013-10-04 15:42 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files\Windows NT 2013-10-04 15:42 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files\Common Files\System 2013-10-04 15:42 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2013-10-04 15:22 - 2013-10-04 15:22 - 00003128 _____ C:\WINDOWS\System32\Tasks\{E2DB31D0-6EAC-4C42-B453-4B647AF08E2B} 2013-10-03 22:18 - 2013-10-03 22:18 - 05238341 _____ C:\ProgramData\SPLA1B2.tmp 2013-10-02 03:38 - 2013-09-15 14:38 - 00694232 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2013-10-02 03:38 - 2013-09-15 14:38 - 00078296 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2013-09-29 11:41 - 2013-07-24 22:30 - 00000000 ____D C:\Users\****\Documents\Privat 2013-09-27 17:17 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2013-09-26 17:54 - 2013-07-24 22:36 - 00000000 ____D C:\Users\****\Desktop\Games 2013-09-26 17:30 - 2013-07-27 14:07 - 00000000 ____D C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam Some content of TEMP: ==================== C:\Users\****\AppData\Local\Temp\BackupSetup.exe C:\Users\****\AppData\Local\Temp\CleanSchedule.exe C:\Users\****\AppData\Local\Temp\vcredist_x64.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-19 11:48 ==================== End Of Log ============================ Addition.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 26-10-2013 Ran by **** at 2013-10-26 10:43:48 Running from C:\Users\****\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Norton Internet Security CBE (Enabled - Up to date) {63DF5164-9100-186D-2187-8DC619EFD8BF} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Norton Internet Security CBE (Enabled - Up to date) {D8BEB080-B73A-17E3-1B37-B6B462689202} FW: Norton Internet Security CBE (Enabled) {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} ==================== Installed Programs ====================== 7-Zip 9.20 (x64 edition) (Version: 9.20.00.0) ABBYY FineReader 6.0 Sprint (x32 Version: 6.00.1990.41618) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117) Adobe Reader XI (11.0.05) - Deutsch (x32 Version: 11.0.05) Adobe Shockwave Player 12.0 (x32 Version: 12.0.3.133) Ashampoo Snap 5 v.5.1.5 (x32 Version: 5.1.5) Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (x32 Version: 2.1.0.7) Audacity 2.0.3 (x32 Version: 2.0.3) BatBrowse 1.0.0 (Version: 1.0.0) Benutzerhandbuch (x32 Version: 1.0.0.9) BlueJ (x32 Version: 3.1.0) Call of Duty: Black Ops II - Multiplayer (x32) Call of Duty: Black Ops II - Zombies (x32) Call of Duty: Black Ops II (x32) CCleaner (Version: 4.05) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32) Dolby Home Theater v4 (x32 Version: 7.2.8000.16) Energy Management (x32 Version: 8.0.2.4) FileZilla Client 3.7.1.1 (x32 Version: 3.7.1.1) Firebird SQL Server - MAGIX Edition (x32 Version: 2.1.26.0) FormatFactory 3.1.1 (x32 Version: 3.1.1) Foxtab (x32) Ghost Recon Online (EU) (HKCU Version: 1.34.2188.2) GIMP 2.8.6 (Version: 2.8.6) Google Chrome (x32 Version: 30.0.1599.101) Google Update Helper (x32 Version: 1.3.21.165) Guitar Pro 6 (x32) Hitman: Absolution (x32) Hitman: Sniper Challenge (x32) Intel AppUp(SM) center (x32 Version: 3.6.1.33057.10) Intel PROSet Wireless Intel(R) Control Center (x32 Version: 1.2.1.1008) Intel(R) Management Engine Components (x32 Version: 8.1.0.1252) Intel(R) Processor Graphics (x32 Version: 9.17.10.2843) Intel(R) Rapid Storage Technology (x32 Version: 11.5.4.1001) Intel(R) SDK for OpenCL - CPU Only Runtime Package (x32 Version: 2.0.0.37149) Intel(R) WiDi (Version: 3.5.34.0) Intel® PROSet/Wireless WiFi-Software (Version: 15.05.2000.1462) Intel® Trusted Connect Service Client (Version: 1.24.388.1) Intelligent Touchpad (x32 Version: 2.00.0012.0723) IrfanView (remove only) (x32 Version: 4.36) Java 7 Update 25 (64-bit) (Version: 7.0.250) Java 7 Update 25 (x32 Version: 7.0.250) Java Auto Updater (x32 Version: 2.1.9.5) Java SE Development Kit 7 Update 25 (64-bit) (Version: 1.7.0.250) JMicron Flash Media Controller Driver (x32 Version: 1.0.71.1) LAME v3.99.3 (for Windows) (x32) League of Legends (x32 Version: 3.0.1) Lenovo Bluetooth with Enhanced Data Rate Software (Version: 12.0.0.2200) Lenovo EasyCamera (x32 Version: 6.1.7600.167) Lenovo OneKey Recovery (Version: 8.0.0.0828) Lenovo OneKey Recovery (x32 Version: 8.0.0.0828) Lenovo PowerDVD10 (x32 Version: 10.0.4331.52) Lenovo YouCam (x32 Version: 4.1.3127) Lexmark 6500 Series MAGIX 3D Maker (embeded) (x32 Version: 6.0.0.8) MAGIX Music Maker 16 Premium (x32 Version: 16.0.0.28) MAGIX Screenshare (x32 Version: 4.3.6.1987) MAGIX Speed burnR (x32 Version: 6.0.1.4) MAGIX Video deluxe 16 Premium 9.0.0.54 (D) (x32 Version: 9.0.0.54) MAGIX Xtreme Foto Designer 6 (x32 Version: 6.0.29.0) Microsoft Office 2010 Service Pack 1 (SP1) (x32) Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Home and Student 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Office 64-bit Components 2010 (Version: 14.0.6029.1000) Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (English) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (French) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Single Image 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Mozilla Firefox 24.0 (x86 de) (x32 Version: 24.0) Mozilla Maintenance Service (x32 Version: 24.0) Mp3tag v2.57 (x32 Version: v2.57) Norton Internet Security CBE (x32 Version: 20.4.0.40) NVIDIA Grafiktreiber 320.49 (Version: 320.49) NVIDIA Install Application (Version: 2.1002.124.810) NVIDIA Optimus 1.10.8 (Version: 1.10.8) NVIDIA PhysX (x32 Version: 9.13.0604) NVIDIA PhysX-Systemsoftware 9.13.0604 (Version: 9.13.0604) NVIDIA Systemsteuerung 320.49 (Version: 320.49) NVIDIA Update 1.10.8 (Version: 1.10.8) NVIDIA Update Components (Version: 1.10.8) Onekey Theater (x32 Version: 3.0.0.9) Pando Media Booster (x32 Version: 2.6.0.7) Power2Go (x32 Version: 5.6.0.9109) PunkBuster Services (x32 Version: 0.993) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6680) Shared C Run-time for x64 (Version: 10.0.0) Skype™ 6.6 (x32 Version: 6.6.106) Steam (x32 Version: 1.0.0.0) SugarSync Manager (x32 Version: 1.9.61.90905) swMSM (x32 Version: 12.0.0.1) Synaptics Pointing Device Driver (Version: 16.2.10.13) Text-To-Speech-Runtime (x32 Version: 1.0.0.0) Unity Web Player (HKCU Version: ) Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (x32) Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2553065) (x32) Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2566458) (x32) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2826026) 32-Bit Edition (x32) Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition (x32) Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition (x32) Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition (x32) Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition (x32) Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (x32) Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition (x32) Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (x32) Update for Microsoft Word 2010 (KB2827323) 32-Bit Edition (x32) Update for Zip Extractor (HKCU) UserGuide (x32 Version: 1.0.0.9) VirtualDJ Home FREE (x32 Version: 7.4) VLC media player 2.0.7 (Version: 2.0.7) Webocton - Scriptly 0.8.95.6 (x32 Version: 0.8.95.6) Windows-Treiberpaket - Lenovo (ACPIVPC) System (06/15/2012 8.1.0.1) (Version: 06/15/2012 8.1.0.1) Windows-Treiberpaket - Lenovo (WUDFRd) LenovoVhid (06/19/2012 10.13.29.733) (Version: 06/19/2012 10.13.29.733) Zip Extractor Packages (HKCU) ==================== Restore Points ========================= 10-10-2013 17:08:50 Windows Update 13-10-2013 17:36:09 Windows Update 20-10-2013 14:51:49 Installed Java 7 Update 45 23-10-2013 11:42:13 Wiederherstellungsvorgang ==================== Hosts content: ========================== 2012-07-26 07:26 - 2012-07-26 07:26 - 00000824 ____N C:\WINDOWS\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {17D56BDB-BDA4-4666-A10B-742237168D11} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-08-21] (Piriform Ltd) Task: {188CC749-EBD6-42FB-BDED-1E4BCF89739A} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\WINDOWS\System32\lpksetup.exe [2012-09-20] (Microsoft Corporation) Task: {2441429B-3461-4E37-87B8-9028C7B4F65A} - System32\Tasks\Norton Internet Security CBE\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security CBE\Engine\20.4.0.40\SymErr.exe [2013-06-04] (Symantec Corporation) Task: {2BA98B35-B011-42CE-BBDD-BE79E4215036} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-23] (Google Inc.) Task: {474C0E16-D6AA-466F-9F08-242197394681} - System32\Tasks\DigitalSite => C:\Users\****\AppData\Roaming\FoxTab\UpdateProc\UpdateTask.exe [2013-04-12] () Task: {4F192888-AA49-4AAD-9FC3-8920E6CDEB2A} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security CBE\Engine\20.4.0.40\WSCStub.exe [2013-06-04] (Symantec Corporation) Task: {6154DCFF-9F98-4739-AA88-B9E635EF9814} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security CBE\Engine\20.4.0.40\SymErr.exe [2013-06-04] (Symantec Corporation) Task: {72035866-A1EC-4835-8FEF-DB76C0AD711E} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc Task: {A1C99C5A-BE87-4916-B4E7-2055D4834003} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security CBE\Engine\20.4.0.40\SymErr.exe [2013-06-04] (Symantec Corporation) Task: {A8E63B2B-5917-4B36-A508-DCE199A187EF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-23] (Google Inc.) Task: {AE80CD1E-1A14-4E09-91B3-E12ED5ABD7FE} - System32\Tasks\FoxTab => C:\Users\****\AppData\Roaming\FoxTab\UpdateProc\UpdateTask.exe [2013-04-12] () Task: {B90BD215-7EFC-433C-B6DE-3C6150B602B4} - System32\Tasks\Microsoft\Windows\Setup\Pre-staged GDR Notification => C:\Windows\system32\NotificationUI.exe [2013-08-16] (Microsoft Corporation) Task: {C92E3D90-0771-45A5-B900-8C72C08AAB83} - System32\Tasks\MirageAgent => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [2012-07-27] (CyberLink) Task: {F1095F9E-9BAF-427D-B86A-79D200C2E80A} - System32\Tasks\Norton Internet Security CBE\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security CBE\Engine\20.4.0.40\SymErr.exe [2013-06-04] (Symantec Corporation) Task: {FB4E5ACD-0921-4EA1-BFFE-DAC2EF4D49E1} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-08] (Adobe Systems Incorporated) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\DigitalSite.job => C:\Users\****\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE Task: C:\WINDOWS\Tasks\FoxTab.job => C:\Users\****\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-07-25 12:06 - 2013-07-25 12:07 - 00176048 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\ModernShared\ErrorReporting\ErrorReporting.dll 2012-08-31 07:54 - 2012-08-24 01:07 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2013-06-27 22:12 - 2013-06-27 22:12 - 00093696 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll 2013-08-23 13:44 - 2013-08-23 13:44 - 00017920 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PSIClient\9b61416a45a6322490dbb27382930695\PSIClient.ni.dll 2012-11-11 19:01 - 2012-06-25 11:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll 2013-07-25 21:30 - 2012-05-30 08:51 - 00699280 ____R () C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY CBE\ENGINE\20.4.0.40\wincfi39.dll 2012-11-11 18:54 - 2012-07-31 18:02 - 00004096 _____ () C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll 2013-10-04 15:49 - 2007-05-24 22:21 - 00278528 _____ () C:\Program Files (x86)\Lexmark 6500 Series\lxdfscw.dll 2013-10-04 15:49 - 2007-05-03 17:39 - 00589824 _____ () C:\Program Files (x86)\Lexmark 6500 Series\lxdfdatr.dll 2013-10-04 15:49 - 2007-03-26 09:39 - 00073728 _____ () C:\Program Files (x86)\Lexmark 6500 Series\lxdfcats.dll 2013-10-04 15:49 - 2007-06-08 10:52 - 00028672 _____ () C:\Program Files (x86)\Lexmark 6500 Series\App4R.Monitor.Common.dll 2013-10-04 15:49 - 2007-06-08 10:52 - 00036864 _____ () C:\Program Files (x86)\Lexmark 6500 Series\App4R.Monitor.Core.dll 2013-10-04 15:49 - 2007-06-08 10:52 - 00057344 _____ () C:\Program Files (x86)\Lexmark 6500 Series\app4r.devmons.mcmdevmon.dll 2013-10-04 15:49 - 2007-06-01 14:06 - 00011776 _____ () C:\Program Files (x86)\Lexmark 6500 Series\App4R.DevMons.MCMDevMon.AutoPlayUtil.dll 2013-10-23 16:28 - 2013-10-09 02:01 - 00698832 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\libglesv2.dll 2013-10-23 16:28 - 2013-10-09 02:01 - 00099792 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\libegl.dll 2013-10-23 16:28 - 2013-10-09 02:02 - 04055504 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dll 2013-10-23 16:28 - 2013-10-09 02:02 - 00415184 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll 2013-10-23 16:28 - 2013-10-09 02:01 - 01604560 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ffmpegsumo.dll 2013-10-23 16:28 - 2013-10-09 02:02 - 13584336 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: USB-IF xHCI USB Host Controller Description: USB-IF xHCI USB Host Controller Class Guid: {8a2edc79-c759-46f2-88af-9d4efe3b5eee} Manufacturer: Intel Corporation Service: XHCIPort Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver Name: Broadcom Bluetooth 4.0 USB Description: Broadcom Bluetooth 4.0 USB Class Guid: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974} Manufacturer: Broadcom Service: BTHUSB Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (10/23/2013 02:00:00 PM) (Source: ESENT) (User: ) Description: svchost (1708) SRUJet: Fehler -1811 (0xfffff8ed) beim Öffnen von Protokolldatei C:\WINDOWS\system32\SRU\SRU003F9.log. Error: (10/20/2013 08:16:11 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: lxdfJSWX.EXE, Version: 3.383.0.0, Zeitstempel: 0x4653c5e0 Name des fehlerhaften Moduls: lxdfJSWX.EXE, Version: 3.383.0.0, Zeitstempel: 0x4653c5e0 Ausnahmecode: 0xc000041d Fehleroffset: 0x000000000001454e ID des fehlerhaften Prozesses: 0x3524 Startzeit der fehlerhaften Anwendung: 0xlxdfJSWX.EXE0 Pfad der fehlerhaften Anwendung: lxdfJSWX.EXE1 Pfad des fehlerhaften Moduls: lxdfJSWX.EXE2 Berichtskennung: lxdfJSWX.EXE3 Vollständiger Name des fehlerhaften Pakets: lxdfJSWX.EXE4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: lxdfJSWX.EXE5 Error: (10/20/2013 08:16:09 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: lxdfJSWX.EXE, Version: 3.383.0.0, Zeitstempel: 0x4653c5e0 Name des fehlerhaften Moduls: lxdfJSWX.EXE, Version: 3.383.0.0, Zeitstempel: 0x4653c5e0 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000001454e ID des fehlerhaften Prozesses: 0x3524 Startzeit der fehlerhaften Anwendung: 0xlxdfJSWX.EXE0 Pfad der fehlerhaften Anwendung: lxdfJSWX.EXE1 Pfad des fehlerhaften Moduls: lxdfJSWX.EXE2 Berichtskennung: lxdfJSWX.EXE3 Vollständiger Name des fehlerhaften Pakets: lxdfJSWX.EXE4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: lxdfJSWX.EXE5 Error: (10/20/2013 08:16:04 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: lxdfJSWX.EXE, Version: 3.383.0.0, Zeitstempel: 0x4653c5e0 Name des fehlerhaften Moduls: lxdfJSWX.EXE, Version: 3.383.0.0, Zeitstempel: 0x4653c5e0 Ausnahmecode: 0xc000041d Fehleroffset: 0x000000000001454e ID des fehlerhaften Prozesses: 0x30a8 Startzeit der fehlerhaften Anwendung: 0xlxdfJSWX.EXE0 Pfad der fehlerhaften Anwendung: lxdfJSWX.EXE1 Pfad des fehlerhaften Moduls: lxdfJSWX.EXE2 Berichtskennung: lxdfJSWX.EXE3 Vollständiger Name des fehlerhaften Pakets: lxdfJSWX.EXE4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: lxdfJSWX.EXE5 Error: (10/20/2013 08:16:02 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: lxdfJSWX.EXE, Version: 3.383.0.0, Zeitstempel: 0x4653c5e0 Name des fehlerhaften Moduls: lxdfJSWX.EXE, Version: 3.383.0.0, Zeitstempel: 0x4653c5e0 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000001454e ID des fehlerhaften Prozesses: 0x30a8 Startzeit der fehlerhaften Anwendung: 0xlxdfJSWX.EXE0 Pfad der fehlerhaften Anwendung: lxdfJSWX.EXE1 Pfad des fehlerhaften Moduls: lxdfJSWX.EXE2 Berichtskennung: lxdfJSWX.EXE3 Vollständiger Name des fehlerhaften Pakets: lxdfJSWX.EXE4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: lxdfJSWX.EXE5 Error: (10/20/2013 08:14:49 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: lxdfcoms.exe, Version: 1.0.2.0, Zeitstempel: 0x464c9d04 Name des fehlerhaften Moduls: lxdfhbn3.dll, Version: 1.0.2.0, Zeitstempel: 0x464c9d06 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000005fc13 ID des fehlerhaften Prozesses: 0x8c0 Startzeit der fehlerhaften Anwendung: 0xlxdfcoms.exe0 Pfad der fehlerhaften Anwendung: lxdfcoms.exe1 Pfad des fehlerhaften Moduls: lxdfcoms.exe2 Berichtskennung: lxdfcoms.exe3 Vollständiger Name des fehlerhaften Pakets: lxdfcoms.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: lxdfcoms.exe5 Error: (10/20/2013 05:45:01 PM) (Source: Application Hang) (User: ) Description: Programm wmplayer.exe, Version 12.0.9200.16420 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 4e4 Startzeit: 01cecda845cf4c71 Endzeit: 4 Anwendungspfad: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Berichts-ID: 917eeeb0-399e-11e3-be8f-b888e39448a7 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (10/20/2013 05:42:25 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: BTWUIExt.exe, Version: 12.0.0.2200, Zeitstempel: 0x5048b7af Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.2.9200.16451, Zeitstempel: 0x50988aa6 Ausnahmecode: 0xe0434352 Fehleroffset: 0x000000000003811c ID des fehlerhaften Prozesses: 0x43e0 Startzeit der fehlerhaften Anwendung: 0xBTWUIExt.exe0 Pfad der fehlerhaften Anwendung: BTWUIExt.exe1 Pfad des fehlerhaften Moduls: BTWUIExt.exe2 Berichtskennung: BTWUIExt.exe3 Vollständiger Name des fehlerhaften Pakets: BTWUIExt.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: BTWUIExt.exe5 Error: (10/20/2013 05:42:24 PM) (Source: .NET Runtime) (User: ) Description: Anwendung: BTWUIExt.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet. Ausnahmeinformationen: System.Windows.Markup.XamlParseException Stapel: bei System.Windows.Markup.WpfXamlLoader.Load(System.Xaml.XamlReader, System.Xaml.IXamlObjectWriterFactory, Boolean, System.Object, System.Xaml.XamlObjectWriterSettings, System.Uri) bei System.Windows.Markup.WpfXamlLoader.LoadBaml(System.Xaml.XamlReader, Boolean, System.Object, System.Xaml.Permissions.XamlAccessLevel, System.Uri) bei System.Windows.Markup.XamlReader.LoadBaml(System.IO.Stream, System.Windows.Markup.ParserContext, System.Object, Boolean) bei System.Windows.Application.LoadBamlStreamWithSyncInfo(System.IO.Stream, System.Windows.Markup.ParserContext) bei System.Windows.Application.LoadComponent(System.Uri, Boolean) bei System.Windows.Application.DoStartup() bei System.Windows.Application.<.ctor>b__1(System.Object) bei System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32) bei MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate) bei System.Windows.Threading.DispatcherOperation.InvokeImpl() bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) bei System.Windows.Threading.DispatcherOperation.Invoke() bei System.Windows.Threading.Dispatcher.ProcessQueue() bei System.Windows.Threading.Dispatcher.WndProcHook(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef) bei MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef) bei MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object) bei System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32) bei MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate) bei System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32) bei MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr) bei MS.Win32.UnsafeNativeMethods.DispatchMessage(System.Windows.Interop.MSG ByRef) bei MS.Win32.UnsafeNativeMethods.DispatchMessage(System.Windows.Interop.MSG ByRef) bei System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame) bei System.Windows.Application.RunInternal(System.Windows.Window) bei System.Windows.Application.Run() bei BTWUIExt.App.Main() Error: (10/20/2013 05:41:02 PM) (Source: Application Hang) (User: ) Description: Programm rundll32.exe, Version 6.2.9200.16384 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 3ea8 Startzeit: 01cecdaab7cd9d5e Endzeit: 2 Anwendungspfad: C:\WINDOWS\system32\rundll32.exe Berichts-ID: 01e4a7b9-399e-11e3-be8f-b888e39448a7 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: System errors: ============= Error: (10/24/2013 09:11:53 PM) (Source: DCOM) (User: ****-PC) Description: App.AppX6v65ke6xy52mzp48tbdgqddy15h0mcbk.mca Error: (10/24/2013 09:11:53 PM) (Source: DCOM) (User: ****-PC) Description: App.AppX1222w7mnscdhak8wye3bynztq2t5x6q9.mca Error: (10/23/2013 01:59:39 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NVIDIA Update Service Daemon" wurde nicht richtig gestartet. Error: (10/23/2013 01:53:51 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Intel(R) PROSet/Wireless Zero Configuration Service" wurde mit folgendem Fehler beendet: %%2147770990 Error: (10/23/2013 01:53:32 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "lxdfCATSCustConnectService" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (10/23/2013 01:53:32 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst lxdfCATSCustConnectService erreicht. Error: (10/20/2013 08:14:57 PM) (Source: Service Control Manager) (User: ) Description: Dienst "lxdf_device" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (10/20/2013 05:52:29 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "lxdfCATSCustConnectService" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (10/20/2013 05:52:29 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst lxdfCATSCustConnectService erreicht. Error: (10/20/2013 03:05:41 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "lxdfCATSCustConnectService" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Microsoft Office Sessions: ========================= Error: (10/23/2013 02:00:00 PM) (Source: ESENT)(User: ) Description: svchost1708SRUJet: C:\WINDOWS\system32\SRU\SRU003F9.log-1811 (0xfffff8ed) Error: (10/20/2013 08:16:11 PM) (Source: Application Error)(User: ) Description: lxdfJSWX.EXE3.383.0.04653c5e0lxdfJSWX.EXE3.383.0.04653c5e0c000041d000000000001454e352401cecdc06f657a14C:\WINDOWS\system32\spool\DRIVERS\x64\3\lxdfJSWX.EXEC:\WINDOWS\system32\spool\DRIVERS\x64\3\lxdfJSWX.EXEb2156521-39b3-11e3-be90-b888e39448a7 Error: (10/20/2013 08:16:09 PM) (Source: Application Error)(User: ) Description: lxdfJSWX.EXE3.383.0.04653c5e0lxdfJSWX.EXE3.383.0.04653c5e0c0000005000000000001454e352401cecdc06f657a14C:\WINDOWS\system32\spool\DRIVERS\x64\3\lxdfJSWX.EXEC:\WINDOWS\system32\spool\DRIVERS\x64\3\lxdfJSWX.EXEb14f7f45-39b3-11e3-be90-b888e39448a7 Error: (10/20/2013 08:16:04 PM) (Source: Application Error)(User: ) Description: lxdfJSWX.EXE3.383.0.04653c5e0lxdfJSWX.EXE3.383.0.04653c5e0c000041d000000000001454e30a801cecdc042f8a633C:\WINDOWS\system32\spool\DRIVERS\x64\3\lxdfJSWX.EXEC:\WINDOWS\system32\spool\DRIVERS\x64\3\lxdfJSWX.EXEadeafefa-39b3-11e3-be90-b888e39448a7 Error: (10/20/2013 08:16:02 PM) (Source: Application Error)(User: ) Description: lxdfJSWX.EXE3.383.0.04653c5e0lxdfJSWX.EXE3.383.0.04653c5e0c0000005000000000001454e30a801cecdc042f8a633C:\WINDOWS\system32\spool\DRIVERS\x64\3\lxdfJSWX.EXEC:\WINDOWS\system32\spool\DRIVERS\x64\3\lxdfJSWX.EXEad16cab6-39b3-11e3-be90-b888e39448a7 Error: (10/20/2013 08:14:49 PM) (Source: Application Error)(User: ) Description: lxdfcoms.exe1.0.2.0464c9d04lxdfhbn3.dll1.0.2.0464c9d06c0000005000000000005fc138c001cecdac61555e08C:\WINDOWS\system32\lxdfcoms.exeC:\WINDOWS\system32\lxdfhbn3.dll81ab787d-39b3-11e3-be90-b888e39448a7 Error: (10/20/2013 05:45:01 PM) (Source: Application Hang)(User: ) Description: wmplayer.exe12.0.9200.164204e401cecda845cf4c714C:\Program Files (x86)\Windows Media Player\wmplayer.exe917eeeb0-399e-11e3-be8f-b888e39448a7 Error: (10/20/2013 05:42:25 PM) (Source: Application Error)(User: ) Description: BTWUIExt.exe12.0.0.22005048b7afKERNELBASE.dll6.2.9200.1645150988aa6e0434352000000000003811c43e001cecdaaf768e19eC:\Program Files\Lenovo\Bluetooth Software\BTWUIExt.exeC:\WINDOWS\system32\KERNELBASE.dll37429728-399e-11e3-be8f-b888e39448a7 Error: (10/20/2013 05:42:24 PM) (Source: .NET Runtime)(User: ) Description: Anwendung: BTWUIExt.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet. Ausnahmeinformationen: System.Windows.Markup.XamlParseException Stapel: bei System.Windows.Markup.WpfXamlLoader.Load(System.Xaml.XamlReader, System.Xaml.IXamlObjectWriterFactory, Boolean, System.Object, System.Xaml.XamlObjectWriterSettings, System.Uri) bei System.Windows.Markup.WpfXamlLoader.LoadBaml(System.Xaml.XamlReader, Boolean, System.Object, System.Xaml.Permissions.XamlAccessLevel, System.Uri) bei System.Windows.Markup.XamlReader.LoadBaml(System.IO.Stream, System.Windows.Markup.ParserContext, System.Object, Boolean) bei System.Windows.Application.LoadBamlStreamWithSyncInfo(System.IO.Stream, System.Windows.Markup.ParserContext) bei System.Windows.Application.LoadComponent(System.Uri, Boolean) bei System.Windows.Application.DoStartup() bei System.Windows.Application.<.ctor>b__1(System.Object) bei System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32) bei MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate) bei System.Windows.Threading.DispatcherOperation.InvokeImpl() bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) bei System.Windows.Threading.DispatcherOperation.Invoke() bei System.Windows.Threading.Dispatcher.ProcessQueue() bei System.Windows.Threading.Dispatcher.WndProcHook(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef) bei MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef) bei MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object) bei System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32) bei MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate) bei System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32) bei MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr) bei MS.Win32.UnsafeNativeMethods.DispatchMessage(System.Windows.Interop.MSG ByRef) bei MS.Win32.UnsafeNativeMethods.DispatchMessage(System.Windows.Interop.MSG ByRef) bei System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame) bei System.Windows.Application.RunInternal(System.Windows.Window) bei System.Windows.Application.Run() bei BTWUIExt.App.Main() Error: (10/20/2013 05:41:02 PM) (Source: Application Hang)(User: ) Description: rundll32.exe6.2.9200.163843ea801cecdaab7cd9d5e2C:\WINDOWS\system32\rundll32.exe01e4a7b9-399e-11e3-be8f-b888e39448a7 CodeIntegrity Errors: =================================== Date: 2013-10-25 23:58:26.750 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-10-25 18:35:15.071 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-10-25 17:23:01.047 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-10-25 14:46:52.742 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-10-24 16:18:45.318 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-10-24 15:50:14.028 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-10-23 21:41:11.516 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-10-23 19:59:23.274 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-10-23 19:59:23.201 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-10-23 17:20:06.136 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Percentage of memory in use: 29% Total physical RAM: 8057.77 MB Available physical RAM: 5719.48 MB Total Pagefile: 9273.77 MB Available Pagefile: 6612.44 MB Total Virtual: 8192 MB Available Virtual: 8191.77 MB ==================== Drives ================================ Drive c: (Windows8_OS) (Fixed) (Total:651.3 GB) (Free:486.76 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:21.97 GB) NTFS Drive e: (FLASHPOINT_DVD02) (CDROM) (Total:4.74 GB) (Free:0 GB) UDF ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 699 GB) (Disk ID: 38E90BD1) Partition: GPT Partition Type ==================== End Of Log ============================ |
27.10.2013, 01:25 | #4 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Firefox: [JavaScript-Anwendung] TypeError: window.flagCache[curip] is undefined Malwarebytes Anti-Rootkit (MBAR) Downloade dir bitte Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers
__________________ Logfiles bitte immer in CODE-Tags posten |
27.10.2013, 14:38 | #5 |
| Firefox: [JavaScript-Anwendung] TypeError: window.flagCache[curip] is undefined Nach dem Klick auf mbar.exe erschien erstmal ein Fenster mit folgender Meldung: Code:
ATTFilter Probable rootkit activity detected Registry value "Applnit_Dlls" has been found, which may be caused by rootkit activity. Note: Press "No" button if you're not sure. If the tool crashes or terminates unexpectedly during a system scan, restart the tool and press "Yes" should this message appear again. Do you want to remove this value and restart the tool? Hier das Logfile: Code:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.07.0.1007 www.malwarebytes.org Database version: v2013.10.27.03 Windows 8 x64 NTFS Internet Explorer 10.0.9200.16721 **** :: ****-PC [administrator] 27.10.2013 14:19:44 mbar-log-2013-10-27 (14-19-44).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: Objects scanned: 246894 Time elapsed: 8 minute(s), 51 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) Physical Sectors Detected: 0 (No malicious items detected) (end) |
27.10.2013, 16:20 | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Firefox: [JavaScript-Anwendung] TypeError: window.flagCache[curip] is undefined Adware/Junkware/Toolbars entfernen 1. Schritt: adwCleaner Downloade Dir bitte AdwCleaner auf deinen Desktop.
2. Schritt: JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
3. Schritt: Frisches Log mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ --> Firefox: [JavaScript-Anwendung] TypeError: window.flagCache[curip] is undefined |
28.10.2013, 12:14 | #7 |
| Firefox: [JavaScript-Anwendung] TypeError: window.flagCache[curip] is undefined Die Scans verliefen ohne besondere Vorkommnisse. AdwCleaner Code:
ATTFilter # AdwCleaner v3.010 - Bericht erstellt am 27/10/2013 um 17:10:41 # Updated 20/10/2013 von Xplode # Betriebssystem : Windows 8 (64 bits) # Benutzername : **** - ****-PC # Gestartet von : C:\Users\****\Downloads\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\apn Ordner Gelöscht : C:\Program Files (x86)\MyPC Backup Ordner Gelöscht : C:\Users\****\AppData\Roaming\digitalsite Ordner Gelöscht : C:\Users\****\AppData\Roaming\Systweak Datei Gelöscht : C:\WINDOWS\System32\roboot64.exe Datei Gelöscht : C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\2zjds9a1.default\foxydeal.sqlite Datei Gelöscht : C:\WINDOWS\Tasks\digitalsite.job Datei Gelöscht : C:\WINDOWS\System32\Tasks\digitalsite ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23} Schlüssel Gelöscht : HKCU\Software\APN PIP Schlüssel Gelöscht : HKCU\Software\dsiteproducts Schlüssel Gelöscht : HKCU\Software\InstallCore Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKLM\Software\InstallCore Schlüssel Gelöscht : HKLM\Software\PIP Schlüssel Gelöscht : HKLM\Software\systweak ***** [ Browser ] ***** -\\ Internet Explorer v10.0.9200.16537 -\\ Mozilla Firefox v24.0 (de) [ Datei : C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\2zjds9a1.default\prefs.js ] -\\ Google Chrome v30.0.1599.101 [ Datei : C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [2218 octets] - [27/10/2013 17:08:51] AdwCleaner[S0].txt - [1885 octets] - [27/10/2013 17:10:41] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1945 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.7 (10.15.2013:3) OS: Windows 8 x64 Ran by Heiko on 27.10.2013 at 17:19:24,00 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} ~~~ Files ~~~ Folders Failed to delete: [Folder] "C:\WINDOWS\syswow64\ai_recyclebin" ~~~ FireFox Emptied folder: C:\Users\Heiko\AppData\Roaming\mozilla\firefox\profiles\2zjds9a1.default\minidumps [6 files] ~~~ Chrome Successfully deleted: [Folder] C:\Users\Heiko\appdata\local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 27.10.2013 at 17:23:44,68 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-10-2013 Ran by **** (administrator) on ****-PC on 27-10-2013 17:26:14 Running from C:\Users\****\Downloads Windows 8 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe (Microsoft Corporation) C:\WINDOWS\system32\WLANExt.exe (Broadcom Corporation.) C:\WINDOWS\system32\BtwRSupportService.exe (Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Microsoft Corporation) C:\WINDOWS\system32\dashost.exe (MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe ( ) C:\WINDOWS\system32\lxdfcoms.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security CBE\Engine\20.4.0.40\ccSvcHst.exe () C:\WINDOWS\SysWOW64\PnkBstrA.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (BatBrowse) C:\Program Files (x86)\BatBrowse\updateBatBrowse.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (BatBrowse) C:\Program Files (x86)\BatBrowse\bin\utilBatBrowse.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security CBE\Engine\20.4.0.40\ccSvcHst.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics) C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe (Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (Lenovo) C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe (Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe () C:\Program Files\Realtek\Audio\HDA\FMAPP.exe () C:\Program Files (x86)\Lexmark 6500 Series\lxdfmon.exe () C:\Program Files (x86)\Lexmark 6500 Series\lxdfamon.exe (CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe (Microsoft) C:\Program Files (x86)\Lenovo\Intelligent Touchpad\IntelligentTouchpad.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\WINDOWS\SysWOW64\notepad.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [HotKeysCmds] - C:\WINDOWS\system32\hkcmd.exe [ ] () HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-27] (Synaptics Incorporated) HKLM\...\Run: [SynLenovoGestureMgr] - C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe [665400 2012-08-27] (Synaptics) HKLM\...\Run: [OnekeyStudio] - C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe [4196432 2012-08-10] (Lenovo) HKLM\...\Run: [Energy Management] - C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17080376 2012-11-11] (Lenovo (Beijing) Limited) HKLM\...\Run: [EnergyUtility] - C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [191544 2012-11-11] (Lenovo(beijing) Limited) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12921488 2012-09-14] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1214608 2012-09-14] (Realtek Semiconductor) HKLM\...\Run: [lxdfmon.exe] - C:\Program Files (x86)\Lexmark 6500 Series\lxdfmon.exe [455600 2007-06-11] () HKLM\...\Run: [lxdfamon] - C:\Program Files (x86)\Lexmark 6500 Series\lxdfamon.exe [20480 2007-06-01] () Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [Steam] - C:\Program Files (x86)\Steam\steam.exe [1813928 2013-10-09] (Valve Corporation) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [277504 2012-08-16] (Intel Corporation) HKLM-x32\...\Run: [YouCam Mirage] - C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2012-07-27] (CyberLink) HKLM-x32\...\Run: [YouCam Tray] - C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [167024 2012-07-27] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateP2GShortCut] - C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [217088 2012-04-18] (CyberLink Corp.) HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.) HKLM-x32\...\Run: [Intel AppUp(SM) center] - C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-12] (Intel Corporation) HKLM-x32\...\Run: [IntellingentTouchpad] - C:\Program Files (x86)\Lenovo\Intelligent Touchpad\IntelligentTouchpad.exe [673336 2012-07-23] (Microsoft) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [TrayServer] - C:\Program Files (x86)\MAGIX\Video_deluxe_16_Premium\Trayserver.exe [90112 2008-08-07] (MAGIX AG) HKLM-x32\...\Run: [Dolby Home Theater v4] - C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [508656 2012-07-25] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [Lexmark 6500 Series] - C:\Program Files (x86)\Lexmark 6500 Series\fm3032.exe [308144 2007-06-11] () AppInit_DLLs: C:\WINDOWS\system32\nvinitx.dll [266448 2013-06-21] (NVIDIA Corporation) AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll [214448 2013-06-21] (NVIDIA Corporation) Startup: C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo13.msn.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com SearchScopes: HKLM - DefaultScope {E94F6640-DF04-4C3A-9ABD-D8246A05E733} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS SearchScopes: HKLM - {E94F6640-DF04-4C3A-9ABD-D8246A05E733} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS SearchScopes: HKLM-x32 - {E94F6640-DF04-4C3A-9ABD-D8246A05E733} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS SearchScopes: HKCU - {E94F6640-DF04-4C3A-9ABD-D8246A05E733} URL = BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security CBE\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation) BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security CBE\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: BatBrowse - {b67b3dbb-c1c9-49d2-b016-2748b0b5017e} - C:\Program Files (x86)\BatBrowse\BatBrowsebho.dll (BatBrowse) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security CBE\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation) DPF: HKLM-x32 {22E5D91F-89E6-4405-AD9C-0AF27BA6F06B} file:///C:/Users/****/Videos/Mario_Abiball/components/hidinputmonitorx.ocx DPF: HKLM-x32 {4F63D44B-6274-4D60-8AB1-CAA7116B8AF3} file:///C:/Users/****/Videos/Mario_Abiball/components/A9.ocx DPF: HKLM-x32 {7030CC6C-1A88-4591-BB5A-651B9F7F0C30} file:///C:/Users/****/Videos/Mario_Abiball/components/wmvhdrating.ocx Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\2zjds9a1.default FF DefaultSearchEngine: Wikipedia (de) FF SelectedSearchEngine: Wikipedia (de) FF Homepage: hxxp://www.google.de/ FF NetworkProxy: "http", "proxy-1.cojobo.net" FF NetworkProxy: "http_port", 3128 FF NetworkProxy: "share_proxy_settings", true FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1203133.dll (Adobe Systems, Inc.) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\WINDOWS\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\****\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: ProxTube - Gesperrte YouTube Videos entsperren - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\2zjds9a1.default\Extensions\ich@maltegoetz.de FF Extension: Flagfox - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\2zjds9a1.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b} FF Extension: Domain Details - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\2zjds9a1.default\Extensions\{152455DE-7B40-4bcf-B5B4-C68A1BE85A91} FF Extension: WOT - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\2zjds9a1.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} FF Extension: firebug - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\2zjds9a1.default\Extensions\firebug@software.joehewitt.com.xpi FF Extension: noscript - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\2zjds9a1.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi FF Extension: Adblock Plus - C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\2zjds9a1.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.1.2\coFFPlgn\ FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.1.2\coFFPlgn\ FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.1.2\IPSFF FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.1.2\IPSFF FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK Chrome: ======= CHR RestoreOnStartup: "hxxp://www.google.de/" CHR Extension: (Docs) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0 CHR Extension: (Google Drive) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0 CHR Extension: (YouTube) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0 CHR Extension: (Adblock Plus) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.6.1_0 CHR Extension: (Google Search) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0 CHR Extension: (uDomainFlag) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\eklbfdpploakpkdakoielobggbhemlnm\0.0.1.5_0 CHR Extension: (Black metallic theme) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbhhihkiaeeioepkklgfpdohnemkjcoi\5_0 CHR Extension: (Gmail) - C:\Users\****\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKLM\...\Chrome\Extension: [dchmpbaclbiioedakpcldenooikekokm] - C:\Users\****\AppData\Local\foxtab_speeddial.crx CHR HKLM-x32\...\Chrome\Extension: [ccncljhbalbbkkfgopogabimepmfkmff] - C:\Program Files (x86)\BatBrowse\ccncljhbalbbkkfgopogabimepmfkmff.crx CHR HKLM-x32\...\Chrome\Extension: [dchmpbaclbiioedakpcldenooikekokm] - C:\Users\****\AppData\Local\foxtab_speeddial.crx CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security CBE\Engine\20.4.0.40\Exts\Chrome.crx ==================== Services (Whitelisted) ================= R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2252088 2012-08-25] (Broadcom Corporation.) R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [957304 2012-09-06] (Broadcom Corporation.) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation) S2 lxdfCATSCustConnectService; C:\WINDOWS\system32\spool\DRIVERS\x64\3\\lxdfserv.exe [33712 2007-05-29] (Lexmark International, Inc.) R2 lxdf_device; C:\WINDOWS\system32\lxdfcoms.exe [1053104 2007-05-29] ( ) R2 lxdf_device; C:\WINDOWS\SysWow64\lxdfcoms.exe [598960 2007-05-29] ( ) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [272176 2012-07-18] () R2 NIS; C:\Program Files (x86)\Norton Internet Security CBE\Engine\20.4.0.40\ccSvcHst.exe [144368 2013-05-21] (Symantec Corporation) R2 PnkBstrA; C:\WINDOWS\SysWow64\PnkBstrA.exe [76888 2013-09-12] () R2 Update BatBrowse; C:\Program Files (x86)\BatBrowse\updateBatBrowse.exe [65824 2013-10-22] (BatBrowse) R2 Util BatBrowse; C:\Program Files (x86)\BatBrowse\bin\utilBatBrowse.exe [65824 2013-10-27] (BatBrowse) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2699568 2012-07-18] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== S3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [165688 2012-08-25] (Broadcom Corporation.) R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.1.2\Definitions\BASHDefs\20131022.001\BHDrvx64.sys [1524824 2013-10-23] (Symantec Corporation) S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation) R1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1404000.028\ccSetx64.sys [169048 2013-04-16] (Symantec Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-08-27] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [140376 2013-08-27] (Symantec Corporation) R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.1.2\Definitions\IPSDefs\20131025.001\IDSvia64.sys [521816 2013-10-18] (Symantec Corporation) R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.1.2\Definitions\VirusDefs\20131026.007\ENG64.SYS [126040 2013-10-23] (Symantec Corporation) R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.1.2\Definitions\VirusDefs\20131026.007\EX64.SYS [2099288 2013-10-23] (Symantec Corporation) R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [4273192 2012-08-19] (Intel Corporation) R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [8222736 2012-06-15] (Realtek Semiconductor Corp.) R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [43832 2012-08-27] (Synaptics Incorporated) R3 SRTSP; C:\Windows\System32\Drivers\NISx64\1404000.028\SRTSP64.SYS [796760 2013-05-16] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1404000.028\SRTSPX64.SYS [36952 2013-03-05] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\NISx64\1404000.028\SYMDS64.SYS [493656 2013-05-21] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\NISx64\1404000.028\SYMEFA64.SYS [1139800 2013-05-23] (Symantec Corporation) S0 SymELAM; C:\Windows\System32\drivers\NISx64\1404000.028\SymELAM.sys [23448 2012-06-20] (Symantec Corporation) R3 SymEvent; C:\WINDOWS\system32\Drivers\SYMEVENT64x86.SYS [177312 2013-07-25] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\NISx64\1404000.028\Ironx64.SYS [224416 2013-03-05] (Symantec Corporation) R1 SymNetS; C:\Windows\System32\Drivers\NISx64\1404000.028\SYMNETS.SYS [433752 2013-04-25] (Symantec Corporation) S3 usb3Hub; C:\Windows\System32\drivers\usb3Hub.sys [48096 2012-08-09] (Windows (R) Win 7 DDK provider) S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink) S3 XHCIPort; C:\Windows\System32\drivers\XHCIPort.sys [188384 2012-08-09] (Windows (R) Win 7 DDK provider) S3 xusb22; C:\Windows\System32\drivers\xusb22.sys [89088 2012-07-26] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-27 17:23 - 2013-10-27 17:23 - 00001416 _____ C:\Users\****\Desktop\JRT.txt 2013-10-27 17:19 - 2013-10-27 17:19 - 00000000 ____D C:\WINDOWS\ERUNT 2013-10-27 17:17 - 2013-10-27 17:17 - 01033335 _____ (Thisisu) C:\Users\****\Downloads\JRT.exe 2013-10-27 17:08 - 2013-10-27 17:10 - 00000000 ____D C:\AdwCleaner 2013-10-27 17:08 - 2013-10-27 17:08 - 01060070 _____ C:\Users\****\Downloads\adwcleaner.exe 2013-10-27 14:19 - 2013-10-27 14:20 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2013-10-27 14:19 - 2013-10-27 14:19 - 00116440 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2013-10-27 14:19 - 2013-10-27 14:19 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-27 14:18 - 2013-10-27 14:40 - 00091352 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2013-10-27 14:15 - 2013-10-27 14:40 - 00000000 ____D C:\Users\****\Desktop\mbar 2013-10-27 14:14 - 2013-10-27 14:14 - 12576792 _____ (Malwarebytes Corp.) C:\Users\****\Downloads\mbar-1.07.0.1007.exe 2013-10-27 13:48 - 2013-10-27 13:48 - 00000580 _____ C:\WINDOWS\PFRO.log 2013-10-27 12:51 - 2013-10-27 12:51 - 00030720 _____ C:\Users\****\Downloads\tab-2-3-2002.xls 2013-10-26 09:43 - 2013-10-26 09:58 - 00035780 _____ C:\Users\****\Downloads\Addition.txt 2013-10-26 09:42 - 2013-10-26 09:42 - 00000000 ____D C:\FRST 2013-10-26 09:36 - 2013-10-26 09:36 - 01956086 _____ (Farbar) C:\Users\****\Downloads\FRST64.exe 2013-10-26 09:31 - 2013-10-27 16:31 - 00000306 _____ C:\WINDOWS\Tasks\FoxTab.job 2013-10-26 09:31 - 2013-10-27 13:54 - 00000000 ____D C:\Program Files (x86)\BatBrowse 2013-10-26 09:31 - 2013-10-26 09:31 - 00002644 _____ C:\WINDOWS\System32\Tasks\FoxTab 2013-10-26 09:31 - 2013-10-26 09:31 - 00000000 ____D C:\Users\****\AppData\Roaming\FoxTab 2013-10-26 09:31 - 2013-10-26 09:31 - 00000000 ____D C:\Users\****\AppData\Roaming\0D0S1L2Z1P1B 2013-10-26 09:30 - 2013-10-26 09:30 - 00364318 _____ C:\Users\****\AppData\Local\foxtab_speeddial.crx 2013-10-26 09:30 - 2013-10-26 09:30 - 00000000 ____D C:\Program Files (x86)\Foxtab 2013-10-23 15:28 - 2013-10-23 15:28 - 00002266 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-10-23 15:18 - 2013-10-27 17:23 - 00001126 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2013-10-23 15:18 - 2013-10-27 17:13 - 00001122 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-23 15:18 - 2013-10-23 15:18 - 00004098 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2013-10-23 15:18 - 2013-10-23 15:18 - 00003862 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2013-10-23 15:10 - 2013-10-23 15:19 - 00000000 ____D C:\Users\****\AppData\Roaming\Opera Software 2013-10-23 15:10 - 2013-10-23 15:19 - 00000000 ____D C:\Users\****\AppData\Local\Opera Software 2013-10-23 15:10 - 2013-10-23 15:19 - 00000000 ____D C:\Program Files (x86)\Opera 2013-10-23 11:59 - 2013-10-23 11:59 - 00000000 ____D C:\WINDOWS\System32\Tasks\Aufgaben der Ereignisanzeige 2013-10-22 17:56 - 2013-10-22 17:56 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies 2013-10-21 14:05 - 2013-10-21 14:06 - 00000000 ____D C:\Users\****\AppData\Local\Google 2013-10-21 14:05 - 2013-10-21 14:06 - 00000000 ____D C:\Program Files (x86)\Google 2013-10-20 20:46 - 2013-10-20 20:46 - 00011792 _____ C:\Users\****\AppData\Local\recently-used.xbel 2013-10-20 15:52 - 2013-10-20 15:52 - 00004886 _____ C:\WINDOWS\SysWOW64\jupdate-1.7.0_45-b18.log 2013-10-20 15:52 - 2013-10-20 15:52 - 00000000 ____D C:\ProgramData\Oracle 2013-10-20 14:17 - 2013-10-23 12:50 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-10-13 17:33 - 2013-08-03 07:40 - 01374208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wdc.dll 2013-10-13 17:33 - 2013-08-03 07:40 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wvc.dll 2013-10-13 17:33 - 2013-08-03 07:40 - 00462336 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmon.ocx 2013-10-13 17:33 - 2013-08-03 06:14 - 00399360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sysmon.ocx 2013-10-13 17:33 - 2013-08-03 06:13 - 01245696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wdc.dll 2013-10-13 17:33 - 2013-08-03 06:13 - 00437248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wvc.dll 2013-10-13 17:33 - 2013-08-02 07:28 - 19758080 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2013-10-13 17:33 - 2013-08-02 07:28 - 10116608 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2013-10-13 17:33 - 2013-08-02 06:08 - 17561088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2013-10-13 17:33 - 2013-08-02 06:08 - 08858112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2013-10-13 17:32 - 2013-08-10 06:21 - 00448512 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll 2013-10-13 17:32 - 2013-08-10 06:21 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncInfo.dll 2013-10-13 17:32 - 2013-08-10 04:58 - 00356352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll 2013-10-13 17:32 - 2013-08-02 07:28 - 00222208 _____ (Microsoft Corporation) C:\WINDOWS\system32\shdocvw.dll 2013-10-13 17:32 - 2013-08-02 07:26 - 02304512 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll 2013-10-13 17:32 - 2013-08-02 06:08 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shdocvw.dll 2013-10-13 17:32 - 2013-08-02 06:06 - 02035712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll 2013-10-13 17:32 - 2013-08-01 11:41 - 02233688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys 2013-10-13 17:32 - 2013-07-31 00:30 - 00386923 _____ C:\WINDOWS\system32\ApnDatabase.xml 2013-10-13 17:32 - 2013-07-25 00:10 - 00158208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mbsmsapi.dll 2013-10-13 17:32 - 2013-07-25 00:06 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\system32\mbsmsapi.dll 2013-10-13 17:32 - 2013-04-10 00:17 - 01125888 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll 2013-10-13 17:32 - 2013-04-09 23:29 - 00893952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll 2013-10-13 15:30 - 2013-10-13 15:30 - 00000000 ____D C:\WINDOWS\System32\Tasks\Norton Internet Security 2013-10-12 13:39 - 2013-10-12 13:40 - 00434712 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2013-10-10 17:49 - 2013-10-10 17:49 - 00000000 ____D C:\Users\****\AppData\Roaming\Unity 2013-10-10 17:45 - 2013-10-10 17:45 - 00000000 ____D C:\Users\****\AppData\Local\Unity 2013-10-10 16:55 - 2013-09-23 00:28 - 01767936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2013-10-10 16:55 - 2013-09-23 00:28 - 01141248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2013-10-10 16:55 - 2013-09-23 00:27 - 14335488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2013-10-10 16:55 - 2013-09-23 00:27 - 13761024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2013-10-10 16:55 - 2013-09-23 00:27 - 02876928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2013-10-10 16:55 - 2013-09-23 00:27 - 02048512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2013-10-10 16:55 - 2013-09-23 00:27 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll 2013-10-10 16:55 - 2013-09-23 00:27 - 00493056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2013-10-10 16:55 - 2013-09-22 23:55 - 02241024 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2013-10-10 16:55 - 2013-09-22 23:55 - 01365504 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2013-10-10 16:55 - 2013-09-22 23:55 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2013-10-10 16:55 - 2013-09-22 23:54 - 19252224 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2013-10-10 16:55 - 2013-09-22 23:54 - 15404544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2013-10-10 16:55 - 2013-09-22 23:54 - 03959296 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2013-10-10 16:55 - 2013-09-22 23:54 - 02647552 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2013-10-10 16:55 - 2013-09-22 23:54 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll 2013-10-10 16:55 - 2013-09-22 23:54 - 00603136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2013-10-10 16:55 - 2013-07-06 01:15 - 00652288 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll 2013-10-10 16:55 - 2013-07-04 03:13 - 00541696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll 2013-10-10 16:55 - 2013-05-15 23:37 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UXInit.dll 2013-10-10 16:55 - 2013-05-15 23:35 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\UXInit.dll 2013-10-10 16:55 - 2013-05-14 14:14 - 02706432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb 2013-10-10 16:55 - 2013-05-14 10:23 - 02706432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb 2013-10-10 16:55 - 2013-04-28 23:28 - 00915968 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxtheme.dll 2013-10-10 16:55 - 2013-02-21 11:29 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesysprep.dll 2013-10-10 16:55 - 2013-02-21 11:29 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll 2013-10-10 16:55 - 2013-02-21 11:29 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll 2013-10-10 16:55 - 2013-02-21 11:29 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll 2013-10-10 16:55 - 2013-02-21 11:14 - 00136704 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesysprep.dll 2013-10-10 16:55 - 2013-02-21 11:14 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll 2013-10-10 16:55 - 2013-02-19 10:53 - 00534528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uxtheme.dll 2013-10-10 16:55 - 2012-11-08 05:20 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll 2013-10-10 16:55 - 2012-11-08 05:20 - 00039936 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll 2013-10-10 16:54 - 2013-08-23 06:11 - 04040192 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2013-10-10 16:54 - 2013-07-05 23:02 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbcir.sys 2013-10-10 16:54 - 2013-07-05 23:01 - 00210560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbvideo.sys 2013-10-10 16:54 - 2013-07-01 23:14 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbprint.sys 2013-10-10 16:54 - 2013-06-29 04:08 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidparse.sys 2013-10-10 16:54 - 2013-06-29 04:07 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidclass.sys 2013-10-10 16:54 - 2013-06-22 06:45 - 00785624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Wdf01000.sys 2013-10-10 16:54 - 2013-06-22 06:45 - 00054488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdfLdr.sys 2013-10-10 16:54 - 2013-05-27 00:17 - 00035328 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll 2013-10-10 16:54 - 2013-05-26 23:59 - 00046080 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll 2013-10-10 16:54 - 2013-05-25 04:15 - 00362496 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll 2013-10-10 16:54 - 2013-05-25 03:32 - 00300032 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll 2013-10-10 16:53 - 2013-07-19 23:13 - 00124112 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll 2013-10-10 16:53 - 2013-07-19 23:13 - 00102608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2013-10-10 16:53 - 2013-07-02 02:41 - 00447320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS 2013-10-10 16:53 - 2013-07-02 02:41 - 00337752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS 2013-10-10 16:53 - 2013-07-02 02:41 - 00213336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UCX01000.SYS 2013-10-10 16:53 - 2013-07-01 02:42 - 00623448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbhub.sys 2013-10-10 16:53 - 2013-07-01 02:42 - 00498008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbport.sys 2013-10-10 16:53 - 2013-07-01 02:42 - 00079192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbehci.sys 2013-10-10 16:53 - 2013-07-01 02:42 - 00021848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbd.sys 2013-10-10 16:53 - 2013-06-29 04:07 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbuhci.sys 2013-10-10 16:53 - 2013-06-29 04:06 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbccgp.sys 2013-10-05 20:00 - 2013-10-05 20:00 - 00000000 ____D C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2013-10-04 14:52 - 2007-05-01 02:14 - 00420352 _____ C:\WINDOWS\system32\lxdfcoin.dll 2013-10-04 14:52 - 2006-10-30 13:38 - 01462272 _____ (Microsoft Corporation) C:\WINDOWS\system32\lxdfg.dll 2013-10-04 14:51 - 2007-05-24 12:44 - 00045568 _____ C:\WINDOWS\system32\LXDFPMON.DLL 2013-10-04 14:51 - 2007-05-24 12:44 - 00014336 _____ C:\WINDOWS\system32\LXDFFXPU.DLL 2013-10-04 14:50 - 2013-10-04 14:50 - 00001076 _____ C:\Users\Public\Desktop\Lexmark Productivity Studio - 6500 Series.LNK 2013-10-04 14:50 - 2013-10-04 14:50 - 00000000 ____D C:\ProgramData\6500 Series 2013-10-04 14:50 - 2007-05-24 12:45 - 00003584 _____ () C:\WINDOWS\system32\LXDFPMRC.DLL 2013-10-04 14:49 - 2013-10-04 14:51 - 00000000 ____D C:\Program Files (x86)\Lexmark 6500 Series 2013-10-04 14:49 - 2007-05-28 12:10 - 00147456 _____ (Lexmark International, Inc.) C:\WINDOWS\SysWOW64\lxdfjswr.dll 2013-10-04 14:49 - 2007-05-28 12:10 - 00114688 _____ (Lexmark International, Inc.) C:\WINDOWS\SysWOW64\lxdfinsr.dll 2013-10-04 14:49 - 2007-05-28 12:10 - 00036864 _____ (Lexmark International, Inc.) C:\WINDOWS\SysWOW64\lxdfcur.dll 2013-10-04 14:49 - 2007-05-28 03:14 - 00208896 _____ (Lexmark International, Inc.) C:\WINDOWS\SysWOW64\lxdfinsb.dll 2013-10-04 14:49 - 2007-05-28 03:14 - 00090112 _____ (Lexmark International, Inc.) C:\WINDOWS\SysWOW64\lxdfcub.dll 2013-10-04 14:49 - 2007-05-28 03:07 - 00176128 _____ (Lexmark International, Inc.) C:\WINDOWS\SysWOW64\lxdfins.dll 2013-10-04 14:49 - 2007-05-28 03:07 - 00077824 _____ (Lexmark International, Inc.) C:\WINDOWS\SysWOW64\lxdfcu.dll 2013-10-04 14:49 - 2007-05-28 03:03 - 00503808 _____ (Lexmark International, Inc.) C:\WINDOWS\SysWOW64\lxdfutil.dll 2013-10-04 14:49 - 2007-05-23 20:39 - 01512613 _____ C:\WINDOWS\SysWOW64\LXDFhelp.chm 2013-10-04 14:49 - 2007-05-23 05:34 - 00385024 _____ () C:\WINDOWS\SysWOW64\lxdfcomx.dll 2013-10-04 14:49 - 2007-05-17 19:08 - 00647168 _____ ( ) C:\WINDOWS\SysWOW64\lxdfpmui.dll 2013-10-04 14:49 - 2007-05-17 19:06 - 01200128 _____ ( ) C:\WINDOWS\SysWOW64\lxdfserv.dll 2013-10-04 14:49 - 2007-05-17 19:00 - 00356352 _____ ( ) C:\WINDOWS\SysWOW64\lxdfinpa.dll 2013-10-04 14:49 - 2007-05-17 18:57 - 00950272 _____ ( ) C:\WINDOWS\SysWOW64\lxdfusb1.dll 2013-10-04 14:49 - 2007-05-17 18:52 - 00348160 _____ C:\WINDOWS\SysWOW64\lxdfinst.dll 2013-10-04 14:49 - 2007-05-17 18:52 - 00339968 _____ ( ) C:\WINDOWS\SysWOW64\lxdfiesc.dll 2013-10-04 14:49 - 2007-01-22 10:53 - 00126976 _____ (Lexmark International Inc.) C:\WINDOWS\SysWOW64\lxdflnks.dll 2013-10-04 14:49 - 2007-01-22 10:53 - 00000060 ____H C:\WINDOWS\system32\lxdfrwrd.ini 2013-10-04 14:49 - 2006-10-24 10:16 - 00983121 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lxdfgf.dll 2013-10-04 14:48 - 2013-10-04 14:54 - 00101925 _____ C:\WINDOWS\system32\LexFiles.ulf 2013-10-04 14:48 - 2013-10-04 14:51 - 00000000 ____D C:\Program Files\Lexmark 6500 Series 2013-10-04 14:48 - 2007-05-29 11:06 - 01053104 _____ ( ) C:\WINDOWS\system32\lxdfcoms.exe 2013-10-04 14:48 - 2007-05-29 11:06 - 00598960 _____ ( ) C:\WINDOWS\SysWOW64\lxdfcoms.exe 2013-10-04 14:48 - 2007-05-29 11:06 - 00598960 _____ ( ) C:\WINDOWS\system32\lxdfcfg.exe 2013-10-04 14:48 - 2007-05-29 11:06 - 00515504 _____ ( ) C:\WINDOWS\system32\lxdfih.exe 2013-10-04 14:48 - 2007-05-29 11:06 - 00365488 _____ ( ) C:\WINDOWS\SysWOW64\lxdfcfg.exe 2013-10-04 14:48 - 2007-05-29 11:06 - 00320432 _____ ( ) C:\WINDOWS\SysWOW64\lxdfih.exe 2013-10-04 14:48 - 2007-05-29 10:49 - 00002003 _____ C:\WINDOWS\SysWOW64\lxdf.loc 2013-10-04 14:48 - 2007-05-29 10:49 - 00002003 _____ C:\WINDOWS\system32\lxdf.loc 2013-10-04 14:48 - 2007-05-28 13:08 - 00130560 _____ (Lexmark International, Inc.) C:\WINDOWS\system32\lxdfjswr.dll 2013-10-04 14:48 - 2007-05-28 13:08 - 00097280 _____ (Lexmark International, Inc.) C:\WINDOWS\system32\lxdfinsr.dll 2013-10-04 14:48 - 2007-05-28 13:08 - 00023552 _____ (Lexmark International, Inc.) C:\WINDOWS\system32\lxdfcur.dll 2013-10-04 14:48 - 2007-05-28 12:39 - 00299520 _____ () C:\WINDOWS\system32\lxdfgrd.dll 2013-10-04 14:48 - 2007-05-28 04:14 - 00189952 _____ (Lexmark International, Inc.) C:\WINDOWS\system32\lxdfinsb.dll 2013-10-04 14:48 - 2007-05-28 04:14 - 00073216 _____ (Lexmark International, Inc.) C:\WINDOWS\system32\lxdfcub.dll 2013-10-04 14:48 - 2007-05-28 04:10 - 00235520 _____ (Lexmark International, Inc.) C:\WINDOWS\system32\lxdfins.dll 2013-10-04 14:48 - 2007-05-28 04:10 - 00100864 _____ (Lexmark International, Inc.) C:\WINDOWS\system32\lxdfcu.dll 2013-10-04 14:48 - 2007-05-28 04:08 - 00715264 _____ (Lexmark International, Inc.) C:\WINDOWS\system32\lxdfutil.dll 2013-10-04 14:48 - 2007-05-23 20:39 - 01512613 _____ C:\WINDOWS\system32\LXDFhelp.chm 2013-10-04 14:48 - 2007-05-17 19:31 - 00980992 _____ ( ) C:\WINDOWS\system32\lxdfpmui.dll 2013-10-04 14:48 - 2007-05-17 19:28 - 01895936 _____ ( ) C:\WINDOWS\system32\lxdfserv.dll 2013-10-04 14:48 - 2007-05-17 19:22 - 00879104 _____ ( ) C:\WINDOWS\system32\lxdflmpm.dll 2013-10-04 14:48 - 2007-05-17 19:22 - 00563200 _____ ( ) C:\WINDOWS\system32\lxdfcomm.dll 2013-10-04 14:48 - 2007-05-17 19:22 - 00541184 _____ ( ) C:\WINDOWS\system32\lxdfinpa.dll 2013-10-04 14:48 - 2007-05-17 19:20 - 01065984 _____ ( ) C:\WINDOWS\system32\lxdfhbn3.dll 2013-10-04 14:48 - 2007-05-17 19:19 - 01501696 _____ ( ) C:\WINDOWS\system32\lxdfusb1.dll 2013-10-04 14:48 - 2007-05-17 19:19 - 01489408 _____ ( ) C:\WINDOWS\system32\lxdfcomc.dll 2013-10-04 14:48 - 2007-05-17 19:15 - 00668672 _____ ( ) C:\WINDOWS\system32\lxdfhcp.dll 2013-10-04 14:48 - 2007-05-17 19:15 - 00509440 _____ ( ) C:\WINDOWS\system32\lxdfiesc.dll 2013-10-04 14:48 - 2007-05-17 19:14 - 00524288 _____ C:\WINDOWS\system32\lxdfinst.dll 2013-10-04 14:48 - 2007-05-17 19:13 - 00047104 _____ ( ) C:\WINDOWS\system32\lxdfprox.dll 2013-10-04 14:48 - 2007-05-17 19:00 - 00565248 _____ ( ) C:\WINDOWS\SysWOW64\lxdflmpm.dll 2013-10-04 14:48 - 2007-05-17 19:00 - 00364544 _____ ( ) C:\WINDOWS\SysWOW64\lxdfcomm.dll 2013-10-04 14:48 - 2007-05-17 18:59 - 00663552 _____ ( ) C:\WINDOWS\SysWOW64\lxdfhbn3.dll 2013-10-04 14:48 - 2007-05-17 18:56 - 00860160 _____ ( ) C:\WINDOWS\SysWOW64\lxdfcomc.dll 2013-10-04 14:48 - 2007-05-17 18:51 - 00053248 _____ ( ) C:\WINDOWS\SysWOW64\lxdfprox.dll 2013-10-04 14:48 - 2007-05-11 02:56 - 00065536 _____ (Lexmark International) C:\WINDOWS\system32\lxdfcfg.dll 2013-10-04 14:48 - 2007-05-11 02:52 - 00077906 _____ (Lexmark International) C:\WINDOWS\SysWOW64\lxdfcfg.dll 2013-10-04 14:48 - 2006-10-24 10:16 - 00983121 _____ (Microsoft Corporation) C:\WINDOWS\system32\lxdfgf.dll 2013-10-04 14:42 - 2013-10-04 14:42 - 00000178 _____ C:\lxdf.log 2013-10-04 14:42 - 2013-10-04 14:42 - 00000047 _____ C:\WINDOWS\WinInit.Ini 2013-10-04 14:22 - 2013-10-04 14:22 - 00003128 _____ C:\WINDOWS\System32\Tasks\{E2DB31D0-6EAC-4C42-B453-4B647AF08E2B} 2013-10-03 21:18 - 2013-10-03 21:18 - 05238341 _____ C:\ProgramData\SPLA1B2.tmp ==================== One Month Modified Files and Folders ======= 2013-10-27 17:23 - 2013-10-27 17:23 - 00001416 _____ C:\Users\****\Desktop\JRT.txt 2013-10-27 17:23 - 2013-10-23 15:18 - 00001126 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2013-10-27 17:19 - 2013-10-27 17:19 - 00000000 ____D C:\WINDOWS\ERUNT 2013-10-27 17:17 - 2013-10-27 17:17 - 01033335 _____ (Thisisu) C:\Users\****\Downloads\JRT.exe 2013-10-27 17:17 - 2012-11-12 02:40 - 00754172 _____ C:\WINDOWS\system32\perfh007.dat 2013-10-27 17:17 - 2012-11-12 02:40 - 00156362 _____ C:\WINDOWS\system32\perfc007.dat 2013-10-27 17:17 - 2012-07-26 08:28 - 01748838 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2013-10-27 17:16 - 2013-07-24 22:51 - 00000000 ____D C:\Users\****\.gimp-2.8 2013-10-27 17:13 - 2013-10-23 15:18 - 00001122 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-27 17:13 - 2012-07-26 06:26 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM 2013-10-27 17:12 - 2012-07-26 08:22 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2013-10-27 17:11 - 2012-07-26 06:26 - 00262144 ___SH C:\WINDOWS\system32\config\BBI 2013-10-27 17:10 - 2013-10-27 17:08 - 00000000 ____D C:\AdwCleaner 2013-10-27 17:08 - 2013-10-27 17:08 - 01060070 _____ C:\Users\****\Downloads\adwcleaner.exe 2013-10-27 17:00 - 2012-07-26 09:12 - 00000000 ____D C:\WINDOWS\system32\sru 2013-10-27 16:54 - 2013-07-24 20:46 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2013-10-27 16:31 - 2013-10-26 09:31 - 00000306 _____ C:\WINDOWS\Tasks\FoxTab.job 2013-10-27 14:40 - 2013-10-27 14:18 - 00091352 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys 2013-10-27 14:40 - 2013-10-27 14:15 - 00000000 ____D C:\Users\****\Desktop\mbar 2013-10-27 14:20 - 2013-10-27 14:19 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2013-10-27 14:19 - 2013-10-27 14:19 - 00116440 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2013-10-27 14:19 - 2013-10-27 14:19 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-10-27 14:14 - 2013-10-27 14:14 - 12576792 _____ (Malwarebytes Corp.) C:\Users\****\Downloads\mbar-1.07.0.1007.exe 2013-10-27 13:54 - 2013-10-26 09:31 - 00000000 ____D C:\Program Files (x86)\BatBrowse 2013-10-27 13:48 - 2013-10-27 13:48 - 00000580 _____ C:\WINDOWS\PFRO.log 2013-10-27 13:39 - 2013-07-25 14:53 - 00000000 ____D C:\Users\****\Documents\MAGIX_Video_deluxe_16_Premium 2013-10-27 12:51 - 2013-10-27 12:51 - 00030720 _____ C:\Users\****\Downloads\tab-2-3-2002.xls 2013-10-26 10:11 - 2013-07-25 01:21 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3713764075-1403762093-349256513-1002 2013-10-26 09:58 - 2013-10-26 09:43 - 00035780 _____ C:\Users\****\Downloads\Addition.txt 2013-10-26 09:42 - 2013-10-26 09:42 - 00000000 ____D C:\FRST 2013-10-26 09:41 - 2013-07-27 12:02 - 00000000 ____D C:\Program Files (x86)\Steam 2013-10-26 09:40 - 2013-07-25 01:15 - 00000000 ___RD C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-10-26 09:36 - 2013-10-26 09:36 - 01956086 _____ (Farbar) C:\Users\****\Downloads\FRST64.exe 2013-10-26 09:31 - 2013-10-26 09:31 - 00002644 _____ C:\WINDOWS\System32\Tasks\FoxTab 2013-10-26 09:31 - 2013-10-26 09:31 - 00000000 ____D C:\Users\****\AppData\Roaming\FoxTab 2013-10-26 09:31 - 2013-10-26 09:31 - 00000000 ____D C:\Users\****\AppData\Roaming\0D0S1L2Z1P1B 2013-10-26 09:30 - 2013-10-26 09:30 - 00364318 _____ C:\Users\****\AppData\Local\foxtab_speeddial.crx 2013-10-26 09:30 - 2013-10-26 09:30 - 00000000 ____D C:\Program Files (x86)\Foxtab 2013-10-23 19:51 - 2013-07-24 22:12 - 00000000 ____D C:\Users\****\AppData\Local\CrashDumps 2013-10-23 19:04 - 2013-08-31 13:33 - 00000000 ____D C:\Users\****\AppData\Roaming\Audacity 2013-10-23 15:52 - 2013-07-30 19:29 - 00000000 ____D C:\Program Files\OblyTile 2013-10-23 15:52 - 2013-07-30 16:38 - 00000000 ____D C:\Users\****\icons 2013-10-23 15:28 - 2013-10-23 15:28 - 00002266 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-10-23 15:19 - 2013-10-23 15:10 - 00000000 ____D C:\Users\****\AppData\Roaming\Opera Software 2013-10-23 15:19 - 2013-10-23 15:10 - 00000000 ____D C:\Users\****\AppData\Local\Opera Software 2013-10-23 15:19 - 2013-10-23 15:10 - 00000000 ____D C:\Program Files (x86)\Opera 2013-10-23 15:18 - 2013-10-23 15:18 - 00004098 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2013-10-23 15:18 - 2013-10-23 15:18 - 00003862 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2013-10-23 12:54 - 2013-07-25 01:13 - 00000000 ____D C:\Users\**** 2013-10-23 12:51 - 2013-08-02 13:28 - 00000000 ____D C:\Users\****\AppData\Local\gtk-2.0 2013-10-23 12:51 - 2013-07-26 12:13 - 00000000 ____D C:\WINDOWS\SysWOW64\NV 2013-10-23 12:51 - 2013-07-26 12:13 - 00000000 ____D C:\WINDOWS\system32\NV 2013-10-23 12:51 - 2013-07-24 19:28 - 00000000 ____D C:\ProgramData\Norton 2013-10-23 12:50 - 2013-10-20 14:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-10-23 12:50 - 2013-07-24 20:21 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-10-23 12:50 - 2012-11-11 17:54 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2013-10-23 12:50 - 2012-11-11 17:54 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-10-23 12:48 - 2012-07-26 09:12 - 00000000 ____D C:\WINDOWS\registration 2013-10-23 12:46 - 2012-11-11 17:55 - 00000000 ____D C:\ProgramData\NVIDIA 2013-10-23 12:45 - 2013-07-24 21:32 - 00000000 ____D C:\Program Files (x86)\Java 2013-10-23 11:59 - 2013-10-23 11:59 - 00000000 ____D C:\WINDOWS\System32\Tasks\Aufgaben der Ereignisanzeige 2013-10-23 11:48 - 2012-07-26 09:12 - 00000000 ____D C:\WINDOWS\AUInstallAgent 2013-10-22 19:48 - 2012-11-11 17:54 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2013-10-22 17:56 - 2013-10-22 17:56 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies 2013-10-21 14:06 - 2013-10-21 14:05 - 00000000 ____D C:\Users\****\AppData\Local\Google 2013-10-21 14:06 - 2013-10-21 14:05 - 00000000 ____D C:\Program Files (x86)\Google 2013-10-21 14:05 - 2013-07-25 11:38 - 00000000 ____D C:\Users\****\AppData\Local\Deployment 2013-10-20 20:46 - 2013-10-20 20:46 - 00011792 _____ C:\Users\****\AppData\Local\recently-used.xbel 2013-10-20 15:52 - 2013-10-20 15:52 - 00004886 _____ C:\WINDOWS\SysWOW64\jupdate-1.7.0_45-b18.log 2013-10-20 15:52 - 2013-10-20 15:52 - 00000000 ____D C:\ProgramData\Oracle 2013-10-20 14:17 - 2013-07-24 20:22 - 00000000 ____D C:\Users\****\AppData\Local\Mozilla 2013-10-18 21:07 - 2013-07-24 22:51 - 00000000 ____D C:\Users\****\AppData\Roaming\vlc 2013-10-18 15:50 - 2013-07-25 10:10 - 00000000 ____D C:\ProgramData\Lx_cats 2013-10-14 20:09 - 2013-07-25 12:05 - 00000000 ____D C:\Users\****\AppData\Roaming\Mp3tag 2013-10-14 14:27 - 2012-07-26 09:12 - 00000000 ____D C:\WINDOWS\rescache 2013-10-14 11:49 - 2013-07-25 19:58 - 00000000 ____D C:\Users\****\Noten 2013-10-14 11:13 - 2013-07-25 01:15 - 00000000 ___RD C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-10-14 11:00 - 2012-07-26 09:12 - 00000000 ___HD C:\WINDOWS\ELAMBKUP 2013-10-14 10:59 - 2012-07-26 09:12 - 00000000 ___RD C:\WINDOWS\ToastData 2013-10-13 19:05 - 2013-07-24 21:31 - 00000000 ____D C:\Users\****\Documents\Schule 2013-10-13 15:30 - 2013-10-13 15:30 - 00000000 ____D C:\WINDOWS\System32\Tasks\Norton Internet Security 2013-10-12 13:40 - 2013-10-12 13:39 - 00434712 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2013-10-11 15:02 - 2013-07-25 09:44 - 00000000 ____D C:\Users\****\AppData\Roaming\Skype 2013-10-10 18:14 - 2013-07-25 12:42 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-10-10 18:13 - 2013-08-16 12:40 - 00000000 ____D C:\WINDOWS\system32\MRT 2013-10-10 18:12 - 2013-07-24 20:51 - 80541720 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2013-10-10 17:49 - 2013-10-10 17:49 - 00000000 ____D C:\Users\****\AppData\Roaming\Unity 2013-10-10 17:45 - 2013-10-10 17:45 - 00000000 ____D C:\Users\****\AppData\Local\Unity 2013-10-08 20:54 - 2013-07-24 20:46 - 00003772 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2013-10-05 20:00 - 2013-10-05 20:00 - 00000000 ____D C:\Users\****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games 2013-10-05 20:00 - 2013-07-25 01:14 - 00000000 ____D C:\Users\****\AppData\Local\Packages 2013-10-04 14:54 - 2013-10-04 14:48 - 00101925 _____ C:\WINDOWS\system32\LexFiles.ulf 2013-10-04 14:51 - 2013-10-04 14:49 - 00000000 ____D C:\Program Files (x86)\Lexmark 6500 Series 2013-10-04 14:51 - 2013-10-04 14:48 - 00000000 ____D C:\Program Files\Lexmark 6500 Series 2013-10-04 14:50 - 2013-10-04 14:50 - 00001076 _____ C:\Users\Public\Desktop\Lexmark Productivity Studio - 6500 Series.LNK 2013-10-04 14:50 - 2013-10-04 14:50 - 00000000 ____D C:\ProgramData\6500 Series 2013-10-04 14:42 - 2013-10-04 14:42 - 00000178 _____ C:\lxdf.log 2013-10-04 14:42 - 2013-10-04 14:42 - 00000047 _____ C:\WINDOWS\WinInit.Ini 2013-10-04 14:42 - 2012-11-11 18:03 - 00000000 ____D C:\Program Files\Lenovo 2013-10-04 14:42 - 2012-07-26 09:12 - 00000000 ____D C:\Program Files\Windows NT 2013-10-04 14:42 - 2012-07-26 09:12 - 00000000 ____D C:\Program Files\Common Files\System 2013-10-04 14:42 - 2012-07-26 09:12 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2013-10-04 14:22 - 2013-10-04 14:22 - 00003128 _____ C:\WINDOWS\System32\Tasks\{E2DB31D0-6EAC-4C42-B453-4B647AF08E2B} 2013-10-03 21:18 - 2013-10-03 21:18 - 05238341 _____ C:\ProgramData\SPLA1B2.tmp 2013-10-02 02:38 - 2013-09-15 13:38 - 00694232 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2013-10-02 02:38 - 2013-09-15 13:38 - 00078296 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2013-09-29 10:41 - 2013-07-24 21:30 - 00000000 ____D C:\Users\****\Documents\Privat 2013-09-27 16:17 - 2012-07-26 09:12 - 00000000 ____D C:\WINDOWS\LiveKernelReports Some content of TEMP: ==================== C:\Users\****\AppData\Local\Temp\BackupSetup.exe C:\Users\****\AppData\Local\Temp\CleanSchedule.exe C:\Users\****\AppData\Local\Temp\Quarantine.exe C:\Users\****\AppData\Local\Temp\vcredist_x64.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-19 10:48 ==================== End Of Log ============================ --- --- --- Addition Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 26-10-2013 Ran by **** at 2013-10-27 17:26:51 Running from C:\Users\****\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Norton Internet Security CBE (Enabled - Up to date) {63DF5164-9100-186D-2187-8DC619EFD8BF} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Norton Internet Security CBE (Enabled - Up to date) {D8BEB080-B73A-17E3-1B37-B6B462689202} FW: Norton Internet Security CBE (Enabled) {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} ==================== Installed Programs ====================== 7-Zip 9.20 (x64 edition) (Version: 9.20.00.0) ABBYY FineReader 6.0 Sprint (x32 Version: 6.00.1990.41618) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117) Adobe Reader XI (11.0.05) - Deutsch (x32 Version: 11.0.05) Adobe Shockwave Player 12.0 (x32 Version: 12.0.3.133) Ashampoo Snap 5 v.5.1.5 (x32 Version: 5.1.5) Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (x32 Version: 2.1.0.7) Audacity 2.0.3 (x32 Version: 2.0.3) BatBrowse 1.0.0 (Version: 1.0.0) Benutzerhandbuch (x32 Version: 1.0.0.9) BlueJ (x32 Version: 3.1.0) Call of Duty: Black Ops II - Multiplayer (x32) Call of Duty: Black Ops II - Zombies (x32) Call of Duty: Black Ops II (x32) CCleaner (Version: 4.05) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32) Dolby Home Theater v4 (x32 Version: 7.2.8000.16) Energy Management (x32 Version: 8.0.2.4) FileZilla Client 3.7.1.1 (x32 Version: 3.7.1.1) Firebird SQL Server - MAGIX Edition (x32 Version: 2.1.26.0) FormatFactory 3.1.1 (x32 Version: 3.1.1) Foxtab (x32) Ghost Recon Online (EU) (HKCU Version: 1.34.2188.2) GIMP 2.8.6 (Version: 2.8.6) Google Chrome (x32 Version: 30.0.1599.101) Google Update Helper (x32 Version: 1.3.21.165) Guitar Pro 6 (x32) Hitman: Absolution (x32) Hitman: Sniper Challenge (x32) Intel AppUp(SM) center (x32 Version: 3.6.1.33057.10) Intel PROSet Wireless Intel(R) Control Center (x32 Version: 1.2.1.1008) Intel(R) Management Engine Components (x32 Version: 8.1.0.1252) Intel(R) Processor Graphics (x32 Version: 9.17.10.2843) Intel(R) Rapid Storage Technology (x32 Version: 11.5.4.1001) Intel(R) SDK for OpenCL - CPU Only Runtime Package (x32 Version: 2.0.0.37149) Intel(R) WiDi (Version: 3.5.34.0) Intel® PROSet/Wireless WiFi-Software (Version: 15.05.2000.1462) Intel® Trusted Connect Service Client (Version: 1.24.388.1) Intelligent Touchpad (x32 Version: 2.00.0012.0723) IrfanView (remove only) (x32 Version: 4.36) Java 7 Update 25 (64-bit) (Version: 7.0.250) Java 7 Update 25 (x32 Version: 7.0.250) Java Auto Updater (x32 Version: 2.1.9.5) Java SE Development Kit 7 Update 25 (64-bit) (Version: 1.7.0.250) JMicron Flash Media Controller Driver (x32 Version: 1.0.71.1) LAME v3.99.3 (for Windows) (x32) League of Legends (x32 Version: 3.0.1) Lenovo Bluetooth with Enhanced Data Rate Software (Version: 12.0.0.2200) Lenovo EasyCamera (x32 Version: 6.1.7600.167) Lenovo OneKey Recovery (Version: 8.0.0.0828) Lenovo OneKey Recovery (x32 Version: 8.0.0.0828) Lenovo PowerDVD10 (x32 Version: 10.0.4331.52) Lenovo YouCam (x32 Version: 4.1.3127) Lexmark 6500 Series MAGIX 3D Maker (embeded) (x32 Version: 6.0.0.8) MAGIX Music Maker 16 Premium (x32 Version: 16.0.0.28) MAGIX Screenshare (x32 Version: 4.3.6.1987) MAGIX Speed burnR (x32 Version: 6.0.1.4) MAGIX Video deluxe 16 Premium 9.0.0.54 (D) (x32 Version: 9.0.0.54) MAGIX Xtreme Foto Designer 6 (x32 Version: 6.0.29.0) Microsoft Office 2010 Service Pack 1 (SP1) (x32) Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Home and Student 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Office 64-bit Components 2010 (Version: 14.0.6029.1000) Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (English) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (French) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Single Image 2010 (x32 Version: 14.0.6029.1000) Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.6029.1000) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Mozilla Firefox 24.0 (x86 de) (x32 Version: 24.0) Mozilla Maintenance Service (x32 Version: 24.0) Mp3tag v2.57 (x32 Version: v2.57) Norton Internet Security CBE (x32 Version: 20.4.0.40) NVIDIA Grafiktreiber 320.49 (Version: 320.49) NVIDIA Install Application (Version: 2.1002.124.810) NVIDIA Optimus 1.10.8 (Version: 1.10.8) NVIDIA PhysX (x32 Version: 9.13.0604) NVIDIA PhysX-Systemsoftware 9.13.0604 (Version: 9.13.0604) NVIDIA Systemsteuerung 320.49 (Version: 320.49) NVIDIA Update 1.10.8 (Version: 1.10.8) NVIDIA Update Components (Version: 1.10.8) Onekey Theater (x32 Version: 3.0.0.9) Pando Media Booster (x32 Version: 2.6.0.7) Power2Go (x32 Version: 5.6.0.9109) PunkBuster Services (x32 Version: 0.993) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6680) Shared C Run-time for x64 (Version: 10.0.0) Skype™ 6.6 (x32 Version: 6.6.106) Steam (x32 Version: 1.0.0.0) SugarSync Manager (x32 Version: 1.9.61.90905) swMSM (x32 Version: 12.0.0.1) Synaptics Pointing Device Driver (Version: 16.2.10.13) Text-To-Speech-Runtime (x32 Version: 1.0.0.0) Unity Web Player (HKCU Version: ) Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (x32) Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2553065) (x32) Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2566458) (x32) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (x32) Update for Microsoft Office 2010 (KB2826026) 32-Bit Edition (x32) Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition (x32) Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition (x32) Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition (x32) Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition (x32) Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (x32) Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition (x32) Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (x32) Update for Microsoft Word 2010 (KB2827323) 32-Bit Edition (x32) Update for Zip Extractor (HKCU) UserGuide (x32 Version: 1.0.0.9) VirtualDJ Home FREE (x32 Version: 7.4) VLC media player 2.0.7 (Version: 2.0.7) Webocton - Scriptly 0.8.95.6 (x32 Version: 0.8.95.6) Windows-Treiberpaket - Lenovo (ACPIVPC) System (06/15/2012 8.1.0.1) (Version: 06/15/2012 8.1.0.1) Windows-Treiberpaket - Lenovo (WUDFRd) LenovoVhid (06/19/2012 10.13.29.733) (Version: 06/19/2012 10.13.29.733) Zip Extractor Packages (HKCU) ==================== Restore Points ========================= 10-10-2013 17:08:50 Windows Update 13-10-2013 17:36:09 Windows Update 20-10-2013 14:51:49 Installed Java 7 Update 45 23-10-2013 11:42:13 Wiederherstellungsvorgang ==================== Hosts content: ========================== 2012-07-26 06:26 - 2012-07-26 06:26 - 00000824 ____N C:\WINDOWS\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {17D56BDB-BDA4-4666-A10B-742237168D11} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-08-21] (Piriform Ltd) Task: {188CC749-EBD6-42FB-BDED-1E4BCF89739A} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\WINDOWS\System32\lpksetup.exe [2012-09-20] (Microsoft Corporation) Task: {2441429B-3461-4E37-87B8-9028C7B4F65A} - System32\Tasks\Norton Internet Security CBE\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security CBE\Engine\20.4.0.40\SymErr.exe [2013-06-04] (Symantec Corporation) Task: {2BA98B35-B011-42CE-BBDD-BE79E4215036} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-23] (Google Inc.) Task: {474C0E16-D6AA-466F-9F08-242197394681} - \DigitalSite No Task File Task: {4F192888-AA49-4AAD-9FC3-8920E6CDEB2A} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security CBE\Engine\20.4.0.40\WSCStub.exe [2013-06-04] (Symantec Corporation) Task: {6154DCFF-9F98-4739-AA88-B9E635EF9814} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security CBE\Engine\20.4.0.40\SymErr.exe [2013-06-04] (Symantec Corporation) Task: {72035866-A1EC-4835-8FEF-DB76C0AD711E} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc Task: {A1C99C5A-BE87-4916-B4E7-2055D4834003} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security CBE\Engine\20.4.0.40\SymErr.exe [2013-06-04] (Symantec Corporation) Task: {A8E63B2B-5917-4B36-A508-DCE199A187EF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-23] (Google Inc.) Task: {AE80CD1E-1A14-4E09-91B3-E12ED5ABD7FE} - System32\Tasks\FoxTab => C:\Users\****\AppData\Roaming\FoxTab\UpdateProc\UpdateTask.exe [2013-04-12] () Task: {B90BD215-7EFC-433C-B6DE-3C6150B602B4} - System32\Tasks\Microsoft\Windows\Setup\Pre-staged GDR Notification => C:\Windows\system32\NotificationUI.exe [2013-08-16] (Microsoft Corporation) Task: {C92E3D90-0771-45A5-B900-8C72C08AAB83} - System32\Tasks\MirageAgent => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [2012-07-27] (CyberLink) Task: {F1095F9E-9BAF-427D-B86A-79D200C2E80A} - System32\Tasks\Norton Internet Security CBE\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security CBE\Engine\20.4.0.40\SymErr.exe [2013-06-04] (Symantec Corporation) Task: {FB4E5ACD-0921-4EA1-BFFE-DAC2EF4D49E1} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-08] (Adobe Systems Incorporated) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\FoxTab.job => C:\Users\****\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2012-11-11 17:54 - 2012-07-31 17:02 - 00004096 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll 2013-10-04 14:51 - 2007-05-24 12:44 - 00045568 _____ () C:\WINDOWS\System32\LXDFPMON.DLL 2013-07-25 10:01 - 2007-04-09 15:59 - 00069632 _____ () C:\WINDOWS\System32\LXDFOEM.DLL 2013-10-04 14:50 - 2007-05-24 12:39 - 00081408 _____ () C:\Program Files (x86)\Lexmark 6500 Series\ipcmt64.dll 2013-10-04 14:52 - 2007-05-25 18:44 - 00138240 _____ () C:\WINDOWS\system32\spool\PRTPROCS\x64\lxdfdrpp.dll 2012-09-06 15:53 - 2012-09-06 15:53 - 00047480 _____ () C:\Program Files\Lenovo\Bluetooth Software\BtwLeAPI.dll 2012-08-31 06:54 - 2012-08-24 00:07 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2013-06-27 21:12 - 2013-06-27 21:12 - 00093696 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll 2013-10-27 14:24 - 2013-10-27 14:24 - 00337920 _____ () C:\Program Files (x86)\BatBrowse\bin\sqlite3.DLL 2013-07-25 20:30 - 2012-05-30 07:51 - 00699280 ____R () C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY CBE\ENGINE\20.4.0.40\wincfi39.dll 2012-11-11 17:54 - 2012-07-31 17:02 - 00004096 _____ () C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll 2013-10-04 14:49 - 2007-05-24 21:21 - 00278528 _____ () C:\Program Files (x86)\Lexmark 6500 Series\lxdfscw.dll 2013-10-04 14:49 - 2007-05-03 16:39 - 00589824 _____ () C:\Program Files (x86)\Lexmark 6500 Series\lxdfdatr.dll 2013-10-04 14:49 - 2007-03-26 08:39 - 00073728 _____ () C:\Program Files (x86)\Lexmark 6500 Series\lxdfcats.dll 2013-10-04 14:49 - 2007-06-08 09:52 - 00028672 _____ () C:\Program Files (x86)\Lexmark 6500 Series\App4R.Monitor.Common.dll 2013-10-04 14:49 - 2007-06-08 09:52 - 00036864 _____ () C:\Program Files (x86)\Lexmark 6500 Series\App4R.Monitor.Core.dll 2013-10-04 14:49 - 2007-06-08 09:52 - 00057344 _____ () C:\Program Files (x86)\Lexmark 6500 Series\app4r.devmons.mcmdevmon.dll 2013-10-04 14:49 - 2007-06-01 13:06 - 00011776 _____ () C:\Program Files (x86)\Lexmark 6500 Series\App4R.DevMons.MCMDevMon.AutoPlayUtil.dll 2013-08-23 12:44 - 2013-08-23 12:44 - 00017920 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PSIClient\9b61416a45a6322490dbb27382930695\PSIClient.ni.dll 2012-11-11 18:01 - 2012-06-25 10:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll 2013-10-23 15:28 - 2013-10-09 01:01 - 00698832 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\libglesv2.dll 2013-10-23 15:28 - 2013-10-09 01:01 - 00099792 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\libegl.dll 2013-10-23 15:28 - 2013-10-09 01:02 - 04055504 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dll 2013-10-23 15:28 - 2013-10-09 01:02 - 00415184 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll 2013-10-23 15:28 - 2013-10-09 01:01 - 01604560 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ffmpegsumo.dll 2013-10-13 13:30 - 2013-10-13 13:30 - 00471552 _____ () C:\Users\****\AppData\Local\Packages\E046963F.LenovoSupport_k1h2ywk1493x8\AC\Microsoft\CLR_v4.0_32\NativeImages\BackgroundT72ca5658#\ba58a72166c7a2ba23dbc4a0de1ccd69\BackgroundTasks_MetricCollection.ni.dll 2013-07-24 21:46 - 2013-07-24 21:46 - 00660992 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.App640a3541#\7193464c9be87709b0e8f59dd3bdeca8\Windows.ApplicationModel.ni.dll 2013-07-24 21:46 - 2013-07-24 21:46 - 00693760 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.Storage\6ad1c9f68ace08186f0671a7de0f8cff\Windows.Storage.ni.dll 2013-07-24 21:46 - 2013-07-24 21:46 - 00491008 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.Networking\48c2e4346c32df24c33f7a095339881c\Windows.Networking.ni.dll 2013-07-24 21:46 - 2013-07-24 21:46 - 00184832 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.Foundation\387a593cd07b32b07cbdf0e94ae9a092\Windows.Foundation.ni.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: USB-IF xHCI USB Host Controller Description: USB-IF xHCI USB Host Controller Class Guid: {8a2edc79-c759-46f2-88af-9d4efe3b5eee} Manufacturer: Intel Corporation Service: XHCIPort Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver Name: Broadcom Bluetooth 4.0 USB Description: Broadcom Bluetooth 4.0 USB Class Guid: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974} Manufacturer: Broadcom Service: BTHUSB Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (10/23/2013 01:00:00 PM) (Source: ESENT) (User: ) Description: svchost (1708) SRUJet: Fehler -1811 (0xfffff8ed) beim Öffnen von Protokolldatei C:\WINDOWS\system32\SRU\SRU003F9.log. Error: (10/20/2013 07:16:11 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: lxdfJSWX.EXE, Version: 3.383.0.0, Zeitstempel: 0x4653c5e0 Name des fehlerhaften Moduls: lxdfJSWX.EXE, Version: 3.383.0.0, Zeitstempel: 0x4653c5e0 Ausnahmecode: 0xc000041d Fehleroffset: 0x000000000001454e ID des fehlerhaften Prozesses: 0x3524 Startzeit der fehlerhaften Anwendung: 0xlxdfJSWX.EXE0 Pfad der fehlerhaften Anwendung: lxdfJSWX.EXE1 Pfad des fehlerhaften Moduls: lxdfJSWX.EXE2 Berichtskennung: lxdfJSWX.EXE3 Vollständiger Name des fehlerhaften Pakets: lxdfJSWX.EXE4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: lxdfJSWX.EXE5 Error: (10/20/2013 07:16:09 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: lxdfJSWX.EXE, Version: 3.383.0.0, Zeitstempel: 0x4653c5e0 Name des fehlerhaften Moduls: lxdfJSWX.EXE, Version: 3.383.0.0, Zeitstempel: 0x4653c5e0 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000001454e ID des fehlerhaften Prozesses: 0x3524 Startzeit der fehlerhaften Anwendung: 0xlxdfJSWX.EXE0 Pfad der fehlerhaften Anwendung: lxdfJSWX.EXE1 Pfad des fehlerhaften Moduls: lxdfJSWX.EXE2 Berichtskennung: lxdfJSWX.EXE3 Vollständiger Name des fehlerhaften Pakets: lxdfJSWX.EXE4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: lxdfJSWX.EXE5 Error: (10/20/2013 07:16:04 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: lxdfJSWX.EXE, Version: 3.383.0.0, Zeitstempel: 0x4653c5e0 Name des fehlerhaften Moduls: lxdfJSWX.EXE, Version: 3.383.0.0, Zeitstempel: 0x4653c5e0 Ausnahmecode: 0xc000041d Fehleroffset: 0x000000000001454e ID des fehlerhaften Prozesses: 0x30a8 Startzeit der fehlerhaften Anwendung: 0xlxdfJSWX.EXE0 Pfad der fehlerhaften Anwendung: lxdfJSWX.EXE1 Pfad des fehlerhaften Moduls: lxdfJSWX.EXE2 Berichtskennung: lxdfJSWX.EXE3 Vollständiger Name des fehlerhaften Pakets: lxdfJSWX.EXE4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: lxdfJSWX.EXE5 Error: (10/20/2013 07:16:02 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: lxdfJSWX.EXE, Version: 3.383.0.0, Zeitstempel: 0x4653c5e0 Name des fehlerhaften Moduls: lxdfJSWX.EXE, Version: 3.383.0.0, Zeitstempel: 0x4653c5e0 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000001454e ID des fehlerhaften Prozesses: 0x30a8 Startzeit der fehlerhaften Anwendung: 0xlxdfJSWX.EXE0 Pfad der fehlerhaften Anwendung: lxdfJSWX.EXE1 Pfad des fehlerhaften Moduls: lxdfJSWX.EXE2 Berichtskennung: lxdfJSWX.EXE3 Vollständiger Name des fehlerhaften Pakets: lxdfJSWX.EXE4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: lxdfJSWX.EXE5 Error: (10/20/2013 07:14:49 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: lxdfcoms.exe, Version: 1.0.2.0, Zeitstempel: 0x464c9d04 Name des fehlerhaften Moduls: lxdfhbn3.dll, Version: 1.0.2.0, Zeitstempel: 0x464c9d06 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000005fc13 ID des fehlerhaften Prozesses: 0x8c0 Startzeit der fehlerhaften Anwendung: 0xlxdfcoms.exe0 Pfad der fehlerhaften Anwendung: lxdfcoms.exe1 Pfad des fehlerhaften Moduls: lxdfcoms.exe2 Berichtskennung: lxdfcoms.exe3 Vollständiger Name des fehlerhaften Pakets: lxdfcoms.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: lxdfcoms.exe5 Error: (10/20/2013 04:45:01 PM) (Source: Application Hang) (User: ) Description: Programm wmplayer.exe, Version 12.0.9200.16420 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 4e4 Startzeit: 01cecda845cf4c71 Endzeit: 4 Anwendungspfad: C:\Program Files (x86)\Windows Media Player\wmplayer.exe Berichts-ID: 917eeeb0-399e-11e3-be8f-b888e39448a7 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (10/20/2013 04:42:25 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: BTWUIExt.exe, Version: 12.0.0.2200, Zeitstempel: 0x5048b7af Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.2.9200.16451, Zeitstempel: 0x50988aa6 Ausnahmecode: 0xe0434352 Fehleroffset: 0x000000000003811c ID des fehlerhaften Prozesses: 0x43e0 Startzeit der fehlerhaften Anwendung: 0xBTWUIExt.exe0 Pfad der fehlerhaften Anwendung: BTWUIExt.exe1 Pfad des fehlerhaften Moduls: BTWUIExt.exe2 Berichtskennung: BTWUIExt.exe3 Vollständiger Name des fehlerhaften Pakets: BTWUIExt.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: BTWUIExt.exe5 Error: (10/20/2013 04:42:24 PM) (Source: .NET Runtime) (User: ) Description: Anwendung: BTWUIExt.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet. Ausnahmeinformationen: System.Windows.Markup.XamlParseException Stapel: bei System.Windows.Markup.WpfXamlLoader.Load(System.Xaml.XamlReader, System.Xaml.IXamlObjectWriterFactory, Boolean, System.Object, System.Xaml.XamlObjectWriterSettings, System.Uri) bei System.Windows.Markup.WpfXamlLoader.LoadBaml(System.Xaml.XamlReader, Boolean, System.Object, System.Xaml.Permissions.XamlAccessLevel, System.Uri) bei System.Windows.Markup.XamlReader.LoadBaml(System.IO.Stream, System.Windows.Markup.ParserContext, System.Object, Boolean) bei System.Windows.Application.LoadBamlStreamWithSyncInfo(System.IO.Stream, System.Windows.Markup.ParserContext) bei System.Windows.Application.LoadComponent(System.Uri, Boolean) bei System.Windows.Application.DoStartup() bei System.Windows.Application.<.ctor>b__1(System.Object) bei System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32) bei MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate) bei System.Windows.Threading.DispatcherOperation.InvokeImpl() bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) bei System.Windows.Threading.DispatcherOperation.Invoke() bei System.Windows.Threading.Dispatcher.ProcessQueue() bei System.Windows.Threading.Dispatcher.WndProcHook(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef) bei MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef) bei MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object) bei System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32) bei MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate) bei System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32) bei MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr) bei MS.Win32.UnsafeNativeMethods.DispatchMessage(System.Windows.Interop.MSG ByRef) bei MS.Win32.UnsafeNativeMethods.DispatchMessage(System.Windows.Interop.MSG ByRef) bei System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame) bei System.Windows.Application.RunInternal(System.Windows.Window) bei System.Windows.Application.Run() bei BTWUIExt.App.Main() Error: (10/20/2013 04:41:02 PM) (Source: Application Hang) (User: ) Description: Programm rundll32.exe, Version 6.2.9200.16384 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 3ea8 Startzeit: 01cecdaab7cd9d5e Endzeit: 2 Anwendungspfad: C:\WINDOWS\system32\rundll32.exe Berichts-ID: 01e4a7b9-399e-11e3-be8f-b888e39448a7 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: System errors: ============= Error: (10/27/2013 05:13:12 PM) (Source: DCOM) (User: ****-PC) Description: AnwendungsspezifischLokalStart{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}****-PC****S-1-5-21-3713764075-1403762093-349256513-1002LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar Error: (10/27/2013 05:13:12 PM) (Source: DCOM) (User: ****-PC) Description: AnwendungsspezifischLokalStart{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}****-PC****S-1-5-21-3713764075-1403762093-349256513-1002LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar Error: (10/27/2013 05:12:32 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "lxdfCATSCustConnectService" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (10/27/2013 05:12:32 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst lxdfCATSCustConnectService erreicht. Error: (10/27/2013 02:40:31 PM) (Source: mbamchameleon) (User: ) Description: e\HarddiskVolume5\PROGRAM FILES (X86)\NORTON INTERNET SECURITY CBE\ENGINE\20.4.0.40\CCSVCHST.EXE Error: (10/27/2013 02:40:30 PM) (Source: mbamchameleon) (User: ) Description: e\HarddiskVolume5\PROGRAM FILES (X86)\NORTON INTERNET SECURITY CBE\ENGINE\20.4.0.40\CCSVCHST.EXE Error: (10/27/2013 02:40:27 PM) (Source: mbamchameleon) (User: ) Description: e\HarddiskVolume5\PROGRAM FILES (X86)\NORTON INTERNET SECURITY CBE\ENGINE\20.4.0.40\CCSVCHST.EXE Error: (10/27/2013 02:40:27 PM) (Source: mbamchameleon) (User: ) Description: e\HarddiskVolume5\PROGRAM FILES (X86)\NORTON INTERNET SECURITY CBE\ENGINE\20.4.0.40\CCSVCHST.EXE Error: (10/27/2013 02:40:27 PM) (Source: mbamchameleon) (User: ) Description: e\HarddiskVolume5\PROGRAM FILES (X86)\NORTON INTERNET SECURITY CBE\ENGINE\20.4.0.40\CCSVCHST.EXE Error: (10/27/2013 02:40:26 PM) (Source: mbamchameleon) (User: ) Description: e\HarddiskVolume5\PROGRAM FILES (X86)\NORTON INTERNET SECURITY CBE\ENGINE\20.4.0.40\CCSVCHST.EXE Microsoft Office Sessions: ========================= Error: (10/23/2013 01:00:00 PM) (Source: ESENT)(User: ) Description: svchost1708SRUJet: C:\WINDOWS\system32\SRU\SRU003F9.log-1811 (0xfffff8ed) Error: (10/20/2013 07:16:11 PM) (Source: Application Error)(User: ) Description: lxdfJSWX.EXE3.383.0.04653c5e0lxdfJSWX.EXE3.383.0.04653c5e0c000041d000000000001454e352401cecdc06f657a14C:\WINDOWS\system32\spool\DRIVERS\x64\3\lxdfJSWX.EXEC:\WINDOWS\system32\spool\DRIVERS\x64\3\lxdfJSWX.EXEb2156521-39b3-11e3-be90-b888e39448a7 Error: (10/20/2013 07:16:09 PM) (Source: Application Error)(User: ) Description: lxdfJSWX.EXE3.383.0.04653c5e0lxdfJSWX.EXE3.383.0.04653c5e0c0000005000000000001454e352401cecdc06f657a14C:\WINDOWS\system32\spool\DRIVERS\x64\3\lxdfJSWX.EXEC:\WINDOWS\system32\spool\DRIVERS\x64\3\lxdfJSWX.EXEb14f7f45-39b3-11e3-be90-b888e39448a7 Error: (10/20/2013 07:16:04 PM) (Source: Application Error)(User: ) Description: lxdfJSWX.EXE3.383.0.04653c5e0lxdfJSWX.EXE3.383.0.04653c5e0c000041d000000000001454e30a801cecdc042f8a633C:\WINDOWS\system32\spool\DRIVERS\x64\3\lxdfJSWX.EXEC:\WINDOWS\system32\spool\DRIVERS\x64\3\lxdfJSWX.EXEadeafefa-39b3-11e3-be90-b888e39448a7 Error: (10/20/2013 07:16:02 PM) (Source: Application Error)(User: ) Description: lxdfJSWX.EXE3.383.0.04653c5e0lxdfJSWX.EXE3.383.0.04653c5e0c0000005000000000001454e30a801cecdc042f8a633C:\WINDOWS\system32\spool\DRIVERS\x64\3\lxdfJSWX.EXEC:\WINDOWS\system32\spool\DRIVERS\x64\3\lxdfJSWX.EXEad16cab6-39b3-11e3-be90-b888e39448a7 Error: (10/20/2013 07:14:49 PM) (Source: Application Error)(User: ) Description: lxdfcoms.exe1.0.2.0464c9d04lxdfhbn3.dll1.0.2.0464c9d06c0000005000000000005fc138c001cecdac61555e08C:\WINDOWS\system32\lxdfcoms.exeC:\WINDOWS\system32\lxdfhbn3.dll81ab787d-39b3-11e3-be90-b888e39448a7 Error: (10/20/2013 04:45:01 PM) (Source: Application Hang)(User: ) Description: wmplayer.exe12.0.9200.164204e401cecda845cf4c714C:\Program Files (x86)\Windows Media Player\wmplayer.exe917eeeb0-399e-11e3-be8f-b888e39448a7 Error: (10/20/2013 04:42:25 PM) (Source: Application Error)(User: ) Description: BTWUIExt.exe12.0.0.22005048b7afKERNELBASE.dll6.2.9200.1645150988aa6e0434352000000000003811c43e001cecdaaf768e19eC:\Program Files\Lenovo\Bluetooth Software\BTWUIExt.exeC:\WINDOWS\system32\KERNELBASE.dll37429728-399e-11e3-be8f-b888e39448a7 Error: (10/20/2013 04:42:24 PM) (Source: .NET Runtime)(User: ) Description: Anwendung: BTWUIExt.exe Frameworkversion: v4.0.30319 Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet. Ausnahmeinformationen: System.Windows.Markup.XamlParseException Stapel: bei System.Windows.Markup.WpfXamlLoader.Load(System.Xaml.XamlReader, System.Xaml.IXamlObjectWriterFactory, Boolean, System.Object, System.Xaml.XamlObjectWriterSettings, System.Uri) bei System.Windows.Markup.WpfXamlLoader.LoadBaml(System.Xaml.XamlReader, Boolean, System.Object, System.Xaml.Permissions.XamlAccessLevel, System.Uri) bei System.Windows.Markup.XamlReader.LoadBaml(System.IO.Stream, System.Windows.Markup.ParserContext, System.Object, Boolean) bei System.Windows.Application.LoadBamlStreamWithSyncInfo(System.IO.Stream, System.Windows.Markup.ParserContext) bei System.Windows.Application.LoadComponent(System.Uri, Boolean) bei System.Windows.Application.DoStartup() bei System.Windows.Application.<.ctor>b__1(System.Object) bei System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32) bei MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate) bei System.Windows.Threading.DispatcherOperation.InvokeImpl() bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) bei System.Windows.Threading.DispatcherOperation.Invoke() bei System.Windows.Threading.Dispatcher.ProcessQueue() bei System.Windows.Threading.Dispatcher.WndProcHook(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef) bei MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef) bei MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object) bei System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32) bei MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate) bei System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32) bei MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr) bei MS.Win32.UnsafeNativeMethods.DispatchMessage(System.Windows.Interop.MSG ByRef) bei MS.Win32.UnsafeNativeMethods.DispatchMessage(System.Windows.Interop.MSG ByRef) bei System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame) bei System.Windows.Application.RunInternal(System.Windows.Window) bei System.Windows.Application.Run() bei BTWUIExt.App.Main() Error: (10/20/2013 04:41:02 PM) (Source: Application Hang)(User: ) Description: rundll32.exe6.2.9200.163843ea801cecdaab7cd9d5e2C:\WINDOWS\system32\rundll32.exe01e4a7b9-399e-11e3-be8f-b888e39448a7 CodeIntegrity Errors: =================================== Date: 2013-10-25 23:58:26.750 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-10-25 18:35:15.071 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-10-25 17:23:01.047 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-10-25 14:46:52.742 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-10-24 16:18:45.318 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-10-24 15:50:14.028 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-10-23 21:41:11.516 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-10-23 19:59:23.274 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-10-23 19:59:23.201 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2013-10-23 17:20:06.136 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Percentage of memory in use: 23% Total physical RAM: 8057.77 MB Available physical RAM: 6198.89 MB Total Pagefile: 9273.77 MB Available Pagefile: 7298.25 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: (Windows8_OS) (Fixed) (Total:651.3 GB) (Free:486.32 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:21.97 GB) NTFS Drive e: (FLASHPOINT_DVD02) (CDROM) (Total:4.74 GB) (Free:0 GB) UDF ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 699 GB) (Disk ID: 38E90BD1) Partition: GPT Partition Type ==================== End Of Log ============================ Vielen Dank für deine Hilfe! |
28.10.2013, 17:10 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Firefox: [JavaScript-Anwendung] TypeError: window.flagCache[curip] is undefined Hm, bitte JRT nochmal neu runterladen und ausführen. Führe e bitte per Rechtsklick als Administrator aus
__________________ Logfiles bitte immer in CODE-Tags posten |
28.10.2013, 17:47 | #9 |
| Firefox: [JavaScript-Anwendung] TypeError: window.flagCache[curip] is undefined Da war ich wohl doch etwas übereifrig... Seitdem ich heute morgen ca. 10 Uhr am PC und in Firefox war, kam die Meldung nicht mehr. Dann kam am Nachmittag noch ein Update am PC (nicht im Internet) ein Update von Java. Eben ein neues Fenster von Firefox geöffnet (am Nachmittag nur das eine Fenster aufgehabt) und nun erscheint wieder die Meldung. -_- Es hängt wohl am Java Update oder? Hier JRT Log Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.7 (10.15.2013:3) OS: Windows 8 x64 Ran by **** on 28.10.2013 at 17:37:06,86 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} ~~~ Files ~~~ Folders Failed to delete: [Folder] "C:\WINDOWS\syswow64\ai_recyclebin" ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 28.10.2013 at 17:41:26,15 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
28.10.2013, 22:19 | #10 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Firefox: [JavaScript-Anwendung] TypeError: window.flagCache[curip] is undefined JavaScript ist etwas ganz anderes als Java. Hast du schonmal ein anderes Firefox-Profil getestet? Irgendwelche Erweiterungen die letzte Zeit für den FF installiert?
__________________ Logfiles bitte immer in CODE-Tags posten |
29.10.2013, 19:28 | #11 |
| Firefox: [JavaScript-Anwendung] TypeError: window.flagCache[curip] is undefined Das mit dem Profil erstellen funktioniert irgenwie nicht Ich habe vor kurzem NoScript hinzugefügt |
30.10.2013, 00:50 | #12 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Firefox: [JavaScript-Anwendung] TypeError: window.flagCache[curip] is undefined Das hat mit einer Erweiterung nun rein garnix zu tun denn die sind immer nur in dem Profil, in dem man sie auch installiert hat. Und mit "funktioniert irgendwie nicht" kann man dir nicht weiterhelfen, da wirst du dich präziser ausdrücken müssen um hilfreiche Antworten erwarten zu können
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Firefox: [JavaScript-Anwendung] TypeError: window.flagCache[curip] is undefined |
adobe, bereits, button, code, deinstalliert, erschein, erscheint, fenster, firefox, folge, folgende, heute, interne, internet, javascript, javascriptproblem, klicke, meldung, neu, neues, neueste, tagen, troja, update, virus, ziemlich, öffnet |