|
Log-Analyse und Auswertung: Windows 7: Mailer-Daemon Mails von gmx ohne EndeWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
29.10.2013, 01:45 | #1 |
| Windows 7: Mailer-Daemon Mails von gmx ohne Ende Hallo, ich bitte um Hilfe bei der Lösung meines Problems. Ich bekomme unentwegt Mails von Mailer Daemon. Diese landen zwar größtenteils in meinem Spam Ordner, aber es macht mich stutzig. Kann es sein, dass meine Accounts bei gmx gehackt wurden oder ich Malware habe? Nur der Übersichthalber: Ich habe meine 3 gmx Konten auf meine Googlemail umgeleitet. Auf meinem System ist bitdefender IS installiert. Habe mich an die Hinweise gehalten und die angeforderten Scans gemacht. Schaffe es leider nicht den Logfile meines Systemscans mit bitdefender, welchen ich schon heute morgen gemacht habe, als Text zu speichern. Ist ne xml. Hatte zwei auffällige Cookies gefunden. Nichts weiter. Jedoch jede Menge geblockte Dateien. Folgend also die Logs: Defogger: Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 23:36 on 28/10/2013 (Kaan) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-10-2013 Ran by Kaan (administrator) on KAAN-PC on 29-10-2013 00:37:50 Running from D:\Downloads neu Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe (AMD) C:\Windows\system32\atiesrxx.exe (IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b20011ea53a6b83e\STacSV64.exe (AMD) C:\Windows\system32\atieclxx.exe (Advanced Micro Devices, Inc.) C:\Windows\system32\atibtmon.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11\WLTRYSVC.EXE (Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11\bcmwltry.exe (Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b20011ea53a6b83e\AESTSr64.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe (Motorola) C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe (Bitdefender) C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11\WLTRAY.EXE (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\IELowutil.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2174760 2010-06-03] (Synaptics Incorporated) HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-03-17] (IDT, Inc.) HKLM\...\Run: [Bdagent] - C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe [1575192 2013-10-24] (Bitdefender) HKLM\...\Run: [Broadcom Wireless Manager UI] - C:\Program Files\Broadcom\Broadcom 802.11\WLTRAY.EXE [7177728 2013-09-30] (Broadcom Corporation) Winlogon\Notify\LBTWlgn: C:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.) HKCU\...\Run: [Google Update] - C:\Users\Kaan\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2011-10-17] (Google Inc.) HKCU\...\Run: [Akamai NetSession Interface] - "C:\Users\Kaan\AppData\Local\Akamai\netsession_win.exe" HKCU\...\Run: [] - [x] HKLM-x32\...\Run: [TP-LINK USB Printer Controller] - C:\Program Files (x86)\TP-LINK\USB Printer Controller\USB Printer Controller.exe [4226048 2012-09-21] () HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-07-22] (Geek Software GmbH) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x51EE0F68E2DDCC01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp SearchScopes: HKCU - {FF223180-DAF0-49C0-BA8F-F987F39C02D5} URL = hxxp://www.google.de/search?q={searchTerms} BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll No File BHO-x32: SwissAcademic.Citavi.Picker.IEPicker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: IE5BarLauncherBHO Class - {78F3A323-798E-4AEA-9A57-88F4B05FD5DD} - C:\Program Files (x86)\vShare.tv plugin\BarLcher.dll (VShare Inc.) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM-x32 - VShareToolBar - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - C:\Program Files (x86)\vShare.tv plugin\BarLcher.dll (VShare Inc.) Toolbar: HKCU - No Name - {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - No File DPF: HKLM-x32 {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} hxxp://download.bitdefender.com/resources/scanner/sources/de/scan8/oscan8.cab DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://active.macromedia.com/flash2/cabs/swflash.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Kaan\AppData\Roaming\Mozilla\Firefox\Profiles\yibf17oj.Testprofil FF Homepage: www.google.de FF Keyword.URL: hxxp://de.search.yahoo.com/search?fr=mcafee&p= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.) FF Plugin: @java.com/DTPlugin,version=10.2.1 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.) FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - D:\Tools\Picasa\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @logitech.com/HarmonyRemote,version=1.0.0 - C:\Program Files (x86)\Logitech\Harmony Remote Driver\NprtHarmonyPlugin.dll (Logitech Inc.) FF Plugin-x32: @mcafee.com/MVT - C:\Program Files (x86)\McAfee\Supportability\MVT\npmvtplugin.dll (McAfee, Inc.) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nokia.com/EnablerPlugin - C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) FF Plugin-x32: @pages.tvunetworks.com/WebPlayer - D:\Tools\TVUPlayer\npTVUAx.dll (TVU networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Kaan\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Kaan\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) FF Plugin HKCU: @talk.google.com/O3DPlugin - C:\Users\Kaan\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll () FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Kaan\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Kaan\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\McSiteAdvisor.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: FireShot - C:\Users\Kaan\AppData\Roaming\Mozilla\Firefox\Profiles\yibf17oj.Testprofil\Extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba} FF Extension: prefs - C:\Users\Kaan\AppData\Roaming\Mozilla\Firefox\Profiles\yibf17oj.Testprofil\Extensions\{37fa1426-b82d-11db-8314-0800200c9a66}.xpi FF Extension: No Name - C:\Users\Kaan\AppData\Roaming\Mozilla\Firefox\Profiles\yibf17oj.Testprofil\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi FF Extension: defaults - C:\Users\Kaan\AppData\Roaming\Mozilla\Firefox\Profiles\yibf17oj.Testprofil\Extensions\{b749fc7c-e949-447f-926c-3f4eed6accfe}.xpi FF Extension: Adblock Plus - C:\Users\Kaan\AppData\Roaming\Mozilla\Firefox\Profiles\yibf17oj.Testprofil\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext FF Extension: bdToolbar - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext FF Extension: bdToolbar - C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext Chrome: ======= CHR HomePage: hxxp://www.hukd.mydealz.de/ CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Kaan\AppData\Local\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\Kaan\AppData\Local\Google\Chrome\Application\30.0.1599.101\pdf.dll () CHR Plugin: (Shockwave Flash) - C:\Users\Kaan\AppData\Local\Google\Chrome\Application\30.0.1599.101\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_228.dll No File CHR Plugin: (vShare.tv plug-in) - C:\Users\Kaan\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0\chvsharetvplg.dll (vShare.tv ) CHR Plugin: (vShare.tv plug-in) - C:\Program Files (x86)\Mozilla Firefox\plugins\npvsharetvplg.dll (vShare.tv ) CHR Plugin: (Bitdefender QuickScan) - C:\Users\Kaan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdnkcidphdcakpkheohlhocaicfamjie\0.9.9.108_0\npqscan.dll No File CHR Plugin: (Microsoft\u00AE Windows Media Player Firefox Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll (Microsoft Corporation) CHR Plugin: (Java Deployment Toolkit 6.0.310.5) - C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll No File CHR Plugin: (Google Talk Plugin) - C:\Users\Kaan\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) CHR Plugin: (Google Talk Plugin Video Accelerator) - C:\Users\Kaan\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll () CHR Plugin: (PDF-XChange Viewer) - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.) CHR Plugin: (Google Update) - C:\Users\Kaan\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll No File CHR Plugin: (Picasa) - D:\Tools\Picasa\Picasa3\npPicasa3.dll (Google, Inc.) CHR Plugin: (TVU Web Player for FireFox) - D:\Tools\TVUPlayer\npTVUAx.dll (TVU networks) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.0.61118.0\npctrl.dll No File CHR Extension: (YouTube) - C:\Users\Kaan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Kaan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (ModHeader) - C:\Users\Kaan\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj\1.2.4_0 CHR Extension: (vshare plugin) - C:\Users\Kaan\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpionmjnkbpcdpcflammlgllecmejgjj\1.3_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\Kaan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0 CHR Extension: (MyHarmony Chrome Plugin) - C:\Users\Kaan\AppData\Local\Google\Chrome\User Data\Default\Extensions\omaonpoimgkmbllpdihbnmgphjoipdhf\1.2.0.0_0 CHR Extension: (Bitdefender QuickScan) - C:\Users\Kaan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdnkcidphdcakpkheohlhocaicfamjie\0.9.9.131_0 CHR Extension: (Gmail) - C:\Users\Kaan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 CHR HKLM-x32\...\Chrome\Extension: [kpionmjnkbpcdpcflammlgllecmejgjj] - C:\Program Files (x86)\vShare.tv plugin\vshareplg.crx CHR HKLM-x32\...\Chrome\Extension: [omaonpoimgkmbllpdihbnmgphjoipdhf] - C:\Program Files (x86)\Logitech\Harmony Remote Driver\harmony_chrome.crx CHR StartMenuInternet: Google Chrome - C:\Users\Kaan\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Services (Whitelisted) ================= R2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b20011ea53a6b83e\AESTSr64.exe [89600 2009-03-03] (Andrea Electronics Corporation) S4 BdDesktopParental; C:\Program Files\Bitdefender\Bitdefender 2013\bdparentalservice.exe [69392 2013-10-24] (Bitdefender) S4 D-Link Wireless N DWA-140_WPS; C:\Program Files (x86)\D-Link\DWA-140 revB\ANIWConnService.exe [53248 2010-06-03] () S4 Motorola Device Manager; C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe [116632 2012-07-17] () R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [80896 2011-03-31] () R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b20011ea53a6b83e\STacSV64.exe [244736 2010-03-17] (IDT, Inc.) R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe [67320 2013-10-24] (Bitdefender) R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe [1645256 2013-10-24] (Bitdefender) R2 wltrysvc; C:\Program Files\Broadcom\Broadcom 802.11\WLTRYSVC.EXE [48128 2013-09-30] (Broadcom Corporation) ==================== Drivers (Whitelisted) ==================== R1 anodlwf; C:\Windows\System32\DRIVERS\anodlwfx.sys [15872 2009-03-06] () R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [727592 2013-10-24] (BitDefender) R3 avchv; C:\Windows\System32\DRIVERS\avchv.sys [261056 2012-11-02] (BitDefender) R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [601360 2013-10-24] (BitDefender) R1 BdfNdisf; c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [93600 2013-04-29] (BitDefender LLC) R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [103504 2011-11-14] (BitDefender LLC) S3 BDSandBox; C:\Windows\system32\drivers\bdsandbox.sys [82824 2013-10-24] (BitDefender SRL) R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [150256 2013-10-24] (BitDefender LLC) S3 libusb0; C:\Windows\System32\drivers\libusb0.sys [29184 2012-03-02] (hxxp://libusb-win32.sourceforge.net) S3 libusb0; C:\Windows\SysWow64\drivers\libusb0.sys [21504 2012-03-02] (hxxp://libusb-win32.sourceforge.net) S3 netr28ux; C:\Windows\System32\DRIVERS\Dnetr28ux.sys [1119072 2010-05-05] (Ralink Technology Corp.) S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19032 2013-03-07] () S3 pwdspio; C:\Windows\system32\pwdspio.sys [9584 2013-03-07] () S1 StarOpen; C:\Windows\SysWow64\Drivers\StarOpen.sys [5632 2006-07-24] () R3 TPLINKUDSMBus; C:\Windows\System32\drivers\TplinkUDSMBus.sys [102688 2012-09-21] (Windows (R) Codename Longhorn DDK provider) S3 TplinkUDSTcpBus; C:\Windows\System32\drivers\TplinkUDSTcpBus.sys [181024 2012-09-21] (Windows (R) Codename Longhorn DDK provider) R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [389240 2013-10-24] (BitDefender S.R.L.) S3 vpnva; system32\DRIVERS\vpnva64.sys [x] U3 kxldqpog; \??\C:\Users\Kaan\AppData\Local\Temp\kxldqpog.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-29 00:35 - 2013-10-29 00:35 - 00000242 _____ C:\Windows\SysWOW64\defogger_enable.log 2013-10-29 00:34 - 2013-10-29 00:34 - 00000470 _____ C:\Windows\SysWOW64\defogger_disable.log 2013-10-28 23:39 - 2013-10-28 23:39 - 00000000 ____D C:\FRST 2013-10-27 17:49 - 2013-10-27 17:49 - 00000000 ____D C:\Users\Kaan\AppData\Local\{8159F150-D71B-4DF6-AFAD-65D31294EBFE} 2013-10-25 11:40 - 2013-10-25 11:40 - 00000000 ____D C:\ProgramData\Oracle 2013-10-25 11:39 - 2013-10-08 06:50 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-10-25 11:39 - 2013-10-08 06:46 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-10-25 11:39 - 2013-10-08 06:46 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-10-25 11:39 - 2013-10-08 06:46 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-10-25 11:38 - 2013-10-25 11:39 - 00004886 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log 2013-10-24 18:40 - 2013-10-24 18:40 - 00082824 _____ (BitDefender SRL) C:\Windows\system32\Drivers\bdsandbox.sys 2013-10-24 01:00 - 2013-10-24 01:00 - 00001074 _____ C:\Users\Public\Desktop\PDF24 Editor.lnk 2013-10-24 01:00 - 2013-10-24 01:00 - 00001059 _____ C:\Users\Public\Desktop\PDF24 Fax.lnk 2013-10-24 01:00 - 2013-10-24 01:00 - 00000000 ____D C:\Users\Kaan\AppData\Local\PDF24 2013-10-24 00:59 - 2013-10-24 01:00 - 00000000 ____D C:\Program Files (x86)\PDF24 2013-10-23 15:25 - 2013-10-20 16:17 - 00047126 ____H C:\Users\Kaan\Desktop\._Scan 1.jpeg 2013-10-23 15:25 - 2013-10-20 16:17 - 00046638 ____H C:\Users\Kaan\Desktop\._Scan 2.jpeg 2013-10-23 15:25 - 2013-10-20 16:17 - 00045829 ____H C:\Users\Kaan\Desktop\._Scan.jpeg 2013-10-23 15:25 - 2011-03-16 18:27 - 00433747 _____ C:\Users\Kaan\Desktop\Scan 2.jpeg 2013-10-23 15:25 - 2011-03-16 18:21 - 00393597 _____ C:\Users\Kaan\Desktop\Scan 1.jpeg 2013-10-23 15:25 - 2011-03-16 18:18 - 00352703 _____ C:\Users\Kaan\Desktop\Scan.jpeg 2013-10-22 19:27 - 2013-09-04 13:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2013-10-22 19:27 - 2013-09-04 13:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2013-10-22 19:27 - 2013-09-04 13:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2013-10-22 19:27 - 2013-09-04 13:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2013-10-22 19:27 - 2013-09-04 13:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2013-10-22 19:27 - 2013-09-04 13:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2013-10-22 19:27 - 2013-09-04 13:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2013-10-18 00:57 - 2013-10-18 00:58 - 00000000 ____D C:\Users\Kaan\Desktop\iPhone 2013-10-15 10:00 - 2013-10-15 10:00 - 00000000 ____D C:\Users\Kaan\Downloads\xbmc-12.2-Frodo-armeabi-v7a 2013-10-15 09:52 - 2013-10-15 09:52 - 01568184 _____ C:\Users\Kaan\Downloads\srt_app_guard.apk 2013-10-15 09:44 - 2013-10-15 09:44 - 02137322 _____ C:\Users\Kaan\Downloads\TubeMate_2.0.6.483.apk 2013-10-15 00:51 - 2013-10-15 00:51 - 46628181 _____ C:\Users\Kaan\Downloads\xbmc-12.2-Frodo-armeabi-v7a.zip 2013-10-15 00:47 - 2013-10-15 00:47 - 09281149 _____ C:\Users\Kaan\Downloads\appstore-android.apk 2013-10-12 02:11 - 2013-09-23 00:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-10-12 02:11 - 2013-09-21 04:38 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-10-12 02:11 - 2013-09-21 04:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-10-12 02:10 - 2013-09-23 00:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-10-12 02:10 - 2013-09-23 00:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-10-12 02:10 - 2013-09-23 00:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-10-12 02:10 - 2013-09-23 00:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-10-12 02:10 - 2013-09-23 00:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-10-12 02:10 - 2013-09-23 00:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-10-12 02:10 - 2013-09-23 00:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-10-12 02:10 - 2013-09-23 00:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-10-12 02:10 - 2013-09-23 00:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-10-12 02:10 - 2013-09-23 00:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-10-12 02:10 - 2013-09-23 00:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-10-12 02:10 - 2013-09-23 00:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-10-12 02:10 - 2013-09-22 23:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-10-12 02:10 - 2013-09-22 23:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-10-12 02:10 - 2013-09-22 23:55 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-10-12 02:10 - 2013-09-22 23:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-10-12 02:10 - 2013-09-22 23:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-10-12 02:10 - 2013-09-22 23:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-10-12 02:10 - 2013-09-22 23:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-10-12 02:10 - 2013-09-22 23:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-10-12 02:10 - 2013-09-22 23:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-10-12 02:10 - 2013-09-22 23:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-10-12 02:10 - 2013-09-22 23:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-10-12 02:10 - 2013-09-22 23:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-10-12 02:10 - 2013-09-22 23:54 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-10-12 02:10 - 2013-09-22 23:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-10-12 02:10 - 2013-09-21 03:48 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-10-12 02:10 - 2013-09-21 03:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-10-11 18:13 - 2013-10-11 18:13 - 00000000 ____D C:\Users\Kaan\AppData\Local\{FEFABE4A-4263-4806-A285-9176D8675AE7} 2013-10-11 09:42 - 2013-07-12 11:41 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys 2013-10-11 09:42 - 2013-07-12 11:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys 2013-10-11 09:42 - 2013-06-06 06:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2013-10-11 09:42 - 2013-06-06 06:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2013-10-11 09:42 - 2013-06-06 06:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2013-10-11 09:42 - 2013-06-06 06:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2013-10-11 09:42 - 2013-06-06 05:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2013-10-11 09:42 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2013-10-11 09:42 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2013-10-11 09:42 - 2013-06-06 04:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2013-10-11 09:42 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2013-10-11 09:42 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2013-10-11 09:41 - 2013-09-14 02:10 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-10-11 09:41 - 2013-09-08 03:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-10-11 09:41 - 2013-09-08 03:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-10-11 09:41 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2013-10-11 09:41 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2013-10-11 09:41 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2013-10-11 09:41 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2013-10-11 09:41 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2013-10-11 09:41 - 2013-07-04 11:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2013-10-10 09:41 - 2013-08-29 02:29 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbser.sys 2013-10-10 09:41 - 2013-07-04 13:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2013-10-10 09:41 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2013-10-10 09:41 - 2013-07-03 05:40 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys 2013-10-10 09:41 - 2013-07-03 05:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2013-10-10 09:41 - 2013-07-03 05:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2013-10-10 09:41 - 2013-06-25 23:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys 2013-10-10 09:40 - 2013-08-29 03:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-10-10 09:40 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-10-10 09:40 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2013-10-10 09:40 - 2013-08-29 03:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-10-10 09:40 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-10-10 09:40 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-10-10 09:40 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-10-10 09:40 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-10-10 09:40 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2013-10-10 09:40 - 2013-08-29 02:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-10-10 09:40 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2013-10-10 09:40 - 2013-08-29 01:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-10-10 09:40 - 2013-08-29 01:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-10-10 09:40 - 2013-08-29 01:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-10-10 09:40 - 2013-08-29 01:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-10-10 09:40 - 2013-08-28 02:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-10-10 09:40 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll 2013-10-10 09:40 - 2013-08-01 13:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2013-10-10 09:40 - 2013-07-20 11:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2013-10-10 09:40 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2013-10-09 09:47 - 2013-10-09 09:47 - 00000000 ____D C:\Program Files (x86)\Smart Projects 2013-10-05 13:59 - 2013-10-05 13:59 - 00000000 ____D C:\Users\Kaan\Downloads\WRE2205_1.00(AAES.2)C0 2013-10-05 12:54 - 2010-06-03 12:36 - 00302080 _____ () C:\Windows\lwd.exe 2013-10-05 12:53 - 2013-10-05 12:55 - 00003977 _____ C:\Windows\system32\RaCoInst.log 2013-10-05 12:53 - 2013-10-05 12:53 - 00000000 ____D C:\Program Files (x86)\D-Link 2013-10-05 12:53 - 2010-05-05 15:10 - 01119072 _____ (Ralink Technology Corp.) C:\Windows\system32\Drivers\Dnetr28ux.sys 2013-10-05 12:53 - 2010-05-05 15:03 - 00326432 _____ (Ralink Technology, Inc.) C:\Windows\system32\RaCoInstx.dll 2013-10-05 12:53 - 2010-05-05 15:03 - 00014051 _____ C:\Windows\system32\RaCoInst.dat 2013-10-05 12:53 - 2009-03-06 17:10 - 00015872 _____ () C:\Windows\system32\Drivers\anodlwfx.sys 2013-10-05 12:52 - 2013-10-05 12:52 - 00000000 ____D C:\Users\Kaan\Downloads\DWA-140_drv_RevB_multi_v1.71s0062-2010-07-02 2013-10-01 11:34 - 2013-10-01 11:35 - 16465992 _____ (Hewlett-Packard Company ) C:\Users\Kaan\Downloads\sp50370.exe 2013-10-01 00:19 - 2013-10-01 00:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-09-30 23:25 - 2013-09-30 23:24 - 07930368 _____ (Broadcom Corporation) C:\Windows\system32\BCMWLCPL.CPL 2013-09-30 23:25 - 2013-09-30 23:24 - 04961800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vcredist_x64.exe 2013-09-30 23:25 - 2013-09-30 23:24 - 04698112 _____ (Broadcom Corporation) C:\Windows\system32\bcmttls.dll 2013-09-30 23:25 - 2013-09-30 23:24 - 03161088 _____ (Microsoft Corporation) C:\Windows\system32\vcredist_x64.exe 2013-09-30 23:25 - 2013-09-30 23:24 - 01058816 _____ (Broadcom Corporation) C:\Windows\system32\BCMLogon.dll 2013-09-30 23:25 - 2013-09-30 23:24 - 00073728 _____ (Broadcom Corporation) C:\Windows\system32\wltrynt.dll 2013-09-30 23:25 - 2013-09-30 23:24 - 00035344 _____ (CACE Technologies, Inc.) C:\Windows\system32\Drivers\npf.sys 2013-09-30 23:25 - 2013-09-30 23:24 - 00022632 _____ (Broadcom Corporation) C:\Windows\system32\Drivers\bcm42rly.sys 2013-09-30 23:25 - 2013-09-30 23:24 - 00000446 _____ C:\Windows\SysWOW64\vcredist_x64.bat 2013-09-30 23:25 - 2013-09-30 23:24 - 00000445 _____ C:\Windows\system32\vcredist_x64.bat 2013-09-30 23:00 - 2013-09-30 23:11 - 90531320 _____ (Hewlett-Packard Company ) C:\Users\Kaan\Downloads\sp60504.exe 2013-09-30 22:49 - 2013-09-30 22:49 - 00000000 ____D C:\Program Files\CPUID 2013-09-30 22:47 - 2013-09-30 22:47 - 00614816 _____ C:\Users\Kaan\Downloads\CPU Z - CHIP-Downloader.exe ==================== One Month Modified Files and Folders ======= 2013-10-29 00:35 - 2013-10-29 00:35 - 00000242 _____ C:\Windows\SysWOW64\defogger_enable.log 2013-10-29 00:35 - 2011-04-13 23:43 - 00000000 ____D C:\Users\Kaan 2013-10-29 00:34 - 2013-10-29 00:34 - 00000470 _____ C:\Windows\SysWOW64\defogger_disable.log 2013-10-29 00:20 - 2011-04-13 23:38 - 01235670 _____ C:\Windows\WindowsUpdate.log 2013-10-29 00:13 - 2011-10-17 11:07 - 00001116 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3539190620-169771348-1185741438-1000UA.job 2013-10-29 00:02 - 2013-04-17 13:34 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-10-28 23:39 - 2013-10-28 23:39 - 00000000 ____D C:\FRST 2013-10-28 23:38 - 2009-07-14 05:45 - 00022208 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-28 23:38 - 2009-07-14 05:45 - 00022208 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-28 21:53 - 2013-04-17 13:34 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-10-28 21:45 - 2013-05-21 09:06 - 00027143 _____ C:\Windows\setupact.log 2013-10-28 21:45 - 2011-10-17 11:07 - 00001064 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3539190620-169771348-1185741438-1000Core.job 2013-10-28 14:38 - 2012-06-19 23:34 - 00003922 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{90BCA438-69EF-4A04-974F-DC7DB84538DB} 2013-10-27 19:04 - 2011-06-06 20:52 - 00000000 ____D C:\Users\Kaan\AppData\Roaming\Skype 2013-10-27 17:59 - 2011-06-06 20:51 - 00000000 ____D C:\ProgramData\Skype 2013-10-27 17:49 - 2013-10-27 17:49 - 00000000 ____D C:\Users\Kaan\AppData\Local\{8159F150-D71B-4DF6-AFAD-65D31294EBFE} 2013-10-26 14:43 - 2012-04-21 16:11 - 00000000 ____D C:\Windows\SysWOW64\Adobe 2013-10-26 11:07 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-10-25 12:14 - 2011-04-14 01:15 - 00000000 ____D C:\Users\Kaan\AppData\Roaming\Mozilla 2013-10-25 11:40 - 2013-10-25 11:40 - 00000000 ____D C:\ProgramData\Oracle 2013-10-25 11:39 - 2013-10-25 11:38 - 00004886 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log 2013-10-25 11:39 - 2013-06-28 10:21 - 00000000 ____D C:\Program Files (x86)\Java 2013-10-25 11:17 - 2013-05-27 07:29 - 00004592 _____ C:\Windows\PFRO.log 2013-10-24 18:40 - 2013-10-24 18:40 - 00082824 _____ (BitDefender SRL) C:\Windows\system32\Drivers\bdsandbox.sys 2013-10-24 18:39 - 2013-04-29 16:58 - 00727592 _____ (BitDefender) C:\Windows\system32\Drivers\avc3.sys 2013-10-24 18:38 - 2013-04-29 16:58 - 00601360 _____ (BitDefender) C:\Windows\system32\Drivers\avckf.sys 2013-10-24 18:38 - 2013-03-31 18:59 - 00150256 _____ (BitDefender LLC) C:\Windows\system32\Drivers\gzflt.sys 2013-10-24 18:38 - 2013-02-06 16:40 - 00389240 _____ (BitDefender S.R.L.) C:\Windows\system32\Drivers\trufos.sys 2013-10-24 01:07 - 2010-11-21 07:50 - 00697098 _____ C:\Windows\system32\perfh007.dat 2013-10-24 01:07 - 2010-11-21 07:50 - 00148362 _____ C:\Windows\system32\perfc007.dat 2013-10-24 01:07 - 2009-07-14 06:13 - 01613412 _____ C:\Windows\system32\PerfStringBackup.INI 2013-10-24 01:06 - 2012-07-05 19:24 - 00000000 ___RD C:\Users\Kaan\Dropbox 2013-10-24 01:06 - 2012-07-05 19:17 - 00000000 ____D C:\Users\Kaan\AppData\Roaming\Dropbox 2013-10-24 01:00 - 2013-10-24 01:00 - 00001074 _____ C:\Users\Public\Desktop\PDF24 Editor.lnk 2013-10-24 01:00 - 2013-10-24 01:00 - 00001059 _____ C:\Users\Public\Desktop\PDF24 Fax.lnk 2013-10-24 01:00 - 2013-10-24 01:00 - 00000000 ____D C:\Users\Kaan\AppData\Local\PDF24 2013-10-24 01:00 - 2013-10-24 00:59 - 00000000 ____D C:\Program Files (x86)\PDF24 2013-10-23 11:42 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF 2013-10-20 16:17 - 2013-10-23 15:25 - 00047126 ____H C:\Users\Kaan\Desktop\._Scan 1.jpeg 2013-10-20 16:17 - 2013-10-23 15:25 - 00046638 ____H C:\Users\Kaan\Desktop\._Scan 2.jpeg 2013-10-20 16:17 - 2013-10-23 15:25 - 00045829 ____H C:\Users\Kaan\Desktop\._Scan.jpeg 2013-10-18 00:59 - 2013-06-10 00:26 - 00000000 ____D C:\Users\Kaan\Desktop\SAP Kurse 2013-10-18 00:59 - 2013-04-24 09:49 - 00000000 ____D C:\Users\Kaan\Desktop\offene Bewerbungen 2013-10-18 00:58 - 2013-10-18 00:57 - 00000000 ____D C:\Users\Kaan\Desktop\iPhone 2013-10-18 00:58 - 2011-10-20 23:07 - 00000000 ____D C:\Users\Kaan\Desktop\Bewerbungsunterlagen aktuell 2013-10-18 00:56 - 2013-04-24 09:47 - 00000000 ____D C:\Users\Kaan\Desktop\Handystuff 2013-10-18 00:54 - 2012-07-16 10:17 - 00000000 ____D C:\Users\Kaan\Desktop\Bewerbung Alara 2013-10-15 10:00 - 2013-10-15 10:00 - 00000000 ____D C:\Users\Kaan\Downloads\xbmc-12.2-Frodo-armeabi-v7a 2013-10-15 09:52 - 2013-10-15 09:52 - 01568184 _____ C:\Users\Kaan\Downloads\srt_app_guard.apk 2013-10-15 09:44 - 2013-10-15 09:44 - 02137322 _____ C:\Users\Kaan\Downloads\TubeMate_2.0.6.483.apk 2013-10-15 00:51 - 2013-10-15 00:51 - 46628181 _____ C:\Users\Kaan\Downloads\xbmc-12.2-Frodo-armeabi-v7a.zip 2013-10-15 00:47 - 2013-10-15 00:47 - 09281149 _____ C:\Users\Kaan\Downloads\appstore-android.apk 2013-10-12 12:21 - 2012-12-06 13:24 - 00000000 ____D C:\Users\Kaan\Documents\Bluetooth-Exchange-Ordner 2013-10-12 10:31 - 2012-04-21 16:09 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-10-12 10:31 - 2012-04-21 16:09 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-10-12 10:28 - 2009-07-14 05:45 - 00295720 _____ C:\Windows\system32\FNTCACHE.DAT 2013-10-12 02:08 - 2012-01-30 16:04 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-10-12 02:08 - 2012-01-30 16:04 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2013-10-12 02:07 - 2012-08-27 22:36 - 01591306 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2013-10-11 18:42 - 2013-01-27 21:55 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-10-11 18:13 - 2013-10-11 18:13 - 00000000 ____D C:\Users\Kaan\AppData\Local\{FEFABE4A-4263-4806-A285-9176D8675AE7} 2013-10-11 14:57 - 2013-04-17 13:34 - 00004102 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-10-11 14:57 - 2013-04-17 13:34 - 00003850 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-10-10 23:57 - 2011-04-14 00:48 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-10-10 20:08 - 2011-10-17 11:07 - 00004084 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3539190620-169771348-1185741438-1000UA 2013-10-10 20:08 - 2011-10-17 11:07 - 00003688 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3539190620-169771348-1185741438-1000Core 2013-10-09 09:47 - 2013-10-09 09:47 - 00000000 ____D C:\Program Files (x86)\Smart Projects 2013-10-08 06:50 - 2013-10-25 11:39 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-10-08 06:46 - 2013-10-25 11:39 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-10-08 06:46 - 2013-10-25 11:39 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-10-08 06:46 - 2013-10-25 11:39 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-10-05 13:59 - 2013-10-05 13:59 - 00000000 ____D C:\Users\Kaan\Downloads\WRE2205_1.00(AAES.2)C0 2013-10-05 12:55 - 2013-10-05 12:53 - 00003977 _____ C:\Windows\system32\RaCoInst.log 2013-10-05 12:53 - 2013-10-05 12:53 - 00000000 ____D C:\Program Files (x86)\D-Link 2013-10-05 12:53 - 2011-04-14 00:35 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-10-05 12:52 - 2013-10-05 12:52 - 00000000 ____D C:\Users\Kaan\Downloads\DWA-140_drv_RevB_multi_v1.71s0062-2010-07-02 2013-10-01 11:35 - 2013-10-01 11:34 - 16465992 _____ (Hewlett-Packard Company ) C:\Users\Kaan\Downloads\sp50370.exe 2013-10-01 09:22 - 2012-04-24 17:01 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-10-01 00:20 - 2013-10-01 00:19 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-10-01 00:20 - 2011-04-14 01:15 - 00000000 ____D C:\Users\Kaan\AppData\Local\Mozilla 2013-09-30 23:58 - 2013-01-30 13:50 - 00000000 ____D C:\Windows\pss 2013-09-30 23:58 - 2011-04-13 23:44 - 00000000 ___RD C:\Users\Kaan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-09-30 23:25 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\zh-HK 2013-09-30 23:25 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\tr-TR 2013-09-30 23:25 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\th-TH 2013-09-30 23:25 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\sl-SI 2013-09-30 23:25 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\sk-SK 2013-09-30 23:25 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\ro-RO 2013-09-30 23:25 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\lv-LV 2013-09-30 23:25 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\lt-LT 2013-09-30 23:25 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\hr-HR 2013-09-30 23:25 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\he-IL 2013-09-30 23:25 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\et-EE 2013-09-30 23:25 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\bg-BG 2013-09-30 23:25 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\ar-SA 2013-09-30 23:25 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\Help 2013-09-30 23:24 - 2013-09-30 23:25 - 07930368 _____ (Broadcom Corporation) C:\Windows\system32\BCMWLCPL.CPL 2013-09-30 23:24 - 2013-09-30 23:25 - 04961800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vcredist_x64.exe 2013-09-30 23:24 - 2013-09-30 23:25 - 04698112 _____ (Broadcom Corporation) C:\Windows\system32\bcmttls.dll 2013-09-30 23:24 - 2013-09-30 23:25 - 03161088 _____ (Microsoft Corporation) C:\Windows\system32\vcredist_x64.exe 2013-09-30 23:24 - 2013-09-30 23:25 - 01058816 _____ (Broadcom Corporation) C:\Windows\system32\BCMLogon.dll 2013-09-30 23:24 - 2013-09-30 23:25 - 00073728 _____ (Broadcom Corporation) C:\Windows\system32\wltrynt.dll 2013-09-30 23:24 - 2013-09-30 23:25 - 00035344 _____ (CACE Technologies, Inc.) C:\Windows\system32\Drivers\npf.sys 2013-09-30 23:24 - 2013-09-30 23:25 - 00022632 _____ (Broadcom Corporation) C:\Windows\system32\Drivers\bcm42rly.sys 2013-09-30 23:24 - 2013-09-30 23:25 - 00000446 _____ C:\Windows\SysWOW64\vcredist_x64.bat 2013-09-30 23:24 - 2013-09-30 23:25 - 00000445 _____ C:\Windows\system32\vcredist_x64.bat 2013-09-30 23:24 - 2011-04-13 23:57 - 04747880 _____ (Broadcom Corporation) C:\Windows\system32\Drivers\BCMWL664.SYS 2013-09-30 23:24 - 2011-04-13 23:57 - 03952640 _____ (Broadcom Corporation) C:\Windows\system32\bcmihvsrv64.dll 2013-09-30 23:24 - 2011-04-13 23:57 - 03617792 _____ (Broadcom Corporation) C:\Windows\system32\bcmihvui64.dll 2013-09-30 23:24 - 2011-04-13 23:57 - 00095584 _____ (Broadcom Corporation) C:\Windows\system32\bcmwlcoi.dll 2013-09-30 23:24 - 2011-04-13 23:57 - 00006656 _____ C:\Windows\system32\bcmwlrc.dll 2013-09-30 23:24 - 2011-04-13 23:57 - 00000000 ____D C:\SWSetup 2013-09-30 23:11 - 2013-09-30 23:00 - 90531320 _____ (Hewlett-Packard Company ) C:\Users\Kaan\Downloads\sp60504.exe 2013-09-30 22:49 - 2013-09-30 22:49 - 00000000 ____D C:\Program Files\CPUID 2013-09-30 22:47 - 2013-09-30 22:47 - 00614816 _____ C:\Users\Kaan\Downloads\CPU Z - CHIP-Downloader.exe Some content of TEMP: ==================== C:\Users\Kaan\AppData\Local\Temp\abelssoft.setup.exe C:\Users\Kaan\AppData\Local\Temp\ANPDApi.dll C:\Users\Kaan\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\Kaan\AppData\Local\Temp\NOSEventMessages.dll C:\Users\Kaan\AppData\Local\Temp\SCC.dll C:\Users\Kaan\AppData\Local\Temp\SkypeSetup.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-10-21 13:55 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-10-2013 Ran by Kaan at 2013-10-28 23:42:53 Running from D:\Downloads neu Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Bitdefender Virenschutz (Enabled - Up to date) {9B5F5313-CAF9-DD97-C460-E778420237B4} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Bitdefender Spyware-Schutz (Enabled - Up to date) {203EB2F7-ECC3-D219-FED0-DC0A39857D09} FW: Bitdefender Firewall (Enabled) {A364D236-8096-DCCF-EF3F-4E4DBCD170CF} ==================== Installed Programs ====================== 7-Zip 9.20 (x64 edition) (Version: 9.20.00.0) AC3Filter 1.63b (x32 Version: 1.63b) Adobe Connect 9 Add-in (HKCU Version: 11,2,369,0) Adobe Digital Editions (x32) Adobe Flash Player 11 ActiveX (x32 Version: 11.7.700.169) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117) Adobe Shockwave Player 12.0 (x32 Version: 12.0.4.144) Amazon MP3-Downloader 1.0.9 (x32) Android SDK Tools (x32 Version: 1.16) Apple Application Support (x32 Version: 2.1.9) Apple Mobile Device Support (Version: 5.2.0.6) Apple Software Update (x32 Version: 2.1.3.127) ARIS Express (x32 Version: 1.00) Bewerbungsfoto-/Passbild-Generator v3.5a (x32) Bitdefender Internet Security 2013 (Version: 16.26.0.1739) Broadcom 2070 Bluetooth 3.0 (Version: 6.3.0.6300) Broadcom 802.11 Wireless LAN Adapter (Version: 5.100.82.143) Broadcom Wireless Utility (Version: 5.100.82.143) Brother MFL-Pro Suite DCP-130C (x32 Version: 1.0.3.0) calibre (x32 Version: 0.9.30) Capture One 6.4 (Version: 6.4.58953.143) CCleaner (Version: 4.01) Citavi (x32 Version: 3.1.15.0) Counter-Strike: Condition Zero (x32) Counter-Strike: Condition Zero Deleted Scenes (x32) Counter-Strike: Global Offensive (x32) CPUID CPU-Z 1.66.1 D3DX10 (x32 Version: 15.4.2368.0902) Day of Defeat (x32) D-Link DWA-140 (x32) Dropbox (HKCU Version: 2.0.22) eReg (x32 Version: 1.20.138.34) Free Audio CD Burner version 1.4.8 (x32) Google Chrome (HKCU Version: 30.0.1599.101) Google Earth Plug-in (x32 Version: 7.1.1.1888) Google Talk Plugin (x32 Version: 4.8.2.15856) Google Update Helper (x32 Version: 1.3.21.165) GPL Ghostscript (x32 Version: 9.07) Harmony Browser Plug-in (x32 Version: 2.0) HashTab 4.0.0.1 (Version: 4.0.0.1) HP ESU for Microsoft Windows 7 (x32 Version: 1.1.8.1) HTC BMP USB Driver (x32 Version: 1.0.5375) HTC Driver Installer (x32 Version: 3.0.0.007) HTC Sync (x32 Version: 3.0.5551) IDT Audio (x32 Version: 1.0.6275.0) inSSIDer (x32 Version: 2.1.6) IrfanView (remove only) (x32 Version: 4.35) IsoBuster 3.2 (x32 Version: 3.2) Java 7 Update 45 (x32 Version: 7.0.450) Java Auto Updater (x32 Version: 2.1.9.8) K-Lite Codec Pack 6.0.4 (Basic) (x32 Version: 6.0.4) Kobo (x32 Version: 2.1.7) LMMS 0.4.11 (x32 Version: 0.4.11) Logitech SetPoint 6.30 (Version: 6.30.43) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300) McAfee Virtual Technician (x32 Version: 6.5.0.2101) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Games for Windows - LIVE Redistributable (x32 Version: 3.5.88.0) Microsoft Games for Windows Marketplace (x32 Version: 3.5.50.0) Microsoft PowerPoint Viewer (x32 Version: 14.0.7015.1000) Microsoft Silverlight (Version: 5.1.20913.0) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (x32 Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft_VC100_CRT_SP1_x64 (Version: 10.0.40219.1) Microsoft_VC100_CRT_SP1_x86 (x32 Version: 10.0.40219.1) Microsoft_VC100_CRT_x86 (x32 Version: 1.0.0) MiniTool Partition Wizard Home Edition 7.8 (x32) Moorhuhn Remake (x32 Version: 1.00.0000) Motorola Device Manager (x32 Version: 2.2.28) Motorola Device Software Update (x32 Version: 1.0.40) Motorola MMCP Drivers Installation 1.0.3 (Version: 1.0.3) Motorola Mobile Drivers Installation 5.9.0 (Version: 5.9.0) Motorola Software Update (x32 Version: 01.16.42) Mozilla Firefox 24.0 (x86 de) (x32 Version: 24.0) Mozilla Maintenance Service (x32 Version: 24.0) Mp3tag v2.51 (x32 Version: v2.51) MPEG2 Codec(libmpeg2/mad) (x32) MSVC80_x64_v2 (Version: 1.0.3.0) MSVC80_x86_v2 (x32 Version: 1.0.3.0) MSVC90_x64 (Version: 1.0.1.2) MSVC90_x86 (x32 Version: 1.0.1.2) MSVCRT (x32 Version: 15.4.2862.0708) MSXML 4.0 SP3 Parser (KB2721691) (x32 Version: 4.30.2114.0) MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0) MSXML 4.0 SP3 Parser (KB973685) (x32 Version: 4.30.2107.0) MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0) Need For Speed™ World (x32 Version: 1.0.0.659) Nokia Connectivity Cable Driver (x32 Version: 7.1.101.0) Nokia Suite (x32 Version: 3.7.22.0) OpenOffice.org 3.3 (x32 Version: 3.3.9567) Paint.NET v3.5.10 (Version: 3.60.0) PC Connectivity Solution (x32 Version: 12.0.76.0) PDF24 Creator 5.7.0 (x32) PDFCreator (x32 Version: 1.7.0) pdfsam (x32 Version: 2.2.0) PDF-XChange Viewer (Version: 2.5.195.0) PhotoFiltre 7 (HKCU) Picasa 3 (x32 Version: 3.9) Project S (x32 Version: 1.0.0000.1) Recuva (Version: 1.43) SAMSUNG Mobile Composite Device Software SAMSUNG Mobile Modem Driver Set Samsung Mobile phone USB driver Drive Software SAMSUNG Mobile USB Modem 1.0 Software SAMSUNG Mobile USB Modem Software Samsung PC Studio 3 (x32 Version: 3.0.0.80601) Samsung PC Studio 3 (x32 Version: 3.2.2.80601) SciPlore MindMapping (x32 Version: Beta 7) Scribus 1.4.2 (x32 Version: 1.4.2) SDFormatter (x32 Version: 3.1.0) SecureW2 EAP Suite 2.0.2 for Windows (x32) Shared C Run-time for x64 (Version: 10.0.0) Skype™ 6.9 (x32 Version: 6.9.106) Spotify (HKCU Version: 0.8.5.1333.g822e0de8) Star Wars: Knights of the Old Republic (x32) Steam (x32 Version: 1.0.0.0) streamWriter (x32) swMSM (x32 Version: 12.0.0.1) Synaptics Pointing Device Driver (Version: 15.0.24.0) TeamViewer 7 (x32 Version: 7.0.13989) Tinypic 3.17b (x32 Version: Tinypic 3.17b) TP-LINK USB Printer Controller (x32 Version: 1.12.0927) TVUPlayer 2.5.3.1 (x32 Version: 2.5.3.1) TwistedBrush Pro Studio (HKCU) Uninstall 1.0.0.1 (x32) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (x32 Version: 3) Visual C++ 9.0 CRT (x86) WinSXS MSM (x32 Version: 9.0) VLC media player 1.1.11 (x32 Version: 1.1.11) vShare.tv plugin 1.3 (x32 Version: 1.3) Winamp (x32 Version: 5.622 ) Windows Live Communications Platform (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3538.0513) Windows Live ID Sign-in Assistant (Version: 7.250.4232.0) Windows Live Installer (x32 Version: 15.4.3502.0922) Windows Live Language Selector (Version: 15.4.3538.0513) Windows Live Messenger (x32 Version: 15.4.3538.0513) Windows Live Photo Common (x32 Version: 15.4.3502.0922) Windows Live PIMT Platform (x32 Version: 15.4.3508.1109) Windows Live SOXE (x32 Version: 15.4.3502.0922) Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922) Windows Live UX Platform (x32 Version: 15.4.3502.0922) Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109) Windows Media Player Firefox Plugin (x32 Version: 1.0.0.8) Windows-Treiberpaket - Leaf Imaging Ltd. Image (02/11/2010 ) (Version: 02/11/2010 ) Windows-Treiberpaket - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0) (Version: 05/31/2012 7.1.2.0) YouTube Song Downloader (x32 Version: 8.2) ==================== Restore Points ========================= ==================== Hosts content: ========================== 2009-07-14 03:34 - 2011-09-22 21:10 - 00000098 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {07DF02AD-115D-4A27-9612-475514395FDC} - System32\Tasks\Motorola Device Manager Engine => C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotorolaDeviceManagerUpdate.exe [2012-07-17] () Task: {0DFCB310-A2C8-4EAC-AC0C-240FD797B84C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-17] (Google Inc.) Task: {1EABFC28-3735-45A0-A016-49457DDD00F4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-17] (Google Inc.) Task: {24FDB1A7-7679-4A8C-BE1C-F8A1A91FB81C} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3539190620-169771348-1185741438-1000UA => C:\Users\Kaan\AppData\Local\Google\Update\GoogleUpdate.exe [2011-10-17] (Google Inc.) Task: {5553C08A-5CE9-4619-B5EB-ABED8B271BAC} - System32\Tasks\Launch HTC Sync Loader => C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe [2011-04-26] () Task: {7023692A-1CFB-4C82-8E36-02AED5D2C1FE} - System32\Tasks\Motorola Device Manager Update => C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotorolaDeviceManagerUpdate.exe [2012-07-17] () Task: {91417B48-09AF-4578-98D5-1B4BBF2136B7} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-04-23] (Piriform Ltd) Task: {AA91A452-36AA-4C72-A009-14429BF9A180} - System32\Tasks\{F64B0071-D4DF-4F3E-BD51-1B8E2815DE04} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2013-10-02] (Skype Technologies S.A.) Task: {B6360C5E-52F1-4672-BBE7-F1BBB7CD660D} - System32\Tasks\{87A70F6E-BBBE-4EBA-82BB-CF587EE23705} => C:\Users\Kaan\Downloads\20060802103341484_PIMSandFile_Manager\Setup.exe Task: {E2C5514E-E72E-4E37-B253-26EBF3B333CE} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3539190620-169771348-1185741438-1000Core => C:\Users\Kaan\AppData\Local\Google\Update\GoogleUpdate.exe [2011-10-17] (Google Inc.) Task: {E59E949D-8A48-47D4-B93E-55ACACCC22D7} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {F5647D7E-2FA5-42C5-8C33-C0DE33D76FFC} - System32\Tasks\Motorola Device Manager Initial Update => C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotorolaDeviceManagerUpdate.exe [2012-07-17] () Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3539190620-169771348-1185741438-1000Core.job => C:\Users\Kaan\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3539190620-169771348-1185741438-1000UA.job => C:\Users\Kaan\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2010-07-29 19:39 - 2010-07-29 19:39 - 00173856 _____ () C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll 2013-03-31 18:58 - 2013-10-24 18:38 - 00265080 _____ () C:\Program Files\Bitdefender\Bitdefender 2013\txmlutil.dll 2012-05-30 19:06 - 2012-05-30 19:06 - 00087912 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2012-05-30 19:06 - 2012-05-30 19:06 - 01242512 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2013-10-01 00:19 - 2013-10-01 00:20 - 03279768 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\TEMP:F8B88761 AlternateDataStreams: C:\Users\Kaan\Downloads\gs907w32.exe:BDU AlternateDataStreams: C:\Users\Kaan\Downloads\HarmonyBrowserPlug-in.exe:BDU AlternateDataStreams: C:\Users\Kaan\Downloads\pwhe78.exe:BDU AlternateDataStreams: C:\Users\Kaan\Downloads\scribus-1.4.2-windows.exe:BDU AlternateDataStreams: C:\Users\Kaan\Downloads\sp50370.exe:BDU ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver" ==================== Faulty Device Manager Devices ============= Name: Broadcom 2070 Bluetooth Description: Broadcom 2070 Bluetooth Class Guid: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974} Manufacturer: Broadcom Service: BTHUSB Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (10/28/2013 09:55:09 PM) (Source: .NET Runtime) (User: ) Description: .NET Runtime version 4.0.30319.1008 - Fehler beim Initialisieren der Profilerstellungs-API-Anfügeinfrastruktur. Dieser Prozess ermöglicht einem Profiler das Anfügen nicht. HRESULT: 0x80004005. Prozess-ID (dezimal): 5552. Meldungs-ID: [0x2509]. Error: (10/28/2013 03:14:06 PM) (Source: .NET Runtime) (User: ) Description: .NET Runtime version 4.0.30319.1008 - Fehler beim Initialisieren der Profilerstellungs-API-Anfügeinfrastruktur. Dieser Prozess ermöglicht einem Profiler das Anfügen nicht. HRESULT: 0x80004005. Prozess-ID (dezimal): 7464. Meldungs-ID: [0x2509]. Error: (10/28/2013 02:52:50 PM) (Source: Application Hang) (User: ) Description: Programm IEXPLORE.EXE, Version 10.0.9200.16720 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1aac Startzeit: 01ced33f32d6342f Endzeit: 86 Anwendungspfad: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Berichts-ID: Error: (10/26/2013 11:09:08 AM) (Source: ATIeRecord) (User: ) Description: ATI EEU Client event error Error: (10/26/2013 11:09:07 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/25/2013 07:21:25 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/25/2013 07:20:55 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: bcmwltry.exe, Version: 5.100.82.143, Zeitstempel: 0x50661901 Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000007ff0048d7d8 ID des fehlerhaften Prozesses: 0x6c4 Startzeit der fehlerhaften Anwendung: 0xbcmwltry.exe0 Pfad der fehlerhaften Anwendung: bcmwltry.exe1 Pfad des fehlerhaften Moduls: bcmwltry.exe2 Berichtskennung: bcmwltry.exe3 Error: (10/25/2013 11:19:13 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/24/2013 06:09:17 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/23/2013 11:51:40 PM) (Source: Brother BrLog) (User: ) Description: CTLCN BrtCTLCN: [2013/10/24 00:51:40.083]: [00004816]: brccMCtl.exe: ErrorMessage.cpp (0241) : -------- error code is [0x03031f04]. System errors: ============= Error: (10/28/2013 10:36:03 PM) (Source: atikmdag) (User: ) Description: Display is not active Error: (10/28/2013 10:36:00 PM) (Source: atikmdag) (User: ) Description: Display is not active Error: (10/28/2013 09:45:23 PM) (Source: atikmdag) (User: ) Description: Display is not active Error: (10/28/2013 09:45:23 PM) (Source: atikmdag) (User: ) Description: Display is not active Error: (10/28/2013 09:35:26 PM) (Source: atikmdag) (User: ) Description: Display is not active Error: (10/28/2013 09:35:25 PM) (Source: atikmdag) (User: ) Description: Display is not active Error: (10/28/2013 00:02:10 PM) (Source: atikmdag) (User: ) Description: Display is not active Error: (10/28/2013 00:02:09 PM) (Source: atikmdag) (User: ) Description: Display is not active Error: (10/28/2013 10:56:55 AM) (Source: atikmdag) (User: ) Description: Display is not active Error: (10/28/2013 10:56:52 AM) (Source: atikmdag) (User: ) Description: Display is not active Microsoft Office Sessions: ========================= Error: (10/28/2013 09:55:09 PM) (Source: .NET Runtime)(User: ) Description: .NET Runtime version 4.0.30319.1008 - Fehler beim Initialisieren der Profilerstellungs-API-Anfügeinfrastruktur. Dieser Prozess ermöglicht einem Profiler das Anfügen nicht. HRESULT: 0x80004005. Prozess-ID (dezimal): 5552. Meldungs-ID: [0x2509]. Error: (10/28/2013 03:14:06 PM) (Source: .NET Runtime)(User: ) Description: .NET Runtime version 4.0.30319.1008 - Fehler beim Initialisieren der Profilerstellungs-API-Anfügeinfrastruktur. Dieser Prozess ermöglicht einem Profiler das Anfügen nicht. HRESULT: 0x80004005. Prozess-ID (dezimal): 7464. Meldungs-ID: [0x2509]. Error: (10/28/2013 02:52:50 PM) (Source: Application Hang)(User: ) Description: IEXPLORE.EXE10.0.9200.167201aac01ced33f32d6342f86C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Error: (10/26/2013 11:09:08 AM) (Source: ATIeRecord)(User: ) Description: Error: (10/26/2013 11:09:07 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/25/2013 07:21:25 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/25/2013 07:20:55 PM) (Source: Application Error)(User: ) Description: bcmwltry.exe5.100.82.14350661901unknown0.0.0.000000000c0000005000007ff0048d7d86c401ced1aee5fb5b92C:\Program Files\Broadcom\Broadcom 802.11\bcmwltry.exeunknown2fb73f33-3da2-11e3-8122-78e3b548a275 Error: (10/25/2013 11:19:13 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/24/2013 06:09:17 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/23/2013 11:51:40 PM) (Source: Brother BrLog)(User: ) Description: CTLCNBrtCTLCN: [2013/10/24 00:51:40.083]: [00004816]: brccMCtl.exe: ErrorMessage.cpp (0241) : -------- error code is [0x03031f04]. ==================== Memory info =========================== Percentage of memory in use: 56% Total physical RAM: 3836.56 MB Available physical RAM: 1666.6 MB Total Pagefile: 7671.3 MB Available Pagefile: 5079.09 MB Total Virtual: 8192 MB Available Virtual: 8191.79 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:78.03 GB) (Free:3.23 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: () (Fixed) (Total:219.96 GB) (Free:49.2 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: D2C16FE5) Partition 1: (Active) - (Size=78 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=220 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Vielen Dank für die Hilfe. VG Kaan |
29.10.2013, 06:33 | #2 |
/// the machine /// TB-Ausbilder | Windows 7: Mailer-Daemon Mails von gmx ohne Ende hi,
__________________das ist ein aktuelles Problem bei GMX, dein Rechner ist sauber.
__________________ |
29.10.2013, 09:51 | #3 |
| Windows 7: Mailer-Daemon Mails von gmx ohne Ende Herzlichen Dank,
__________________Das sind doch mal gute Nachrichten. Hatte schon die Befürchtung mein System neu ansetzen zu müssen. Und die Zeit dafür könnte kaum ungünstiger sein. Ihr seid alle echt top hier. VG Kaan |
29.10.2013, 15:42 | #4 |
/// the machine /// TB-Ausbilder | Windows 7: Mailer-Daemon Mails von gmx ohne Ende Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Windows 7: Mailer-Daemon Mails von gmx ohne Ende |
adblock, akamai, browser, cpu-z, defender, device driver, error, explorer, farbar, farbar recovery scan tool, fehler, firefox, flash player, homepage, installation, logfile, malware, mozilla, plug-in, prozess, registry, schutz, security, services.exe, software, spam, svchost.exe, system, temp, tracker, usb, vcredist, windows |