![]() |
|
Plagegeister aller Art und deren Bekämpfung: hallo lieber betreiber ich habe leider nun auch dieses blöde nation zoomWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 |
![]() ![]() | ![]() hallo lieber betreiber ich habe leider nun auch dieses blöde nation zoom hallo leider werde ich dieses nation zoom auch net los , habe hier ein bissche gelesen und schonmal das 64 bit ding zum scannen runter geladen hier jetzt die ergebnisse.. Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 31-12-2013 Ran by gundi (administrator) on GUNDI-PC on 31-12-2013 14:34:04 Running from C:\Users\gundi\Downloads Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE (SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe () C:\Windows\System32\PSIService.exe (Tlapia) C:\Program Files\sysTPL\sysTPLMonitor.exe (Tlapia) C:\Program Files\sysTPL\sysTPLService.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (cyberlink) C:\Program Files\Cyberlink\Shared files\brs.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe () C:\Windows\vsnpstd3.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avcenter.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe [178712 2007-10-08] (Intel Corporation) HKLM\...\Run: [BDRegion] - C:\Program Files\Cyberlink\Shared files\brs.exe [75048 2010-03-13] (cyberlink) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [6724128 2009-02-03] (Realtek Semiconductor) HKLM\...\Run: [Skytel] - C:\Program Files\Realtek\Audio\HDA\SkyTel.exe [1833504 2009-02-03] (Realtek Semiconductor Corp.) HKLM\...\Run: [snpstd3] - C:\Windows\vsnpstd3.exe [827392 2006-09-19] () HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup HKLM\...\Run: [NvMediaCenter] - RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [NeroFilterCheck] - C:\Windows\System32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-12] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [mobilegeni daemon] - C:\Program Files\Mobogenie\DaemonProcess.exe HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DSEPlugins\Direct3DVideoOutput.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DSEPlugins\Direct3DVideoOutput.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DSEPlugins\DivXPlaybackModule.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DSEPlugins\DivXPlaybackModule.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXBannerAdPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXBannerAdPlugin.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXDownloadManagerPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXDownloadManagerPlugin.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXMediaManagerPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXMediaManagerPlugin.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXPlayerPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXPlayerPlugin.dll",DllRegisterServer HKCU\...\Run: [EPSON SX100 Series] - C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIEDE.EXE /FU "C:\Windows\TEMP\E_S88DD.tmp" /EF "HKCU" HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\wmpnscfg.exe [202240 2008-01-21] (Microsoft Corporation) HKCU\...\Run: [NextLive] - C:\Windows\system32\rundll32.exe "C:\Users\gundi\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l HKCU\...0c966feabec1\InprocServer32: [Default-shell32] ATTENTION! ====> ZeroAccess? HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\Gast\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter AppInit_DLLs: c:\progra~1\search~1\datamngr\mgrldr.dll c:\docume~1\ settings\all users\application data\browserprotect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8} [ ] () dditional scan result of Farbar Recovery Scan Tool (x86) Version: 31-12-2013 Ran by gundi at 2013-12-31 14:35:23 Running from C:\Users\gundi\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== ABBYY FineReader 6.0 Sprint (Version: 6.00.1395.4512 - ABBYY Software House) Adobe Flash Player 11 ActiveX (Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Reader X (10.1.8) - Deutsch (Version: 10.1.8 - Adobe Systems Incorporated) Adobe Shockwave Player 12.0 (Version: 12.0.2.122 - Adobe Systems, Inc.) Apple Application Support (Version: 2.1.5 - Apple Inc.) Apple Software Update (Version: 2.1.3.127 - Apple Inc.) Ashampoo Burning Studio 6 FREE (Version: 6.7.6 - ashampoo GmbH & Co. KG) Avira Free Antivirus (Version: 14.0.2.286 - Avira) CCleaner (Version: 4.00 - Piriform) Compatibility Pack für 2007 Office System (Version: 12.0.6612.1000 - Microsoft Corporation) CorelDRAW Essential Edition 3 (Version: - Corel Corporation) CorelDRAW Essential Edition 3 (Version: 3.0 - Corel Corporation) CyberLink PowerDVD 10 (Version: 10.0.1516 - CyberLink Corp.) D3DX10 (Version: 15.4.2368.0902 - Microsoft) DE (Version: 3.0 - Corel Corporation) Druckerdeinstallation für EPSON SX100 Series (Version: - SEIKO EPSON Corporation) Epson Easy Photo Print 2 (Version: 2.0.0.0 - SEIKO EPSON CORPORATION) EPSON Scan (Version: - ) Google Chrome (Version: 31.0.1650.63 - Google Inc.) Google Update Helper (Version: 1.3.22.3 - Google Inc.) HyperCam 2 (Version: - ) ImagXpress (Version: 7.0.74.0 - Nero AG) Intel(R) Matrix Storage Manager (Version: - ) Java 7 Update 45 (Version: 7.0.450 - Oracle) Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Junk Mail filter update (Version: 15.4.3502.0922 - Microsoft Corporation) LightScribe System Software (Version: 1.18.8.1 - LightScribe) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office PowerPoint Viewer 2007 (German) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Primary Interoperability Assemblies 2005 (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [DEU] (Version: 3.1.0000 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Works (Version: 9.7.0621 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (Version: 3.0.5305.0 - Microsoft Corp.) MSVCRT (Version: 15.4.2862.0708 - Microsoft) MSXML 4.0 SP2 (KB936181) (Version: 4.20.9848.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB941833) (Version: 4.20.9849.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0 - Microsoft Corporation) Nero (Version: 5.5.9.8 - ahead software gmbh) Nero Suite (Version: - ) neroxml (Version: 1.0.0 - Nero AG) NVIDIA Drivers (Version: 1.3 - NVIDIA Corporation) NVIDIA PhysX (Version: 9.09.0203 - NVIDIA Corporation) Octoshape add-in for Adobe Flash Player (Version: - ) OpenOffice.org 3.3 (Version: 3.3.9567 - OpenOffice.org) PC Camer@ (Version: 1.0.4.3 - Ihr Firmenname) PCSpeedUp (Version: - www.pcspeedup.com) PokerStars (Version: - PokerStars) QuickEngine (Version: 1.0.1 - Tlapia) Realtek High Definition Audio Driver (Version: 6.0.1.5783 - Realtek Semiconductor Corp.) Segoe UI (Version: 15.4.2271.0615 - Microsoft Corp) Skype™ 6.6 (Version: 6.6.106 - Skype Technologies S.A.) Spelling Dictionaries Support For Adobe Reader 9 (Version: 9.0.0 - Adobe Systems Incorporated) swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) System Requirements Lab (Version: - ) sysTPL (Version: 1.0.0 - Tlapia) Ulead Photo Express 3.0 SE (Version: - ) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (Version: 3 - Microsoft Corporation) Update Manager (Version: 4.60 - Corel Corporation) VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0 - DivX, Inc) Windows Live Communications Platform (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Essentials (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Essentials (Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live Fotogalerie (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Windows Live Installer (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Mail (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Messenger (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Movie Maker (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Photo Common (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Photo Gallery (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live PIMT Platform (Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live SOXE (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live SOXE Definitions (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live UX Platform (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live UX Platform Language Pack (Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live Writer (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Writer Resources (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Media Player Firefox Plugin (Version: 1.0.0.8 - Microsoft Corp) WinRAR (Version: - ) ==================== Restore Points ========================= 25-10-2013 16:25:47 Geplanter Prüfpunkt 26-10-2013 13:59:43 Geplanter Prüfpunkt 28-10-2013 14:18:05 Geplanter Prüfpunkt 30-10-2013 10:57:26 Geplanter Prüfpunkt 31-10-2013 10:41:42 Geplanter Prüfpunkt 01-11-2013 12:53:50 Geplanter Prüfpunkt 02-11-2013 15:01:41 Geplanter Prüfpunkt 03-11-2013 11:23:31 Geplanter Prüfpunkt 05-11-2013 17:10:04 Geplanter Prüfpunkt 08-11-2013 20:29:18 Geplanter Prüfpunkt 10-11-2013 15:28:45 Geplanter Prüfpunkt 11-11-2013 15:38:42 Removed Google Earth. 11-11-2013 16:43:04 Removed Google Earth. 11-11-2013 17:20:49 Installed QuickEngine 11-11-2013 17:45:49 Removed Java(TM) 6 Update 22 11-11-2013 17:47:07 Removed Java(TM) 6 Update 37 11-11-2013 17:50:45 Removed Facebook Video Calling 1.2.0.287 11-11-2013 18:02:08 Removed QuickTime 12-11-2013 16:13:53 Konfiguriert PowerDVD 13-11-2013 14:10:30 Geplanter Prüfpunkt 13-11-2013 15:14:22 Windows Update 17-11-2013 10:15:45 Geplanter Prüfpunkt 18-11-2013 19:40:58 Geplanter Prüfpunkt 19-11-2013 10:24:53 Geplanter Prüfpunkt 21-11-2013 17:36:55 Geplanter Prüfpunkt 22-11-2013 12:19:14 Geplanter Prüfpunkt 24-11-2013 19:00:12 Geplanter Prüfpunkt 25-11-2013 14:16:43 Geplanter Prüfpunkt 26-11-2013 09:36:32 Geplanter Prüfpunkt 27-11-2013 18:26:51 Geplanter Prüfpunkt 28-11-2013 09:59:25 Geplanter Prüfpunkt 29-11-2013 14:57:55 Geplanter Prüfpunkt 01-12-2013 14:47:38 Geplanter Prüfpunkt 02-12-2013 09:51:43 Geplanter Prüfpunkt 09-12-2013 16:37:10 Geplanter Prüfpunkt 11-12-2013 11:37:10 Windows Update 14-12-2013 12:45:26 Geplanter Prüfpunkt 16-12-2013 13:24:12 Geplanter Prüfpunkt 18-12-2013 12:16:20 Geplanter Prüfpunkt 22-12-2013 12:47:10 Geplanter Prüfpunkt 23-12-2013 13:22:41 Geplanter Prüfpunkt 28-12-2013 16:15:46 Geplanter Prüfpunkt 29-12-2013 15:15:14 Geplanter Prüfpunkt 31-12-2013 12:54:39 Uniblue SpeedUpMyPC installation ==================== Hosts content: ========================== 2006-11-02 11:23 - 2006-09-18 22:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {2251D488-4EBE-413B-9170-82FD97C65510} - System32\Tasks\Plus-HD-1.2-chromeinstaller => C:\Program Files\Plus-HD-1.2\Plus-HD-1.2-chromeinstaller.exe <==== ATTENTION Task: {2A6D5DCD-BE66-4DFE-9AF7-5A51F0D196F0} - System32\Tasks\Re-markit Update => C:\Program Files\Re-markit\ReMarkit_up.exe <==== ATTENTION Task: {2E1FA6B1-DE11-4B99-A160-3406FC66C8AA} - System32\Tasks\Plus-HD-1.2-updater => C:\Program Files\Plus-HD-1.2\Plus-HD-1.2-updater.exe <==== ATTENTION Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {35655400-4B7E-41DC-B5EF-4738BC56B3F3} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-03-25] (Piriform Ltd) Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {424D1112-4183-4C48-92FF-4FF9F8DCC871} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files\Ask.com\UpdateTask.exe Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\System32\RacAgent.exe [2008-01-21] (Microsoft Corporation) Task: {45FA3731-31DD-488B-A3C5-F8A6760453DD} - System32\Tasks\temp_Plus-HD-1.2-enabler => C:\Users\gundi\AppData\Local\Temp\nsw673E.tmp\Plus-HD-1.2-enabler.exe <==== ATTENTION Task: {48EF12C9-25E7-4774-8027-846B638E7740} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3813596177-1276424280-2619024677-1000UA => C:\Users\gundi\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: {4C1C7DC7-3DDC-43FC-AB43-2256C24ADB89} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-11] (Adobe Systems Incorporated) Task: {51D3A3CA-95A5-43CF-B8DB-BC32023BD86E} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files\TuneUp Utilities 2013\OneClick.exe Task: {55E4AC30-B974-4C21-BD4F-E7A40712C31F} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3813596177-1276424280-2619024677-1000Core => C:\Users\gundi\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: {638764FF-409C-41C9-88B6-8D72E6A31983} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-05-21] (Google Inc.) Task: {63F6E6A7-4290-4845-BBBB-F0ED798FB6A2} - System32\Tasks\{20B5A60C-7771-4AB2-A801-66932EF41167} => C:\Program Files\Skype\Phone\Skype.exe [2013-06-21] (Skype Technologies S.A.) Task: {72504F05-9EE4-4D80-B59C-94694196A304} - System32\Tasks\Plus-HD-1.2-firefoxinstaller => C:\Program Files\Plus-HD-1.2\Plus-HD-1.2-firefoxinstaller.exe <==== ATTENTION Task: {762D8C1B-FCB1-42F6-BFBC-C67867CD872F} - System32\Tasks\Plus-HD-1.2-enabler => C:\Program Files\Plus-HD-1.2\Plus-HD-1.2-enabler.exe <==== ATTENTION Task: {898885D5-D91A-4A4D-9267-7E8F9C59DCA5} - System32\Tasks\Plus-HD-1.2-codedownloader => C:\Program Files\Plus-HD-1.2\Plus-HD-1.2-codedownloader.exe <==== ATTENTION Task: {983BF916-345A-4B5C-9351-64B56A82F8F4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-05-21] (Google Inc.) Task: {9A07FDFF-02BB-44BB-B547-BE47A8623094} - System32\Tasks\EPUpdater => C:\Users\gundi\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe <==== ATTENTION Task: {9DC09BC8-90F4-450E-A7E6-EC8ED992A202} - System32\Tasks\SpeedUpMyPC Startup => C:\Program Files\Uniblue\SpeedUpMyPC\speedupmypc.exe Task: {A728AE6B-5AB8-4223-AD3E-E6341441A01C} - System32\Tasks\Microsoft\Windows\PLA\System\ConvertLogEntries => Rundll32.exe %windir%\system32\pla.dll,PlaConvertLogEntries Task: {D973E425-2C1B-40C9-9B48-B9C4F41806B7} - System32\Tasks\SpeedUpMyPC Maintenance => C:\Program Files\Uniblue\SpeedUpMyPC\speedupmypc.exe Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\System32\gatherWirelessInfo.vbs [2008-01-21] () Task: {EE138026-69C2-45ED-8A8C-99F9ED448BBA} - System32\Tasks\BrowserProtect => Sc.exe start BrowserProtect <==== ATTENTION Task: {F3EDA4C2-91C9-4BB3-9314-3777B27627F8} - System32\Tasks\PC SpeedUp Service Deactivator => C:\Program Files\PC Beschleunigen\PCSUSD.exe <==== ATTENTION Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-12-04 19:23 - 2013-12-04 03:48 - 04055504 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll 2013-12-04 19:23 - 2013-12-04 03:48 - 00399312 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll 2013-12-04 19:23 - 2013-12-04 03:47 - 01619408 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\ffmpegsumo.dll 2013-12-04 19:23 - 2013-12-04 03:47 - 00702416 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\libglesv2.dll 2013-12-04 19:23 - 2013-12-04 03:47 - 00099792 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\libegl.dll 2013-12-04 19:23 - 2013-12-04 03:48 - 13586896 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\gundi\Documents\clip0001.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0002.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0003.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0004.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0005.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0006.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0007.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0008.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0009.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0010.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0014.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0015.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0018.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0019.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0020.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0021.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0022.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0023.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0024.avi:TOC.WMV ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: 802.11b/g/n USB Wireless Network Adapter Description: 802.11b/g/n USB Wireless Network Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Service: netr28u Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (12/31/2013 02:20:59 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/31/2013 02:14:55 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/31/2013 01:55:06 PM) (Source: Windows Installer 3.1) (User: ) Description: WindowsFür diesen Befehl ist nicht genügend Speicher verfügbar. Error: (12/31/2013 01:54:01 PM) (Source: VSS) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005. Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess. Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {511fbf08-20ae-46ed-8c2b-4415c0752b80} Error: (12/31/2013 11:58:55 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/31/2013 10:44:40 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2013 05:05:51 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2013 11:50:48 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2013 09:13:43 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/29/2013 11:28:43 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (12/31/2013 02:20:59 PM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/31/2013 02:14:55 PM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/31/2013 11:58:59 AM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/31/2013 10:44:40 AM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/30/2013 05:05:51 PM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/30/2013 11:50:48 AM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/30/2013 09:13:44 AM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/29/2013 11:28:44 PM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/29/2013 01:56:52 PM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/29/2013 10:18:49 AM) (Source: Service Control Manager) (User: ) Description: i8042prt Microsoft Office Sessions: ========================= Error: (12/31/2013 02:20:59 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/31/2013 02:14:55 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/31/2013 01:55:06 PM) (Source: Windows Installer 3.1)(User: ) Description: WindowsFür diesen Befehl ist nicht genügend Speicher verfügbar. Error: (12/31/2013 01:54:01 PM) (Source: VSS)(User: ) Description: 0x80070005 Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {511fbf08-20ae-46ed-8c2b-4415c0752b80} Error: (12/31/2013 11:58:55 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/31/2013 10:44:40 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2013 05:05:51 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2013 11:50:48 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2013 09:13:43 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/29/2013 11:28:43 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 ==================== Memory info =========================== Percentage of memory in use: 44% Total physical RAM: 3325.27 MB Available physical RAM: 1846.54 MB Total Pagefile: 6870.36 MB Available Pagefile: 5072.93 MB Total Virtual: 2047.88 MB Available Virtual: 1901.96 MB ==================== Drives ================================ Drive c: (BOOT) (Fixed) (Total:911.51 GB) (Free:731.74 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (RECOVER) (Fixed) (Total:19.99 GB) (Free:8.92 GB) FAT32 Drive i: () (Removable) (Total:3.69 GB) (Free:0.43 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 932 GB) (Disk ID: F98D6E74) Partition 1: (Active) - (Size=912 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=20 GB) - (Type=OF Extended) ======================================================== Disk: 4 (Size: 4 GB) (Disk ID: 00000000) Partition 1: (Not Active) - (Size=4 GB) - (Type=0B) ==================== End Of Log ============================ Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 31-12-2013 Ran by gundi (administrator) on GUNDI-PC on 31-12-2013 14:39:12 Running from C:\Users\gundi\Downloads Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE (SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe () C:\Windows\System32\PSIService.exe (Tlapia) C:\Program Files\sysTPL\sysTPLMonitor.exe (Tlapia) C:\Program Files\sysTPL\sysTPLService.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (cyberlink) C:\Program Files\Cyberlink\Shared files\brs.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe () C:\Windows\vsnpstd3.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe [178712 2007-10-08] (Intel Corporation) HKLM\...\Run: [BDRegion] - C:\Program Files\Cyberlink\Shared files\brs.exe [75048 2010-03-13] (cyberlink) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [6724128 2009-02-03] (Realtek Semiconductor) HKLM\...\Run: [Skytel] - C:\Program Files\Realtek\Audio\HDA\SkyTel.exe [1833504 2009-02-03] (Realtek Semiconductor Corp.) HKLM\...\Run: [snpstd3] - C:\Windows\vsnpstd3.exe [827392 2006-09-19] () HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup HKLM\...\Run: [NvMediaCenter] - RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [NeroFilterCheck] - C:\Windows\System32\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-12] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [mobilegeni daemon] - C:\Program Files\Mobogenie\DaemonProcess.exe HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXDFXAudioPlugin.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DSEPlugins\Direct3DVideoOutput.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DSEPlugins\Direct3DVideoOutput.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DSEPlugins\DivXPlaybackModule.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DSEPlugins\DivXPlaybackModule.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXBannerAdPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXBannerAdPlugin.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXDownloadManagerPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXDownloadManagerPlugin.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXMediaManagerPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXMediaManagerPlugin.dll",DllRegisterServer HKLM\...\Runonce: [B Register C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXPlayerPlugin.dll] - "C:\Windows\system32\rundll32.exe" "C:\Program Files\DivX\DivX Plus Player\DPXPlugins\DPXPlayerPlugin.dll",DllRegisterServer HKCU\...\Run: [EPSON SX100 Series] - C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIEDE.EXE /FU "C:\Windows\TEMP\E_S88DD.tmp" /EF "HKCU" HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\wmpnscfg.exe [202240 2008-01-21] (Microsoft Corporation) HKCU\...\Run: [NextLive] - C:\Windows\system32\rundll32.exe "C:\Users\gundi\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l HKCU\...0c966feabec1\InprocServer32: [Default-shell32] ATTENTION! ====> ZeroAccess? HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\Gast\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter AppInit_DLLs: c:\progra~1\search~1\datamngr\mgrldr.dll c:\docume~1\ settings\all users\application data\browserprotect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8} [ ] () ==================== Internet (Whitelisted) ==================== ProxyServer: http=127.0.0.1:8877;https=127.0.0.1:8877 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snap.do/?publisher=Bundlore&dpid=Bundlore&co=DE&userid=a4353f1e-ff9e-4eb2-9a56-babf7f482139&searchtype=ds&q={searchTerms}&installDate=23/05/2013 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.facebook.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.nationzoom.com/?type=hp&ts=1388494413&from=tugs&uid=HitachiXHDT721010SLA360_STF605MH2G0D8K2G0D8KX HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snap.do/?publisher=Bundlore&dpid=Bundlore&co=DE&userid=a4353f1e-ff9e-4eb2-9a56-babf7f482139&searchtype=ds&q={searchTerms}&installDate=23/05/2013 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.nationzoom.com/?type=hp&ts=1388494413&from=tugs&uid=HitachiXHDT721010SLA360_STF605MH2G0D8K2G0D8KX HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.nationzoom.com/?type=hp&ts=1388494413&from=tugs&uid=HitachiXHDT721010SLA360_STF605MH2G0D8K2G0D8KX HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1388494413&from=tugs&uid=HitachiXHDT721010SLA360_STF605MH2G0D8K2G0D8KX&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.nationzoom.com/web/?type=ds&ts=1388494413&from=tugs&uid=HitachiXHDT721010SLA360_STF605MH2G0D8K2G0D8KX&q={searchTerms} StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.nationzoom.com/?type=sc&ts=1388494413&from=tugs&uid=HitachiXHDT721010SLA360_STF605MH2G0D8K2G0D8KX SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1388494413&from=tugs&uid=HitachiXHDT721010SLA360_STF605MH2G0D8K2G0D8KX&q={searchTerms} SearchScopes: HKLM - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snap.do/?publisher=Bundlore&dpid=Bundlore&co=DE&userid=a4353f1e-ff9e-4eb2-9a56-babf7f482139&searchtype=ds&q={searchTerms}&installDate=23/05/2013 SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1388494413&from=tugs&uid=HitachiXHDT721010SLA360_STF605MH2G0D8K2G0D8KX&q={searchTerms} SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=362&systemid=406&apn_uid=2863021520344074&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms} SearchScopes: HKCU - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=362&systemid=406&apn_uid=2863021520344074&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms} SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snap.do/?publisher=Bundlore&dpid=Bundlore&co=DE&userid=a4353f1e-ff9e-4eb2-9a56-babf7f482139&searchtype=ds&q={searchTerms}&installDate=23/05/2013 SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.delta-search.com/?q={searchTerms}&affID=119781&tt=gc_&babsrc=SP_ss&mntrId=CEDA02242178B865 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1388494413&from=tugs&uid=HitachiXHDT721010SLA360_STF605MH2G0D8K2G0D8KX&q={searchTerms} SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=362&systemid=406&apn_uid=2863021520344074&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms} BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.) Toolbar: HKLM - No Name - !{EEE6C35B-6118-11DC-9C72-001320C79847} - No File Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File Toolbar: HKCU - No Name - {40C3CC16-7269-4B32-9531-17F2950FB06F} - No File DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab DPF: {CAFEEFAC-0017-0000-0045-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default FF user.js: detected! => C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\user.js FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.) FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Windows\system32\npdeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\searchplugins\askcom.xml FF SearchPlugin: C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\searchplugins\babylon.xml FF SearchPlugin: C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\searchplugins\delta.xml FF SearchPlugin: C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\searchplugins\MyStart Search.xml FF SearchPlugin: C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\searchplugins\Search_Results.xml FF SearchPlugin: C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\searchplugins\sweetim.xml FF SearchPlugin: C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\searchplugins\Web Search.xml FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml FF Extension: Conduit Engine - C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\Extensions\engine@conduit.com FF Extension: HDvid Codec - C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\Extensions\hdvc@hdvc.com FF Extension: Microsoft .NET Framework Assistant - C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} FF Extension: GoPhotoIt - C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\Extensions\gophoto@gophoto.it.xpi FF Extension: HDvid Codec - C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\Extensions\hdvc@hdvc.com.xpi FF Extension: M2k Downloader - C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\Extensions\m2k@m2kdownloader.com.xpi FF Extension: SweetPacks Toolbar for Firefox - C:\Users\gundi\AppData\Roaming\Mozilla\Firefox\Profiles\53jx5ozj.default\Extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ Chrome: ======= CHR HomePage: hxxp://www.nationzoom.com/?type=hp&ts=1388494413&from=tugs&uid=HitachiXHDT721010SLA360_STF605MH2G0D8K2G0D8KX CHR RestoreOnStartup: "https://www.facebook.com/logout.php" CHR Plugin: (Shockwave Flash) - C:\Users\gundi\AppData\Local\Google\Chrome\User Data\PepperFlash\11.7.700.202\pepflashplayer.dll No File CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin.dll No File CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin2.dll No File CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin3.dll No File CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin4.dll No File CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin5.dll No File CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin6.dll No File CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files\QuickTime\plugins\npqtplugin7.dll No File CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll No File CHR Plugin: (DivX Plus Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll No File CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll No File CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U21) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Unity Player) - C:\Users\gundi\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll No File CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\gundi\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.) CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_202.dll No File CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Extension: (Extended Protection) - C:\Users\gundi\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml\1.3_0 CHR Extension: (Lightning Newtab) - C:\Users\gundi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.1.7.9_0 CHR Extension: (Google Wallet) - C:\Users\gundi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0 CHR HKLM\...\Chrome\Extension: [ifohbjbgfchkkfhphahclmkpgejiplfo] - C:\Users\gundi\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx CHR HKLM\...\Chrome\Extension: [jpmbfleldcgkldadpdinhjjopdfpjfjp] - C:\Users\gundi\AppData\Local\Wajam\Chrome\wajam.crx CHR HKLM\...\Chrome\Extension: [kpkbnefaikfaeadgidhpoanckoiaheli] - C:\Program Files\HDvidCodec.com\HDvidCodec10.crx CHR HKLM\...\Chrome\Extension: [lbbbdmbjkgojacipgefbifkiebpcdjhn] - C:\Program Files\Movie2KDownloader.com\m2kDownloader10.crx CHR HKLM\...\Chrome\Extension: [pfmopbbadnfoelckkcmjjeaaegjpjjbk] - C:\Program Files\Gophoto.it\gophotoit14.crx CHR StartMenuInternet: Google Chrome - C:\Program Files\Google\Chrome\Application\chrome.exe hxxp://www.nationzoom.com/?type=sc&ts=1388494413&from=tugs&uid=HitachiXHDT721010SLA360_STF605MH2G0D8K2G0D8KX ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-12-12] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-19] (Avira Operations GmbH & Co. KG) R2 EPSON_EB_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE [143872 2007-12-17] (SEIKO EPSON CORPORATION) R2 EPSON_PM_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE [113664 2007-01-11] (SEIKO EPSON CORPORATION) R2 ProtexisLicensing; C:\Windows\system32\PSIService.exe [177704 2007-06-05] () R2 sysTPLMonitor.exe; C:\Program Files\sysTPL\sysTPLMonitor.exe [395888 2013-11-27] (Tlapia) R2 sysTPLService.exe; C:\Program Files\sysTPL\sysTPLService.exe [394352 2013-11-27] (Tlapia) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-12] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-12] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-10-07] (Avira Operations GmbH & Co. KG) R3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [554496 2007-09-21] (Ralink Technology Corp.) S3 PAC207; C:\Windows\System32\DRIVERS\PFC027.SYS [506112 2006-11-20] (PixArt Imaging Inc.) S3 SNPSTD3; C:\Windows\System32\DRIVERS\snpstd3.sys [10252544 2007-03-27] (Sonix Co. Ltd.) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-02-09] (Avira GmbH) R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}; C:\Program Files\CyberLink\PowerDVD10\NavFilter\000.fcl [87536 2010-03-13] (CyberLink Corp.) S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-31 14:35 - 2013-12-31 14:39 - 00025130 _____ C:\Users\gundi\Downloads\Addition.txt 2013-12-31 14:34 - 2013-12-31 14:39 - 00022680 _____ C:\Users\gundi\Downloads\FRST.txt 2013-12-31 14:33 - 2013-12-31 14:33 - 01064333 _____ (Farbar) C:\Users\gundi\Downloads\FRST.exe 2013-12-31 14:33 - 2013-12-31 14:33 - 00000000 ____D C:\FRST 2013-12-31 14:32 - 2013-12-31 14:32 - 01272360 _____ (iMesh Inc) C:\Users\gundi\Downloads\iMeshSetup-r1487-w-bc.exe 2013-12-31 14:32 - 2013-12-31 14:32 - 00000615 _____ C:\Users\Public\Desktop\iMesh-Installation fortsetzen.lnk 2013-12-31 14:32 - 2013-12-31 14:32 - 00000000 ____D C:\Program Files\iMesh Applications 2013-12-31 14:13 - 2013-12-31 14:13 - 00002420 _____ C:\Windows\PFRO.log 2013-12-31 13:55 - 2013-12-31 13:55 - 00000554 _____ C:\Windows\KB893803v2.log 2013-12-31 13:54 - 2013-12-31 14:20 - 00000000 ____D C:\Users\gundi\AppData\Roaming\newnext.me 2013-12-31 13:54 - 2013-12-31 14:03 - 00000000 ____D C:\Users\gundi\AppData\Local\Mobogenie 2013-12-31 13:54 - 2013-12-31 14:00 - 00000000 ____D C:\Program Files\MyPC Backup 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 ____D C:\Users\gundi\Documents\Mobogenie 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 ____D C:\Users\gundi\AppData\Local\genienext 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 ____D C:\Users\gundi\AppData\Local\cache 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 ____D C:\Users\gundi\.android 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 _____ C:\Users\gundi\daemonprocess.txt 2013-12-31 13:53 - 2013-12-31 14:01 - 00000000 ____D C:\Users\gundi\AppData\Local\Lollipop 2013-12-31 13:53 - 2013-12-31 13:53 - 00000000 ____D C:\ProgramData\WPM 2013-12-31 13:48 - 2013-12-31 13:48 - 00479792 _____ C:\Users\gundi\Downloads\Player Setup (1).exe 2013-12-31 13:47 - 2013-12-31 13:47 - 00479792 _____ C:\Users\gundi\Downloads\Player Setup.exe 2013-12-27 14:34 - 2013-12-27 14:38 - 186446085 _____ C:\Users\gundi\Desktop\2127343972001_2854723499001_EV108893-KleineHaendeGrossePfoten-source-ST.mp4 2013-12-27 14:16 - 2013-12-27 14:28 - 901182774 _____ C:\Users\gundi\Desktop\2127343972001_2854993219001_EV114583-SophieUndShiba-source-ST.mp4 2013-12-15 17:30 - 2013-12-15 17:30 - 00000000 ____D C:\Users\gundi\AppData\Local\{DE5AA92A-FFD5-4755-AB87-389C7C1A6D06} 2013-12-11 12:37 - 2013-11-15 00:13 - 12344320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-11 12:37 - 2013-11-14 23:50 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-11 12:37 - 2013-11-14 23:50 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-11 12:37 - 2013-11-14 23:43 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-11 12:37 - 2013-11-14 23:42 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-11 12:37 - 2013-11-14 23:42 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-11 12:37 - 2013-11-14 23:41 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-11 12:37 - 2013-11-14 23:40 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-11 12:37 - 2013-11-14 23:38 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-11 12:37 - 2013-11-14 23:38 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-11 12:37 - 2013-11-14 23:38 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-11 12:37 - 2013-11-14 23:37 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-11 12:37 - 2013-11-14 23:36 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-11 12:37 - 2013-11-14 23:36 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-11 12:37 - 2013-11-14 23:35 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-11 12:37 - 2013-11-14 23:32 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-11 10:48 - 2013-10-30 03:12 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\SysFxUI.dll 2013-12-11 10:48 - 2013-10-30 02:43 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-12-11 10:48 - 2013-10-30 01:43 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-12-11 10:48 - 2013-10-30 01:35 - 02050560 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-12-11 10:48 - 2013-10-22 08:19 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-11 10:48 - 2013-10-11 03:08 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-11 10:48 - 2013-10-11 03:08 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-11 10:48 - 2013-10-11 03:08 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wshcon.dll 2013-12-11 10:48 - 2013-10-11 01:35 - 00155648 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-11 10:48 - 2013-10-11 01:35 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-12-01 16:00 - 2013-12-01 16:00 - 01050264 _____ (Unity Technologies ApS) C:\Users\gundi\Downloads\UnityWebPlayer (2).exe 2013-12-01 15:59 - 2013-12-01 15:59 - 01050264 _____ (Unity Technologies ApS) C:\Users\gundi\Downloads\UnityWebPlayer (1).exe ==================== One Month Modified Files and Folders ======= 2013-12-31 14:39 - 2013-12-31 14:35 - 00025130 _____ C:\Users\gundi\Downloads\Addition.txt 2013-12-31 14:39 - 2013-12-31 14:34 - 00022680 _____ C:\Users\gundi\Downloads\FRST.txt 2013-12-31 14:33 - 2013-12-31 14:33 - 01064333 _____ (Farbar) C:\Users\gundi\Downloads\FRST.exe 2013-12-31 14:33 - 2013-12-31 14:33 - 00000000 ____D C:\FRST 2013-12-31 14:32 - 2013-12-31 14:32 - 01272360 _____ (iMesh Inc) C:\Users\gundi\Downloads\iMeshSetup-r1487-w-bc.exe 2013-12-31 14:32 - 2013-12-31 14:32 - 00000615 _____ C:\Users\Public\Desktop\iMesh-Installation fortsetzen.lnk 2013-12-31 14:32 - 2013-12-31 14:32 - 00000000 ____D C:\Program Files\iMesh Applications 2013-12-31 14:27 - 2010-05-21 14:53 - 00001096 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-12-31 14:24 - 2011-10-13 13:50 - 01216690 _____ C:\Windows\WindowsUpdate.log 2013-12-31 14:20 - 2013-12-31 13:54 - 00000000 ____D C:\Users\gundi\AppData\Roaming\newnext.me 2013-12-31 14:19 - 2010-05-21 14:53 - 00001092 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-12-31 14:19 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-12-31 14:19 - 2006-11-02 13:47 - 00003744 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-12-31 14:19 - 2006-11-02 13:47 - 00003744 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-12-31 14:18 - 2006-11-02 14:01 - 00032530 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-12-31 14:13 - 2013-12-31 14:13 - 00002420 _____ C:\Windows\PFRO.log 2013-12-31 14:03 - 2013-12-31 13:54 - 00000000 ____D C:\Users\gundi\AppData\Local\Mobogenie 2013-12-31 14:01 - 2013-12-31 13:53 - 00000000 ____D C:\Users\gundi\AppData\Local\Lollipop 2013-12-31 14:00 - 2013-12-31 13:54 - 00000000 ____D C:\Program Files\MyPC Backup 2013-12-31 13:57 - 2006-11-02 11:33 - 01539286 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-31 13:55 - 2013-12-31 13:55 - 00000554 _____ C:\Windows\KB893803v2.log 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 ____D C:\Users\gundi\Documents\Mobogenie 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 ____D C:\Users\gundi\AppData\Local\genienext 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 ____D C:\Users\gundi\AppData\Local\cache 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 ____D C:\Users\gundi\.android 2013-12-31 13:54 - 2013-12-31 13:54 - 00000000 _____ C:\Users\gundi\daemonprocess.txt 2013-12-31 13:54 - 2009-06-06 12:46 - 00000000 ____D C:\Users\gundi 2013-12-31 13:53 - 2013-12-31 13:53 - 00000000 ____D C:\ProgramData\WPM 2013-12-31 13:53 - 2013-06-28 13:42 - 00001171 _____ C:\Users\gundi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-12-31 13:53 - 2012-10-03 13:05 - 00002193 _____ C:\Users\gundi\Desktop\Google Chrome.lnk 2013-12-31 13:48 - 2013-12-31 13:48 - 00479792 _____ C:\Users\gundi\Downloads\Player Setup (1).exe 2013-12-31 13:47 - 2013-12-31 13:47 - 00479792 _____ C:\Users\gundi\Downloads\Player Setup.exe 2013-12-31 13:41 - 2012-06-25 11:43 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-12-29 13:09 - 2010-10-20 20:12 - 00000000 ____D C:\Windows\Minidump 2013-12-27 14:38 - 2013-12-27 14:34 - 186446085 _____ C:\Users\gundi\Desktop\2127343972001_2854723499001_EV108893-KleineHaendeGrossePfoten-source-ST.mp4 2013-12-27 14:28 - 2013-12-27 14:16 - 901182774 _____ C:\Users\gundi\Desktop\2127343972001_2854993219001_EV114583-SophieUndShiba-source-ST.mp4 2013-12-21 15:10 - 2009-06-08 14:06 - 00007408 _____ C:\Users\gundi\AppData\Roaming\wklnhst.dat 2013-12-15 17:30 - 2013-12-15 17:30 - 00000000 ____D C:\Users\gundi\AppData\Local\{DE5AA92A-FFD5-4755-AB87-389C7C1A6D06} 2013-12-12 13:12 - 2013-02-09 23:04 - 00135648 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2013-12-12 13:12 - 2013-02-09 23:04 - 00090400 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2013-12-11 19:41 - 2012-06-25 11:43 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-12-11 19:41 - 2011-08-12 21:56 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-12-11 15:43 - 2006-11-02 13:47 - 00398720 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-11 15:40 - 2009-04-02 14:28 - 00000000 ____D C:\Windows\system32\RTCOM 2013-12-11 12:40 - 2013-08-14 10:55 - 00000000 ____D C:\Windows\system32\MRT 2013-12-11 12:38 - 2006-11-02 11:24 - 88123800 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2013-12-01 16:00 - 2013-12-01 16:00 - 01050264 _____ (Unity Technologies ApS) C:\Users\gundi\Downloads\UnityWebPlayer (2).exe 2013-12-01 15:59 - 2013-12-01 15:59 - 01050264 _____ (Unity Technologies ApS) C:\Users\gundi\Downloads\UnityWebPlayer (1).exe Some content of TEMP: ==================== C:\Users\gundi\AppData\Local\Temp\avgnt.exe C:\Users\gundi\AppData\Local\Temp\BackupSetup.exe C:\Users\gundi\AppData\Local\Temp\kwfoalaflmgnptk.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-31 14:25 ==================== End Of Log ============================ Additional scan result of Farbar Recovery Scan Tool (x86) Version: 31-12-2013 Ran by gundi at 2013-12-31 14:39:40 Running from C:\Users\gundi\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== ABBYY FineReader 6.0 Sprint (Version: 6.00.1395.4512 - ABBYY Software House) Adobe Flash Player 11 ActiveX (Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Reader X (10.1.8) - Deutsch (Version: 10.1.8 - Adobe Systems Incorporated) Adobe Shockwave Player 12.0 (Version: 12.0.2.122 - Adobe Systems, Inc.) Apple Application Support (Version: 2.1.5 - Apple Inc.) Apple Software Update (Version: 2.1.3.127 - Apple Inc.) Ashampoo Burning Studio 6 FREE (Version: 6.7.6 - ashampoo GmbH & Co. KG) Avira Free Antivirus (Version: 14.0.2.286 - Avira) CCleaner (Version: 4.00 - Piriform) Compatibility Pack für 2007 Office System (Version: 12.0.6612.1000 - Microsoft Corporation) CorelDRAW Essential Edition 3 (Version: - Corel Corporation) CorelDRAW Essential Edition 3 (Version: 3.0 - Corel Corporation) CyberLink PowerDVD 10 (Version: 10.0.1516 - CyberLink Corp.) D3DX10 (Version: 15.4.2368.0902 - Microsoft) DE (Version: 3.0 - Corel Corporation) Druckerdeinstallation für EPSON SX100 Series (Version: - SEIKO EPSON Corporation) Epson Easy Photo Print 2 (Version: 2.0.0.0 - SEIKO EPSON CORPORATION) EPSON Scan (Version: - ) Google Chrome (Version: 31.0.1650.63 - Google Inc.) Google Update Helper (Version: 1.3.22.3 - Google Inc.) HyperCam 2 (Version: - ) ImagXpress (Version: 7.0.74.0 - Nero AG) Intel(R) Matrix Storage Manager (Version: - ) Java 7 Update 45 (Version: 7.0.450 - Oracle) Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Junk Mail filter update (Version: 15.4.3502.0922 - Microsoft Corporation) LightScribe System Software (Version: 1.18.8.1 - LightScribe) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office PowerPoint Viewer 2007 (German) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Primary Interoperability Assemblies 2005 (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [DEU] (Version: 3.1.0000 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Works (Version: 9.7.0621 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (Version: 3.0.5305.0 - Microsoft Corp.) MSVCRT (Version: 15.4.2862.0708 - Microsoft) MSXML 4.0 SP2 (KB936181) (Version: 4.20.9848.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB941833) (Version: 4.20.9849.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0 - Microsoft Corporation) Nero (Version: 5.5.9.8 - ahead software gmbh) Nero Suite (Version: - ) neroxml (Version: 1.0.0 - Nero AG) NVIDIA Drivers (Version: 1.3 - NVIDIA Corporation) NVIDIA PhysX (Version: 9.09.0203 - NVIDIA Corporation) Octoshape add-in for Adobe Flash Player (Version: - ) OpenOffice.org 3.3 (Version: 3.3.9567 - OpenOffice.org) PC Camer@ (Version: 1.0.4.3 - Ihr Firmenname) PCSpeedUp (Version: - www.pcspeedup.com) PokerStars (Version: - PokerStars) QuickEngine (Version: 1.0.1 - Tlapia) Realtek High Definition Audio Driver (Version: 6.0.1.5783 - Realtek Semiconductor Corp.) Segoe UI (Version: 15.4.2271.0615 - Microsoft Corp) Skype™ 6.6 (Version: 6.6.106 - Skype Technologies S.A.) Spelling Dictionaries Support For Adobe Reader 9 (Version: 9.0.0 - Adobe Systems Incorporated) swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) System Requirements Lab (Version: - ) sysTPL (Version: 1.0.0 - Tlapia) Ulead Photo Express 3.0 SE (Version: - ) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (Version: 3 - Microsoft Corporation) Update Manager (Version: 4.60 - Corel Corporation) VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0 - DivX, Inc) Windows Live Communications Platform (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Essentials (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Essentials (Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live Fotogalerie (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Windows Live Installer (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Mail (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Messenger (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Movie Maker (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Photo Common (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Photo Gallery (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live PIMT Platform (Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live SOXE (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live SOXE Definitions (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live UX Platform (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live UX Platform Language Pack (Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live Writer (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Live Writer Resources (Version: 15.4.3502.0922 - Microsoft Corporation) Windows Media Player Firefox Plugin (Version: 1.0.0.8 - Microsoft Corp) WinRAR (Version: - ) ==================== Restore Points ========================= 25-10-2013 16:25:47 Geplanter Prüfpunkt 26-10-2013 13:59:43 Geplanter Prüfpunkt 28-10-2013 14:18:05 Geplanter Prüfpunkt 30-10-2013 10:57:26 Geplanter Prüfpunkt 31-10-2013 10:41:42 Geplanter Prüfpunkt 01-11-2013 12:53:50 Geplanter Prüfpunkt 02-11-2013 15:01:41 Geplanter Prüfpunkt 03-11-2013 11:23:31 Geplanter Prüfpunkt 05-11-2013 17:10:04 Geplanter Prüfpunkt 08-11-2013 20:29:18 Geplanter Prüfpunkt 10-11-2013 15:28:45 Geplanter Prüfpunkt 11-11-2013 15:38:42 Removed Google Earth. 11-11-2013 16:43:04 Removed Google Earth. 11-11-2013 17:20:49 Installed QuickEngine 11-11-2013 17:45:49 Removed Java(TM) 6 Update 22 11-11-2013 17:47:07 Removed Java(TM) 6 Update 37 11-11-2013 17:50:45 Removed Facebook Video Calling 1.2.0.287 11-11-2013 18:02:08 Removed QuickTime 12-11-2013 16:13:53 Konfiguriert PowerDVD 13-11-2013 14:10:30 Geplanter Prüfpunkt 13-11-2013 15:14:22 Windows Update 17-11-2013 10:15:45 Geplanter Prüfpunkt 18-11-2013 19:40:58 Geplanter Prüfpunkt 19-11-2013 10:24:53 Geplanter Prüfpunkt 21-11-2013 17:36:55 Geplanter Prüfpunkt 22-11-2013 12:19:14 Geplanter Prüfpunkt 24-11-2013 19:00:12 Geplanter Prüfpunkt 25-11-2013 14:16:43 Geplanter Prüfpunkt 26-11-2013 09:36:32 Geplanter Prüfpunkt 27-11-2013 18:26:51 Geplanter Prüfpunkt 28-11-2013 09:59:25 Geplanter Prüfpunkt 29-11-2013 14:57:55 Geplanter Prüfpunkt 01-12-2013 14:47:38 Geplanter Prüfpunkt 02-12-2013 09:51:43 Geplanter Prüfpunkt 09-12-2013 16:37:10 Geplanter Prüfpunkt 11-12-2013 11:37:10 Windows Update 14-12-2013 12:45:26 Geplanter Prüfpunkt 16-12-2013 13:24:12 Geplanter Prüfpunkt 18-12-2013 12:16:20 Geplanter Prüfpunkt 22-12-2013 12:47:10 Geplanter Prüfpunkt 23-12-2013 13:22:41 Geplanter Prüfpunkt 28-12-2013 16:15:46 Geplanter Prüfpunkt 29-12-2013 15:15:14 Geplanter Prüfpunkt 31-12-2013 12:54:39 Uniblue SpeedUpMyPC installation ==================== Hosts content: ========================== 2006-11-02 11:23 - 2006-09-18 22:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {2251D488-4EBE-413B-9170-82FD97C65510} - System32\Tasks\Plus-HD-1.2-chromeinstaller => C:\Program Files\Plus-HD-1.2\Plus-HD-1.2-chromeinstaller.exe <==== ATTENTION Task: {2A6D5DCD-BE66-4DFE-9AF7-5A51F0D196F0} - System32\Tasks\Re-markit Update => C:\Program Files\Re-markit\ReMarkit_up.exe <==== ATTENTION Task: {2E1FA6B1-DE11-4B99-A160-3406FC66C8AA} - System32\Tasks\Plus-HD-1.2-updater => C:\Program Files\Plus-HD-1.2\Plus-HD-1.2-updater.exe <==== ATTENTION Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {35655400-4B7E-41DC-B5EF-4738BC56B3F3} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-03-25] (Piriform Ltd) Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {424D1112-4183-4C48-92FF-4FF9F8DCC871} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files\Ask.com\UpdateTask.exe Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\System32\RacAgent.exe [2008-01-21] (Microsoft Corporation) Task: {45FA3731-31DD-488B-A3C5-F8A6760453DD} - System32\Tasks\temp_Plus-HD-1.2-enabler => C:\Users\gundi\AppData\Local\Temp\nsw673E.tmp\Plus-HD-1.2-enabler.exe <==== ATTENTION Task: {48EF12C9-25E7-4774-8027-846B638E7740} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3813596177-1276424280-2619024677-1000UA => C:\Users\gundi\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: {4C1C7DC7-3DDC-43FC-AB43-2256C24ADB89} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-11] (Adobe Systems Incorporated) Task: {51D3A3CA-95A5-43CF-B8DB-BC32023BD86E} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files\TuneUp Utilities 2013\OneClick.exe Task: {55E4AC30-B974-4C21-BD4F-E7A40712C31F} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3813596177-1276424280-2619024677-1000Core => C:\Users\gundi\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: {638764FF-409C-41C9-88B6-8D72E6A31983} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-05-21] (Google Inc.) Task: {63F6E6A7-4290-4845-BBBB-F0ED798FB6A2} - System32\Tasks\{20B5A60C-7771-4AB2-A801-66932EF41167} => C:\Program Files\Skype\Phone\Skype.exe [2013-06-21] (Skype Technologies S.A.) Task: {72504F05-9EE4-4D80-B59C-94694196A304} - System32\Tasks\Plus-HD-1.2-firefoxinstaller => C:\Program Files\Plus-HD-1.2\Plus-HD-1.2-firefoxinstaller.exe <==== ATTENTION Task: {762D8C1B-FCB1-42F6-BFBC-C67867CD872F} - System32\Tasks\Plus-HD-1.2-enabler => C:\Program Files\Plus-HD-1.2\Plus-HD-1.2-enabler.exe <==== ATTENTION Task: {898885D5-D91A-4A4D-9267-7E8F9C59DCA5} - System32\Tasks\Plus-HD-1.2-codedownloader => C:\Program Files\Plus-HD-1.2\Plus-HD-1.2-codedownloader.exe <==== ATTENTION Task: {983BF916-345A-4B5C-9351-64B56A82F8F4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-05-21] (Google Inc.) Task: {9A07FDFF-02BB-44BB-B547-BE47A8623094} - System32\Tasks\EPUpdater => C:\Users\gundi\AppData\Roaming\BABSOL~1\Shared\BabMaint.exe <==== ATTENTION Task: {9DC09BC8-90F4-450E-A7E6-EC8ED992A202} - System32\Tasks\SpeedUpMyPC Startup => C:\Program Files\Uniblue\SpeedUpMyPC\speedupmypc.exe Task: {A728AE6B-5AB8-4223-AD3E-E6341441A01C} - System32\Tasks\Microsoft\Windows\PLA\System\ConvertLogEntries => Rundll32.exe %windir%\system32\pla.dll,PlaConvertLogEntries Task: {D973E425-2C1B-40C9-9B48-B9C4F41806B7} - System32\Tasks\SpeedUpMyPC Maintenance => C:\Program Files\Uniblue\SpeedUpMyPC\speedupmypc.exe Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\System32\gatherWirelessInfo.vbs [2008-01-21] () Task: {EE138026-69C2-45ED-8A8C-99F9ED448BBA} - System32\Tasks\BrowserProtect => Sc.exe start BrowserProtect <==== ATTENTION Task: {F3EDA4C2-91C9-4BB3-9314-3777B27627F8} - System32\Tasks\PC SpeedUp Service Deactivator => C:\Program Files\PC Beschleunigen\PCSUSD.exe <==== ATTENTION Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-02-09 23:04 - 2013-03-09 17:56 - 00397704 _____ () C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll 2013-12-04 19:23 - 2013-12-04 03:48 - 04055504 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll 2013-12-04 19:23 - 2013-12-04 03:48 - 00399312 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll 2013-12-04 19:23 - 2013-12-04 03:47 - 01619408 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\ffmpegsumo.dll 2013-12-04 19:23 - 2013-12-04 03:47 - 00702416 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\libglesv2.dll 2013-12-04 19:23 - 2013-12-04 03:47 - 00099792 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\libegl.dll 2009-07-27 13:17 - 2008-09-16 19:18 - 00132608 _____ () C:\Program Files\WinRAR\rarext.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\gundi\Documents\clip0001.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0002.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0003.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0004.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0005.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0006.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0007.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0008.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0009.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0010.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0014.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0015.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0018.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0019.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0020.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0021.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0022.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0023.avi:TOC.WMV AlternateDataStreams: C:\Users\gundi\Documents\clip0024.avi:TOC.WMV ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: 802.11b/g/n USB Wireless Network Adapter Description: 802.11b/g/n USB Wireless Network Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Service: netr28u Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (12/31/2013 02:20:59 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/31/2013 02:14:55 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/31/2013 01:55:06 PM) (Source: Windows Installer 3.1) (User: ) Description: WindowsFür diesen Befehl ist nicht genügend Speicher verfügbar. Error: (12/31/2013 01:54:01 PM) (Source: VSS) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005. Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess. Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {511fbf08-20ae-46ed-8c2b-4415c0752b80} Error: (12/31/2013 11:58:55 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/31/2013 10:44:40 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2013 05:05:51 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2013 11:50:48 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2013 09:13:43 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/29/2013 11:28:43 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (12/31/2013 02:20:59 PM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/31/2013 02:14:55 PM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/31/2013 11:58:59 AM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/31/2013 10:44:40 AM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/30/2013 05:05:51 PM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/30/2013 11:50:48 AM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/30/2013 09:13:44 AM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/29/2013 11:28:44 PM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/29/2013 01:56:52 PM) (Source: Service Control Manager) (User: ) Description: i8042prt Error: (12/29/2013 10:18:49 AM) (Source: Service Control Manager) (User: ) Description: i8042prt Microsoft Office Sessions: ========================= Error: (12/31/2013 02:20:59 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/31/2013 02:14:55 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/31/2013 01:55:06 PM) (Source: Windows Installer 3.1)(User: ) Description: WindowsFür diesen Befehl ist nicht genügend Speicher verfügbar. Error: (12/31/2013 01:54:01 PM) (Source: VSS)(User: ) Description: 0x80070005 Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {511fbf08-20ae-46ed-8c2b-4415c0752b80} Error: (12/31/2013 11:58:55 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/31/2013 10:44:40 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2013 05:05:51 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2013 11:50:48 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2013 09:13:43 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/29/2013 11:28:43 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 ==================== Memory info =========================== Percentage of memory in use: 46% Total physical RAM: 3325.27 MB Available physical RAM: 1771.3 MB Total Pagefile: 6870.36 MB Available Pagefile: 4922.81 MB Total Virtual: 2047.88 MB Available Virtual: 1897.96 MB ==================== Drives ================================ Drive c: (BOOT) (Fixed) (Total:911.51 GB) (Free:731.74 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (RECOVER) (Fixed) (Total:19.99 GB) (Free:8.92 GB) FAT32 Drive i: () (Removable) (Total:3.69 GB) (Free:0.43 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 932 GB) (Disk ID: F98D6E74) Partition 1: (Active) - (Size=912 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=20 GB) - (Type=OF Extended) ======================================================== Disk: 4 (Size: 4 GB) (Disk ID: 00000000) Partition 1: (Not Active) - (Size=4 GB) - (Type=0B) ==================== End Of Log ============================ uch hoffe sie können was damit anfangen und mir helfen............. ![]() |