|
Plagegeister aller Art und deren Bekämpfung: ich werde die Startseite awesomehp nicht los, was kann ich noch tun?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
09.04.2014, 23:15 | #16 | ||
Ruhe in Frieden † 2019 | ich werde die Startseite awesomehp nicht los, was kann ich noch tun? Hallo Christine, Zitat:
Zitat:
Ich schreib dir das grad nochmal auf Schritt 1 Downloade dir bitte Shortcut Cleaner (by Grinler) auf deinen Desktop.
Den nächsten Schritt brauchst du nur machen, wenn nach Schritt 1 die Startseite immer noch so ist optionaler Schritt 2
Schritt 3 Falls du FRST noch auf dem Rechner hast, bei Addition den Haken reinsetzen und dann einfach auf Scan drücken, ansonsten neu laden Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
|
12.04.2014, 15:39 | #17 |
| ich werde die Startseite awesomehp nicht los, was kann ich noch tun?Code:
ATTFilter Shortcut Cleaner 1.3.3 by Lawrence Abrams (Grinler) hxxp://www.bleepingcomputer.com/ Copyright 2008-2014 BleepingComputer.com More Information about Shortcut Cleaner can be found at this link: hxxp://www.bleepingcomputer.com/download/shortcut-cleaner/ Windows Version: Windows 8.1 Program started at: 04/12/2014 04:21:16 PM. Scanning for registry hijacks: * No issues found in the Registry. Searching for Hijacked Shortcuts: Searching C:\Users\Christine\AppData\Roaming\Microsoft\Windows\Start Menu\ * Shortcut Cleaned: C:\Users\Christine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk => C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.awesomehp.com/?type=sc&ts=1391958121&from=tugs&uid=ST1000DM003-1CH162_Z1D6TAT8XXXXZ1D6TAT8 Searching C:\ProgramData\Microsoft\Windows\Start Menu\ * Shortcut Cleaned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MEDIONhome.lnk => C:\Program Files (x86)\Internet Explorer\iexplore.exe hxxp://www.awesomehp.com/?type=sc&ts=1391958121&from=tugs&uid=ST1000DM003-1CH162_Z1D6TAT8XXXXZ1D6TAT8 * Shortcut Cleaned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk => C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://www.awesomehp.com/?type=sc&ts=1391958121&from=tugs&uid=ST1000DM003-1CH162_Z1D6TAT8XXXXZ1D6TAT8 * Shortcut Cleaned: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Welcome.lnk => C:\Program Files (x86)\Internet Explorer\iexplore.exe hxxp://www.awesomehp.com/?type=sc&ts=1391958121&from=tugs&uid=ST1000DM003-1CH162_Z1D6TAT8XXXXZ1D6TAT8 Searching C:\Users\Christine\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\ * Shortcut Cleaned: C:\Users\Christine\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.awesomehp.com/?type=sc&ts=1391958121&from=tugs&uid=ST1000DM003-1CH162_Z1D6TAT8XXXXZ1D6TAT8 * Shortcut Cleaned: C:\Users\Christine\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk => C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.awesomehp.com/?type=sc&ts=1391958121&from=tugs&uid=ST1000DM003-1CH162_Z1D6TAT8XXXXZ1D6TAT8 Searching C:\Users\Public\Desktop\ * Shortcut Cleaned: C:\Users\Public\Desktop\Mozilla Firefox.lnk => C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://www.awesomehp.com/?type=sc&ts=1391958121&from=tugs&uid=ST1000DM003-1CH162_Z1D6TAT8XXXXZ1D6TAT8 Searching C:\Users\Christine\Desktop 7 bad shortcuts found. Program finished at: 04/12/2014 04:21:18 PM Execution time: 0 hours(s), 0 minute(s), and 1 seconds(s) FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014 (ATTENTION: ====> FRST version is 30 days old and could be outdated) Ran by Christine (administrator) on SNOWDONIA on 12-04-2014 16:34:46 Running from C:\Users\Christine\Desktop Windows 8.1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe () C:\Program Files\CyberLink\Shared files\RichVideo64.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe (Microsoft Corporation) C:\Windows\system32\dashost.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20461_x64__8wekyb3d8bbwe\LiveComm.exe (Microsoft Corporation) C:\Windows\System32\skydrive.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\system32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6600\Bin\HPNetworkCommunicatorCom.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6600\Bin\HPNetworkCommunicator.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [IAStorIcon] - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation) HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13647576 2013-08-27] (Realtek Semiconductor) HKLM-x32\...\Run: [CLMLServer_For_P2G8] - C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [110144 2013-03-05] (CyberLink) HKLM-x32\...\Run: [CLVirtualDrive] - C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [492248 2012-12-26] (CyberLink Corp.) HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [95192 2013-03-11] (CyberLink Corp.) HKLM-x32\...\Run: [AVG_UI] - C:\Program Files (x86)\AVG\AVG2014\avgui.exe [4971024 2014-03-19] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard) HKLM-x32\...\Run: [] - [X] Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer: [ConfirmFileDelete] 1 HKU\S-1-5-21-1264655104-1241458557-895395880-1001\...\Run: [AVG-Secure-Search-Update_1213b] - C:\Users\Christine\AppData\Roaming\AVG 1213b Campaign\AVG-Secure-Search-Update-1213b.exe /PROMPT /mid=1f08500ba37747d2a1cd51564423c578-9f30602e2779c12f56d98f271d662434c69bb14d /CMPID=1213b HKU\S-1-5-21-1264655104-1241458557-895395880-1001\...\Run: [HP Officejet 6600 (NET)] - C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.) HKU\S-1-5-21-1264655104-1241458557-895395880-1001\...\MountPoints2: {defa6949-6e29-11e3-8279-d43d7eb0282d} - "I:\pushinst.exe" Startup: C:\Users\Christine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Officejet 6600 (Netzwerk).lnk ShortcutTarget: Tintenwarnungen überwachen - HP Officejet 6600 (Netzwerk).lnk -> C:\Program Files\HP\HP Officejet 6600\Bin\HPStatusBL.dll (Hewlett-Packard Co.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.mysearchdial.com/?f=1&a=dsites05_14_15_ff&cd=2XzuyEtN2Y1L1Qzu0DyEtA0DyB0E0BtDtBzztB0DtByC0DyCtN0D0Tzu0SzztAtDtN1L2XzutBtFtCzytFyDtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StAyDyC0FyCyCzz0FtGyDzytCyDtG0EtCtCtCtGyCzyyD0AtGtD0F0C0B0Azz0AyDzzyCtAyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBzzzz0DtCyCtB0BtGyD0FtBzztG0D0D0AtDtGyBzytA0EtGyEtAzytC0FyC0FtC0CtCzzyE2Q&cr=611196884&ir= HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.mysearchdial.com/?f=1&a=dsites05_14_15_ff&cd=2XzuyEtN2Y1L1Qzu0DyEtA0DyB0E0BtDtBzztB0DtByC0DyCtN0D0Tzu0SzztAtDtN1L2XzutBtFtCzytFyDtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StAyDyC0FyCyCzz0FtGyDzytCyDtG0EtCtCtCtGyCzyyD0AtGtD0F0C0B0Azz0AyDzzyCtAyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBzzzz0DtCyCtB0BtGyD0FtBzztG0D0D0AtDtGyBzytA0EtGyEtAzytC0FyC0FtC0CtCzzyE2Q&cr=611196884&ir= HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.mysearchdial.com/?f=1&a=dsites05_14_15_ff&cd=2XzuyEtN2Y1L1Qzu0DyEtA0DyB0E0BtDtBzztB0DtByC0DyCtN0D0Tzu0SzztAtDtN1L2XzutBtFtCzytFyDtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StAyDyC0FyCyCzz0FtGyDzytCyDtG0EtCtCtCtGyCzyyD0AtGtD0F0C0B0Azz0AyDzzyCtAyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBzzzz0DtCyCtB0BtGyD0FtBzztG0D0D0AtDtGyBzytA0EtGyEtAzytC0FyC0FtC0CtCzzyE2Q&cr=611196884&ir= SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM - {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=dsites05_14_15_ff&cd=2XzuyEtN2Y1L1Qzu0DyEtA0DyB0E0BtDtBzztB0DtByC0DyCtN0D0Tzu0SzztAtDtN1L2XzutBtFtCzytFyDtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StAyDyC0FyCyCzz0FtGyDzytCyDtG0EtCtCtCtGyCzyyD0AtGtD0F0C0B0Azz0AyDzzyCtAyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBzzzz0DtCyCtB0BtGyD0FtBzztG0D0D0AtDtGyBzytA0EtGyEtAzytC0FyC0FtC0CtCzzyE2Q&cr=611196884&ir= SearchScopes: HKCU - DefaultScope {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=dsites05_14_15_ff&cd=2XzuyEtN2Y1L1Qzu0DyEtA0DyB0E0BtDtBzztB0DtByC0DyCtN0D0Tzu0SzztAtDtN1L2XzutBtFtCzytFyDtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StAyDyC0FyCyCzz0FtGyDzytCyDtG0EtCtCtCtGyCzyyD0AtGtD0F0C0B0Azz0AyDzzyCtAyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBzzzz0DtCyCtB0BtGyD0FtBzztG0D0D0AtDtGyBzytA0EtGyEtAzytC0FyC0FtC0CtCzzyE2Q&cr=611196884&ir= SearchScopes: HKCU - {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=dsites05_14_15_ff&cd=2XzuyEtN2Y1L1Qzu0DyEtA0DyB0E0BtDtBzztB0DtByC0DyCtN0D0Tzu0SzztAtDtN1L2XzutBtFtCzytFyDtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StAyDyC0FyCyCzz0FtGyDzytCyDtG0EtCtCtCtGyCzyyD0AtGtD0F0C0B0Azz0AyDzzyCtAyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBzzzz0DtCyCtB0BtGyD0FtBzztG0D0D0AtDtGyBzytA0EtGyEtAzytC0FyC0FtC0CtCzzyE2Q&cr=611196884&ir= SearchScopes: HKCU - {AC7CEB9D-BCAF-4023-900F-CABEC8534B83} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=LCJB BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: mysearchdial Helper Object - {EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD} - C:\Program Files (x86)\Mysearchdial\1.8.29.0\bh\mysearchdial.dll (MySearchDial) Toolbar: HKLM-x32 - mysearchdial Toolbar - {3004627E-F8E9-4E8B-909D-316753CBA923} - C:\Program Files (x86)\Mysearchdial\1.8.29.0\mysearchdialTlbr.dll (MySearchDial) Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\k726cbo5.default-1391963932618 FF user.js: detected! => C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\k726cbo5.default-1391963932618\user.js FF DefaultSearchEngine: Mysearchdial FF SearchEngineOrder.1: Mysearchdial FF SelectedSearchEngine: Mysearchdial FF Homepage: hxxp://start.mysearchdial.com/?f=1&a=dsites05_14_15_ff&cd=2XzuyEtN2Y1L1Qzu0DyEtA0DyB0E0BtDtBzztB0DtByC0DyCtN0D0Tzu0SzztAtDtN1L2XzutBtFtCzytFyDtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StAyDyC0FyCyCzz0FtGyDzytCyDtG0EtCtCtCtGyCzyyD0AtGtD0F0C0B0Azz0AyDzzyCtAyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBzzzz0DtCyCtB0BtGyD0FtBzztG0D0D0AtDtGyBzytA0EtGyEtAzytC0FyC0FtC0CtCzzyE2Q&cr=611196884&ir= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @videolan.org/vlc,version=2.1.1 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\k726cbo5.default-1391963932618\searchplugins\Mysearchdial.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: mysearchdial.com - C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\k726cbo5.default-1391963932618\Extensions\ffxtlbr@mysearchdial.com [2014-04-09] FF Extension: MySearchDial - C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\k726cbo5.default-1391963932618\Extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}.xpi [2014-04-09] FF HKLM-x32\...\Firefox\Extensions: [{20d1f7b3-7721-4da0-b6f3-78bb4d7248f4}] - C:\Program Files (x86)\Browser Guard\browserguard.xpi FF Extension: Browser Guard - C:\Program Files (x86)\Browser Guard\browserguard.xpi [2014-02-24] ==================== Services (Whitelisted) ================= R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3782672 2014-02-23] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [348008 2013-09-24] (AVG Technologies CZ, s.r.o.) R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2211000 2014-03-30] (Microsoft Corporation) R2 CyberLink PowerDVD 10 MS Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe [74712 2013-03-11] (CyberLink) R2 CyberLink PowerDVD 10 MS Service; C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe [316376 2013-03-11] (CyberLink) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [386344 2010-08-19] () S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [348392 2013-10-31] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2013-10-31] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra) S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [20496 2013-09-04] (AVG Technologies CZ, s.r.o.) R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [150808 2013-11-25] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [243480 2013-11-25] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [196376 2013-11-25] (AVG Technologies CZ, s.r.o.) R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [212280 2013-11-01] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [294712 2013-10-31] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123704 2013-10-01] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31544 2013-09-10] (AVG Technologies CZ, s.r.o.) R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [252728 2013-10-21] (AVG Technologies CZ, s.r.o.) S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider) R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-05] (CyberLink) S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation) S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation) S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation) R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-11] (Microsoft Corporation) S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-04] (Intel Corporation) R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation) S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation) S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation) R3 RtlWlanu; C:\Windows\system32\DRIVERS\rtwlanu.sys [1975000 2013-07-31] (Realtek Semiconductor Corporation ) S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-10-26] (Microsoft Corporation) S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-10-05] (Microsoft Corporation) R3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124760 2013-10-31] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-12 16:21 - 2014-04-12 16:21 - 00441592 _____ (Bleeping Computer, LLC) C:\Users\Christine\Downloads\sc-cleaner.exe 2014-04-12 16:21 - 2014-04-12 16:21 - 00005450 _____ () C:\sc-cleaner.txt 2014-04-09 18:56 - 2014-04-12 16:00 - 00000091 _____ () C:\Users\Christine\AppData\Roaming\WB.CFG 2014-04-09 17:59 - 2014-04-09 17:59 - 00001196 _____ () C:\Users\Christine\Desktop\Continue Zip Extractor Installation.lnk 2014-04-09 17:56 - 2014-04-12 16:23 - 00000326 _____ () C:\Windows\Tasks\Digital Sites.job 2014-04-09 17:56 - 2014-04-12 15:56 - 00000326 _____ () C:\Windows\Tasks\MySearchDial.job 2014-04-09 17:56 - 2014-04-09 18:00 - 00002664 _____ () C:\Windows\System32\Tasks\Digital Sites 2014-04-09 17:56 - 2014-04-09 17:56 - 00002664 _____ () C:\Windows\System32\Tasks\MySearchDial 2014-04-09 17:56 - 2014-04-09 17:56 - 00001130 _____ () C:\Users\Public\Desktop\Open It!.lnk 2014-04-09 17:56 - 2014-04-09 17:56 - 00000000 ____D () C:\Users\Christine\AppData\Roaming\mysearchdial 2014-04-09 17:56 - 2014-04-09 17:56 - 00000000 ____D () C:\Users\Christine\AppData\Roaming\DigitalSites 2014-04-09 17:56 - 2014-04-09 17:56 - 00000000 ____D () C:\Users\Christine\AppData\Roaming\0D0S1L2Z1P1B 2014-04-09 17:56 - 2014-04-09 17:56 - 00000000 ____D () C:\Program Files (x86)\OpenIt 2014-04-09 17:56 - 2014-04-09 17:56 - 00000000 ____D () C:\Program Files (x86)\Mysearchdial 2014-04-09 17:56 - 2014-04-09 17:56 - 00000000 ____D () C:\Program Files (x86)\Browser Guard 2014-04-09 17:55 - 2014-04-09 17:55 - 00686048 _____ () C:\Users\Christine\Downloads\ZipExtractorSetup.exe 2014-04-09 16:40 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-09 16:40 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-09 16:40 - 2014-03-10 12:35 - 02008408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-09 16:40 - 2014-03-10 12:35 - 00377176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\clfs.sys 2014-04-09 16:40 - 2014-03-06 11:19 - 01287576 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-09 16:40 - 2014-03-06 11:02 - 01109424 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2014-04-09 16:40 - 2014-03-06 08:17 - 00835584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2014-04-09 16:40 - 2014-03-06 08:10 - 01036288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-09 16:38 - 2014-04-09 16:38 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-09 16:38 - 2014-04-09 16:38 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-08 17:22 - 2014-04-08 17:23 - 00029962 _____ () C:\Users\Christine\Desktop\Addition.txt 2014-04-07 22:01 - 2014-04-07 22:01 - 00000000 ____D () C:\Users\Christine\Downloads\ri1CgthP 2014-04-07 21:55 - 2014-04-07 21:55 - 00379736 _____ () C:\Users\Christine\Downloads\ri1CgthP.zip 2014-04-05 22:50 - 2014-04-12 16:34 - 00017302 _____ () C:\Users\Christine\Desktop\FRST.txt 2014-04-05 16:10 - 2014-04-05 16:10 - 02347384 _____ (ESET) C:\Users\Christine\Downloads\esetsmartinstaller_enu.exe 2014-03-31 18:18 - 2014-03-31 18:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-26 19:21 - 2014-04-12 16:33 - 00000000 ___RD () C:\Users\Christine\SkyDrive 2014-03-25 23:01 - 2014-03-25 23:01 - 548760847 _____ () C:\Windows\MEMORY.DMP 2014-03-25 23:01 - 2014-03-25 23:01 - 00280008 _____ () C:\Windows\Minidump\032514-33125-01.dmp 2014-03-25 23:01 - 2014-03-25 23:01 - 00000000 ____D () C:\Windows\Minidump 2014-03-25 17:42 - 2014-02-22 14:16 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe 2014-03-25 17:42 - 2014-02-22 13:24 - 00124416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe 2014-03-20 19:12 - 2014-01-08 03:46 - 00325464 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\USBXHCI.SYS 2014-03-20 19:12 - 2014-01-08 03:41 - 01530712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2014-03-20 19:12 - 2014-01-08 03:41 - 00382808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys 2014-03-20 19:12 - 2014-01-04 17:54 - 00138240 _____ () C:\Windows\system32\OEMLicense.dll 2014-03-20 19:12 - 2014-01-04 17:08 - 00103936 _____ () C:\Windows\SysWOW64\OEMLicense.dll 2014-03-20 19:12 - 2014-01-04 16:08 - 00206336 _____ (Microsoft Corporation) C:\Windows\system32\WSClient.dll 2014-03-20 19:12 - 2014-01-04 15:53 - 00174592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSClient.dll 2014-03-20 19:12 - 2014-01-03 01:54 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2014-03-20 19:12 - 2014-01-03 01:48 - 00336896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2014-03-20 19:12 - 2014-01-01 03:55 - 01720560 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2014-03-20 19:12 - 2014-01-01 03:52 - 00481944 _____ (Microsoft Corporation) C:\Windows\system32\mfsvr.dll 2014-03-20 19:12 - 2014-01-01 02:56 - 01472048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2014-03-20 19:12 - 2014-01-01 02:55 - 00381168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsvr.dll 2014-03-20 19:12 - 2014-01-01 01:59 - 00802816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll 2014-03-20 19:12 - 2014-01-01 01:57 - 01214976 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll 2014-03-20 19:12 - 2014-01-01 01:56 - 00960512 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll 2014-03-20 19:12 - 2013-12-31 01:34 - 00218112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sti.dll 2014-03-20 19:12 - 2013-12-31 01:33 - 00770560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReAgent.dll 2014-03-20 19:12 - 2013-12-31 01:32 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\sti.dll 2014-03-20 19:12 - 2013-12-31 01:31 - 00947712 _____ (Microsoft Corporation) C:\Windows\system32\reseteng.dll 2014-03-20 19:12 - 2013-12-31 01:31 - 00914944 _____ (Microsoft Corporation) C:\Windows\system32\ReAgent.dll 2014-03-20 19:12 - 2013-12-27 17:09 - 00419160 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll 2014-03-20 19:12 - 2013-12-27 10:57 - 00842752 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.dll 2014-03-20 19:12 - 2013-12-27 10:57 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncHost.exe 2014-03-20 19:12 - 2013-12-27 10:23 - 00749056 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncCore.dll 2014-03-20 19:12 - 2013-12-27 09:03 - 00630272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsSpellCheckingFacility.dll 2014-03-20 19:12 - 2013-12-27 09:03 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncHost.exe 2014-03-20 19:12 - 2013-12-27 08:37 - 00588800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncCore.dll 2014-03-20 19:12 - 2013-12-21 09:21 - 00376320 _____ (Microsoft Corporation) C:\Windows\system32\pnrpsvc.dll 2014-03-20 19:12 - 2013-12-17 09:21 - 00408576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys 2014-03-20 19:12 - 2013-12-14 08:31 - 13949440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll 2014-03-20 19:12 - 2013-12-14 08:19 - 18576384 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll 2014-03-20 19:12 - 2013-12-13 12:54 - 00131160 _____ (Microsoft Corporation) C:\Windows\system32\easinvoker.exe 2014-03-20 19:12 - 2013-12-13 08:36 - 00178176 _____ (Microsoft Corporation) C:\Windows\system32\easwrt.dll 2014-03-20 19:12 - 2013-12-13 07:32 - 00140800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\easwrt.dll 2014-03-20 19:12 - 2013-12-09 10:05 - 21199256 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-03-20 19:12 - 2013-12-09 06:51 - 18643560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-03-15 15:17 - 2014-03-15 15:17 - 00001167 _____ () C:\Users\Public\Desktop\ALDI Bestellsoftware.lnk 2014-03-15 15:15 - 2014-03-15 15:17 - 00000000 ____D () C:\Program Files (x86)\ALDI Bestellsoftware 2014-03-15 15:11 - 2014-03-15 15:15 - 272937504 _____ () C:\Users\Christine\Downloads\ALDI_Bestellsoftware_Setup(2).exe 2014-03-15 15:07 - 2014-03-15 15:09 - 00000000 ____D () C:\Users\Christine\Desktop\Fotobuch 2014-03-15 15:04 - 2014-03-15 15:07 - 272937504 _____ () C:\Users\Christine\Downloads\ALDI_Bestellsoftware_Setup(1).exe 2014-03-15 14:51 - 2014-03-15 14:54 - 272937504 _____ () C:\Users\Christine\Downloads\ALDI_Bestellsoftware_Setup.exe 2014-03-15 14:27 - 2014-03-15 15:09 - 00113664 ___SH () C:\Users\Christine\Documents\Thumbs.db 2014-03-14 14:30 - 2014-03-14 14:30 - 00000000 ____D () C:\Users\Christine\AppData\Roaming\Malwarebytes 2014-03-14 14:29 - 2014-03-14 14:29 - 00001125 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-14 14:29 - 2014-03-14 14:29 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-03-14 14:29 - 2014-03-14 14:29 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-03-14 14:29 - 2013-04-04 15:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-14 14:27 - 2014-03-14 14:27 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Christine\Downloads\mbam-setup-1.75.0.1300.exe 2014-03-13 16:55 - 2014-03-13 16:55 - 00029019 _____ () C:\Users\Christine\Downloads\Addition.txt 2014-03-13 16:54 - 2014-04-12 16:34 - 00000000 ____D () C:\FRST 2014-03-13 16:54 - 2014-03-13 16:55 - 00037939 _____ () C:\Users\Christine\Downloads\FRST.txt 2014-03-13 16:54 - 2014-03-13 16:54 - 02157056 _____ (Farbar) C:\Users\Christine\Downloads\FRST64(1).exe 2014-03-13 16:53 - 2014-03-13 16:53 - 02157056 _____ (Farbar) C:\Users\Christine\Desktop\FRST64.exe 2014-03-13 16:25 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-13 16:25 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-13 16:25 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-13 16:25 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-13 16:25 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-13 16:25 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-13 16:25 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-13 16:25 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-13 16:25 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-13 16:25 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-13 16:25 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-13 16:25 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-13 16:25 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-13 16:25 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-13 16:25 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-03-13 16:25 - 2014-01-31 18:15 - 00311640 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys 2014-03-13 16:25 - 2014-01-31 18:07 - 00233920 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2014-03-13 16:25 - 2014-01-31 18:06 - 02133208 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll 2014-03-13 16:25 - 2014-01-31 15:47 - 02143960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll 2014-03-13 16:25 - 2014-01-31 11:06 - 00716288 _____ (Microsoft Corporation) C:\Windows\system32\swprv.dll 2014-03-13 16:25 - 2014-01-29 10:53 - 00458616 _____ (Microsoft Corporation) C:\Windows\system32\WerFault.exe 2014-03-13 16:25 - 2014-01-29 10:53 - 00407024 _____ (Microsoft Corporation) C:\Windows\system32\Faultrep.dll 2014-03-13 16:25 - 2014-01-29 10:49 - 01928144 _____ (Microsoft Corporation) C:\Windows\system32\combase.dll 2014-03-13 16:25 - 2014-01-29 10:47 - 02543960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-03-13 16:25 - 2014-01-29 09:44 - 01371824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\combase.dll 2014-03-13 16:25 - 2014-01-29 09:44 - 00408480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe 2014-03-13 16:25 - 2014-01-29 09:44 - 00369280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Faultrep.dll 2014-03-13 16:25 - 2014-01-29 08:41 - 00208896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpencom.dll 2014-03-13 16:25 - 2014-01-29 02:36 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\rdpencom.dll 2014-03-13 16:25 - 2014-01-27 21:07 - 04175360 _____ (Microsoft Corporation) C:\Windows\system32\dbgeng.dll 2014-03-13 16:25 - 2014-01-27 21:06 - 00064512 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2014-03-13 16:25 - 2014-01-27 21:04 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\DWWIN.EXE 2014-03-13 16:25 - 2014-01-27 20:23 - 02873344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbgeng.dll 2014-03-13 16:25 - 2014-01-27 20:21 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2014-03-13 16:25 - 2014-01-27 20:20 - 00138752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWWIN.EXE 2014-03-13 16:25 - 2014-01-27 20:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll 2014-03-13 16:25 - 2014-01-27 19:43 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll 2014-03-13 16:25 - 2014-01-27 19:18 - 01486848 _____ (Microsoft Corporation) C:\Windows\system32\dbghelp.dll 2014-03-13 16:25 - 2014-01-27 19:00 - 01238016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbghelp.dll 2014-03-13 16:25 - 2014-01-27 17:58 - 05770752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2014-03-13 16:25 - 2014-01-27 17:50 - 06640640 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2014-03-13 16:25 - 2014-01-27 13:45 - 00386722 _____ () C:\Windows\system32\ApnDatabase.xml 2014-03-13 16:25 - 2014-01-18 01:04 - 00764864 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll 2014-03-13 16:25 - 2014-01-17 23:54 - 00669352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmpeg2srcsnk.dll 2014-03-13 16:25 - 2013-12-21 16:51 - 06353960 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe 2014-03-13 16:25 - 2013-12-21 10:54 - 00447488 _____ (Microsoft Corporation) C:\Windows\system32\sppcomapi.dll 2014-03-13 16:25 - 2013-12-20 12:18 - 01643584 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2014-03-13 16:25 - 2013-12-20 12:18 - 01507704 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2014-03-13 16:24 - 2014-02-11 05:04 - 04189184 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-13 16:24 - 2014-02-11 04:43 - 00488448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-03-13 16:24 - 2014-02-11 04:04 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-13 16:24 - 2013-10-31 02:29 - 00236888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdFilter.sys 2014-03-13 16:24 - 2013-10-31 02:29 - 00124760 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdNisDrv.sys 2014-03-13 16:24 - 2013-10-31 02:28 - 00035856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdBoot.sys ==================== One Month Modified Files and Folders ======= 2014-04-12 16:34 - 2014-04-05 22:50 - 00017302 _____ () C:\Users\Christine\Desktop\FRST.txt 2014-04-12 16:34 - 2014-03-13 16:54 - 00000000 ____D () C:\FRST 2014-04-12 16:33 - 2014-03-26 19:21 - 00000000 ___RD () C:\Users\Christine\SkyDrive 2014-04-12 16:33 - 2013-12-25 15:19 - 01514399 _____ () C:\Windows\WindowsUpdate.log 2014-04-12 16:23 - 2014-04-09 17:56 - 00000326 _____ () C:\Windows\Tasks\Digital Sites.job 2014-04-12 16:21 - 2014-04-12 16:21 - 00441592 _____ (Bleeping Computer, LLC) C:\Users\Christine\Downloads\sc-cleaner.exe 2014-04-12 16:21 - 2014-04-12 16:21 - 00005450 _____ () C:\sc-cleaner.txt 2014-04-12 16:21 - 2013-12-25 16:15 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-12 16:21 - 2013-12-25 15:54 - 00001163 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-04-12 16:21 - 2013-12-25 15:36 - 00001454 _____ () C:\Users\Christine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-04-12 16:02 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\sru 2014-04-12 16:00 - 2014-04-09 18:56 - 00000091 _____ () C:\Users\Christine\AppData\Roaming\WB.CFG 2014-04-12 15:56 - 2014-04-09 17:56 - 00000326 _____ () C:\Windows\Tasks\MySearchDial.job 2014-04-12 15:39 - 2014-01-31 20:01 - 00000000 ____D () C:\Program Files\Microsoft Office 15 2014-04-12 15:37 - 2013-12-25 15:42 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1264655104-1241458557-895395880-1001 2014-04-12 15:31 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\AppReadiness 2014-04-12 15:24 - 2013-12-25 15:59 - 00000000 ____D () C:\ProgramData\MFAData 2014-04-10 16:33 - 2013-09-02 09:52 - 00765378 _____ () C:\Windows\system32\perfh007.dat 2014-04-10 16:33 - 2013-09-02 09:52 - 00159696 _____ () C:\Windows\system32\perfc007.dat 2014-04-10 16:33 - 2013-09-02 09:20 - 01780340 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-10 16:27 - 2013-08-22 16:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-09 21:05 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\BBI 2014-04-09 18:00 - 2014-04-09 17:56 - 00002664 _____ () C:\Windows\System32\Tasks\Digital Sites 2014-04-09 17:59 - 2014-04-09 17:59 - 00001196 _____ () C:\Users\Christine\Desktop\Continue Zip Extractor Installation.lnk 2014-04-09 17:56 - 2014-04-09 17:56 - 00002664 _____ () C:\Windows\System32\Tasks\MySearchDial 2014-04-09 17:56 - 2014-04-09 17:56 - 00001130 _____ () C:\Users\Public\Desktop\Open It!.lnk 2014-04-09 17:56 - 2014-04-09 17:56 - 00000000 ____D () C:\Users\Christine\AppData\Roaming\mysearchdial 2014-04-09 17:56 - 2014-04-09 17:56 - 00000000 ____D () C:\Users\Christine\AppData\Roaming\DigitalSites 2014-04-09 17:56 - 2014-04-09 17:56 - 00000000 ____D () C:\Users\Christine\AppData\Roaming\0D0S1L2Z1P1B 2014-04-09 17:56 - 2014-04-09 17:56 - 00000000 ____D () C:\Program Files (x86)\OpenIt 2014-04-09 17:56 - 2014-04-09 17:56 - 00000000 ____D () C:\Program Files (x86)\Mysearchdial 2014-04-09 17:56 - 2014-04-09 17:56 - 00000000 ____D () C:\Program Files (x86)\Browser Guard 2014-04-09 17:55 - 2014-04-09 17:55 - 00686048 _____ () C:\Users\Christine\Downloads\ZipExtractorSetup.exe 2014-04-09 17:21 - 2013-12-25 17:14 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-09 17:20 - 2013-12-25 17:14 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-09 16:38 - 2014-04-09 16:38 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-09 16:38 - 2014-04-09 16:38 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-08 17:23 - 2014-04-08 17:22 - 00029962 _____ () C:\Users\Christine\Desktop\Addition.txt 2014-04-07 22:01 - 2014-04-07 22:01 - 00000000 ____D () C:\Users\Christine\Downloads\ri1CgthP 2014-04-07 21:55 - 2014-04-07 21:55 - 00379736 _____ () C:\Users\Christine\Downloads\ri1CgthP.zip 2014-04-07 20:26 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\ELAM 2014-04-05 22:54 - 2013-12-25 15:54 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-04-05 22:54 - 2013-09-02 09:14 - 00029564 _____ () C:\Windows\PFRO.log 2014-04-05 16:10 - 2014-04-05 16:10 - 02347384 _____ (ESET) C:\Users\Christine\Downloads\esetsmartinstaller_enu.exe 2014-03-31 23:23 - 2014-02-23 11:24 - 00693240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-31 23:23 - 2014-02-23 11:24 - 00105464 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-31 18:18 - 2014-03-31 18:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-31 17:27 - 2013-12-25 16:00 - 00001001 _____ () C:\Users\Public\Desktop\AVG 2014.lnk 2014-03-31 03:16 - 2014-04-09 16:40 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 01:57 - 2014-04-09 16:40 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-26 19:21 - 2013-12-25 15:39 - 00000000 __RDO () C:\Users\Christine\SkyDrive.old 2014-03-26 19:21 - 2013-12-25 15:35 - 00000000 ____D () C:\Users\Christine 2014-03-25 23:01 - 2014-03-25 23:01 - 548760847 _____ () C:\Windows\MEMORY.DMP 2014-03-25 23:01 - 2014-03-25 23:01 - 00280008 _____ () C:\Windows\Minidump\032514-33125-01.dmp 2014-03-25 23:01 - 2014-03-25 23:01 - 00000000 ____D () C:\Windows\Minidump 2014-03-24 17:50 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\rescache 2014-03-21 19:35 - 2013-12-25 15:37 - 00000000 ___RD () C:\Users\Christine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-03-21 19:35 - 2013-12-25 15:37 - 00000000 ___RD () C:\Users\Christine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-03-20 23:54 - 2013-08-22 17:36 - 00000000 ___RD () C:\Windows\ToastData 2014-03-15 15:17 - 2014-03-15 15:17 - 00001167 _____ () C:\Users\Public\Desktop\ALDI Bestellsoftware.lnk 2014-03-15 15:17 - 2014-03-15 15:15 - 00000000 ____D () C:\Program Files (x86)\ALDI Bestellsoftware 2014-03-15 15:15 - 2014-03-15 15:11 - 272937504 _____ () C:\Users\Christine\Downloads\ALDI_Bestellsoftware_Setup(2).exe 2014-03-15 15:09 - 2014-03-15 15:07 - 00000000 ____D () C:\Users\Christine\Desktop\Fotobuch 2014-03-15 15:09 - 2014-03-15 14:27 - 00113664 ___SH () C:\Users\Christine\Documents\Thumbs.db 2014-03-15 15:07 - 2014-03-15 15:04 - 272937504 _____ () C:\Users\Christine\Downloads\ALDI_Bestellsoftware_Setup(1).exe 2014-03-15 15:07 - 2014-01-30 22:53 - 00736256 ___SH () C:\Users\Christine\Desktop\Thumbs.db 2014-03-15 14:54 - 2014-03-15 14:51 - 272937504 _____ () C:\Users\Christine\Downloads\ALDI_Bestellsoftware_Setup.exe 2014-03-14 14:38 - 2013-08-22 16:46 - 00038028 _____ () C:\Windows\setupact.log 2014-03-14 14:30 - 2014-03-14 14:30 - 00000000 ____D () C:\Users\Christine\AppData\Roaming\Malwarebytes 2014-03-14 14:29 - 2014-03-14 14:29 - 00001125 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-14 14:29 - 2014-03-14 14:29 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-03-14 14:29 - 2014-03-14 14:29 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-03-14 14:27 - 2014-03-14 14:27 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Christine\Downloads\mbam-setup-1.75.0.1300.exe 2014-03-14 12:34 - 2013-08-22 16:44 - 00394952 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-13 21:15 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2014-03-13 21:15 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2014-03-13 21:15 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Windows Defender 2014-03-13 21:15 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender 2014-03-13 16:55 - 2014-03-13 16:55 - 00029019 _____ () C:\Users\Christine\Downloads\Addition.txt 2014-03-13 16:55 - 2014-03-13 16:54 - 00037939 _____ () C:\Users\Christine\Downloads\FRST.txt 2014-03-13 16:54 - 2014-03-13 16:54 - 02157056 _____ (Farbar) C:\Users\Christine\Downloads\FRST64(1).exe 2014-03-13 16:53 - 2014-03-13 16:53 - 02157056 _____ (Farbar) C:\Users\Christine\Desktop\FRST64.exe Some content of TEMP: ==================== C:\Users\Christine\AppData\Local\Temp\BackupSetup.exe C:\Users\Christine\AppData\Local\Temp\ICReinstall_ZipExtractorSetup.exe C:\Users\Christine\AppData\Local\Temp\OfficeSetup.exe C:\Users\Christine\AppData\Local\Temp\Quarantine.exe C:\Users\Christine\AppData\Local\Temp\Setup.X86.de-DE_HomeStudentRetail_39a7859d-667d-4560-ba8d-b7b14d319606_TX_DB_.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys [2014-03-13 16:25] - [2014-01-31 18:15] - 0311640 ___AC (Microsoft Corporation) C85C075DE5B6D0FE116043054DE8EE02 LastRegBack: 2014-04-03 17:33 ==================== End Of Log ============================ --- --- --- --- --- --- --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-03-2014 Ran by Christine at 2014-04-12 16:35:07 Running from C:\Users\Christine\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {B5F5C120-2089-702E-0001-553BB0D5A664} ==================== Installed Programs ====================== Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated) ALDI Bestellsoftware 4.13.1 (HKLM-x32\...\ALDI Bestellsoftware) (Version: 4.13.1 - ORWO Net) Ashampoo AppLauncher (Medion) v.1.0.0 (HKLM-x32\...\Ashampoo AppLauncher (Medion)_is1) (Version: 1.0.0 - Ashampoo GmbH & Co. KG) AVG 2014 (HKLM\...\AVG) (Version: 2014.0.4355 - AVG Technologies) AVG 2014 (Version: 14.0.3882 - AVG Technologies) Hidden AVG 2014 (Version: 14.0.4355 - AVG Technologies) Hidden Browser Guard (HKLM-x32\...\Browser Guard) (Version: - ) CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.2.4478 - CDBurnerXP) CyberLink LabelPrint 2.5 (x32 Version: 2.5.5415 - CyberLink Corp.) Hidden CyberLink MediaEspresso 6.5 (x32 Version: 6.5.3807_46074 - CyberLink Corp.) Hidden CyberLink PhotoDirector 3 (x32 Version: 3.0.4017 - CyberLink Corp.) Hidden CyberLink Power2Go 8 (x32 Version: 8.0.0.2426b - CyberLink Corp.) Hidden CyberLink PowerDirector (Version: 9.0.0.5129 - CyberLink Corp.) Hidden CyberLink PowerDVD 10 (x32 Version: 10.0.5211.02 - CyberLink Corp.) Hidden CyberLink PowerDVD Copy 1.5 (x32 Version: 1.5.0.3725 - CyberLink Corp.) Hidden CyberLink PowerRecover (HKLM-x32\...\InstallShield_{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}) (Version: 5.7.0.0913 - CyberLink Corp.) CyberLink PowerRecover (Version: 5.7.0.0913 - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Fotogalerie (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Fotogalerija (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Fotogalleri (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Fotogalleriet (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Fotoğraf Galerisi (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Fotótár (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Galeria de Fotografias (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Galería de fotos (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Galeria fotografii (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Galerie de photos (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden HP Officejet 6600 - Grundlegende Software für das Gerät (HKLM\...\{F58934BD-F483-43EB-B307-CFFD88B18455}) (Version: 28.0.1315.0 - Hewlett-Packard Co.) HP Officejet 6600 Hilfe (HKLM-x32\...\{2FA81482-5570-4CF0-9A10-D61D2F164916}) (Version: 140.0.2.2 - Hewlett Packard) HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard) I.R.I.S. OCR (HKLM-x32\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3282 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.0.1016 - Intel Corporation) Intel(R) Rapid Storage Technology (Version: 12.8.0.1016 - Intel Corporation) Hidden Java 7 Update 45 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417045FF}) (Version: 7.0.450 - Oracle) Malwarebytes Anti-Malware Version 1.75.0.1300 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation) Medion Home Cinema 10 (HKLM-x32\...\InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}) (Version: 10.0 - CyberLink Corp.) Medion Home Cinema 10 (x32 Version: 10.2419 - CyberLink Corp.) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office Home and Student 2013 - de-de (HKLM\...\HomeStudentRetail - de-de) (Version: 15.0.4605.1003 - Microsoft Corporation) Microsoft SkyDrive (HKCU\...\SkyDriveSetup.exe) (Version: 17.0.2015.0811 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Mozilla Firefox 28.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden Mysearchdial (HKLM-x32\...\mysearchdial) (Version: - Mysearchdial) <==== ATTENTION Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4605.1003 - Microsoft Corporation) Hidden Office 15 Click-to-Run Licensing Component (Version: 15.0.4605.1003 - Microsoft Corporation) Hidden Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4605.1003 - Microsoft Corporation) Hidden Open It! (HKLM-x32\...\OpenIt Open It!) (Version: 1.1.1 - OpenIt) Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Photo Gallery (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden PhotoNow (x32 Version: 1.1.7717 - CyberLink Corp.) Hidden Podstawowe programy Windows Live (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Raccolta foto (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.18.621.2013 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7027 - Realtek Semiconductor Corp.) Studie zur Verbesserung von HP Officejet 6600 Produkten (HKLM\...\{E1A11879-5771-4E52-BA2E-CD5DD65BF970}) (Version: 28.0.1315.0 - Hewlett-Packard Co.) Update for Zip Extractor (HKCU\...\Digital Sites) (Version: - Update for Zip Extractor) <==== ATTENTION Valokuvavalikoima (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies) Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) VLC media player 2.1.1 (HKLM\...\VLC media player) (Version: 2.1.1 - VideoLAN) Windows Live (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Communications Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation) Windows Live Essentials (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Temel Parçalar (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Liven peruspaketti (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden WinZip Malware Protector (HKLM-x32\...\WinZip Malware Protector_is1) (Version: 2.1.1000.10798 - WinZip International LLC) Zip Extractor Packages (HKCU\...\Zip Extractor Packages) (Version: - ) <==== ATTENTION Συλλογή φωτογραφιών (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden ==================== Restore Points ========================= 25-03-2014 16:28:44 Windows Update 03-04-2014 15:35:13 Geplanter Prüfpunkt 09-04-2014 15:19:33 Windows Update ==================== Hosts content: ========================== 2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask Task: {24182636-8513-4F0F-8131-B33CB17A2FED} - System32\Tasks\HPCustParticipation HP Officejet 6600 => C:\Program Files\HP\HP Officejet 6600\Bin\HPCustPartic.exe [2012-10-17] (Hewlett-Packard Co.) Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate Task: {34D802AF-4975-45FB-BB01-F428220DE692} - System32\Tasks\Digital Sites => C:\Users\Christine\AppData\Roaming\DigitalSites\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation) Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation) Task: {456D62CB-00F4-4F88-BC0D-9DF289B1A31C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-12] (Adobe Systems Incorporated) Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance Task: {65C41B78-5E18-4C1B-AD67-D5575E3EE3D7} - System32\Tasks\WinZip Malware Protector_startup => C:\Program Files (x86)\WinZip Malware Protector\WinZipMalwareProtector.exe Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask Task: {93ECF6BE-7DF9-4834-A390-6805351876DD} - System32\Tasks\MySearchDial => C:\Users\Christine\AppData\Roaming\mysearchdial\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work Task: {A7824422-8CF5-45C2-9003-E500D975832B} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2014-04-09] (Microsoft Corporation) Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE Task: {F27EFEF5-F3CD-4665-87F9-B2FB4E5B4313} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2014-03-30] (Microsoft Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\Digital Sites.job => C:\Users\CHRIST~1\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\Windows\Tasks\MySearchDial.job => C:\Users\CHRIST~1\AppData\Roaming\MYSEAR~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION ==================== Loaded Modules (whitelisted) ============= 2013-09-03 07:50 - 2010-08-19 18:43 - 00386344 _____ () C:\Program Files\CyberLink\Shared files\RichVideo64.exe 2014-03-21 19:44 - 2013-10-31 18:13 - 00102568 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll 2014-01-31 20:01 - 2014-03-25 13:21 - 00629928 _____ () C:\Program Files\Microsoft Office 15\ClientX64\StreamServer.dll 2014-04-12 15:24 - 2014-04-12 15:27 - 00183296 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20461_x64__8wekyb3d8bbwe\ErrorReporting.dll 2014-03-31 18:18 - 2014-03-31 18:18 - 03642480 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2013-09-03 07:48 - 2013-03-05 05:40 - 00626240 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll 2013-03-05 12:41 - 2013-03-05 12:41 - 00015424 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\Christine\SkyDrive:ms-properties AlternateDataStreams: C:\Users\Christine\SkyDrive.old:ms-properties ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= Name: WLAN USB Device Description: WLAN USB Device Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (04/09/2014 09:04:31 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: firefox.exe, Version: 28.0.0.5186, Zeitstempel: 0x53240e37 Name des fehlerhaften Moduls: xul.dll, Version: 28.0.0.5186, Zeitstempel: 0x53240e04 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00184729 ID des fehlerhaften Prozesses: 0x1654 Startzeit der fehlerhaften Anwendung: 0xfirefox.exe0 Pfad der fehlerhaften Anwendung: firefox.exe1 Pfad des fehlerhaften Moduls: firefox.exe2 Berichtskennung: firefox.exe3 Vollständiger Name des fehlerhaften Pakets: firefox.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: firefox.exe5 Error: (04/09/2014 08:37:42 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.3.9600.16441, Zeitstempel: 0x5265dec8 Name des fehlerhaften Moduls: igd10iumd64.dll, Version: 10.18.10.3282, Zeitstempel: 0x521badba Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000000d4d4 ID des fehlerhaften Prozesses: 0x10f0 Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Vollständiger Name des fehlerhaften Pakets: Explorer.EXE4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Explorer.EXE5 Error: (04/07/2014 10:00:48 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifest. Error: (04/05/2014 10:45:54 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifest. Error: (04/05/2014 04:16:08 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifest. Error: (04/05/2014 04:16:04 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifest. Error: (04/05/2014 04:10:53 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifest. Error: (04/05/2014 04:10:53 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifest. Error: (03/19/2014 06:25:39 PM) (Source: Application Hang) (User: ) Description: Programm LiveComm.exe, Version 17.5.9600.20413 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1b40 Startzeit: 01cf438f2491045b Endzeit: 4294967295 Anwendungspfad: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20413_x64__8wekyb3d8bbwe\LiveComm.exe Berichts-ID: 18696153-af83-11e3-8285-d43d7eb0282d Vollständiger Name des fehlerhaften Pakets: microsoft.windowscommunicationsapps_17.5.9600.20413_x64__8wekyb3d8bbwe Anwendungs-ID, die relativ zum fehlerhaften Paket ist: ppleae38af2e007f4358a809ac99a64a67c1 Error: (02/09/2014 05:41:34 PM) (Source: Microsoft Office 15) (User: ) Description: Application: winword.exe; IdentityType: Unknown; HasToken: 1; AutoOrgId: 0; Roaming: 0; LvuxSqm: 0; SppReady: 1; CurrentHr: 0x803d0013; CorrelationId: {D58AA837-318E-461D-9AA0-781376544E29}; OlsErrorCode: 0x407; CurrentProductReleaseId: HomeStudentRetail; AllProductReleaseIds (from store): HomeStudentRetail System errors: ============= Error: (03/25/2014 11:01:29 PM) (Source: BugCheck) (User: ) Description: 0x000000ab (0x0000000000000004, 0x0000000000000210, 0x0000000000000000, 0x0000000000000002)C:\Windows\MEMORY.DMP032514-33125-01 Error: (03/25/2014 11:01:19 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 25.03.2014 um 19:12:39 unerwartet heruntergefahren. Error: (03/12/2014 08:08:22 PM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 40. Der Windows-SChannel-Fehlerstatus lautet: 252. Error: (03/12/2014 08:08:22 PM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 40. Der Windows-SChannel-Fehlerstatus lautet: 252. Error: (03/11/2014 10:28:42 PM) (Source: DCOM) (User: SNOWDONIA) Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9} Error: (03/11/2014 10:28:42 PM) (Source: DCOM) (User: SNOWDONIA) Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9} Error: (03/06/2014 09:24:55 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 06.03.2014 um 18:24:58 unerwartet heruntergefahren. Error: (02/23/2014 11:25:07 AM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT) Description: Fehler bei der CBS-Clientinitialisierung. Letzter Fehler: 0x80080005 Error: (02/23/2014 11:25:07 AM) (Source: DCOM) (User: NT-AUTORITÄT) Description: {752073A1-23F2-4396-85F0-8FDB879ED0ED} Error: (02/21/2014 10:47:14 PM) (Source: DCOM) (User: SNOWDONIA) Description: {4AA0A5C4-1B9B-4F2E-99D7-99C6AEC83474} Microsoft Office Sessions: ========================= Error: (04/09/2014 09:04:31 PM) (Source: Application Error)(User: ) Description: firefox.exe28.0.0.518653240e37xul.dll28.0.0.518653240e04c000000500184729165401cf5422e74f4904C:\Program Files (x86)\Mozilla Firefox\firefox.exeC:\Program Files (x86)\Mozilla Firefox\xul.dllc7a60cd5-c019-11e3-8288-d43d7eb0282d Error: (04/09/2014 08:37:42 PM) (Source: Application Error)(User: ) Description: Explorer.EXE6.3.9600.164415265dec8igd10iumd64.dll10.18.10.3282521badbac0000005000000000000d4d410f001cf54013de732c6C:\Windows\Explorer.EXEC:\Windows\SYSTEM32\igd10iumd64.dll0880ec07-c016-11e3-8288-d43d7eb0282d Error: (04/07/2014 10:00:48 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifestC:\Users\Christine\Downloads\esetsmartinstaller_enu.exe Error: (04/05/2014 10:45:54 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifestC:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe Error: (04/05/2014 04:16:08 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifestC:\Users\Christine\Downloads\esetsmartinstaller_enu.exe Error: (04/05/2014 04:16:04 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifestC:\Users\Christine\Downloads\esetsmartinstaller_enu.exe Error: (04/05/2014 04:10:53 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifestC:\Users\Christine\Downloads\esetsmartinstaller_enu.exe Error: (04/05/2014 04:10:53 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifestC:\Users\Christine\Downloads\esetsmartinstaller_enu.exe Error: (03/19/2014 06:25:39 PM) (Source: Application Hang)(User: ) Description: LiveComm.exe17.5.9600.204131b4001cf438f2491045b4294967295C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20413_x64__8wekyb3d8bbwe\LiveComm.exe18696153-af83-11e3-8285-d43d7eb0282dmicrosoft.windowscommunicationsapps_17.5.9600.20413_x64__8wekyb3d8bbweppleae38af2e007f4358a809ac99a64a67c1 Error: (02/09/2014 05:41:34 PM) (Source: Microsoft Office 15)(User: ) Description: Application: winword.exe; IdentityType: Unknown; HasToken: 1; AutoOrgId: 0; Roaming: 0; LvuxSqm: 0; SppReady: 1; CurrentHr: 0x803d0013; CorrelationId: {D58AA837-318E-461D-9AA0-781376544E29}; OlsErrorCode: 0x407; CurrentProductReleaseId: HomeStudentRetail; AllProductReleaseIds (from store): HomeStudentRetail ==================== Memory info =========================== Percentage of memory in use: 42% Total physical RAM: 4018.27 MB Available physical RAM: 2292.99 MB Total Pagefile: 8114.27 MB Available Pagefile: 6352.03 MB Total Virtual: 131072 MB Available Virtual: 131071.83 MB ==================== Drives ================================ Drive c: (Boot) (Fixed) (Total:869.8 GB) (Free:818.85 GB) NTFS Drive d: (Recover) (Fixed) (Total:60 GB) (Free:45.16 GB) NTFS Drive e: (Lexar) (Removable) (Total:29.24 GB) (Free:10.54 GB) FAT32 Drive h: (KINGSTON) (Removable) (Total:7.45 GB) (Free:3.06 GB) FAT32 Drive j: (ADATA UFD) (Removable) (Total:3.76 GB) (Free:0.5 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 932 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ======================================================== Disk: 1 (Size: 7 GB) (Disk ID: 4197726C) Partition 1: (Not Active) - (Size=7 GB) - (Type=0B) ======================================================== Disk: 3 (Size: 4 GB) (Disk ID: 04DD5721) Partition 1: (Not Active) - (Size=4 GB) - (Type=0C) ======================================================== Disk: 4 (MBR Code: Windows XP) (Size: 29 GB) (Disk ID: C3072E18) Partition: GPT Partition Type. ==================== End Of Log ============================ jetzt ist sie weg! vielen dank!! aber dafür hab ich jetzt mysearchdial... tut mir leid! ich bin so blöd |
13.04.2014, 15:51 | #18 |
Ruhe in Frieden † 2019 | ich werde die Startseite awesomehp nicht los, was kann ich noch tun? Hallo Christine,
__________________ich möchte dir dringend Ad-Block-Plus ans Herz legen, da sind viele Klick-Versuchungen schon mal gebannt, weil sie gar nicht erst im Browser auftauchen. Hier findest du die Möglichkeit dich darüber zu informieren und es dir, wenn du möchtest, zu installieren. Schritt 1 Bitte deinstalliere folgende Programme: Mysearchdial Open It! Update for Zip Extractor Zip Extractor Packages Dazu drücke auf: Windowstaste und X dann: Programme und Funktionen --> Programm auswählen --> entfernen Schritt 2 Starte noch mal den Adwarecleaner, falls er sich nicht mehr auf deinem Rechner befindet , lade ihn dir erneut runter. Hier nochmal die Anleitung: Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt 3 Starte noch einmal FRST.
__________________ |
14.04.2014, 13:00 | #19 |
| ich werde die Startseite awesomehp nicht los, was kann ich noch tun?Code:
ATTFilter # AdwCleaner v3.023 - Bericht erstellt am 14/04/2014 um 13:46:39 # Aktualisiert 01/04/2014 von Xplode # Betriebssystem : Windows 8.1 (64 bits) # Benutzername : Christine - SNOWDONIA # Gestartet von : C:\Users\Christine\Downloads\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\WPM Ordner Gelöscht : C:\Program Files (x86)\SupTab Ordner Gelöscht : C:\Users\Christine\AppData\Roaming\DigitalSites Ordner Gelöscht : C:\Users\Christine\AppData\Roaming\Mysearchdial Datei Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk Datei Gelöscht : C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\k726cbo5.default-1391963932618\user.js Datei Gelöscht : C:\Windows\Tasks\Digital Sites.job Datei Gelöscht : C:\Windows\System32\Tasks\Digital Sites Datei Gelöscht : C:\Windows\Tasks\MySearchDial.job Datei Gelöscht : C:\Windows\System32\Tasks\MySearchDial ***** [ Verknüpfungen ] ***** Verknüpfung Desinfiziert : C:\Users\Christine\Desktop\ALDI Süd Blumen Service.lnk Verknüpfung Desinfiziert : C:\Users\Christine\Desktop\ALDI Süd Reisen.lnk Verknüpfung Desinfiziert : C:\Users\Christine\Desktop\ALDI Süd Startseite.lnk Verknüpfung Desinfiziert : C:\Users\Christine\Desktop\ALDI Talk.lnk ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\esrv.mysearchdialesrvc Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\esrv.mysearchdialesrvc.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C292AD0A-C11F-479B-B8DB-743E72D283B0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D40753C7-8A59-4C1F-BE88-C300F4624D5B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{C292AD0A-C11F-479B-B8DB-743E72D283B0} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8} Schlüssel Gelöscht : HKCU\Software\dsiteproducts Schlüssel Gelöscht : HKCU\Software\InstallCore Schlüssel Gelöscht : HKCU\Software\mysearchdial.com Schlüssel Gelöscht : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0} Schlüssel Gelöscht : HKLM\Software\supTab Schlüssel Gelöscht : HKLM\Software\supWPM Schlüssel Gelöscht : HKLM\Software\Wpm ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16518 Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] -\\ Mozilla Firefox v28.0 (de) [ Datei : C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\k726cbo5.default-1391963932618\prefs.js ] Zeile gelöscht : user_pref("browser.search.order.1", "Mysearchdial"); Zeile gelöscht : user_pref("browser.search.selectedEngine", "Mysearchdial"); Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://start.mysearchdial.com/?f=1&a=dsites05_14_15_ff&cd=2XzuyEtN2Y1L1Qzu0DyEtA0DyB0E0BtDtBzztB0DtByC0DyCtN0D0Tzu0SzztAtDtN1L2XzutBtFtCzytFyDtFtDtN1L1CzutCyEtDt[...] Zeile gelöscht : user_pref("extensions.mysearchdial.AL", 4); Zeile gelöscht : user_pref("extensions.mysearchdial.aflt", "dsites05_14_15_ff"); Zeile gelöscht : user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}"); Zeile gelöscht : user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1Qzu0DyEtA0DyB0E0BtDtBzztB0DtByC0DyCtN0D0Tzu0SzztAtDtN1L2XzutBtFtCzytFyDtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StAyDyC0FyCyCzz0FtGyDzytCy[...] Zeile gelöscht : user_pref("extensions.mysearchdial.cntry", "DE"); Zeile gelöscht : user_pref("extensions.mysearchdial.cr", "611196884"); Zeile gelöscht : user_pref("extensions.mysearchdial.dfltLng", ""); Zeile gelöscht : user_pref("extensions.mysearchdial.dfltSrch", true); Zeile gelöscht : user_pref("extensions.mysearchdial.dnsErr", true); Zeile gelöscht : user_pref("extensions.mysearchdial.dpkLst", "3654782829,1334533236,1121012847,231756876,1895130307,603719297,4288797614,3754950497,426401714,3046281807,752626116,1657571787,3224935090,2597085128,18285[...] Zeile gelöscht : user_pref("extensions.mysearchdial.excTlbr", false); Zeile gelöscht : user_pref("extensions.mysearchdial.hdrMd5", "105355F662B017D883577C95354860F1"); Zeile gelöscht : user_pref("extensions.mysearchdial.hmpg", true); Zeile gelöscht : user_pref("extensions.mysearchdial.hmpgUrl", "hxxp://start.mysearchdial.com/?f=1&a=dsites05_14_15_ff&cd=2XzuyEtN2Y1L1Qzu0DyEtA0DyB0E0BtDtBzztB0DtByC0DyCtN0D0Tzu0SzztAtDtN1L2XzutBtFtCzytFyDtFtDtN1L1Czu[...] Zeile gelöscht : user_pref("extensions.mysearchdial.id", "D43D7EB0282D26D6"); Zeile gelöscht : user_pref("extensions.mysearchdial.instlDay", "16169"); Zeile gelöscht : user_pref("extensions.mysearchdial.instlRef", "140305_a"); Zeile gelöscht : user_pref("extensions.mysearchdial.lastB", "hxxp://start.mysearchdial.com/?f=1&a=dsites05_14_15_ff&cd=2XzuyEtN2Y1L1Qzu0DyEtA0DyB0E0BtDtBzztB0DtByC0DyCtN0D0Tzu0SzztAtDtN1L2XzutBtFtCzytFyDtFtDtN1L1CzutC[...] Zeile gelöscht : user_pref("extensions.mysearchdial.lastVrsnTs", "1.8.29.017:56:15"); Zeile gelöscht : user_pref("extensions.mysearchdial.newTabUrl", "hxxp://start.mysearchdial.com/?f=2&a=dsites05_14_15_ff&cd=2XzuyEtN2Y1L1Qzu0DyEtA0DyB0E0BtDtBzztB0DtByC0DyCtN0D0Tzu0SzztAtDtN1L2XzutBtFtCzytFyDtFtDtN1L1C[...] Zeile gelöscht : user_pref("extensions.mysearchdial.pnu_base", "{\"newVrsn\":\"95\",\"lastVrsn\":\"95\",\"vrsnLoad\":\"\",\"showMsg\":\"false\",\"showSilent\":\"false\",\"msgTs\":0,\"lstMsgTs\":\"0\"}"); Zeile gelöscht : user_pref("extensions.mysearchdial.prdct", "mysearchdial"); Zeile gelöscht : user_pref("extensions.mysearchdial.prtnrId", "mysearchdial"); Zeile gelöscht : user_pref("extensions.mysearchdial.sg", "none"); Zeile gelöscht : user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial"); Zeile gelöscht : user_pref("extensions.mysearchdial.tlbrId", "base"); Zeile gelöscht : user_pref("extensions.mysearchdial.tlbrSrchUrl", "hxxp://start.mysearchdial.com/?f=3&a=dsites05_14_15_ff&cd=2XzuyEtN2Y1L1Qzu0DyEtA0DyB0E0BtDtBzztB0DtByC0DyCtN0D0Tzu0SzztAtDtN1L2XzutBtFtCzytFyDtFtDtN1L[...] Zeile gelöscht : user_pref("extensions.mysearchdial.vrsn", "1.8.29.0"); Zeile gelöscht : user_pref("extensions.mysearchdial.vrsni", "1.8.29.0"); Zeile gelöscht : user_pref("extensions.mysearchdial_i.newTab", false); Zeile gelöscht : user_pref("extensions.mysearchdial_i.smplGrp", "none"); Zeile gelöscht : user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.29.017:56:15"); ************************* AdwCleaner[R2].txt - [808 octets] - [12/02/2014 18:52:39] AdwCleaner[R3].txt - [8867 octets] - [14/04/2014 13:43:29] AdwCleaner[S2].txt - [868 octets] - [12/02/2014 18:53:40] AdwCleaner[S3].txt - [7042 octets] - [14/04/2014 13:46:39] ########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [7102 octets] ########## FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-04-2014 01 Ran by Christine (administrator) on SNOWDONIA on 14-04-2014 13:49:27 Running from C:\Users\Christine\Desktop Windows 8.1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe () C:\Program Files\CyberLink\Shared files\RichVideo64.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe (Microsoft Corporation) C:\Windows\system32\dashost.exe (Microsoft Corporation) C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17031_none_fa50b3979b1bcb4a\TiWorker.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20461_x64__8wekyb3d8bbwe\LiveComm.exe (Microsoft Corporation) C:\Windows\System32\skydrive.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\system32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6600\Bin\HPNetworkCommunicatorCom.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6600\Bin\HPNetworkCommunicator.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation) HKLM\...\Run: [IgfxTray] => C:\Windows\system32\igfxtray.exe [391152 2013-08-30] (Intel Corporation) HKLM\...\Run: [HotKeysCmds] => C:\Windows\system32\hkcmd.exe [771056 2013-08-30] (Intel Corporation) HKLM\...\Run: [Persistence] => C:\Windows\system32\igfxpers.exe [769520 2013-08-30] (Intel Corporation) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13647576 2013-08-27] (Realtek Semiconductor) HKLM-x32\...\Run: [CLMLServer_For_P2G8] => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [110144 2013-03-05] (CyberLink) HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [492248 2012-12-26] (CyberLink Corp.) HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [95192 2013-03-11] (CyberLink Corp.) HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [4971024 2014-03-19] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer: [ConfirmFileDelete] 1 HKU\S-1-5-21-1264655104-1241458557-895395880-1001\...\Run: [AVG-Secure-Search-Update_1213b] => C:\Users\Christine\AppData\Roaming\AVG 1213b Campaign\AVG-Secure-Search-Update-1213b.exe /PROMPT /mid=1f08500ba37747d2a1cd51564423c578-9f30602e2779c12f56d98f271d662434c69bb14d /CMPID=1213b HKU\S-1-5-21-1264655104-1241458557-895395880-1001\...\Run: [HP Officejet 6600 (NET)] => C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.) HKU\S-1-5-21-1264655104-1241458557-895395880-1001\...\MountPoints2: {defa6949-6e29-11e3-8279-d43d7eb0282d} - "I:\pushinst.exe" Startup: C:\Users\Christine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Officejet 6600 (Netzwerk).lnk ShortcutTarget: Tintenwarnungen überwachen - HP Officejet 6600 (Netzwerk).lnk -> C:\Program Files\HP\HP Officejet 6600\Bin\HPStatusBL.dll (Hewlett-Packard Co.) ==================== Internet (Whitelisted) ==================== SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKCU - {AC7CEB9D-BCAF-4023-900F-CABEC8534B83} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=LCJB BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Christine\AppData\Roaming\Mozilla\Firefox\Profiles\k726cbo5.default-1391963932618 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @videolan.org/vlc,version=2.1.1 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml ==================== Services (Whitelisted) ================= R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3782672 2014-02-23] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [348008 2013-09-24] (AVG Technologies CZ, s.r.o.) R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2211000 2014-03-30] (Microsoft Corporation) R2 CyberLink PowerDVD 10 MS Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe [74712 2013-03-11] (CyberLink) R2 CyberLink PowerDVD 10 MS Service; C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe [316376 2013-03-11] (CyberLink) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [386344 2010-08-19] () S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [348392 2013-10-31] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2013-10-31] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra) S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [20496 2013-09-04] (AVG Technologies CZ, s.r.o.) R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [150808 2013-11-25] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [243480 2013-11-25] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [196376 2013-11-25] (AVG Technologies CZ, s.r.o.) R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [212280 2013-11-01] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [294712 2013-10-31] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123704 2013-10-01] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31544 2013-09-10] (AVG Technologies CZ, s.r.o.) R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [252728 2013-10-21] (AVG Technologies CZ, s.r.o.) S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider) R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-05] (CyberLink) S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation) S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation) S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation) R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-11] (Microsoft Corporation) S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-04] (Intel Corporation) R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation) S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation) S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation) R3 RtlWlanu; C:\Windows\system32\DRIVERS\rtwlanu.sys [1975000 2013-07-31] (Realtek Semiconductor Corporation ) S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-10-26] (Microsoft Corporation) S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-10-05] (Microsoft Corporation) R3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124760 2013-10-31] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-14 13:49 - 2014-04-14 13:49 - 00000000 ____D () C:\Users\Christine\Desktop\FRST-OlderVersion 2014-04-14 13:05 - 2014-04-14 13:05 - 01426178 _____ () C:\Users\Christine\Downloads\adwcleaner.exe 2014-04-14 12:38 - 2014-04-14 12:38 - 00069632 _____ () C:\Users\Christine\Desktop\RichDad Finanzplaner.xls 2014-04-12 16:21 - 2014-04-12 16:21 - 00441592 _____ (Bleeping Computer, LLC) C:\Users\Christine\Downloads\sc-cleaner.exe 2014-04-12 16:21 - 2014-04-12 16:21 - 00005450 _____ () C:\sc-cleaner.txt 2014-04-09 18:56 - 2014-04-12 16:00 - 00000091 _____ () C:\Users\Christine\AppData\Roaming\WB.CFG 2014-04-09 17:55 - 2014-04-09 17:55 - 00686048 _____ () C:\Users\Christine\Downloads\ZipExtractorSetup.exe 2014-04-09 16:40 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-09 16:40 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-09 16:40 - 2014-03-10 12:35 - 02008408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-09 16:40 - 2014-03-10 12:35 - 00377176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\clfs.sys 2014-04-09 16:40 - 2014-03-06 11:19 - 01287576 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-09 16:40 - 2014-03-06 11:02 - 01109424 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2014-04-09 16:40 - 2014-03-06 08:17 - 00835584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2014-04-09 16:40 - 2014-03-06 08:10 - 01036288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-09 16:38 - 2014-04-09 16:38 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-09 16:38 - 2014-04-09 16:38 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-07 22:01 - 2014-04-07 22:01 - 00000000 ____D () C:\Users\Christine\Downloads\ri1CgthP 2014-04-07 21:55 - 2014-04-07 21:55 - 00379736 _____ () C:\Users\Christine\Downloads\ri1CgthP.zip 2014-04-05 22:50 - 2014-04-14 13:49 - 00013143 _____ () C:\Users\Christine\Desktop\FRST.txt 2014-04-05 16:10 - 2014-04-05 16:10 - 02347384 _____ (ESET) C:\Users\Christine\Downloads\esetsmartinstaller_enu.exe 2014-03-31 18:18 - 2014-03-31 18:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-26 19:21 - 2014-04-14 13:47 - 00000000 ___RD () C:\Users\Christine\SkyDrive 2014-03-25 23:01 - 2014-03-25 23:01 - 548760847 _____ () C:\Windows\MEMORY.DMP 2014-03-25 23:01 - 2014-03-25 23:01 - 00280008 _____ () C:\Windows\Minidump\032514-33125-01.dmp 2014-03-25 23:01 - 2014-03-25 23:01 - 00000000 ____D () C:\Windows\Minidump 2014-03-25 17:42 - 2014-02-22 14:16 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe 2014-03-25 17:42 - 2014-02-22 13:24 - 00124416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe 2014-03-20 19:12 - 2014-01-08 03:46 - 00325464 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\USBXHCI.SYS 2014-03-20 19:12 - 2014-01-08 03:41 - 01530712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2014-03-20 19:12 - 2014-01-08 03:41 - 00382808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys 2014-03-20 19:12 - 2014-01-04 17:54 - 00138240 _____ () C:\Windows\system32\OEMLicense.dll 2014-03-20 19:12 - 2014-01-04 17:08 - 00103936 _____ () C:\Windows\SysWOW64\OEMLicense.dll 2014-03-20 19:12 - 2014-01-04 16:08 - 00206336 _____ (Microsoft Corporation) C:\Windows\system32\WSClient.dll 2014-03-20 19:12 - 2014-01-04 15:53 - 00174592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSClient.dll 2014-03-20 19:12 - 2014-01-03 01:54 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2014-03-20 19:12 - 2014-01-03 01:48 - 00336896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2014-03-20 19:12 - 2014-01-01 03:55 - 01720560 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2014-03-20 19:12 - 2014-01-01 03:52 - 00481944 _____ (Microsoft Corporation) C:\Windows\system32\mfsvr.dll 2014-03-20 19:12 - 2014-01-01 02:56 - 01472048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2014-03-20 19:12 - 2014-01-01 02:55 - 00381168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsvr.dll 2014-03-20 19:12 - 2014-01-01 01:59 - 00802816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll 2014-03-20 19:12 - 2014-01-01 01:57 - 01214976 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll 2014-03-20 19:12 - 2014-01-01 01:56 - 00960512 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll 2014-03-20 19:12 - 2013-12-31 01:34 - 00218112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sti.dll 2014-03-20 19:12 - 2013-12-31 01:33 - 00770560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReAgent.dll 2014-03-20 19:12 - 2013-12-31 01:32 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\sti.dll 2014-03-20 19:12 - 2013-12-31 01:31 - 00947712 _____ (Microsoft Corporation) C:\Windows\system32\reseteng.dll 2014-03-20 19:12 - 2013-12-31 01:31 - 00914944 _____ (Microsoft Corporation) C:\Windows\system32\ReAgent.dll 2014-03-20 19:12 - 2013-12-27 17:09 - 00419160 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll 2014-03-20 19:12 - 2013-12-27 10:57 - 00842752 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.dll 2014-03-20 19:12 - 2013-12-27 10:57 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncHost.exe 2014-03-20 19:12 - 2013-12-27 10:23 - 00749056 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncCore.dll 2014-03-20 19:12 - 2013-12-27 09:03 - 00630272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsSpellCheckingFacility.dll 2014-03-20 19:12 - 2013-12-27 09:03 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncHost.exe 2014-03-20 19:12 - 2013-12-27 08:37 - 00588800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncCore.dll 2014-03-20 19:12 - 2013-12-21 09:21 - 00376320 _____ (Microsoft Corporation) C:\Windows\system32\pnrpsvc.dll 2014-03-20 19:12 - 2013-12-17 09:21 - 00408576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys 2014-03-20 19:12 - 2013-12-14 08:31 - 13949440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll 2014-03-20 19:12 - 2013-12-14 08:19 - 18576384 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll 2014-03-20 19:12 - 2013-12-13 12:54 - 00131160 _____ (Microsoft Corporation) C:\Windows\system32\easinvoker.exe 2014-03-20 19:12 - 2013-12-13 08:36 - 00178176 _____ (Microsoft Corporation) C:\Windows\system32\easwrt.dll 2014-03-20 19:12 - 2013-12-13 07:32 - 00140800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\easwrt.dll 2014-03-20 19:12 - 2013-12-09 10:05 - 21199256 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-03-20 19:12 - 2013-12-09 06:51 - 18643560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-03-15 15:17 - 2014-03-15 15:17 - 00001167 _____ () C:\Users\Public\Desktop\ALDI Bestellsoftware.lnk 2014-03-15 15:15 - 2014-03-15 15:17 - 00000000 ____D () C:\Program Files (x86)\ALDI Bestellsoftware 2014-03-15 15:11 - 2014-03-15 15:15 - 272937504 _____ () C:\Users\Christine\Downloads\ALDI_Bestellsoftware_Setup(2).exe 2014-03-15 15:07 - 2014-03-15 15:09 - 00000000 ____D () C:\Users\Christine\Desktop\Fotobuch 2014-03-15 15:04 - 2014-03-15 15:07 - 272937504 _____ () C:\Users\Christine\Downloads\ALDI_Bestellsoftware_Setup(1).exe 2014-03-15 14:51 - 2014-03-15 14:54 - 272937504 _____ () C:\Users\Christine\Downloads\ALDI_Bestellsoftware_Setup.exe 2014-03-15 14:27 - 2014-03-15 15:09 - 00113664 ___SH () C:\Users\Christine\Documents\Thumbs.db ==================== One Month Modified Files and Folders ======= 2014-04-14 13:49 - 2014-04-14 13:49 - 00000000 ____D () C:\Users\Christine\Desktop\FRST-OlderVersion 2014-04-14 13:49 - 2014-04-05 22:50 - 00013143 _____ () C:\Users\Christine\Desktop\FRST.txt 2014-04-14 13:49 - 2014-03-13 16:54 - 00000000 ____D () C:\FRST 2014-04-14 13:49 - 2014-03-13 16:53 - 02157568 _____ (Farbar) C:\Users\Christine\Desktop\FRST64.exe 2014-04-14 13:47 - 2014-03-26 19:21 - 00000000 ___RD () C:\Users\Christine\SkyDrive 2014-04-14 13:47 - 2013-08-22 16:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-14 13:46 - 2014-02-12 18:52 - 00000000 ____D () C:\AdwCleaner 2014-04-14 13:46 - 2013-12-25 15:36 - 00001224 _____ () C:\Users\Christine\Desktop\ALDI Süd Blumen Service.lnk 2014-04-14 13:46 - 2013-12-25 15:36 - 00001200 _____ () C:\Users\Christine\Desktop\ALDI Süd Reisen.lnk 2014-04-14 13:46 - 2013-12-25 15:36 - 00001156 _____ () C:\Users\Christine\Desktop\ALDI Talk.lnk 2014-04-14 13:46 - 2013-12-25 15:36 - 00001136 _____ () C:\Users\Christine\Desktop\ALDI Süd Startseite.lnk 2014-04-14 13:21 - 2013-12-25 16:15 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-14 13:13 - 2013-09-02 09:52 - 00765378 _____ () C:\Windows\system32\perfh007.dat 2014-04-14 13:13 - 2013-09-02 09:52 - 00159696 _____ () C:\Windows\system32\perfc007.dat 2014-04-14 13:13 - 2013-09-02 09:20 - 01780340 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-14 13:06 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\BBI 2014-04-14 13:05 - 2014-04-14 13:05 - 01426178 _____ () C:\Users\Christine\Downloads\adwcleaner.exe 2014-04-14 13:02 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\sru 2014-04-14 12:59 - 2013-12-25 15:42 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1264655104-1241458557-895395880-1001 2014-04-14 12:49 - 2013-09-02 09:14 - 00030450 _____ () C:\Windows\PFRO.log 2014-04-14 12:48 - 2013-12-25 15:19 - 01536493 _____ () C:\Windows\WindowsUpdate.log 2014-04-14 12:38 - 2014-04-14 12:38 - 00069632 _____ () C:\Users\Christine\Desktop\RichDad Finanzplaner.xls 2014-04-14 12:38 - 2013-12-25 15:59 - 00000000 ____D () C:\ProgramData\MFAData 2014-04-14 12:33 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\AppReadiness 2014-04-12 16:21 - 2014-04-12 16:21 - 00441592 _____ (Bleeping Computer, LLC) C:\Users\Christine\Downloads\sc-cleaner.exe 2014-04-12 16:21 - 2014-04-12 16:21 - 00005450 _____ () C:\sc-cleaner.txt 2014-04-12 16:21 - 2013-12-25 15:54 - 00001163 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-04-12 16:21 - 2013-12-25 15:36 - 00001454 _____ () C:\Users\Christine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-04-12 16:00 - 2014-04-09 18:56 - 00000091 _____ () C:\Users\Christine\AppData\Roaming\WB.CFG 2014-04-12 15:39 - 2014-01-31 20:01 - 00000000 ____D () C:\Program Files\Microsoft Office 15 2014-04-09 17:55 - 2014-04-09 17:55 - 00686048 _____ () C:\Users\Christine\Downloads\ZipExtractorSetup.exe 2014-04-09 17:21 - 2013-12-25 17:14 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-09 17:20 - 2013-12-25 17:14 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-09 16:38 - 2014-04-09 16:38 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-09 16:38 - 2014-04-09 16:38 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-07 22:01 - 2014-04-07 22:01 - 00000000 ____D () C:\Users\Christine\Downloads\ri1CgthP 2014-04-07 21:55 - 2014-04-07 21:55 - 00379736 _____ () C:\Users\Christine\Downloads\ri1CgthP.zip 2014-04-07 20:26 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\ELAM 2014-04-05 22:54 - 2013-12-25 15:54 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-04-05 16:10 - 2014-04-05 16:10 - 02347384 _____ (ESET) C:\Users\Christine\Downloads\esetsmartinstaller_enu.exe 2014-03-31 23:23 - 2014-02-23 11:24 - 00693240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-31 23:23 - 2014-02-23 11:24 - 00105464 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-03-31 18:18 - 2014-03-31 18:18 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-31 17:27 - 2013-12-25 16:00 - 00001001 _____ () C:\Users\Public\Desktop\AVG 2014.lnk 2014-03-31 03:16 - 2014-04-09 16:40 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 01:57 - 2014-04-09 16:40 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-26 19:21 - 2013-12-25 15:39 - 00000000 __RDO () C:\Users\Christine\SkyDrive.old 2014-03-26 19:21 - 2013-12-25 15:35 - 00000000 ____D () C:\Users\Christine 2014-03-25 23:01 - 2014-03-25 23:01 - 548760847 _____ () C:\Windows\MEMORY.DMP 2014-03-25 23:01 - 2014-03-25 23:01 - 00280008 _____ () C:\Windows\Minidump\032514-33125-01.dmp 2014-03-25 23:01 - 2014-03-25 23:01 - 00000000 ____D () C:\Windows\Minidump 2014-03-24 17:50 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\rescache 2014-03-21 19:35 - 2013-12-25 15:37 - 00000000 ___RD () C:\Users\Christine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-03-21 19:35 - 2013-12-25 15:37 - 00000000 ___RD () C:\Users\Christine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-03-20 23:54 - 2013-08-22 17:36 - 00000000 ___RD () C:\Windows\ToastData 2014-03-15 15:17 - 2014-03-15 15:17 - 00001167 _____ () C:\Users\Public\Desktop\ALDI Bestellsoftware.lnk 2014-03-15 15:17 - 2014-03-15 15:15 - 00000000 ____D () C:\Program Files (x86)\ALDI Bestellsoftware 2014-03-15 15:15 - 2014-03-15 15:11 - 272937504 _____ () C:\Users\Christine\Downloads\ALDI_Bestellsoftware_Setup(2).exe 2014-03-15 15:09 - 2014-03-15 15:07 - 00000000 ____D () C:\Users\Christine\Desktop\Fotobuch 2014-03-15 15:09 - 2014-03-15 14:27 - 00113664 ___SH () C:\Users\Christine\Documents\Thumbs.db 2014-03-15 15:07 - 2014-03-15 15:04 - 272937504 _____ () C:\Users\Christine\Downloads\ALDI_Bestellsoftware_Setup(1).exe 2014-03-15 15:07 - 2014-01-30 22:53 - 00736256 ___SH () C:\Users\Christine\Desktop\Thumbs.db 2014-03-15 14:54 - 2014-03-15 14:51 - 272937504 _____ () C:\Users\Christine\Downloads\ALDI_Bestellsoftware_Setup.exe Some content of TEMP: ==================== C:\Users\Christine\AppData\Local\Temp\BackupSetup.exe C:\Users\Christine\AppData\Local\Temp\ICReinstall_ZipExtractorSetup.exe C:\Users\Christine\AppData\Local\Temp\OfficeSetup.exe C:\Users\Christine\AppData\Local\Temp\Quarantine.exe C:\Users\Christine\AppData\Local\Temp\Setup.X86.de-DE_HomeStudentRetail_39a7859d-667d-4560-ba8d-b7b14d319606_TX_DB_.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys [2014-03-13 16:25] - [2014-01-31 18:15] - 0311640 ___AC (Microsoft Corporation) C85C075DE5B6D0FE116043054DE8EE02 LastRegBack: 2014-04-14 12:59 ==================== End Of Log ============================ --- --- --- --- --- --- --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-04-2014 01 Ran by Christine at 2014-04-14 13:49:51 Running from C:\Users\Christine\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: AVG AntiVirus Free Edition 2014 (Enabled - Up to date) {B5F5C120-2089-702E-0001-553BB0D5A664} ==================== Installed Programs ====================== Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated) ALDI Bestellsoftware 4.13.1 (HKLM-x32\...\ALDI Bestellsoftware) (Version: 4.13.1 - ORWO Net) Ashampoo AppLauncher (Medion) v.1.0.0 (HKLM-x32\...\Ashampoo AppLauncher (Medion)_is1) (Version: 1.0.0 - Ashampoo GmbH & Co. KG) AVG 2014 (HKLM\...\AVG) (Version: 2014.0.4355 - AVG Technologies) AVG 2014 (Version: 14.0.3882 - AVG Technologies) Hidden AVG 2014 (Version: 14.0.4355 - AVG Technologies) Hidden CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.2.4478 - CDBurnerXP) CyberLink LabelPrint 2.5 (x32 Version: 2.5.5415 - CyberLink Corp.) Hidden CyberLink MediaEspresso 6.5 (x32 Version: 6.5.3807_46074 - CyberLink Corp.) Hidden CyberLink PhotoDirector 3 (x32 Version: 3.0.4017 - CyberLink Corp.) Hidden CyberLink Power2Go 8 (x32 Version: 8.0.0.2426b - CyberLink Corp.) Hidden CyberLink PowerDirector (Version: 9.0.0.5129 - CyberLink Corp.) Hidden CyberLink PowerDVD 10 (x32 Version: 10.0.5211.02 - CyberLink Corp.) Hidden CyberLink PowerDVD Copy 1.5 (x32 Version: 1.5.0.3725 - CyberLink Corp.) Hidden CyberLink PowerRecover (HKLM-x32\...\InstallShield_{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}) (Version: 5.7.0.0913 - CyberLink Corp.) CyberLink PowerRecover (Version: 5.7.0.0913 - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Fotogalerie (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Fotogalerija (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Fotogalleri (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Fotogalleriet (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Fotoğraf Galerisi (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Fotótár (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Galeria de Fotografias (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Galería de fotos (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Galeria fotografii (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Galerie de photos (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden HP Officejet 6600 - Grundlegende Software für das Gerät (HKLM\...\{F58934BD-F483-43EB-B307-CFFD88B18455}) (Version: 28.0.1315.0 - Hewlett-Packard Co.) HP Officejet 6600 Hilfe (HKLM-x32\...\{2FA81482-5570-4CF0-9A10-D61D2F164916}) (Version: 140.0.2.2 - Hewlett Packard) HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard) I.R.I.S. OCR (HKLM-x32\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3282 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.0.1016 - Intel Corporation) Intel(R) Rapid Storage Technology (Version: 12.8.0.1016 - Intel Corporation) Hidden Java 7 Update 45 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417045FF}) (Version: 7.0.450 - Oracle) Malwarebytes Anti-Malware Version 1.75.0.1300 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation) Medion Home Cinema 10 (HKLM-x32\...\InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}) (Version: 10.0 - CyberLink Corp.) Medion Home Cinema 10 (x32 Version: 10.2419 - CyberLink Corp.) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office Home and Student 2013 - de-de (HKLM\...\HomeStudentRetail - de-de) (Version: 15.0.4605.1003 - Microsoft Corporation) Microsoft SkyDrive (HKCU\...\SkyDriveSetup.exe) (Version: 17.0.2015.0811 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Mozilla Firefox 28.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4605.1003 - Microsoft Corporation) Hidden Office 15 Click-to-Run Licensing Component (Version: 15.0.4605.1003 - Microsoft Corporation) Hidden Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4605.1003 - Microsoft Corporation) Hidden Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Photo Gallery (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden PhotoNow (x32 Version: 1.1.7717 - CyberLink Corp.) Hidden Podstawowe programy Windows Live (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Raccolta foto (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.18.621.2013 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7027 - Realtek Semiconductor Corp.) Studie zur Verbesserung von HP Officejet 6600 Produkten (HKLM\...\{E1A11879-5771-4E52-BA2E-CD5DD65BF970}) (Version: 28.0.1315.0 - Hewlett-Packard Co.) Valokuvavalikoima (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies) Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) VLC media player 2.1.1 (HKLM\...\VLC media player) (Version: 2.1.1 - VideoLAN) Windows Live (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Communications Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation) Windows Live Essentials (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Temel Parçalar (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Liven peruspaketti (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden WinZip Malware Protector (HKLM-x32\...\WinZip Malware Protector_is1) (Version: 2.1.1000.10798 - WinZip International LLC) Συλλογή φωτογραφιών (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden ==================== Restore Points ========================= 25-03-2014 16:28:44 Windows Update 03-04-2014 15:35:13 Geplanter Prüfpunkt 09-04-2014 15:19:33 Windows Update ==================== Hosts content: ========================== 2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {03DCE08C-E6A0-4B69-A50C-D878DC099742} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2014-04-09] (Microsoft Corporation) Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask Task: {24182636-8513-4F0F-8131-B33CB17A2FED} - System32\Tasks\HPCustParticipation HP Officejet 6600 => C:\Program Files\HP\HP Officejet 6600\Bin\HPCustPartic.exe [2012-10-17] (Hewlett-Packard Co.) Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate Task: {34D802AF-4975-45FB-BB01-F428220DE692} - \Digital Sites ATTENTION ====> No Task File Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation) Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation) Task: {456D62CB-00F4-4F88-BC0D-9DF289B1A31C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-12] (Adobe Systems Incorporated) Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance Task: {65C41B78-5E18-4C1B-AD67-D5575E3EE3D7} - System32\Tasks\WinZip Malware Protector_startup => C:\Program Files (x86)\WinZip Malware Protector\WinZipMalwareProtector.exe Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask Task: {93ECF6BE-7DF9-4834-A390-6805351876DD} - \MySearchDial ATTENTION ====> No Task File Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE Task: {F27EFEF5-F3CD-4665-87F9-B2FB4E5B4313} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2014-03-30] (Microsoft Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2014-03-21 19:44 - 2013-10-31 18:13 - 00102568 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll 2014-01-31 20:01 - 2014-03-25 13:21 - 00629928 _____ () C:\Program Files\Microsoft Office 15\ClientX64\StreamServer.dll 2013-09-03 07:50 - 2010-08-19 18:43 - 00386344 _____ () C:\Program Files\CyberLink\Shared files\RichVideo64.exe 2014-04-12 15:24 - 2014-04-12 15:27 - 00183296 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20461_x64__8wekyb3d8bbwe\ErrorReporting.dll 2013-09-03 07:48 - 2013-03-05 05:40 - 00626240 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll 2013-03-05 12:41 - 2013-03-05 12:41 - 00015424 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll 2014-03-31 18:18 - 2014-03-31 18:18 - 03642480 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\Christine\SkyDrive:ms-properties AlternateDataStreams: C:\Users\Christine\SkyDrive.old:ms-properties ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= Name: WLAN USB Device Description: WLAN USB Device Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (04/14/2014 01:43:18 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: firefox.exe, Version: 28.0.0.5186, Zeitstempel: 0x53240e37 Name des fehlerhaften Moduls: xul.dll, Version: 28.0.0.5186, Zeitstempel: 0x53240e04 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00184729 ID des fehlerhaften Prozesses: 0x3fc Startzeit der fehlerhaften Anwendung: 0xfirefox.exe0 Pfad der fehlerhaften Anwendung: firefox.exe1 Pfad des fehlerhaften Moduls: firefox.exe2 Berichtskennung: firefox.exe3 Vollständiger Name des fehlerhaften Pakets: firefox.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: firefox.exe5 Error: (04/09/2014 09:04:31 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: firefox.exe, Version: 28.0.0.5186, Zeitstempel: 0x53240e37 Name des fehlerhaften Moduls: xul.dll, Version: 28.0.0.5186, Zeitstempel: 0x53240e04 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00184729 ID des fehlerhaften Prozesses: 0x1654 Startzeit der fehlerhaften Anwendung: 0xfirefox.exe0 Pfad der fehlerhaften Anwendung: firefox.exe1 Pfad des fehlerhaften Moduls: firefox.exe2 Berichtskennung: firefox.exe3 Vollständiger Name des fehlerhaften Pakets: firefox.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: firefox.exe5 Error: (04/09/2014 08:37:42 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.3.9600.16441, Zeitstempel: 0x5265dec8 Name des fehlerhaften Moduls: igd10iumd64.dll, Version: 10.18.10.3282, Zeitstempel: 0x521badba Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000000d4d4 ID des fehlerhaften Prozesses: 0x10f0 Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Vollständiger Name des fehlerhaften Pakets: Explorer.EXE4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Explorer.EXE5 Error: (04/07/2014 10:00:48 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifest. Error: (04/05/2014 10:45:54 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifest. Error: (04/05/2014 04:16:08 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifest. Error: (04/05/2014 04:16:04 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifest. Error: (04/05/2014 04:10:53 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifest. Error: (04/05/2014 04:10:53 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifest. Error: (03/19/2014 06:25:39 PM) (Source: Application Hang) (User: ) Description: Programm LiveComm.exe, Version 17.5.9600.20413 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1b40 Startzeit: 01cf438f2491045b Endzeit: 4294967295 Anwendungspfad: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20413_x64__8wekyb3d8bbwe\LiveComm.exe Berichts-ID: 18696153-af83-11e3-8285-d43d7eb0282d Vollständiger Name des fehlerhaften Pakets: microsoft.windowscommunicationsapps_17.5.9600.20413_x64__8wekyb3d8bbwe Anwendungs-ID, die relativ zum fehlerhaften Paket ist: ppleae38af2e007f4358a809ac99a64a67c1 System errors: ============= Error: (04/14/2014 01:46:50 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Superfetch" wurde mit folgendem Fehler beendet: %%1062 Error: (03/25/2014 11:01:29 PM) (Source: BugCheck) (User: ) Description: 0x000000ab (0x0000000000000004, 0x0000000000000210, 0x0000000000000000, 0x0000000000000002)C:\Windows\MEMORY.DMP032514-33125-01 Error: (03/25/2014 11:01:19 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 25.03.2014 um 19:12:39 unerwartet heruntergefahren. Error: (03/12/2014 08:08:22 PM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 40. Der Windows-SChannel-Fehlerstatus lautet: 252. Error: (03/12/2014 08:08:22 PM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert und an den Remoteendpunkt gesendet. Dies kann dazu führen, dass die Verbindung beendet wird. Die schwerwiegende Warnung hat folgenden für das TLS-Protokoll definierten Code: 40. Der Windows-SChannel-Fehlerstatus lautet: 252. Error: (03/11/2014 10:28:42 PM) (Source: DCOM) (User: SNOWDONIA) Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9} Error: (03/11/2014 10:28:42 PM) (Source: DCOM) (User: SNOWDONIA) Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9} Error: (03/06/2014 09:24:55 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 06.03.2014 um 18:24:58 unerwartet heruntergefahren. Error: (02/23/2014 11:25:07 AM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT) Description: Fehler bei der CBS-Clientinitialisierung. Letzter Fehler: 0x80080005 Error: (02/23/2014 11:25:07 AM) (Source: DCOM) (User: NT-AUTORITÄT) Description: {752073A1-23F2-4396-85F0-8FDB879ED0ED} Microsoft Office Sessions: ========================= Error: (04/14/2014 01:43:18 PM) (Source: Application Error)(User: ) Description: firefox.exe28.0.0.518653240e37xul.dll28.0.0.518653240e04c0000005001847293fc01cf57d1d42a2f74C:\Program Files (x86)\Mozilla Firefox\firefox.exeC:\Program Files (x86)\Mozilla Firefox\xul.dllf8906559-c3c9-11e3-828b-d43d7eb0282d Error: (04/09/2014 09:04:31 PM) (Source: Application Error)(User: ) Description: firefox.exe28.0.0.518653240e37xul.dll28.0.0.518653240e04c000000500184729165401cf5422e74f4904C:\Program Files (x86)\Mozilla Firefox\firefox.exeC:\Program Files (x86)\Mozilla Firefox\xul.dllc7a60cd5-c019-11e3-8288-d43d7eb0282d Error: (04/09/2014 08:37:42 PM) (Source: Application Error)(User: ) Description: Explorer.EXE6.3.9600.164415265dec8igd10iumd64.dll10.18.10.3282521badbac0000005000000000000d4d410f001cf54013de732c6C:\Windows\Explorer.EXEC:\Windows\SYSTEM32\igd10iumd64.dll0880ec07-c016-11e3-8288-d43d7eb0282d Error: (04/07/2014 10:00:48 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifestC:\Users\Christine\Downloads\esetsmartinstaller_enu.exe Error: (04/05/2014 10:45:54 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifestC:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe Error: (04/05/2014 04:16:08 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifestC:\Users\Christine\Downloads\esetsmartinstaller_enu.exe Error: (04/05/2014 04:16:04 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifestC:\Users\Christine\Downloads\esetsmartinstaller_enu.exe Error: (04/05/2014 04:10:53 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifestC:\Users\Christine\Downloads\esetsmartinstaller_enu.exe Error: (04/05/2014 04:10:53 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_62475f7becb72503.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.16384_none_a9f4965301334e09.manifestC:\Users\Christine\Downloads\esetsmartinstaller_enu.exe Error: (03/19/2014 06:25:39 PM) (Source: Application Hang)(User: ) Description: LiveComm.exe17.5.9600.204131b4001cf438f2491045b4294967295C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20413_x64__8wekyb3d8bbwe\LiveComm.exe18696153-af83-11e3-8285-d43d7eb0282dmicrosoft.windowscommunicationsapps_17.5.9600.20413_x64__8wekyb3d8bbweppleae38af2e007f4358a809ac99a64a67c1 ==================== Memory info =========================== Percentage of memory in use: 40% Total physical RAM: 4018.27 MB Available physical RAM: 2374.59 MB Total Pagefile: 8114.27 MB Available Pagefile: 6510.6 MB Total Virtual: 131072 MB Available Virtual: 131071.83 MB ==================== Drives ================================ Drive c: (Boot) (Fixed) (Total:869.8 GB) (Free:818.82 GB) NTFS Drive d: (Recover) (Fixed) (Total:60 GB) (Free:45.16 GB) NTFS Drive e: (Lexar) (Removable) (Total:29.24 GB) (Free:10.54 GB) FAT32 Drive h: (KINGSTON) (Removable) (Total:7.45 GB) (Free:3.06 GB) FAT32 Drive j: (ADATA UFD) (Removable) (Total:3.76 GB) (Free:0.5 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 932 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ======================================================== Disk: 1 (Size: 7 GB) (Disk ID: 4197726C) Partition 1: (Not Active) - (Size=7 GB) - (Type=0B) ======================================================== Disk: 2 (Size: 4 GB) (Disk ID: 04DD5721) Partition 1: (Not Active) - (Size=4 GB) - (Type=0C) ======================================================== Disk: 4 (MBR Code: Windows XP) (Size: 29 GB) (Disk ID: C3072E18) Partition: GPT Partition Type. ==================== End Of Log ============================ Bin gespannt! und dankeeeeee |
14.04.2014, 21:35 | #20 |
Ruhe in Frieden † 2019 | ich werde die Startseite awesomehp nicht los, was kann ich noch tun? Ja, das sieht schon fast gut aus Ich seh da aber noch zwei Antivirenprogramme, du solltest dich für eines von beiden entscheiden und das andere deinstallieren. Und Java (siehe auch mein allclean auf Seite 1) updaten . Schritt 1 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\Users\Christine\Downloads\ZipExtractorSetup.exe C:\Users\Christine\AppData\Local\Temp\ICReinstall_ZipExtractorSetup.exe C:\Users\Christine\AppData\Local\Temp\BackupSetup.exe Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
|
Themen zu ich werde die Startseite awesomehp nicht los, was kann ich noch tun? |
arten, awesomehp, awesomehp entfernen, eingefangen, gen, installieren, internet, pup.optional.awesomehp.a, pup.optional.bundleinstaller.a, pup.optional.conduit.a, pup.optional.iepluginservice.a, pup.optional.skytech.a, pup.optional.suptab.a, pup.optional.wpmanager, seite, startseite, troja, trojaner, trojaner board, updates, verändert |