|
Plagegeister aller Art und deren Bekämpfung: Viel Werbung bei internet explorerWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
18.04.2014, 17:49 | #1 |
| Viel Werbung bei internet explorer Hallo com Schon seit längere zeit habe ich das problem das vertstärkt werbung auftritt im internet explorer.Ich habe leider nicht viel ahnung mit viren usw Vieleicht könnnt ihr ja helfen |
18.04.2014, 20:14 | #2 |
/// the machine /// TB-Ausbilder | Viel Werbung bei internet explorer hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
19.04.2014, 07:51 | #3 |
| Viel Werbung bei internet explorer hier die AdditionFRST Additions Logfile:
__________________Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-04-2014 01 Ran by Daniel at 2014-04-19 08:33:56 Running from C:\Users\Daniel\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== 50CoupoNs (HKLM-x32\...\{CF987D06-1DCF-7B36-5B43-13BC8699C44C}) (Version: - 550CoupoNs) <==== ATTENTION Adobe Acrobat 4.0 (HKLM-x32\...\Adobe Acrobat 4.0) (Version: - ) Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Reader X (10.1.9) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.9 - Adobe Systems Incorporated) Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.4.144 - Adobe Systems, Inc.) Advanced Audio FX Engine (HKLM-x32\...\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd) Airport Simulator 2013 Demo Version 1.0 (HKLM-x32\...\{67F30877-CBBB-425C-9511-93181EFB8F08}_is1) (Version: 1.0 - rondomedia) Ask Toolbar (HKLM-x32\...\{86D4B82A-ABED-442A-BE86-96357B70F4FE}) (Version: 1.15.14.0 - Ask.com) <==== ATTENTION Ask Toolbar Updater (HKCU\...\{79A765E1-C399-405B-85AF-466F52E918B0}) (Version: 1.2.3.29495 - Ask.com) <==== ATTENTION Assassin's Creed II (HKLM\...\{8570BEE8-0CA3-4977-9AB1-80ED93F0513C}) (Version: 1.00 - Ubisoft) Assassin's Creed II (HKLM-x32\...\{8570BEE8-0CA3-4977-9AB1-80ED93F0513C}) (Version: 1.00 - Ubisoft) Assistant (HKLM-x32\...\{5F189DF5-2D05-472B-9091-84D9848AE48B}{699fd52f}) (Version: - Verified Publisher) Audiograbber 1.83 SE (HKLM-x32\...\Audiograbber) (Version: 1.83 SE - Audiograbber) Bau-Simulator 2012 Version 1.0 (HKLM-x32\...\{AEF59382-3FF1-4EBF-A93E-CCC474DCEA3F}_is1) (Version: 1.0 - weltenbauer. Software Entwicklung GmbH) Black_Box v1 (HKLM-x32\...\Assassin's Creed 2_is1) (Version: - ) Blue Byte Game Channel (HKLM-x32\...\Blue Byte Game Channel) (Version: - UbiSoft) Bombenterror (HKCU\...\Bombenterror) (Version: - ) Coupon Alerts (HKLM-x32\...\37436_Coupon Alerts) (Version: 1.3 - Smart Apps) <==== ATTENTION Craften Terminal 3.4.5011.37604 (HKLM-x32\...\{4e7c3936-7c06-4ef0-928b-c5d92f372578}_is1) (Version: 3.4.5011.37604 - Craften.de) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Dart701OU (HKCU\...\Dart701OU) (Version: - ) DeaalExpREss (HKLM-x32\...\{25F259ED-12F6-429F-5783-527C3E2F8586}) (Version: - DeealExpress) DealPly (HKCU\...\DealPly) (Version: - ) <==== ATTENTION Dell DataSafe Local Backup - Support Software (HKLM-x32\...\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 9.4.57 - Dell Inc.) Dell DataSafe Local Backup (HKLM-x32\...\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 9.4.57 - Dell Inc.) Dell DataSafe Online (HKLM-x32\...\{7EC66A95-AC2D-4127-940B-0445A526AB2F}) (Version: 2.1.19634 - Dell) Dell Edoc Viewer (HKLM\...\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc) Dell Getting Started Guide (HKLM-x32\...\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.) Dell MusicStage (HKLM-x32\...\{3255BC3F-32BA-41ED-93A0-B9AEB6CDD9E6}) (Version: 1.5.201.0 - Fingertapps) Dell PhotoStage (HKLM-x32\...\{E4335E82-17B3-460F-9E70-39D9BC269DB3}) (Version: 1.5.0.65 - ArcSoft) Dell Stage (HKLM-x32\...\{56A0DD94-47D9-4AC8-B5A1-8A8CA77C4B89}) (Version: 1.5.201.0 - Fingertapps) Dell Touchpad (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 7.1209.101.204 - ALPS ELECTRIC CO., LTD.) Dell VideoStage (HKLM-x32\...\InstallShield_{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}) (Version: 1.2.0.1712 - CyberLink Corp.) Dell VideoStage (x32 Version: 1.2.0.1712 - CyberLink Corp.) Hidden Dell Webcam Central (HKLM-x32\...\Dell Webcam Central) (Version: 2.00.44 - Creative Technology Ltd) Delta Chrome Toolbar (HKLM-x32\...\Delta Chrome Toolbar) (Version: - Visual Tools) <==== ATTENTION Delta toolbar (HKLM-x32\...\delta) (Version: 1.8.21.5 - Delta) <==== ATTENTION Demolition Company (HKLM-x32\...\DemolitionCompanyDE_is1) (Version: - GIANTS Software) Demolition Company Demo (HKLM-x32\...\DemolitionCompanyDemoDE_is1) (Version: - GIANTS Software) Die Siedler IV (HKLM-x32\...\S4Uninst) (Version: - ) Die Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.67.2 - Electronic Arts) Die Sims™ 3 Showtime (HKLM-x32\...\{3BBFD444-5FAB-49F6-98B1-A1954E831399}) (Version: 12.0.273 - Electronic Arts) DirectX 9 Runtime (x32 Version: 1.00.0000 - Sonic Solutions) Hidden Euro Truck Simulator 2 (HKLM-x32\...\{1B705E8F-9893-4486-B5D7-4F7FEB9C871E}_is1) (Version: 1.1.1 - SCS Software) FileConverter 1.3 Toolbar (HKLM-x32\...\FileConverter_1.3 Toolbar) (Version: 6.9.0.16 - FileConverter 1.3) FTDownloader (HKLM-x32\...\1ClickDownload) (Version: 2.1 Build 26473 - FTDownloader.com) <==== ATTENTION Funmoods (HKLM-x32\...\funmoods) (Version: - Volonet Ltd) <==== ATTENTION GameSpy Arcade (HKLM-x32\...\GameSpy Arcade) (Version: - ) German Truck Simulator 1.00 (HKLM-x32\...\German Truck Simulator) (Version: 1.00 - ) GIANTS Editor 5.0.1 (HKLM-x32\...\giants_editor_5.0.1_is1) (Version: 5.0.1 - GIANTS Software GmbH) GIMP 2.8.6 (HKLM\...\GIMP-2_is1) (Version: 2.8.6 - The GIMP Team) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 32.0.1700.102 - Google Inc.) Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) Hidden Grand Ages Rome 1.01 (HKLM-x32\...\Civitas3) (Version: 1.01 - Kalypso Media) Grand Theft Auto San Andreas (HKLM-x32\...\{086BADF8-9B1F-4E89-B207-2EDA520972D6}) (Version: 1.00.00001 - Rockstar Games) grieatsaaVeRR (HKLM-x32\...\{CA41BB14-E67B-1653-C57B-5CA99418A866}) (Version: 3.1.0.1554 - grreatsaver) <==== ATTENTION GS-Enabler (HKLM-x32\...\S-960308484) (Version: 4.3.0.1686 - PremiumSoft) <==== ATTENTION Hamburg Demolition Addon version 1.0 (HKLM-x32\...\Hamburg Demolition Addon_is1) (Version: 1.0 - ) Holzfäller Simulator 2012 (HKLM-x32\...\Woodcutter Simulator 2012) (Version: - ) IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6324.0 - IDT) Iminent (HKLM-x32\...\IMBoosterARP) (Version: 6.23.53.0 - Iminent) <==== ATTENTION Iminent (x32 Version: 6.23.53.0 - Iminent) Hidden <==== ATTENTION Iminent Toolbar For Internet Explorer (HKLM-x32\...\{A76AA284-E52D-47E6-9E4F-B85DBF8E35C3}) (Version: 3.26.0 - Iminent) <==== ATTENTION Install Supporter 1.80 (HKLM-x32\...\{5F189DF5-2D05-472B-9091-84D9848AE48B}{1a34a8e0}) (Version: - Certified Publisher) Intel PROSet Wireless (Version: - ) Hidden Intel PROSet Wireless (x32 Version: - ) Hidden Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1118 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2361 - Intel Corporation) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{7CE8BE79-ABC3-4B2C-9543-28ED2B0A9EA8}) (Version: 1.2.0.0587 - Intel Corporation) Intel(R) PROSet/Wireless WiFi-Software (HKLM\...\{25FBDA9A-E868-4B3B-B9FF-D923818511A1}) (Version: 14.2.0000 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.0.1008 - Intel Corporation) Intel(R) WiDi (HKLM-x32\...\{25680C01-6753-4FE9-A891-7857F26457C1}) (Version: 2.1.35.0 - Intel Corporation) Intel(R) Wireless Display (HKLM\...\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version: - ) Internet Explorer Toolbar 4.6 by SweetPacks (HKLM-x32\...\{C3E85EE9-5892-4142-B537-BCEB3DAC4C3D}) (Version: 4.6.0004 - SweetIM Technologies Ltd.) <==== ATTENTION Java Auto Updater (x32 Version: 2.0.7.2 - Sun Microsystems, Inc.) Hidden Java(TM) 6 Update 27 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86416027FF}) (Version: 6.0.270 - Oracle) Java(TM) 6 Update 38 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216038FF}) (Version: 6.0.380 - Oracle) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden KLIX (HKCU\...\KLIX) (Version: - ) Landwirtschafts Simulator 2011 (HKLM-x32\...\FarmingSimulator2011DE_is1) (Version: 1.0 - GIANTS Software) Landwirtschafts Simulator 2013 (HKLM-x32\...\FarmingSimulator2013DE_is1) (Version: 1.0 - GIANTS Software) Landwirtschafts Simulator 2013 Demo (HKLM-x32\...\FarmingSimulator2013DemoDE_is1) (Version: 1.0 - GIANTS Software) Landwirtschafts Simulator 2013 Hagensted Modified 2013 (HKLM-x32\...\{F09E06EB-D878-4E4E-9190-84E3C4C1DC27}_is1) (Version: Landwirtschafts Simulator 2013 Hagensted Modified 3.1.0 - Black Panther Group) League of Legends (HKLM-x32\...\{92606477-9366-4D3B-8AE3-6BE4B29727AB}) (Version: 1.3 - Riot Games) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Train Simulator (HKLM-x32\...\Train Simulator 1.0) (Version: - ) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{820B6609-4C97-3A2B-B644-573B06A0F0CC}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Mindjet (HKLM-x32\...\{6D1AFA44-6E87-41F5-B7D4-4C457A98A3A3}) (Version: 11.1.353 - Mindjet) Minecraft PC Gamer Demo version 1.5 (HKLM-x32\...\{55D65D27-C0CD-4375-9021-F3D3D024ED90}_is1) (Version: 1.5 - Mojang) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) My Dell (HKLM\...\PC-Doctor for Windows) (Version: 3.4.6308.28 - PC-Doctor, Inc.) Need for Speed™ Most Wanted (HKLM-x32\...\{A48B9CD8-C2BA-4EC9-0081-7260D238C7CF}) (Version: - ) NVIDIA 3D Vision Treiber 268.30 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 268.30 - NVIDIA Corporation) NVIDIA Grafiktreiber 268.30 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 268.30 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.2.22.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.2.22.1 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.265.41.0 - NVIDIA Corporation) Hidden NVIDIA Optimus 1.0.21 (Version: 1.0.21 - NVIDIA Corporation) Hidden NVIDIA PhysX (HKLM-x32\...\{1C4551A6-4743-4093-91E4-1477CD655043}) (Version: 9.09.0203 - NVIDIA Corporation) NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.12.6830 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 268.30 (Version: 268.30 - NVIDIA Corporation) Hidden NVIDIA Update Components (Version: 1.0.21 - NVIDIA Corporation) Hidden NWZ-B170 WALKMAN Guide (HKLM-x32\...\{B91B14D5-B817-4C79-BEF6-0A7A23FE6C61}) (Version: 2.1.0.33220 - Sony Corporation) OpenOffice.org 3.4.1 (HKLM-x32\...\{2303AEEA-0FA8-4AFD-80A9-8F86BA4B44D2}) (Version: 3.41.9593 - Apache Software Foundation) Origin (HKLM-x32\...\Origin) (Version: 9.2.1.4399 - Electronic Arts, Inc.) Packs World 2 (HKCU\...\Packs World 2) (Version: - ) Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.8 - Pando Networks Inc.) PDF-XChange 3 (HKLM\...\PDF-XChange 3_is1) (Version: - Tracker Software) PhotoShowExpress (x32 Version: 2.0.063 - Sonic Solutions) Hidden Plus-HD-2.2 (HKLM-x32\...\Plus-HD-2.2) (Version: 1.27.153.6 - Plus HD) <==== ATTENTION PoolBallMasch (HKCU\...\PoolBallMasch) (Version: - ) Puzzle Ship (HKCU\...\Puzzle Ship) (Version: - ) Quickset64 (HKLM\...\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 10.09.20 - Dell Inc.) RBVirtualFolder64Inst (Version: 1.00.0000 - Roxio, Inc.) Hidden Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.31.1025.2010 - Realtek) Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30126 - Realtek Semiconductor Corp.) Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.32.0 - Renesas Electronics Corporation) Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.32.0 - Renesas Electronics Corporation) Hidden Roxio Activation Module (x32 Version: 1.0 - Roxio) Hidden Roxio BackOnTrack (x32 Version: 1.3.3 - Roxio) Hidden Roxio Burn (x32 Version: 1.8 - Roxio) Hidden Roxio Creator Starter (HKLM-x32\...\{6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}) (Version: 12.1.77.0 - Roxio) Roxio Creator Starter (x32 Version: 1.0.439 - Roxio) Hidden Roxio Creator Starter (x32 Version: 5.0.0 - Roxio) Hidden Roxio Express Labeler 3 (x32 Version: 3.2.2 - Roxio) Hidden Roxio File Backup (Version: 1.3.2 - Roxio) Hidden Schwebebahn-Simulator 2013 Demo (HKLM-x32\...\{983E191D-6DE0-4E12-811B-61E4A514A665}_is1) (Version: - rondomedia Marketing & Vertriebs GmbH) SimCity 4 Deluxe (HKLM-x32\...\{3F0D0ABE-CDAF-431A-00BC-CBBE018EA74E}) (Version: - ) Skiregion Simulator 2012 Demo (HKLM-x32\...\SkiRegionSimulator2012DemoDE_is1) (Version: 1.0 - GIANTS Software) Skype Toolbars (HKLM-x32\...\{981029E0-7FC9-4CF3-AB39-6F133621921A}) (Version: 1.0.4051 - Skype Technologies S.A.) Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) Softonic toolbar on IE and Chrome (HKLM-x32\...\Softonic) (Version: 1.8.16.10 - Softonic) <==== ATTENTION Sonic CinePlayer Decoder Pack (x32 Version: 4.3.0 - Sonic Solutions) Hidden SpinTires Tech Demo (June 060613) (HKLM-x32\...\{9AF7D6F5-50A5-432C-9F7B-83BCE03B11A0}) (Version: 1.3 - Oovee) Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) Stronghold (HKLM-x32\...\{C917BA70-28A3-4C74-B163-41FD8C8E1A5A}) (Version: 1.20.0000 - Firefly Studios) Stronghold 2 (HKLM-x32\...\{16D2C649-CBA8-44EE-B730-12584667D487}) (Version: 1.40.1000 - Firefly Studios) Stronghold Crusader Extreme (HKLM-x32\...\{8C3727F2-8E37-49E4-820C-03B1677F53B6}) (Version: 1.20.0000 - Firefly Studios) Stronghold Legends (HKLM-x32\...\{66A405D2-BA14-4594-BF36-B3B544F0754E}) (Version: 1.20.0000 - Firefly Studios) SweetIM for Messenger 3.7 (HKLM-x32\...\{A0C9DF2B-89B5-4483-8983-18A68200F1B4}) (Version: 3.7.0007 - SweetIM Technologies Ltd.) <==== ATTENTION SweetPacks bundle uninstaller (HKLM-x32\...\{953AA732-9AFB-49C9-84A4-7F96CA0A08DA}) (Version: 1.0.0001 - SweetIM Technologies Ltd.) <==== ATTENTION swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden TubeeeItAdBlockFr (HKLM-x32\...\{94EEB800-E533-7AE1-5C31-0446E1C0537C}) (Version: - TubeIutAdBlockFri) Upd Inst (HKLM-x32\...\S-5153193369) (Version: 1.3.0.1133 - PremiumSoft) Update Manager for SweetPacks 1.1 (HKLM-x32\...\{EA8FA6BE-29BE-4AF2-9352-841F83215EB0}) (Version: 1.1.0008 - SweetIM Technologies Ltd.) <==== ATTENTION Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden WinRAR 4.20 (32-Bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH) WiseConvert 1.3 Toolbar (HKLM-x32\...\WiseConvert_1.3 Toolbar) (Version: 6.9.0.16 - WiseConvert 1.3) Worms Reloaded (HKLM-x32\...\Steam App 22600) (Version: - Team17) Yontoo 1.10.04 (HKLM\...\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}) (Version: 1.10.04 - Yontoo LLC) <==== ATTENTION YoutubeAdblocker (HKLM-x32\...\{4820778D-AB0D-6D18-C316-52A6A0E1D507}) (Version: 4.3.0.1656 - YoutubeAdblocker) <==== ATTENTION ==================== Restore Points ========================= 17-03-2014 14:33:31 Windows-Sicherung 19-03-2014 09:00:11 Windows Update 22-03-2014 17:00:54 Windows Update 23-03-2014 14:56:16 Installiert The Sims 3 23-03-2014 18:00:31 Windows-Sicherung 03-04-2014 14:09:21 Windows Update 03-04-2014 14:16:19 Windows-Sicherung 06-04-2014 17:07:17 Windows-Sicherung 12-04-2014 16:54:05 Windows Update 12-04-2014 18:26:53 Windows Update 13-04-2014 17:00:36 Windows-Sicherung 18-04-2014 15:28:12 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2014-03-01 07:40 - 00000871 ____A C:\windows\system32\Drivers\etc\hosts 54.204.28.26 cbaiddeoemldinncijanafifphajjppj ==================== Scheduled Tasks (whitelisted) ============= Task: {02D6417B-C037-46FC-B9B9-F8E62A2B986A} - System32\Tasks\EPUpdater => C:\Users\Daniel\AppData\Roaming\BabSolution\Shared\BabMaint.exe [2013-06-06] () <==== ATTENTION Task: {041DCCF9-7534-40F7-95D2-8827A27C37A1} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\My Dell\sessionchecker.exe [2013-09-06] (PC-Doctor, Inc.) Task: {1B77930F-D063-49C1-A53B-E1335C48DA34} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-12] (Adobe Systems Incorporated) Task: {1CD4D816-4476-4533-84A6-A35261E0C784} - System32\Tasks\Plus-HD-2.2-codedownloader => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-codedownloader.exe [2013-06-15] (Plus HD) <==== ATTENTION Task: {28F9629D-C097-4D31-8155-5C14115641A5} - System32\Tasks\Upd Inst-S-5153193369 => c:\programdata\superbapp\upd inst\Upd Inst.exe [2014-04-18] () Task: {30693492-09AF-4A61-933C-DA4081E04649} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-03] (Google Inc.) Task: {4166CC7A-E67E-4FF7-808A-D6224D6F036A} - System32\Tasks\DealPly => C:\Users\Daniel\AppData\Roaming\DealPly\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: {59520B43-A622-40DA-8C08-DC8218260209} - System32\Tasks\FF Watcher {AF1C556F-48FB-4E74-AA3F-A1BA1EB90CE9} => C:\Program Files\V-bates\PrefHelper.exe Task: {771665F3-CE9D-4213-8048-ABB425604BA5} - System32\Tasks\Plus-HD-2.2-firefoxinstaller => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-firefoxinstaller.exe [2013-06-15] (Plus HD) <==== ATTENTION Task: {96C97277-4FD5-457D-812C-1978A9590605} - System32\Tasks\bench-sys => C:\Program Files (x86)\Bench\Updater\Updater.exe [2013-10-26] () <==== ATTENTION Task: {B27938C9-84B8-49AD-80E6-E0A59E3BB401} - System32\Tasks\GS-Enabler-S-960308484 => c:\programdata\quickset\gs-enabler\GS-Enabler.exe [2012-12-31] () <==== ATTENTION Task: {BB6CEB9B-1B34-4396-AD32-435B749C2D91} - System32\Tasks\Plus-HD-2.2-chromeinstaller => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-chromeinstaller.exe [2013-06-15] (Plus HD) <==== ATTENTION Task: {C4D7C316-EED4-4B0A-9186-D137A8B3EA18} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe Task: {CECCCC8F-3070-4007-9CC2-773AD8FF9B9B} - System32\Tasks\bench-S-1-5-21-1581266947-2377902997-3130898050-1001 => C:\Program Files (x86)\Bench\Updater\Updater.exe [2013-10-26] () <==== ATTENTION Task: {E05D277D-55FE-4439-AC8A-CE6452AFB679} - System32\Tasks\Plus-HD-2.2-updater => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-updater.exe [2013-06-15] (Plus HD) <==== ATTENTION Task: {E857708A-CA8F-41E9-BECC-4CBB6C1C3C87} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files (x86)\Ask.com\UpdateTask.exe [2012-12-10] () <==== ATTENTION Task: {EA9CF47E-1E18-47AB-A932-7B62443AB705} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {F39BC62F-6F82-46F7-B432-64B9C15DA3AE} - System32\Tasks\YourFile DownloaderUpdate => C:\Program Files (x86)\YourFileDownloader\YourFileUpdater.exe <==== ATTENTION Task: {F42E3D21-6559-4A9B-B7E0-265C907564F1} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\My Dell\uaclauncher.exe [2013-09-06] (PC-Doctor, Inc.) Task: {F64FB64F-F1B1-42D1-B1D6-4333B0C9F3C1} - System32\Tasks\Funmoods => C:\Users\Daniel\AppData\Roaming\Funmoods\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION Task: {F7653518-FD35-4C1F-B002-565A9FAB1291} - System32\Tasks\Plus-HD-2.2-enabler => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-enabler.exe [2013-12-24] (Plus HD) <==== ATTENTION Task: {F8854EF9-6AFD-465F-BFAC-76C60F602DC9} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-03] (Google Inc.) Task: {FD3447C9-3BF7-4D48-B88C-CB90BBCD03EE} - \DealPlyUpdate ATTENTION ====> No Task File Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\windows\Tasks\bench-S-1-5-21-1581266947-2377902997-3130898050-1001.job => C:\Program Files (x86)\Bench\Updater\Updater.exe <==== ATTENTION Task: C:\windows\Tasks\bench-sys.job => C:\Program Files (x86)\Bench\Updater\Updater.exe <==== ATTENTION Task: C:\windows\Tasks\FF Watcher {AF1C556F-48FB-4E74-AA3F-A1BA1EB90CE9}.job => C:\Program Files\V-bates\PrefHelper.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GS-Enabler-S-960308484.job => c:\programdata\quickset\gs-enabler\GS-Enabler.exe <==== ATTENTION Task: C:\windows\Tasks\Plus-HD-2.2-chromeinstaller.job => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-chromeinstaller.exe <==== ATTENTION Task: C:\windows\Tasks\Plus-HD-2.2-codedownloader.job => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-codedownloader.exe <==== ATTENTION Task: C:\windows\Tasks\Plus-HD-2.2-enabler.job => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-enabler.exe <==== ATTENTION Task: C:\windows\Tasks\Plus-HD-2.2-firefoxinstaller.job => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-firefoxinstaller.exe <==== ATTENTION Task: C:\windows\Tasks\Plus-HD-2.2-updater.job => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-updater.exe <==== ATTENTION Task: C:\windows\Tasks\Upd Inst-S-5153193369.job => c:\programdata\superbapp\upd inst\Upd Inst.exe ==================== Loaded Modules (whitelisted) ============= 2014-04-04 13:59 - 2014-04-04 13:59 - 04395520 _____ () C:\ProgramData\Assistant\Assistant_x64.dll 2012-12-31 11:54 - 2012-12-31 11:54 - 00729600 _____ () c:\programdata\quickset\gs-enabler\GS-Enabler.exe 2011-07-28 03:07 - 2011-07-28 03:07 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll 2011-09-26 03:03 - 2011-07-08 17:12 - 02749248 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE 2011-09-26 04:31 - 2011-04-10 20:40 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2011-07-28 03:07 - 2011-07-28 03:07 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll 2014-02-27 19:11 - 2014-02-27 19:11 - 00049664 _____ () C:\Program Files (x86)\Bench\BService\bservice.exe 2014-02-27 19:11 - 2014-02-27 19:11 - 00060416 _____ () C:\Program Files (x86)\Bench\Wd\wd.exe 2014-02-28 08:48 - 2014-02-28 08:48 - 00247848 _____ () C:\Program Files (x86)\Coupon Alerts\FrameworkEngine.exe 2014-04-18 19:01 - 2014-04-18 19:01 - 04210176 _____ () C:\Program Files (x86)\Assistant_x64.dll 2014-04-18 19:01 - 2014-04-18 19:01 - 00729600 _____ () c:\programdata\superbapp\upd inst\Upd Inst.exe 2014-04-04 13:59 - 2014-04-04 13:59 - 04223488 _____ () C:\ProgramData\Assistant\Assistant.dll 2014-04-04 13:59 - 2014-04-04 13:59 - 00177488 _____ () C:\ProgramData\Assistant\AssistantSvc.dll 2014-02-15 07:59 - 2014-02-15 07:59 - 00169472 _____ () C:\windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\0a0467413a424068d1471448ff6ca6cc\IsdiInterop.ni.dll 2011-09-26 02:15 - 2010-11-06 06:50 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll 2014-02-27 19:11 - 2014-02-27 19:11 - 00049664 _____ () C:\Program Files (x86)\Bench\BService\bhelper.dll 2014-04-18 19:01 - 2014-04-18 19:01 - 00174928 _____ () C:\Program Files (x86)\AssistantSvc.dll 2014-04-18 19:01 - 2014-04-18 19:01 - 04296192 _____ () C:\Program Files (x86)\Assistant.dll 2014-04-13 17:05 - 2014-04-13 17:05 - 00425472 _____ () C:\ProgramData\DeaalExpREss\VQs.dll 2012-12-31 11:53 - 2012-12-31 11:53 - 00423936 _____ () C:\Program Files (x86)\grieatsaaVeRR\XRE4I3ID.dll 2013-12-30 20:43 - 2013-12-30 20:43 - 00423936 _____ () C:\Program Files (x86)\YoutubeAdblocker\RAzq.dll 2014-01-31 18:37 - 2014-01-31 18:37 - 00426496 _____ () C:\ProgramData\TubeeeItAdBlockFr\sOyw.dll 2014-02-28 11:50 - 2014-02-28 11:50 - 00425984 _____ () C:\ProgramData\50CoupoNs\Dolpq3mDX5.dll 2012-12-30 20:41 - 2012-12-30 20:41 - 00423936 _____ () C:\Program Files (x86)\ggReatsaver\6esXyz.dll 2014-02-28 08:48 - 2014-02-28 08:48 - 00258088 _____ () C:\Program Files (x86)\Coupon Alerts\FrameworkBHO.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:373E1720 ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver" ==================== Disabled items from MSCONFIG ============== MSCONFIG\startupfolder: C:^Users^Daniel^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.4.1.lnk => C:\windows\pss\OpenOffice.org 3.4.1.lnk.Startup MSCONFIG\startupreg: ApnUpdater => "C:\Program Files (x86)\Ask.com\Updater\Updater.exe" MSCONFIG\startupreg: Dell Webcam Central => "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2 MSCONFIG\startupreg: DellStage => "C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\start.umj" --startup MSCONFIG\startupreg: Desktop Disc Tool => "c:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" MSCONFIG\startupreg: EA Core => "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent MSCONFIG\startupreg: Iminent => C:\Program Files (x86)\Iminent\Iminent.exe /warmup "F77F87E5-A6BD-4922-A530-EDF63D7E9F8C" MSCONFIG\startupreg: IminentMessenger => C:\Program Files (x86)\Iminent\Iminent.Messengers.exe MSCONFIG\startupreg: MMReminderService => C:\Program Files (x86)\Mindjet\MindManager 11\MMReminderService.exe MSCONFIG\startupreg: Optimizer Pro => C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe MSCONFIG\startupreg: Pando Media Booster => C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\Steam.exe" -silent MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" MSCONFIG\startupreg: SweetIM => C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe ==================== Faulty Device Manager Devices ============= Name: High Definition Audio-Controller Description: High Definition Audio-Controller Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: HDAudBus Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Intel(R) Centrino(R) Wireless-N 1030 Description: Intel(R) Centrino(R) Wireless-N 1030 Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Intel Corporation Service: NETwNs64 Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (04/18/2014 06:30:01 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16521, Zeitstempel: 0x53114399 Name des fehlerhaften Moduls: 6esXyz.dll, Version: 1.1.0.0, Zeitstempel: 0x52b8d8cd Ausnahmecode: 0xc0000005 Fehleroffset: 0x0001a84c ID des fehlerhaften Prozesses: 0x1390 Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0 Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1 Pfad des fehlerhaften Moduls: IEXPLORE.EXE2 Berichtskennung: IEXPLORE.EXE3 Error: (04/18/2014 06:29:59 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16521, Zeitstempel: 0x53114399 Name des fehlerhaften Moduls: Dolpq3mDX5.dll, Version: 1.1.0.0, Zeitstempel: 0x52ea8dc0 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0001aa76 ID des fehlerhaften Prozesses: 0x17fc Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0 Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1 Pfad des fehlerhaften Moduls: IEXPLORE.EXE2 Berichtskennung: IEXPLORE.EXE3 Error: (04/18/2014 06:26:32 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16521, Zeitstempel: 0x53114399 Name des fehlerhaften Moduls: sOyw.dll, Version: 1.1.0.0, Zeitstempel: 0x52e9c87d Ausnahmecode: 0xc0000005 Fehleroffset: 0x0001af80 ID des fehlerhaften Prozesses: 0x1784 Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0 Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1 Pfad des fehlerhaften Moduls: IEXPLORE.EXE2 Berichtskennung: IEXPLORE.EXE3 Error: (04/18/2014 06:26:30 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16521, Zeitstempel: 0x53114399 Name des fehlerhaften Moduls: RAzq.dll, Version: 1.1.0.0, Zeitstempel: 0x52b8d8cd Ausnahmecode: 0xc0000005 Fehleroffset: 0x0001a84c ID des fehlerhaften Prozesses: 0x31c Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0 Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1 Pfad des fehlerhaften Moduls: IEXPLORE.EXE2 Berichtskennung: IEXPLORE.EXE3 Error: (04/18/2014 06:26:24 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16521, Zeitstempel: 0x53114399 Name des fehlerhaften Moduls: XRE4I3ID.dll, Version: 1.1.0.0, Zeitstempel: 0x52b8d8cd Ausnahmecode: 0xc0000005 Fehleroffset: 0x0001a84c ID des fehlerhaften Prozesses: 0xec8 Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0 Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1 Pfad des fehlerhaften Moduls: IEXPLORE.EXE2 Berichtskennung: IEXPLORE.EXE3 Error: (04/18/2014 06:26:19 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16521, Zeitstempel: 0x53114399 Name des fehlerhaften Moduls: MSHTML.dll, Version: 11.0.9600.16659, Zeitstempel: 0x5338aef8 Ausnahmecode: 0x80000003 Fehleroffset: 0x0079a7f4 ID des fehlerhaften Prozesses: 0xb30 Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0 Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1 Pfad des fehlerhaften Moduls: IEXPLORE.EXE2 Berichtskennung: IEXPLORE.EXE3 Error: (04/18/2014 06:13:22 PM) (Source: Customer Experience Improvement Program) (User: ) Description: 80004005 Error: (04/18/2014 06:03:56 PM) (Source: Application Hang) (User: ) Description: Programm iexplore.exe, Version 11.0.9600.16521 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1278 Startzeit: 01cf5b1bbc50f886 Endzeit: 16 Anwendungspfad: C:\Program Files\Internet Explorer\iexplore.exe Berichts-ID: Error: (04/18/2014 05:27:48 PM) (Source: TOASTER.EXE) (User: ) Description: An Unhandled Exception occured. Der Prozess kann nicht auf die Datei "C:\Users\Daniel\AppData\local\softthinks\scheduler.xml" zugreifen, da sie von einem anderen Prozess verwendet wird. bei System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) bei System.IO.FileStream.Init(String path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath, Boolean bFromProxy) bei System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize) bei System.Xml.XmlDownloadManager.GetStream(Uri uri, ICredentials credentials) bei System.Xml.XmlUrlResolver.GetEntity(Uri absoluteUri, String role, Type ofObjectToReturn) bei System.Xml.XmlTextReaderImpl.OpenUrlDelegate(Object xmlResolver) bei System.Threading.CompressedStack.runTryCode(Object userData) bei System.Runtime.CompilerServices.RuntimeHelpers.ExecuteCodeWithGuaranteedCleanup(TryCode code, CleanupCode backoutCode, Object userData) bei System.Threading.CompressedStack.Run(CompressedStack compressedStack, ContextCallback callback, Object state) bei System.Xml.XmlTextReaderImpl.OpenUrl() bei System.Xml.XmlTextReaderImpl.Read() bei System.Xml.XmlLoader.Load(XmlDocument doc, XmlReader reader, Boolean preserveWhitespace) bei System.Xml.XmlDocument.Load(XmlReader reader) bei System.Xml.XmlDocument.Load(String filename) bei Toaster.SchedulerReader.read() bei Toaster.Notifications.FullSystemBackup.FsbHelper.IsFsbScheduledNow() bei Toaster.Notifications.FullSystemBackup.FsbHelper.CheckReminder() bei Toaster.Helper.CheckReminders(ObservableCollection`1 notificationHelpers) bei Toaster.MainWindowViewModel.NotificationsTimerTick(Object sender, EventArgs e) bei System.Windows.Threading.DispatcherTimer.FireTick(Object unused) bei System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate callback, Object args, Boolean isSingleParameter) bei System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler) Error: (04/18/2014 05:24:37 PM) (Source: CVHSVC) (User: ) Description: Nur zur Information. (Stream product id=0x0066): Streaming Failed System errors: ============= Error: (04/18/2014 07:00:53 PM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (04/18/2014 07:00:53 PM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (04/18/2014 07:00:47 PM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (04/18/2014 07:00:47 PM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (04/13/2014 07:22:02 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst SftService erreicht. Error: (04/13/2014 07:21:32 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst SftService erreicht. Error: (04/13/2014 07:19:47 AM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 13.04.2014 um 07:18:22 unerwartet heruntergefahren. Error: (04/04/2014 02:05:01 PM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (03/25/2014 06:22:10 PM) (Source: DCOM) (User: ) Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Error: (03/22/2014 08:48:34 PM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Microsoft Office Sessions: ========================= Error: (04/18/2014 06:30:01 PM) (Source: Application Error)(User: ) Description: IEXPLORE.EXE11.0.9600.16521531143996esXyz.dll1.1.0.052b8d8cdc00000050001a84c139001cf5b23724689b7C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Program Files (x86)\ggReatsaver\6esXyz.dllb012067a-c716-11e3-a467-ac72899e2a90 Error: (04/18/2014 06:29:59 PM) (Source: Application Error)(User: ) Description: IEXPLORE.EXE11.0.9600.1652153114399Dolpq3mDX5.dll1.1.0.052ea8dc0c00000050001aa7617fc01cf5b236f7c6ce4C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\ProgramData\50CoupoNs\Dolpq3mDX5.dllae7175aa-c716-11e3-a467-ac72899e2a90 Error: (04/18/2014 06:26:32 PM) (Source: Application Error)(User: ) Description: IEXPLORE.EXE11.0.9600.1652153114399sOyw.dll1.1.0.052e9c87dc00000050001af80178401cf5b22f5be2c01C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\ProgramData\TubeeeItAdBlockFr\sOyw.dll33874764-c716-11e3-a467-ac72899e2a90 Error: (04/18/2014 06:26:30 PM) (Source: Application Error)(User: ) Description: IEXPLORE.EXE11.0.9600.1652153114399RAzq.dll1.1.0.052b8d8cdc00000050001a84c31c01cf5b2127df4b84C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Program Files (x86)\YoutubeAdblocker\RAzq.dll325435e1-c716-11e3-a467-ac72899e2a90 Error: (04/18/2014 06:26:24 PM) (Source: Application Error)(User: ) Description: IEXPLORE.EXE11.0.9600.1652153114399XRE4I3ID.dll1.1.0.052b8d8cdc00000050001a84cec801cf5b22f09e95caC:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Program Files (x86)\grieatsaaVeRR\XRE4I3ID.dll2e6ed54e-c716-11e3-a467-ac72899e2a90 Error: (04/18/2014 06:26:19 PM) (Source: Application Error)(User: ) Description: IEXPLORE.EXE11.0.9600.1652153114399MSHTML.dll11.0.9600.166595338aef8800000030079a7f4b3001cf5b211e8cfe8aC:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\windows\system32\MSHTML.dll2b98932b-c716-11e3-a467-ac72899e2a90 Error: (04/18/2014 06:13:22 PM) (Source: Customer Experience Improvement Program)(User: ) Description: 80004005 Error: (04/18/2014 06:03:56 PM) (Source: Application Hang)(User: ) Description: iexplore.exe11.0.9600.16521127801cf5b1bbc50f88616C:\Program Files\Internet Explorer\iexplore.exe Error: (04/18/2014 05:27:48 PM) (Source: TOASTER.EXE)(User: ) Description: An Unhandled Exception occured. Der Prozess kann nicht auf die Datei "C:\Users\Daniel\AppData\local\softthinks\scheduler.xml" zugreifen, da sie von einem anderen Prozess verwendet wird. bei System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) bei System.IO.FileStream.Init(String path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath, Boolean bFromProxy) bei System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize) bei System.Xml.XmlDownloadManager.GetStream(Uri uri, ICredentials credentials) bei System.Xml.XmlUrlResolver.GetEntity(Uri absoluteUri, String role, Type ofObjectToReturn) bei System.Xml.XmlTextReaderImpl.OpenUrlDelegate(Object xmlResolver) bei System.Threading.CompressedStack.runTryCode(Object userData) bei System.Runtime.CompilerServices.RuntimeHelpers.ExecuteCodeWithGuaranteedCleanup(TryCode code, CleanupCode backoutCode, Object userData) bei System.Threading.CompressedStack.Run(CompressedStack compressedStack, ContextCallback callback, Object state) bei System.Xml.XmlTextReaderImpl.OpenUrl() bei System.Xml.XmlTextReaderImpl.Read() bei System.Xml.XmlLoader.Load(XmlDocument doc, XmlReader reader, Boolean preserveWhitespace) bei System.Xml.XmlDocument.Load(XmlReader reader) bei System.Xml.XmlDocument.Load(String filename) bei Toaster.SchedulerReader.read() bei Toaster.Notifications.FullSystemBackup.FsbHelper.IsFsbScheduledNow() bei Toaster.Notifications.FullSystemBackup.FsbHelper.CheckReminder() bei Toaster.Helper.CheckReminders(ObservableCollection`1 notificationHelpers) bei Toaster.MainWindowViewModel.NotificationsTimerTick(Object sender, EventArgs e) bei System.Windows.Threading.DispatcherTimer.FireTick(Object unused) bei System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate callback, Object args, Boolean isSingleParameter) bei System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler) Error: (04/18/2014 05:24:37 PM) (Source: CVHSVC)(User: ) Description: (Stream product id=0x0066): Streaming Failed ==================== Memory info =========================== Percentage of memory in use: 44% Total physical RAM: 4003.16 MB Available physical RAM: 2212.66 MB Total Pagefile: 8004.51 MB Available Pagefile: 5375.48 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:581.42 GB) (Free:442.54 GB) NTFS Drive d: (LS2013) (CDROM) (Total:1.36 GB) (Free:0 GB) CDFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596 GB) (Disk ID: E78DF937) Partition 1: (Not Active) - (Size=100 MB) - (Type=DE) Partition 2: (Active) - (Size=15 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=581 GB) - (Type=07 NTFS) ==================== End Of Log ============================ und die frst Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-04-2014 01 Ran by Daniel at 2014-04-19 08:33:56 Running from C:\Users\Daniel\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== 50CoupoNs (HKLM-x32\...\{CF987D06-1DCF-7B36-5B43-13BC8699C44C}) (Version: - 550CoupoNs) <==== ATTENTION Adobe Acrobat 4.0 (HKLM-x32\...\Adobe Acrobat 4.0) (Version: - ) Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Reader X (10.1.9) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.9 - Adobe Systems Incorporated) Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.4.144 - Adobe Systems, Inc.) Advanced Audio FX Engine (HKLM-x32\...\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd) Airport Simulator 2013 Demo Version 1.0 (HKLM-x32\...\{67F30877-CBBB-425C-9511-93181EFB8F08}_is1) (Version: 1.0 - rondomedia) Ask Toolbar (HKLM-x32\...\{86D4B82A-ABED-442A-BE86-96357B70F4FE}) (Version: 1.15.14.0 - Ask.com) <==== ATTENTION Ask Toolbar Updater (HKCU\...\{79A765E1-C399-405B-85AF-466F52E918B0}) (Version: 1.2.3.29495 - Ask.com) <==== ATTENTION Assassin's Creed II (HKLM\...\{8570BEE8-0CA3-4977-9AB1-80ED93F0513C}) (Version: 1.00 - Ubisoft) Assassin's Creed II (HKLM-x32\...\{8570BEE8-0CA3-4977-9AB1-80ED93F0513C}) (Version: 1.00 - Ubisoft) Assistant (HKLM-x32\...\{5F189DF5-2D05-472B-9091-84D9848AE48B}{699fd52f}) (Version: - Verified Publisher) Audiograbber 1.83 SE (HKLM-x32\...\Audiograbber) (Version: 1.83 SE - Audiograbber) Bau-Simulator 2012 Version 1.0 (HKLM-x32\...\{AEF59382-3FF1-4EBF-A93E-CCC474DCEA3F}_is1) (Version: 1.0 - weltenbauer. Software Entwicklung GmbH) Black_Box v1 (HKLM-x32\...\Assassin's Creed 2_is1) (Version: - ) Blue Byte Game Channel (HKLM-x32\...\Blue Byte Game Channel) (Version: - UbiSoft) Bombenterror (HKCU\...\Bombenterror) (Version: - ) Coupon Alerts (HKLM-x32\...\37436_Coupon Alerts) (Version: 1.3 - Smart Apps) <==== ATTENTION Craften Terminal 3.4.5011.37604 (HKLM-x32\...\{4e7c3936-7c06-4ef0-928b-c5d92f372578}_is1) (Version: 3.4.5011.37604 - Craften.de) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Dart701OU (HKCU\...\Dart701OU) (Version: - ) DeaalExpREss (HKLM-x32\...\{25F259ED-12F6-429F-5783-527C3E2F8586}) (Version: - DeealExpress) DealPly (HKCU\...\DealPly) (Version: - ) <==== ATTENTION Dell DataSafe Local Backup - Support Software (HKLM-x32\...\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 9.4.57 - Dell Inc.) Dell DataSafe Local Backup (HKLM-x32\...\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 9.4.57 - Dell Inc.) Dell DataSafe Online (HKLM-x32\...\{7EC66A95-AC2D-4127-940B-0445A526AB2F}) (Version: 2.1.19634 - Dell) Dell Edoc Viewer (HKLM\...\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc) Dell Getting Started Guide (HKLM-x32\...\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.) Dell MusicStage (HKLM-x32\...\{3255BC3F-32BA-41ED-93A0-B9AEB6CDD9E6}) (Version: 1.5.201.0 - Fingertapps) Dell PhotoStage (HKLM-x32\...\{E4335E82-17B3-460F-9E70-39D9BC269DB3}) (Version: 1.5.0.65 - ArcSoft) Dell Stage (HKLM-x32\...\{56A0DD94-47D9-4AC8-B5A1-8A8CA77C4B89}) (Version: 1.5.201.0 - Fingertapps) Dell Touchpad (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 7.1209.101.204 - ALPS ELECTRIC CO., LTD.) Dell VideoStage (HKLM-x32\...\InstallShield_{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}) (Version: 1.2.0.1712 - CyberLink Corp.) Dell VideoStage (x32 Version: 1.2.0.1712 - CyberLink Corp.) Hidden Dell Webcam Central (HKLM-x32\...\Dell Webcam Central) (Version: 2.00.44 - Creative Technology Ltd) Delta Chrome Toolbar (HKLM-x32\...\Delta Chrome Toolbar) (Version: - Visual Tools) <==== ATTENTION Delta toolbar (HKLM-x32\...\delta) (Version: 1.8.21.5 - Delta) <==== ATTENTION Demolition Company (HKLM-x32\...\DemolitionCompanyDE_is1) (Version: - GIANTS Software) Demolition Company Demo (HKLM-x32\...\DemolitionCompanyDemoDE_is1) (Version: - GIANTS Software) Die Siedler IV (HKLM-x32\...\S4Uninst) (Version: - ) Die Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.67.2 - Electronic Arts) Die Sims™ 3 Showtime (HKLM-x32\...\{3BBFD444-5FAB-49F6-98B1-A1954E831399}) (Version: 12.0.273 - Electronic Arts) DirectX 9 Runtime (x32 Version: 1.00.0000 - Sonic Solutions) Hidden Euro Truck Simulator 2 (HKLM-x32\...\{1B705E8F-9893-4486-B5D7-4F7FEB9C871E}_is1) (Version: 1.1.1 - SCS Software) FileConverter 1.3 Toolbar (HKLM-x32\...\FileConverter_1.3 Toolbar) (Version: 6.9.0.16 - FileConverter 1.3) FTDownloader (HKLM-x32\...\1ClickDownload) (Version: 2.1 Build 26473 - FTDownloader.com) <==== ATTENTION Funmoods (HKLM-x32\...\funmoods) (Version: - Volonet Ltd) <==== ATTENTION GameSpy Arcade (HKLM-x32\...\GameSpy Arcade) (Version: - ) German Truck Simulator 1.00 (HKLM-x32\...\German Truck Simulator) (Version: 1.00 - ) GIANTS Editor 5.0.1 (HKLM-x32\...\giants_editor_5.0.1_is1) (Version: 5.0.1 - GIANTS Software GmbH) GIMP 2.8.6 (HKLM\...\GIMP-2_is1) (Version: 2.8.6 - The GIMP Team) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 32.0.1700.102 - Google Inc.) Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) Hidden Grand Ages Rome 1.01 (HKLM-x32\...\Civitas3) (Version: 1.01 - Kalypso Media) Grand Theft Auto San Andreas (HKLM-x32\...\{086BADF8-9B1F-4E89-B207-2EDA520972D6}) (Version: 1.00.00001 - Rockstar Games) grieatsaaVeRR (HKLM-x32\...\{CA41BB14-E67B-1653-C57B-5CA99418A866}) (Version: 3.1.0.1554 - grreatsaver) <==== ATTENTION GS-Enabler (HKLM-x32\...\S-960308484) (Version: 4.3.0.1686 - PremiumSoft) <==== ATTENTION Hamburg Demolition Addon version 1.0 (HKLM-x32\...\Hamburg Demolition Addon_is1) (Version: 1.0 - ) Holzfäller Simulator 2012 (HKLM-x32\...\Woodcutter Simulator 2012) (Version: - ) IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6324.0 - IDT) Iminent (HKLM-x32\...\IMBoosterARP) (Version: 6.23.53.0 - Iminent) <==== ATTENTION Iminent (x32 Version: 6.23.53.0 - Iminent) Hidden <==== ATTENTION Iminent Toolbar For Internet Explorer (HKLM-x32\...\{A76AA284-E52D-47E6-9E4F-B85DBF8E35C3}) (Version: 3.26.0 - Iminent) <==== ATTENTION Install Supporter 1.80 (HKLM-x32\...\{5F189DF5-2D05-472B-9091-84D9848AE48B}{1a34a8e0}) (Version: - Certified Publisher) Intel PROSet Wireless (Version: - ) Hidden Intel PROSet Wireless (x32 Version: - ) Hidden Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1118 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2361 - Intel Corporation) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{7CE8BE79-ABC3-4B2C-9543-28ED2B0A9EA8}) (Version: 1.2.0.0587 - Intel Corporation) Intel(R) PROSet/Wireless WiFi-Software (HKLM\...\{25FBDA9A-E868-4B3B-B9FF-D923818511A1}) (Version: 14.2.0000 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.0.1008 - Intel Corporation) Intel(R) WiDi (HKLM-x32\...\{25680C01-6753-4FE9-A891-7857F26457C1}) (Version: 2.1.35.0 - Intel Corporation) Intel(R) Wireless Display (HKLM\...\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version: - ) Internet Explorer Toolbar 4.6 by SweetPacks (HKLM-x32\...\{C3E85EE9-5892-4142-B537-BCEB3DAC4C3D}) (Version: 4.6.0004 - SweetIM Technologies Ltd.) <==== ATTENTION Java Auto Updater (x32 Version: 2.0.7.2 - Sun Microsystems, Inc.) Hidden Java(TM) 6 Update 27 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86416027FF}) (Version: 6.0.270 - Oracle) Java(TM) 6 Update 38 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216038FF}) (Version: 6.0.380 - Oracle) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden KLIX (HKCU\...\KLIX) (Version: - ) Landwirtschafts Simulator 2011 (HKLM-x32\...\FarmingSimulator2011DE_is1) (Version: 1.0 - GIANTS Software) Landwirtschafts Simulator 2013 (HKLM-x32\...\FarmingSimulator2013DE_is1) (Version: 1.0 - GIANTS Software) Landwirtschafts Simulator 2013 Demo (HKLM-x32\...\FarmingSimulator2013DemoDE_is1) (Version: 1.0 - GIANTS Software) Landwirtschafts Simulator 2013 Hagensted Modified 2013 (HKLM-x32\...\{F09E06EB-D878-4E4E-9190-84E3C4C1DC27}_is1) (Version: Landwirtschafts Simulator 2013 Hagensted Modified 3.1.0 - Black Panther Group) League of Legends (HKLM-x32\...\{92606477-9366-4D3B-8AE3-6BE4B29727AB}) (Version: 1.3 - Riot Games) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Train Simulator (HKLM-x32\...\Train Simulator 1.0) (Version: - ) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{820B6609-4C97-3A2B-B644-573B06A0F0CC}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Mindjet (HKLM-x32\...\{6D1AFA44-6E87-41F5-B7D4-4C457A98A3A3}) (Version: 11.1.353 - Mindjet) Minecraft PC Gamer Demo version 1.5 (HKLM-x32\...\{55D65D27-C0CD-4375-9021-F3D3D024ED90}_is1) (Version: 1.5 - Mojang) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) My Dell (HKLM\...\PC-Doctor for Windows) (Version: 3.4.6308.28 - PC-Doctor, Inc.) Need for Speed™ Most Wanted (HKLM-x32\...\{A48B9CD8-C2BA-4EC9-0081-7260D238C7CF}) (Version: - ) NVIDIA 3D Vision Treiber 268.30 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 268.30 - NVIDIA Corporation) NVIDIA Grafiktreiber 268.30 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 268.30 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.2.22.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.2.22.1 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.265.41.0 - NVIDIA Corporation) Hidden NVIDIA Optimus 1.0.21 (Version: 1.0.21 - NVIDIA Corporation) Hidden NVIDIA PhysX (HKLM-x32\...\{1C4551A6-4743-4093-91E4-1477CD655043}) (Version: 9.09.0203 - NVIDIA Corporation) NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.12.6830 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 268.30 (Version: 268.30 - NVIDIA Corporation) Hidden NVIDIA Update Components (Version: 1.0.21 - NVIDIA Corporation) Hidden NWZ-B170 WALKMAN Guide (HKLM-x32\...\{B91B14D5-B817-4C79-BEF6-0A7A23FE6C61}) (Version: 2.1.0.33220 - Sony Corporation) OpenOffice.org 3.4.1 (HKLM-x32\...\{2303AEEA-0FA8-4AFD-80A9-8F86BA4B44D2}) (Version: 3.41.9593 - Apache Software Foundation) Origin (HKLM-x32\...\Origin) (Version: 9.2.1.4399 - Electronic Arts, Inc.) Packs World 2 (HKCU\...\Packs World 2) (Version: - ) Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.8 - Pando Networks Inc.) PDF-XChange 3 (HKLM\...\PDF-XChange 3_is1) (Version: - Tracker Software) PhotoShowExpress (x32 Version: 2.0.063 - Sonic Solutions) Hidden Plus-HD-2.2 (HKLM-x32\...\Plus-HD-2.2) (Version: 1.27.153.6 - Plus HD) <==== ATTENTION PoolBallMasch (HKCU\...\PoolBallMasch) (Version: - ) Puzzle Ship (HKCU\...\Puzzle Ship) (Version: - ) Quickset64 (HKLM\...\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 10.09.20 - Dell Inc.) RBVirtualFolder64Inst (Version: 1.00.0000 - Roxio, Inc.) Hidden Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.31.1025.2010 - Realtek) Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30126 - Realtek Semiconductor Corp.) Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.32.0 - Renesas Electronics Corporation) Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.32.0 - Renesas Electronics Corporation) Hidden Roxio Activation Module (x32 Version: 1.0 - Roxio) Hidden Roxio BackOnTrack (x32 Version: 1.3.3 - Roxio) Hidden Roxio Burn (x32 Version: 1.8 - Roxio) Hidden Roxio Creator Starter (HKLM-x32\...\{6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}) (Version: 12.1.77.0 - Roxio) Roxio Creator Starter (x32 Version: 1.0.439 - Roxio) Hidden Roxio Creator Starter (x32 Version: 5.0.0 - Roxio) Hidden Roxio Express Labeler 3 (x32 Version: 3.2.2 - Roxio) Hidden Roxio File Backup (Version: 1.3.2 - Roxio) Hidden Schwebebahn-Simulator 2013 Demo (HKLM-x32\...\{983E191D-6DE0-4E12-811B-61E4A514A665}_is1) (Version: - rondomedia Marketing & Vertriebs GmbH) SimCity 4 Deluxe (HKLM-x32\...\{3F0D0ABE-CDAF-431A-00BC-CBBE018EA74E}) (Version: - ) Skiregion Simulator 2012 Demo (HKLM-x32\...\SkiRegionSimulator2012DemoDE_is1) (Version: 1.0 - GIANTS Software) Skype Toolbars (HKLM-x32\...\{981029E0-7FC9-4CF3-AB39-6F133621921A}) (Version: 1.0.4051 - Skype Technologies S.A.) Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) Softonic toolbar on IE and Chrome (HKLM-x32\...\Softonic) (Version: 1.8.16.10 - Softonic) <==== ATTENTION Sonic CinePlayer Decoder Pack (x32 Version: 4.3.0 - Sonic Solutions) Hidden SpinTires Tech Demo (June 060613) (HKLM-x32\...\{9AF7D6F5-50A5-432C-9F7B-83BCE03B11A0}) (Version: 1.3 - Oovee) Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) Stronghold (HKLM-x32\...\{C917BA70-28A3-4C74-B163-41FD8C8E1A5A}) (Version: 1.20.0000 - Firefly Studios) Stronghold 2 (HKLM-x32\...\{16D2C649-CBA8-44EE-B730-12584667D487}) (Version: 1.40.1000 - Firefly Studios) Stronghold Crusader Extreme (HKLM-x32\...\{8C3727F2-8E37-49E4-820C-03B1677F53B6}) (Version: 1.20.0000 - Firefly Studios) Stronghold Legends (HKLM-x32\...\{66A405D2-BA14-4594-BF36-B3B544F0754E}) (Version: 1.20.0000 - Firefly Studios) SweetIM for Messenger 3.7 (HKLM-x32\...\{A0C9DF2B-89B5-4483-8983-18A68200F1B4}) (Version: 3.7.0007 - SweetIM Technologies Ltd.) <==== ATTENTION SweetPacks bundle uninstaller (HKLM-x32\...\{953AA732-9AFB-49C9-84A4-7F96CA0A08DA}) (Version: 1.0.0001 - SweetIM Technologies Ltd.) <==== ATTENTION swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden TubeeeItAdBlockFr (HKLM-x32\...\{94EEB800-E533-7AE1-5C31-0446E1C0537C}) (Version: - TubeIutAdBlockFri) Upd Inst (HKLM-x32\...\S-5153193369) (Version: 1.3.0.1133 - PremiumSoft) Update Manager for SweetPacks 1.1 (HKLM-x32\...\{EA8FA6BE-29BE-4AF2-9352-841F83215EB0}) (Version: 1.1.0008 - SweetIM Technologies Ltd.) <==== ATTENTION Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden WinRAR 4.20 (32-Bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH) WiseConvert 1.3 Toolbar (HKLM-x32\...\WiseConvert_1.3 Toolbar) (Version: 6.9.0.16 - WiseConvert 1.3) Worms Reloaded (HKLM-x32\...\Steam App 22600) (Version: - Team17) Yontoo 1.10.04 (HKLM\...\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}) (Version: 1.10.04 - Yontoo LLC) <==== ATTENTION YoutubeAdblocker (HKLM-x32\...\{4820778D-AB0D-6D18-C316-52A6A0E1D507}) (Version: 4.3.0.1656 - YoutubeAdblocker) <==== ATTENTION ==================== Restore Points ========================= 17-03-2014 14:33:31 Windows-Sicherung 19-03-2014 09:00:11 Windows Update 22-03-2014 17:00:54 Windows Update 23-03-2014 14:56:16 Installiert The Sims 3 23-03-2014 18:00:31 Windows-Sicherung 03-04-2014 14:09:21 Windows Update 03-04-2014 14:16:19 Windows-Sicherung 06-04-2014 17:07:17 Windows-Sicherung 12-04-2014 16:54:05 Windows Update 12-04-2014 18:26:53 Windows Update 13-04-2014 17:00:36 Windows-Sicherung 18-04-2014 15:28:12 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2014-03-01 07:40 - 00000871 ____A C:\windows\system32\Drivers\etc\hosts 54.204.28.26 cbaiddeoemldinncijanafifphajjppj ==================== Scheduled Tasks (whitelisted) ============= Task: {02D6417B-C037-46FC-B9B9-F8E62A2B986A} - System32\Tasks\EPUpdater => C:\Users\Daniel\AppData\Roaming\BabSolution\Shared\BabMaint.exe [2013-06-06] () <==== ATTENTION Task: {041DCCF9-7534-40F7-95D2-8827A27C37A1} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\My Dell\sessionchecker.exe [2013-09-06] (PC-Doctor, Inc.) Task: {1B77930F-D063-49C1-A53B-E1335C48DA34} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-12] (Adobe Systems Incorporated) Task: {1CD4D816-4476-4533-84A6-A35261E0C784} - System32\Tasks\Plus-HD-2.2-codedownloader => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-codedownloader.exe [2013-06-15] (Plus HD) <==== ATTENTION Task: {28F9629D-C097-4D31-8155-5C14115641A5} - System32\Tasks\Upd Inst-S-5153193369 => c:\programdata\superbapp\upd inst\Upd Inst.exe [2014-04-18] () Task: {30693492-09AF-4A61-933C-DA4081E04649} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-03] (Google Inc.) Task: {4166CC7A-E67E-4FF7-808A-D6224D6F036A} - System32\Tasks\DealPly => C:\Users\Daniel\AppData\Roaming\DealPly\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: {59520B43-A622-40DA-8C08-DC8218260209} - System32\Tasks\FF Watcher {AF1C556F-48FB-4E74-AA3F-A1BA1EB90CE9} => C:\Program Files\V-bates\PrefHelper.exe Task: {771665F3-CE9D-4213-8048-ABB425604BA5} - System32\Tasks\Plus-HD-2.2-firefoxinstaller => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-firefoxinstaller.exe [2013-06-15] (Plus HD) <==== ATTENTION Task: {96C97277-4FD5-457D-812C-1978A9590605} - System32\Tasks\bench-sys => C:\Program Files (x86)\Bench\Updater\Updater.exe [2013-10-26] () <==== ATTENTION Task: {B27938C9-84B8-49AD-80E6-E0A59E3BB401} - System32\Tasks\GS-Enabler-S-960308484 => c:\programdata\quickset\gs-enabler\GS-Enabler.exe [2012-12-31] () <==== ATTENTION Task: {BB6CEB9B-1B34-4396-AD32-435B749C2D91} - System32\Tasks\Plus-HD-2.2-chromeinstaller => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-chromeinstaller.exe [2013-06-15] (Plus HD) <==== ATTENTION Task: {C4D7C316-EED4-4B0A-9186-D137A8B3EA18} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe Task: {CECCCC8F-3070-4007-9CC2-773AD8FF9B9B} - System32\Tasks\bench-S-1-5-21-1581266947-2377902997-3130898050-1001 => C:\Program Files (x86)\Bench\Updater\Updater.exe [2013-10-26] () <==== ATTENTION Task: {E05D277D-55FE-4439-AC8A-CE6452AFB679} - System32\Tasks\Plus-HD-2.2-updater => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-updater.exe [2013-06-15] (Plus HD) <==== ATTENTION Task: {E857708A-CA8F-41E9-BECC-4CBB6C1C3C87} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files (x86)\Ask.com\UpdateTask.exe [2012-12-10] () <==== ATTENTION Task: {EA9CF47E-1E18-47AB-A932-7B62443AB705} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {F39BC62F-6F82-46F7-B432-64B9C15DA3AE} - System32\Tasks\YourFile DownloaderUpdate => C:\Program Files (x86)\YourFileDownloader\YourFileUpdater.exe <==== ATTENTION Task: {F42E3D21-6559-4A9B-B7E0-265C907564F1} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\My Dell\uaclauncher.exe [2013-09-06] (PC-Doctor, Inc.) Task: {F64FB64F-F1B1-42D1-B1D6-4333B0C9F3C1} - System32\Tasks\Funmoods => C:\Users\Daniel\AppData\Roaming\Funmoods\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION Task: {F7653518-FD35-4C1F-B002-565A9FAB1291} - System32\Tasks\Plus-HD-2.2-enabler => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-enabler.exe [2013-12-24] (Plus HD) <==== ATTENTION Task: {F8854EF9-6AFD-465F-BFAC-76C60F602DC9} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-03] (Google Inc.) Task: {FD3447C9-3BF7-4D48-B88C-CB90BBCD03EE} - \DealPlyUpdate ATTENTION ====> No Task File Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\windows\Tasks\bench-S-1-5-21-1581266947-2377902997-3130898050-1001.job => C:\Program Files (x86)\Bench\Updater\Updater.exe <==== ATTENTION Task: C:\windows\Tasks\bench-sys.job => C:\Program Files (x86)\Bench\Updater\Updater.exe <==== ATTENTION Task: C:\windows\Tasks\FF Watcher {AF1C556F-48FB-4E74-AA3F-A1BA1EB90CE9}.job => C:\Program Files\V-bates\PrefHelper.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GS-Enabler-S-960308484.job => c:\programdata\quickset\gs-enabler\GS-Enabler.exe <==== ATTENTION Task: C:\windows\Tasks\Plus-HD-2.2-chromeinstaller.job => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-chromeinstaller.exe <==== ATTENTION Task: C:\windows\Tasks\Plus-HD-2.2-codedownloader.job => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-codedownloader.exe <==== ATTENTION Task: C:\windows\Tasks\Plus-HD-2.2-enabler.job => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-enabler.exe <==== ATTENTION Task: C:\windows\Tasks\Plus-HD-2.2-firefoxinstaller.job => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-firefoxinstaller.exe <==== ATTENTION Task: C:\windows\Tasks\Plus-HD-2.2-updater.job => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-updater.exe <==== ATTENTION Task: C:\windows\Tasks\Upd Inst-S-5153193369.job => c:\programdata\superbapp\upd inst\Upd Inst.exe ==================== Loaded Modules (whitelisted) ============= 2014-04-04 13:59 - 2014-04-04 13:59 - 04395520 _____ () C:\ProgramData\Assistant\Assistant_x64.dll 2012-12-31 11:54 - 2012-12-31 11:54 - 00729600 _____ () c:\programdata\quickset\gs-enabler\GS-Enabler.exe 2011-07-28 03:07 - 2011-07-28 03:07 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll 2011-09-26 03:03 - 2011-07-08 17:12 - 02749248 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE 2011-09-26 04:31 - 2011-04-10 20:40 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2011-07-28 03:07 - 2011-07-28 03:07 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll 2014-02-27 19:11 - 2014-02-27 19:11 - 00049664 _____ () C:\Program Files (x86)\Bench\BService\bservice.exe 2014-02-27 19:11 - 2014-02-27 19:11 - 00060416 _____ () C:\Program Files (x86)\Bench\Wd\wd.exe 2014-02-28 08:48 - 2014-02-28 08:48 - 00247848 _____ () C:\Program Files (x86)\Coupon Alerts\FrameworkEngine.exe 2014-04-18 19:01 - 2014-04-18 19:01 - 04210176 _____ () C:\Program Files (x86)\Assistant_x64.dll 2014-04-18 19:01 - 2014-04-18 19:01 - 00729600 _____ () c:\programdata\superbapp\upd inst\Upd Inst.exe 2014-04-04 13:59 - 2014-04-04 13:59 - 04223488 _____ () C:\ProgramData\Assistant\Assistant.dll 2014-04-04 13:59 - 2014-04-04 13:59 - 00177488 _____ () C:\ProgramData\Assistant\AssistantSvc.dll 2014-02-15 07:59 - 2014-02-15 07:59 - 00169472 _____ () C:\windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\0a0467413a424068d1471448ff6ca6cc\IsdiInterop.ni.dll 2011-09-26 02:15 - 2010-11-06 06:50 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll 2014-02-27 19:11 - 2014-02-27 19:11 - 00049664 _____ () C:\Program Files (x86)\Bench\BService\bhelper.dll 2014-04-18 19:01 - 2014-04-18 19:01 - 00174928 _____ () C:\Program Files (x86)\AssistantSvc.dll 2014-04-18 19:01 - 2014-04-18 19:01 - 04296192 _____ () C:\Program Files (x86)\Assistant.dll 2014-04-13 17:05 - 2014-04-13 17:05 - 00425472 _____ () C:\ProgramData\DeaalExpREss\VQs.dll 2012-12-31 11:53 - 2012-12-31 11:53 - 00423936 _____ () C:\Program Files (x86)\grieatsaaVeRR\XRE4I3ID.dll 2013-12-30 20:43 - 2013-12-30 20:43 - 00423936 _____ () C:\Program Files (x86)\YoutubeAdblocker\RAzq.dll 2014-01-31 18:37 - 2014-01-31 18:37 - 00426496 _____ () C:\ProgramData\TubeeeItAdBlockFr\sOyw.dll 2014-02-28 11:50 - 2014-02-28 11:50 - 00425984 _____ () C:\ProgramData\50CoupoNs\Dolpq3mDX5.dll 2012-12-30 20:41 - 2012-12-30 20:41 - 00423936 _____ () C:\Program Files (x86)\ggReatsaver\6esXyz.dll 2014-02-28 08:48 - 2014-02-28 08:48 - 00258088 _____ () C:\Program Files (x86)\Coupon Alerts\FrameworkBHO.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:373E1720 ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver" ==================== Disabled items from MSCONFIG ============== MSCONFIG\startupfolder: C:^Users^Daniel^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.4.1.lnk => C:\windows\pss\OpenOffice.org 3.4.1.lnk.Startup MSCONFIG\startupreg: ApnUpdater => "C:\Program Files (x86)\Ask.com\Updater\Updater.exe" MSCONFIG\startupreg: Dell Webcam Central => "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2 MSCONFIG\startupreg: DellStage => "C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\start.umj" --startup MSCONFIG\startupreg: Desktop Disc Tool => "c:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" MSCONFIG\startupreg: EA Core => "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent MSCONFIG\startupreg: Iminent => C:\Program Files (x86)\Iminent\Iminent.exe /warmup "F77F87E5-A6BD-4922-A530-EDF63D7E9F8C" MSCONFIG\startupreg: IminentMessenger => C:\Program Files (x86)\Iminent\Iminent.Messengers.exe MSCONFIG\startupreg: MMReminderService => C:\Program Files (x86)\Mindjet\MindManager 11\MMReminderService.exe MSCONFIG\startupreg: Optimizer Pro => C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe MSCONFIG\startupreg: Pando Media Booster => C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\Steam.exe" -silent MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" MSCONFIG\startupreg: SweetIM => C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe ==================== Faulty Device Manager Devices ============= Name: High Definition Audio-Controller Description: High Definition Audio-Controller Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: HDAudBus Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Intel(R) Centrino(R) Wireless-N 1030 Description: Intel(R) Centrino(R) Wireless-N 1030 Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Intel Corporation Service: NETwNs64 Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (04/18/2014 06:30:01 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16521, Zeitstempel: 0x53114399 Name des fehlerhaften Moduls: 6esXyz.dll, Version: 1.1.0.0, Zeitstempel: 0x52b8d8cd Ausnahmecode: 0xc0000005 Fehleroffset: 0x0001a84c ID des fehlerhaften Prozesses: 0x1390 Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0 Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1 Pfad des fehlerhaften Moduls: IEXPLORE.EXE2 Berichtskennung: IEXPLORE.EXE3 Error: (04/18/2014 06:29:59 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16521, Zeitstempel: 0x53114399 Name des fehlerhaften Moduls: Dolpq3mDX5.dll, Version: 1.1.0.0, Zeitstempel: 0x52ea8dc0 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0001aa76 ID des fehlerhaften Prozesses: 0x17fc Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0 Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1 Pfad des fehlerhaften Moduls: IEXPLORE.EXE2 Berichtskennung: IEXPLORE.EXE3 Error: (04/18/2014 06:26:32 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16521, Zeitstempel: 0x53114399 Name des fehlerhaften Moduls: sOyw.dll, Version: 1.1.0.0, Zeitstempel: 0x52e9c87d Ausnahmecode: 0xc0000005 Fehleroffset: 0x0001af80 ID des fehlerhaften Prozesses: 0x1784 Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0 Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1 Pfad des fehlerhaften Moduls: IEXPLORE.EXE2 Berichtskennung: IEXPLORE.EXE3 Error: (04/18/2014 06:26:30 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16521, Zeitstempel: 0x53114399 Name des fehlerhaften Moduls: RAzq.dll, Version: 1.1.0.0, Zeitstempel: 0x52b8d8cd Ausnahmecode: 0xc0000005 Fehleroffset: 0x0001a84c ID des fehlerhaften Prozesses: 0x31c Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0 Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1 Pfad des fehlerhaften Moduls: IEXPLORE.EXE2 Berichtskennung: IEXPLORE.EXE3 Error: (04/18/2014 06:26:24 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16521, Zeitstempel: 0x53114399 Name des fehlerhaften Moduls: XRE4I3ID.dll, Version: 1.1.0.0, Zeitstempel: 0x52b8d8cd Ausnahmecode: 0xc0000005 Fehleroffset: 0x0001a84c ID des fehlerhaften Prozesses: 0xec8 Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0 Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1 Pfad des fehlerhaften Moduls: IEXPLORE.EXE2 Berichtskennung: IEXPLORE.EXE3 Error: (04/18/2014 06:26:19 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16521, Zeitstempel: 0x53114399 Name des fehlerhaften Moduls: MSHTML.dll, Version: 11.0.9600.16659, Zeitstempel: 0x5338aef8 Ausnahmecode: 0x80000003 Fehleroffset: 0x0079a7f4 ID des fehlerhaften Prozesses: 0xb30 Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0 Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1 Pfad des fehlerhaften Moduls: IEXPLORE.EXE2 Berichtskennung: IEXPLORE.EXE3 Error: (04/18/2014 06:13:22 PM) (Source: Customer Experience Improvement Program) (User: ) Description: 80004005 Error: (04/18/2014 06:03:56 PM) (Source: Application Hang) (User: ) Description: Programm iexplore.exe, Version 11.0.9600.16521 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1278 Startzeit: 01cf5b1bbc50f886 Endzeit: 16 Anwendungspfad: C:\Program Files\Internet Explorer\iexplore.exe Berichts-ID: Error: (04/18/2014 05:27:48 PM) (Source: TOASTER.EXE) (User: ) Description: An Unhandled Exception occured. Der Prozess kann nicht auf die Datei "C:\Users\Daniel\AppData\local\softthinks\scheduler.xml" zugreifen, da sie von einem anderen Prozess verwendet wird. bei System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) bei System.IO.FileStream.Init(String path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath, Boolean bFromProxy) bei System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize) bei System.Xml.XmlDownloadManager.GetStream(Uri uri, ICredentials credentials) bei System.Xml.XmlUrlResolver.GetEntity(Uri absoluteUri, String role, Type ofObjectToReturn) bei System.Xml.XmlTextReaderImpl.OpenUrlDelegate(Object xmlResolver) bei System.Threading.CompressedStack.runTryCode(Object userData) bei System.Runtime.CompilerServices.RuntimeHelpers.ExecuteCodeWithGuaranteedCleanup(TryCode code, CleanupCode backoutCode, Object userData) bei System.Threading.CompressedStack.Run(CompressedStack compressedStack, ContextCallback callback, Object state) bei System.Xml.XmlTextReaderImpl.OpenUrl() bei System.Xml.XmlTextReaderImpl.Read() bei System.Xml.XmlLoader.Load(XmlDocument doc, XmlReader reader, Boolean preserveWhitespace) bei System.Xml.XmlDocument.Load(XmlReader reader) bei System.Xml.XmlDocument.Load(String filename) bei Toaster.SchedulerReader.read() bei Toaster.Notifications.FullSystemBackup.FsbHelper.IsFsbScheduledNow() bei Toaster.Notifications.FullSystemBackup.FsbHelper.CheckReminder() bei Toaster.Helper.CheckReminders(ObservableCollection`1 notificationHelpers) bei Toaster.MainWindowViewModel.NotificationsTimerTick(Object sender, EventArgs e) bei System.Windows.Threading.DispatcherTimer.FireTick(Object unused) bei System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate callback, Object args, Boolean isSingleParameter) bei System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler) Error: (04/18/2014 05:24:37 PM) (Source: CVHSVC) (User: ) Description: Nur zur Information. (Stream product id=0x0066): Streaming Failed System errors: ============= Error: (04/18/2014 07:00:53 PM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (04/18/2014 07:00:53 PM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (04/18/2014 07:00:47 PM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (04/18/2014 07:00:47 PM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (04/13/2014 07:22:02 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst SftService erreicht. Error: (04/13/2014 07:21:32 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst SftService erreicht. Error: (04/13/2014 07:19:47 AM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 13.04.2014 um 07:18:22 unerwartet heruntergefahren. Error: (04/04/2014 02:05:01 PM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (03/25/2014 06:22:10 PM) (Source: DCOM) (User: ) Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Error: (03/22/2014 08:48:34 PM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Microsoft Office Sessions: ========================= Error: (04/18/2014 06:30:01 PM) (Source: Application Error)(User: ) Description: IEXPLORE.EXE11.0.9600.16521531143996esXyz.dll1.1.0.052b8d8cdc00000050001a84c139001cf5b23724689b7C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Program Files (x86)\ggReatsaver\6esXyz.dllb012067a-c716-11e3-a467-ac72899e2a90 Error: (04/18/2014 06:29:59 PM) (Source: Application Error)(User: ) Description: IEXPLORE.EXE11.0.9600.1652153114399Dolpq3mDX5.dll1.1.0.052ea8dc0c00000050001aa7617fc01cf5b236f7c6ce4C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\ProgramData\50CoupoNs\Dolpq3mDX5.dllae7175aa-c716-11e3-a467-ac72899e2a90 Error: (04/18/2014 06:26:32 PM) (Source: Application Error)(User: ) Description: IEXPLORE.EXE11.0.9600.1652153114399sOyw.dll1.1.0.052e9c87dc00000050001af80178401cf5b22f5be2c01C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\ProgramData\TubeeeItAdBlockFr\sOyw.dll33874764-c716-11e3-a467-ac72899e2a90 Error: (04/18/2014 06:26:30 PM) (Source: Application Error)(User: ) Description: IEXPLORE.EXE11.0.9600.1652153114399RAzq.dll1.1.0.052b8d8cdc00000050001a84c31c01cf5b2127df4b84C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Program Files (x86)\YoutubeAdblocker\RAzq.dll325435e1-c716-11e3-a467-ac72899e2a90 Error: (04/18/2014 06:26:24 PM) (Source: Application Error)(User: ) Description: IEXPLORE.EXE11.0.9600.1652153114399XRE4I3ID.dll1.1.0.052b8d8cdc00000050001a84cec801cf5b22f09e95caC:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Program Files (x86)\grieatsaaVeRR\XRE4I3ID.dll2e6ed54e-c716-11e3-a467-ac72899e2a90 Error: (04/18/2014 06:26:19 PM) (Source: Application Error)(User: ) Description: IEXPLORE.EXE11.0.9600.1652153114399MSHTML.dll11.0.9600.166595338aef8800000030079a7f4b3001cf5b211e8cfe8aC:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\windows\system32\MSHTML.dll2b98932b-c716-11e3-a467-ac72899e2a90 Error: (04/18/2014 06:13:22 PM) (Source: Customer Experience Improvement Program)(User: ) Description: 80004005 Error: (04/18/2014 06:03:56 PM) (Source: Application Hang)(User: ) Description: iexplore.exe11.0.9600.16521127801cf5b1bbc50f88616C:\Program Files\Internet Explorer\iexplore.exe Error: (04/18/2014 05:27:48 PM) (Source: TOASTER.EXE)(User: ) Description: An Unhandled Exception occured. Der Prozess kann nicht auf die Datei "C:\Users\Daniel\AppData\local\softthinks\scheduler.xml" zugreifen, da sie von einem anderen Prozess verwendet wird. bei System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) bei System.IO.FileStream.Init(String path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath, Boolean bFromProxy) bei System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize) bei System.Xml.XmlDownloadManager.GetStream(Uri uri, ICredentials credentials) bei System.Xml.XmlUrlResolver.GetEntity(Uri absoluteUri, String role, Type ofObjectToReturn) bei System.Xml.XmlTextReaderImpl.OpenUrlDelegate(Object xmlResolver) bei System.Threading.CompressedStack.runTryCode(Object userData) bei System.Runtime.CompilerServices.RuntimeHelpers.ExecuteCodeWithGuaranteedCleanup(TryCode code, CleanupCode backoutCode, Object userData) bei System.Threading.CompressedStack.Run(CompressedStack compressedStack, ContextCallback callback, Object state) bei System.Xml.XmlTextReaderImpl.OpenUrl() bei System.Xml.XmlTextReaderImpl.Read() bei System.Xml.XmlLoader.Load(XmlDocument doc, XmlReader reader, Boolean preserveWhitespace) bei System.Xml.XmlDocument.Load(XmlReader reader) bei System.Xml.XmlDocument.Load(String filename) bei Toaster.SchedulerReader.read() bei Toaster.Notifications.FullSystemBackup.FsbHelper.IsFsbScheduledNow() bei Toaster.Notifications.FullSystemBackup.FsbHelper.CheckReminder() bei Toaster.Helper.CheckReminders(ObservableCollection`1 notificationHelpers) bei Toaster.MainWindowViewModel.NotificationsTimerTick(Object sender, EventArgs e) bei System.Windows.Threading.DispatcherTimer.FireTick(Object unused) bei System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate callback, Object args, Boolean isSingleParameter) bei System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler) Error: (04/18/2014 05:24:37 PM) (Source: CVHSVC)(User: ) Description: (Stream product id=0x0066): Streaming Failed ==================== Memory info =========================== Percentage of memory in use: 44% Total physical RAM: 4003.16 MB Available physical RAM: 2212.66 MB Total Pagefile: 8004.51 MB Available Pagefile: 5375.48 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:581.42 GB) (Free:442.54 GB) NTFS Drive d: (LS2013) (CDROM) (Total:1.36 GB) (Free:0 GB) CDFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596 GB) (Disk ID: E78DF937) Partition 1: (Not Active) - (Size=100 MB) - (Type=DE) Partition 2: (Active) - (Size=15 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=581 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
19.04.2014, 08:00 | #4 |
| Viel Werbung bei internet explorer also hier fst FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-04-2014 01 Ran by Daniel (administrator) on DANIELS-PC on 19-04-2014 08:33:18 Running from C:\Users\Daniel\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\windows\system32\nvvsvc.exe (IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation) C:\windows\system32\nvvsvc.exe () c:\programdata\quickset\gs-enabler\GS-Enabler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe (Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Dell, Inc.) C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (SoftThinks SAS) C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Iminent) C:\Program Files (x86)\Common Files\Umbrella\umbrella.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe () C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\IELowutil.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe (Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Windows Net) C:\Users\Daniel\AppData\Roaming\Windows Net Data\net.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe () C:\Program Files (x86)\Bench\BService\bservice.exe () C:\Program Files (x86)\Bench\Wd\wd.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\HidFind.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apntex.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe () C:\Program Files (x86)\Coupon Alerts\FrameworkEngine.exe () c:\programdata\superbapp\upd inst\Upd Inst.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [525312 2011-01-25] (IDT, Inc.) HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [609144 2011-04-13] (Alps Electric Co., Ltd.) HKLM\...\Run: [QuickSet] => C:\Program Files\Dell\QuickSet\QuickSet.exe [3666800 2011-01-22] (Dell Inc.) HKLM\...\Run: [NVHotkey] => C:\Windows\system32\nvHotkey.dll [312936 2011-04-22] (NVIDIA Corporation) HKLM\...\Run: [IntelPAN] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-07-28] (Intel(R) Corporation) HKLM\...\Run: [BTMTrayAgent] => C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll [10365952 2011-05-19] (Intel Corporation) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-06] (Intel Corporation) HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [RoxWatchTray] => c:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe [240112 2010-11-25] (Sonic Solutions) HKLM-x32\...\Run: [Dell DataSafe Online] => C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe [1117528 2010-08-26] (Dell, Inc.) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40312 2013-12-18] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AccuWeatherWidget] => C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe [885760 2011-04-30] () HKLM-x32\...\Run: [BService] => C:\Program Files (x86)\Bench\BService\bservice.exe [49664 2014-02-27] () HKLM-x32\...\Run: [Wd] => C:\Program Files (x86)\Bench\Wd\wd.exe [60416 2014-02-27] () HKLM-x32\...\Runonce: [Coupon Alerts-repairJob] - wscript.exe "C:\Users\Daniel\AppData\Local\Coupon Alerts\repair.js" "Coupon Alerts-repairJob" [X] Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-1581266947-2377902997-3130898050-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [1811368 2013-09-06] (Valve Corporation) HKU\S-1-5-21-1581266947-2377902997-3130898050-1000\...\Run: [Pando Media Booster] => C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3093624 2013-01-28] () HKU\S-1-5-21-1581266947-2377902997-3130898050-1000\...\MountPoints2: {60ce2062-e7d3-11e0-b986-806e6f6e6963} - D:\Autorun.exe HKU\S-1-5-21-1581266947-2377902997-3130898050-1001\...\Run: [LiveSupport] => "C:\Program Files (x86)\LiveSupport\LiveSupport.exe" /noshow /log HKU\S-1-5-21-1581266947-2377902997-3130898050-1001\...\Policies\Explorer: [DisallowRun] 1 HKU\S-1-5-21-1581266947-2377902997-3130898050-1001\...\MountPoints2: {60ce2062-e7d3-11e0-b986-806e6f6e6963} - D:\cdstart.exe AppInit_DLLs: c:\progra~3\bitguard\271769~1.27\{c16c1~1\loader.dll => c:\progra~3\bitguard\271769~1.27\{c16c1~1\loader.dll File Not Found AppInit_DLLs: c:\windows\system32\nvinitx.dll => c:\windows\system32\nvinitx.dll [226920 2011-04-22] (NVIDIA Corporation) AppInit_DLLs: C:\PROGRA~3\ASSIST~1\ASSIST~2.DLL => C:\ProgramData\Assistant\Assistant_x64.dll [4395520 2014-04-04] () AppInit_DLLs: C:\PROGRA~2\ASSIST~2.DLL => C:\Program Files (x86)\Assistant_x64.dll [4210176 2014-04-18] () AppInit_DLLs-x32: c:\progra~3\assist~1\assist~1.dll => C:\ProgramData\Assistant\Assistant.dll [4223488 2014-04-04] () AppInit_DLLs-x32: c:\progra~2\assist~1.dll => C:\Program Files (x86)\Assistant.dll [4296192 2014-04-18] () Startup: C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\net.lnk ShortcutTarget: net.lnk -> C:\Users\Daniel\AppData\Roaming\Windows Net Data\net.exe (Windows Net) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/?gfe_rd=cr&ei=-05RU_rkMYSrtQbHjoDIDw HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.modhoster.de/ HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.aartemis.com/web/?type=ds&ts=1386964404&from=oneinstaller&uid=TOSHIBAXMK6475GSX_61RAB98ZBXX61RAB98ZB&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://aartemis.com/?type=hp&ts=1386964404&from=oneinstaller&uid=TOSHIBAXMK6475GSX_61RAB98ZBXX61RAB98ZB HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://aartemis.com/?type=hp&ts=1386964404&from=oneinstaller&uid=TOSHIBAXMK6475GSX_61RAB98ZBXX61RAB98ZB HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.aartemis.com/web/?type=ds&ts=1386964404&from=oneinstaller&uid=TOSHIBAXMK6475GSX_61RAB98ZBXX61RAB98ZB&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.aartemis.com/web/?type=ds&ts=1386964404&from=oneinstaller&uid=TOSHIBAXMK6475GSX_61RAB98ZBXX61RAB98ZB&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://aartemis.com/?type=hp&ts=1386964404&from=oneinstaller&uid=TOSHIBAXMK6475GSX_61RAB98ZBXX61RAB98ZB HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://aartemis.com/?type=hp&ts=1386964404&from=oneinstaller&uid=TOSHIBAXMK6475GSX_61RAB98ZBXX61RAB98ZB HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.aartemis.com/web/?type=ds&ts=1386964404&from=oneinstaller&uid=TOSHIBAXMK6475GSX_61RAB98ZBXX61RAB98ZB&q={searchTerms} URLSearchHook: HKLM-x32 - FileConverter 1.3 Toolbar - {78e516ef-11de-47a1-8364-a99b917ec5ee} - C:\Program Files (x86)\FileConverter_1.3\prxtbFile.dll (Conduit Ltd.) URLSearchHook: HKLM-x32 - WiseConvert 1.3 Toolbar - {213c8ed6-1d78-4d8f-8729-25006aa86a76} - C:\Program Files (x86)\WiseConvert_1.3\prxtbWis0.dll (Conduit Ltd.) StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://aartemis.com/?type=sc&ts=1386964404&from=oneinstaller&uid=TOSHIBAXMK6475GSX_61RAB98ZBXX61RAB98ZB SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.aartemis.com/web/?type=ds&ts=1386964404&from=oneinstaller&uid=TOSHIBAXMK6475GSX_61RAB98ZBXX61RAB98ZB&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.aartemis.com/web/?type=ds&ts=1386964404&from=oneinstaller&uid=TOSHIBAXMK6475GSX_61RAB98ZBXX61RAB98ZB&q={searchTerms} SearchScopes: HKLM - {796A7C9D-388B-0A72-01A7-24C6CA0BD0DF} URL = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=362&systemid=406&apn_dtid=BND406&apn_ptnrs=AG6&o=APN10645&apn_uid=8202232622004519&q={searchTerms} SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD21} URL = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=1129&systemid=1&apn_dtid=IME001&apn_ptnrs=AGE&o=APN10653&apn_uid=0177269719204841&q={searchTerms} SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=drive&cd=2XzuyEtN2Y1L1Qzu0A0CyBtBzzzyzy0EtB0AzytDzzyC0DyEtN0D0Tzu0CyEtCtAtN1L2XzutBtFtBtFtCtFyEyBzztN1L1Czu1Q1C1L2X1P&cr=1698090698&ir= SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.aartemis.com/web/?type=ds&ts=1386964404&from=oneinstaller&uid=TOSHIBAXMK6475GSX_61RAB98ZBXX61RAB98ZB&q={searchTerms} SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.aartemis.com/web/?type=ds&ts=1386964404&from=oneinstaller&uid=TOSHIBAXMK6475GSX_61RAB98ZBXX61RAB98ZB&q={searchTerms} SearchScopes: HKLM-x32 - {51BBDD2E-B05E-12EE-257E-747A5C0C4C84} URL = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=362&systemid=406&apn_dtid=BND406&apn_ptnrs=AG6&o=APN10645&apn_uid=8202232622004519&q={searchTerms} SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD21} URL = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=1129&systemid=1&apn_dtid=IME001&apn_ptnrs=AGE&o=APN10653&apn_uid=0177269719204841&q={searchTerms} SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=drive&cd=2XzuyEtN2Y1L1Qzu0A0CyBtBzzzyzy0EtB0AzytDzzyC0DyEtN0D0Tzu0CyEtCtAtN1L2XzutBtFtBtFtCtFyEyBzztN1L1Czu1Q1C1L2X1P&cr=1698090698&ir= SearchScopes: HKLM-x32 - {BFFED5CA-8BDF-47CC-AED0-23F4E6D77732} URL = hxxp://search.iminent.com/?appId=0721DB1F-9959-4541-9671-935CA5C890F9&sv=6&ref=toolbox&q={searchTerms} SearchScopes: HKLM-x32 - {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://search.sweetim.com/search.asp?src=6&q={searchTerms}&crg=3.1010006.10028&barid={DE47A95C-599F-11E2-9856-AC72899E2A90} BHO: DeaalExpREss - {20906D33-ADCE-FAE7-043C-D23F2E87411A} - C:\ProgramData\DeaalExpREss\VQs.x64.dll () BHO: grieatsaaVeRR - {46D3E824-C87B-E1E3-8702-573AAF66DB11} - C:\Program Files (x86)\grieatsaaVeRR\XRE4I3ID.x64.dll () BHO: YoutubeAdblocker - {7383F059-5CA3-2E19-74A3-C88AC682D533} - C:\Program Files (x86)\YoutubeAdblocker\RAzq.x64.dll () BHO: TubeeeItAdBlockFr - {761AA56E-7866-B945-FDE3-427455140C5B} - C:\ProgramData\TubeeeItAdBlockFr\sOyw.x64.dll () BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: IMinent WebBooster (BHO) - {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} - C:\Program Files (x86)\Iminent\Minibar.InternetExplorer.BHOx64.dll (SIEN) BHO: 50CoupoNs - {B2DAB82D-9CB4-3B46-233C-D8BCC8C7B528} - C:\ProgramData\50CoupoNs\Dolpq3mDX5.x64.dll () BHO: ggReatsaver - {D2D0552A-B02B-6EEA-D21D-ADB212E682F9} - C:\Program Files (x86)\ggReatsaver\6esXyz.x64.dll () BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO: Coupon Alerts BHO - {F791D8AE-47E8-40A5-A913-EB2D2AF29602} - C:\Program Files (x86)\Coupon Alerts\FrameworkBHO64.dll () BHO-x32: Plus-HD-2.2 - {11111111-1111-1111-1111-110311301136} - C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-bho.dll No File BHO-x32: DeaalExpREss - {20906D33-ADCE-FAE7-043C-D23F2E87411A} - C:\ProgramData\DeaalExpREss\VQs.dll () BHO-x32: WiseConvert 1.3 Toolbar - {213c8ed6-1d78-4d8f-8729-25006aa86a76} - C:\Program Files (x86)\WiseConvert_1.3\prxtbWis0.dll (Conduit Ltd.) BHO-x32: grieatsaaVeRR - {46D3E824-C87B-E1E3-8702-573AAF66DB11} - C:\Program Files (x86)\grieatsaaVeRR\XRE4I3ID.dll () BHO-x32: TBSB01620 Class - {58124A0B-DC32-4180-9BFF-E0E21AE34026} - C:\Program Files (x86)\IMinent Toolbar\tbcore3.dll () BHO-x32: CmjBrowserHelperObject Object - {6FE6A929-59D1-4763-91AD-29B61CFFB35B} - C:\Program Files (x86)\Mindjet\MindManager 11\Mm8InternetExplorer.dll (Mindjet) BHO-x32: YoutubeAdblocker - {7383F059-5CA3-2E19-74A3-C88AC682D533} - C:\Program Files (x86)\YoutubeAdblocker\RAzq.dll () BHO-x32: Funmoods Helper Object - {75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} - C:\Program Files (x86)\Funmoods\1.8.4.0\bh\escort.dll (Funmoods BHO) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) BHO-x32: TubeeeItAdBlockFr - {761AA56E-7866-B945-FDE3-427455140C5B} - C:\ProgramData\TubeeeItAdBlockFr\sOyw.dll () BHO-x32: FileConverter 1.3 Toolbar - {78e516ef-11de-47a1-8364-a99b917ec5ee} - C:\Program Files (x86)\FileConverter_1.3\prxtbFile.dll (Conduit Ltd.) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: IMinent WebBooster (BHO) - {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} - C:\Program Files (x86)\Iminent\Minibar.InternetExplorer.BHOx86.dll (SIEN) BHO-x32: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO-x32: 50CoupoNs - {B2DAB82D-9CB4-3B46-233C-D8BCC8C7B528} - C:\ProgramData\50CoupoNs\Dolpq3mDX5.dll () BHO-x32: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files (x86)\Delta\delta\1.8.21.5\bh\delta.dll (Delta-search.com) BHO-x32: ggReatsaver - {D2D0552A-B02B-6EEA-D21D-ADB212E682F9} - C:\Program Files (x86)\ggReatsaver\6esXyz.dll () BHO-x32: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: Softonic Helper Object - {E87806B5-E908-45FD-AF5E-957D83E58E68} - C:\Program Files (x86)\Softonic\Softonic\1.8.16.10\bh\Softonic.dll (Softonic.com) BHO-x32: SweetPacks Browser Helper - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) BHO-x32: Coupon Alerts BHO - {F791D8AE-47E8-40A5-A913-EB2D2AF29602} - C:\Program Files (x86)\Coupon Alerts\FrameworkBHO.dll () Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File Toolbar: HKLM-x32 - FileConverter 1.3 Toolbar - {78e516ef-11de-47a1-8364-a99b917ec5ee} - C:\Program Files (x86)\FileConverter_1.3\prxtbFile.dll (Conduit Ltd.) Toolbar: HKLM-x32 - Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask) Toolbar: HKLM-x32 - SweetPacks Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.) Toolbar: HKLM-x32 - WiseConvert 1.3 Toolbar - {213c8ed6-1d78-4d8f-8729-25006aa86a76} - C:\Program Files (x86)\WiseConvert_1.3\prxtbWis0.dll (Conduit Ltd.) Toolbar: HKLM-x32 - Funmoods Toolbar - {A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - C:\Program Files (x86)\Funmoods\1.8.4.0\escorTlbr.dll (Funmoods) Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File Toolbar: HKLM-x32 - Softonic Toolbar - {5018CFD2-804D-4C99-9F81-25EAEA2769DE} - C:\Program Files (x86)\Softonic\Softonic\1.8.16.10\SoftonicTlbr.dll (Softonic.com) Toolbar: HKLM-x32 - Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files (x86)\Delta\delta\1.8.21.5\deltaTlbr.dll (Delta-search.com) Toolbar: HKLM-x32 - IMinent Toolbar - {977AE9CC-AF83-45E8-9E03-E2798216E2D5} - C:\Program Files (x86)\IMinent Toolbar\tbcore3.dll () Toolbar: HKCU - No Name - {78E516EF-11DE-47A1-8364-A99B917EC5EE} - No File Toolbar: HKCU - No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File Toolbar: HKCU - No Name - {213C8ED6-1D78-4D8F-8729-25006AA86A76} - No File Toolbar: HKCU - No Name - {977AE9CC-AF83-45E8-9E03-E2798216E2D5} - No File DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: HKLM-x32 {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: HKLM-x32 {6A060448-60F9-11D5-A6CD-0002B31F7455} Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Hosts: 54.204.28.26 cbaiddeoemldinncijanafifphajjppj Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=1.6.0_38 - C:\windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.) FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Extension: No Name - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\profiles\extensions\extensions [2013-11-28] FF Extension: FTdownloader V4.0 - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\profiles\extensions\ftdownloader4@ftdownloader.com.xpi [2013-05-28] FF Extension: GoPhotoIt - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\profiles\extensions\gophoto@gophoto.it.xpi [2012-07-31] FF HKLM\...\Firefox\Extensions: [{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}] - C:\Program Files\V-bates\Firefox FF HKLM-x32\...\Firefox\Extensions: [{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}] - C:\Program Files\V-bates\Firefox Chrome: ======= CHR HomePage: hxxp://search.conduit.com/?ctid=CT3318001&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP3406600D-8B6E-4642-92FE-6631067E5FFC&SSPV= CHR StartupUrls: "hxxp://search.conduit.com/?ctid=CT3318001&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP3406600D-8B6E-4642-92FE-6631067E5FFC&SSPV=" CHR DefaultSearchKeyword: conduit.search CHR DefaultSearchProvider: Conduit Search CHR DefaultSearchURL: hxxp://search.conduit.com/Results.aspx?ctid=CT3318001&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SP3406600D-8B6E-4642-92FE-6631067E5FFC&q={searchTerms}&SSPV= CHR DefaultNewTabURL: CHR Extension: (Coupon Alerts) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbaiddeoemldinncijanafifphajjppj [2014-03-23] CHR Extension: (Softonic Chrome Toolbar) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\elchiiiejkobdbblfejjkbphbddgmljf [2013-08-28] CHR Extension: (Delta Toolbar) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde [2013-08-28] CHR Extension: (50CoupoNs) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgfooclchnnmdmlcgalepkplcagfkefd [2014-02-28] CHR Extension: (Lightning Newtab) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo [2014-01-09] CHR Extension: (SweetIM for Facebook) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn [2013-08-28] CHR Extension: (Plus-HD-2.2) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo [2014-01-10] CHR Extension: (Torch Share) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\kiplfnciaokpcennlkldkdaeaaomamof [2013-08-28] CHR Extension: (Amazon-Icon) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkcedibhemacmilmkpndpkoidlnmgngg [2014-01-09] CHR Extension: (TubeeeItAdBlockFr) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlmcpcpjbcokhnolhkickdekbenbakbb [2014-03-16] CHR Extension: (Google Wallet) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-28] CHR Extension: (SweetPacks Chrome Extension) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj [2013-08-28] CHR Extension: (GoPhoto.it) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfmopbbadnfoelckkcmjjeaaegjpjjbk [2013-08-28] CHR HKLM-x32\...\Chrome\Extension: [bebnnlollpcjnfpkafhoclljaojgnfok] - C:\Program Files (x86)\FTDownloader.com\FTDownloader10.crx [2013-08-28] CHR HKLM-x32\...\Chrome\Extension: [elchiiiejkobdbblfejjkbphbddgmljf] - C:\Program Files (x86)\Softonic\Softonic\1.8.16.10\Softonic.crx [2013-03-03] CHR HKLM-x32\...\Chrome\Extension: [eooncjejnppfjjklapaamhcdmjbilmde] - C:\Users\Daniel\AppData\Roaming\BabSolution\CR\Delta.crx [2013-06-15] CHR HKLM-x32\...\Chrome\Extension: [ifohbjbgfchkkfhphahclmkpgejiplfo] - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx [2013-12-13] CHR HKLM-x32\...\Chrome\Extension: [jcdgjdiieiljkfkdcloehkohchhpekkn] - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetFB.crx [2013-01-08] CHR HKLM-x32\...\Chrome\Extension: [kiplfnciaokpcennlkldkdaeaaomamof] - C:\Users\Daniel\AppData\Local\Torch\Plugins\TorchPlugin.crx [2013-02-16] CHR HKLM-x32\...\Chrome\Extension: [mkcedibhemacmilmkpndpkoidlnmgngg] - C:\Users\Daniel\ChromeExtensions\mkcedibhemacmilmkpndpkoidlnmgngg\amazon.crx [2013-11-28] CHR HKLM-x32\...\Chrome\Extension: [ogccgbmabaphcakpiclgcnmcnimhokcj] - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetNT.crx [2013-01-08] CHR HKLM-x32\...\Chrome\Extension: [ojcgaoafcmbadjkfdippkdddgkeaipbn] - C:\Program Files (x86)\DealPly\DealPly.crx [2013-01-08] CHR HKLM-x32\...\Chrome\Extension: [pfmopbbadnfoelckkcmjjeaaegjpjjbk] - C:\Program Files (x86)\Gophoto.it\gophotoit14.crx [2012-07-31] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 1a34a8e0; C:\Program Files (x86)\AssistantSvc.dll [174928 2014-04-18] () R2 699fd52f; C:\ProgramData\Assistant\AssistantSvc.dll [177488 2014-04-04] () R2 LPDSVC; C:\Windows\system32\lpdsvc.dll [45568 2009-07-14] (Microsoft Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-07-28] () R2 SProtection; C:\Program Files (x86)\Common Files\Umbrella\umbrella.exe [3052864 2014-04-12] (Iminent) S2 Windows Download Module; C:\Windows\SysWOW64\winmodule.exe [780075 2014-04-17] () ==================== Drivers (Whitelisted) ==================== ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-19 08:33 - 2014-04-19 08:33 - 00028738 _____ () C:\Users\Daniel\Desktop\FRST.txt 2014-04-19 08:33 - 2014-04-19 08:33 - 00000000 ____D () C:\FRST 2014-04-19 08:32 - 2014-04-19 08:32 - 02158592 _____ (Farbar) C:\Users\Daniel\Desktop\FRST64.exe 2014-04-18 19:01 - 2014-04-18 19:01 - 04296192 _____ () C:\Program Files (x86)\Assistant.dll 2014-04-18 19:01 - 2014-04-18 19:01 - 04210176 _____ () C:\Program Files (x86)\Assistant_x64.dll 2014-04-18 19:01 - 2014-04-18 19:01 - 00323680 _____ (SuperbApp) C:\Users\Daniel\Desktop\Defogger.exe.exe 2014-04-18 19:01 - 2014-04-18 19:01 - 00174928 _____ () C:\Program Files (x86)\AssistantSvc.dll 2014-04-18 19:01 - 2014-04-18 19:01 - 00002680 _____ () C:\windows\System32\Tasks\Upd Inst-S-5153193369 2014-04-18 19:01 - 2014-04-18 19:01 - 00000434 ____H () C:\windows\Tasks\Upd Inst-S-5153193369.job 2014-04-18 19:01 - 2014-04-18 19:01 - 00000000 ____D () C:\ProgramData\SuperbApp 2014-04-18 18:17 - 2014-04-18 18:35 - 56909952 _____ () C:\Users\Daniel\Documents\Pack_Portalkran_und_Mitnahmestapler.zip 2014-04-18 17:39 - 2014-04-18 17:39 - 01512321 _____ () C:\Users\Daniel\Desktop\Savegame_Editor.rar 2014-04-17 20:36 - 2014-04-17 21:11 - 00780075 _____ () C:\windows\SysWOW64\winmodule.exe 2014-04-17 20:36 - 2013-09-02 18:40 - 00675195 _____ () C:\windows\SysWOW64\winupdater.exe 2014-04-13 17:05 - 2014-04-13 17:05 - 00000000 ____D () C:\ProgramData\DeaalExpREss 2014-04-12 18:59 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-04-12 18:59 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2014-04-12 18:59 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb 2014-04-12 18:59 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2014-04-12 18:59 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll 2014-04-12 18:59 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll 2014-04-12 18:59 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll 2014-04-12 18:59 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll 2014-04-12 18:59 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll 2014-04-12 18:59 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll 2014-04-12 18:59 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll 2014-04-12 18:59 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe 2014-04-12 18:59 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll 2014-04-12 18:59 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe 2014-04-12 18:59 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe 2014-04-12 18:59 - 2014-02-04 04:37 - 00027584 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Diskdump.sys 2014-04-12 18:59 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\windows\system32\Drivers\msiscsi.sys 2014-04-12 18:59 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\windows\system32\Drivers\storport.sys 2014-04-12 18:59 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\iologmsg.dll 2014-04-12 18:59 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\iologmsg.dll 2014-04-12 18:59 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys 2014-04-04 13:59 - 2014-04-04 13:59 - 00000000 ____D () C:\ProgramData\Assistant 2014-04-03 16:28 - 2014-04-03 16:28 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\Ubisoft 2014-04-03 16:28 - 2014-04-03 16:28 - 00000000 ____D () C:\ProgramData\Ubisoft 2014-04-03 16:12 - 2014-04-03 16:12 - 00000000 ____D () C:\Program Files (x86)\Black_Box ==================== One Month Modified Files and Folders ======= 2014-04-19 08:33 - 2014-04-19 08:33 - 00028738 _____ () C:\Users\Daniel\Desktop\FRST.txt 2014-04-19 08:33 - 2014-04-19 08:33 - 00000000 ____D () C:\FRST 2014-04-19 08:32 - 2014-04-19 08:32 - 02158592 _____ (Farbar) C:\Users\Daniel\Desktop\FRST64.exe 2014-04-19 08:31 - 2011-09-26 04:55 - 00679316 _____ () C:\windows\system32\perfh007.dat 2014-04-19 08:31 - 2011-09-26 04:55 - 00141304 _____ () C:\windows\system32\perfc007.dat 2014-04-19 08:31 - 2009-07-14 07:13 - 01567338 _____ () C:\windows\system32\PerfStringBackup.INI 2014-04-19 08:29 - 2011-09-26 02:08 - 01232732 _____ () C:\windows\WindowsUpdate.log 2014-04-19 08:28 - 2014-01-14 15:33 - 00000284 _____ () C:\windows\Tasks\FF Watcher {AF1C556F-48FB-4E74-AA3F-A1BA1EB90CE9}.job 2014-04-19 08:28 - 2013-12-13 21:53 - 00000346 _____ () C:\windows\Tasks\bench-sys.job 2014-04-19 08:28 - 2013-12-13 21:53 - 00000346 _____ () C:\windows\Tasks\bench-S-1-5-21-1581266947-2377902997-3130898050-1001.job 2014-04-19 08:28 - 2013-06-15 13:58 - 00001908 _____ () C:\windows\Tasks\Plus-HD-2.2-chromeinstaller.job 2014-04-19 08:28 - 2013-06-15 13:58 - 00001832 _____ () C:\windows\Tasks\Plus-HD-2.2-firefoxinstaller.job 2014-04-19 08:28 - 2013-06-15 13:58 - 00001200 _____ () C:\windows\Tasks\Plus-HD-2.2-codedownloader.job 2014-04-19 08:28 - 2013-06-15 13:58 - 00001196 _____ () C:\windows\Tasks\Plus-HD-2.2-updater.job 2014-04-19 08:28 - 2013-06-15 13:58 - 00001100 _____ () C:\windows\Tasks\Plus-HD-2.2-enabler.job 2014-04-19 08:28 - 2013-01-03 20:39 - 00001110 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-19 08:28 - 2013-01-02 10:30 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job 2014-04-18 19:01 - 2014-04-18 19:01 - 04296192 _____ () C:\Program Files (x86)\Assistant.dll 2014-04-18 19:01 - 2014-04-18 19:01 - 04210176 _____ () C:\Program Files (x86)\Assistant_x64.dll 2014-04-18 19:01 - 2014-04-18 19:01 - 00323680 _____ (SuperbApp) C:\Users\Daniel\Desktop\Defogger.exe.exe 2014-04-18 19:01 - 2014-04-18 19:01 - 00174928 _____ () C:\Program Files (x86)\AssistantSvc.dll 2014-04-18 19:01 - 2014-04-18 19:01 - 00002680 _____ () C:\windows\System32\Tasks\Upd Inst-S-5153193369 2014-04-18 19:01 - 2014-04-18 19:01 - 00000434 ____H () C:\windows\Tasks\Upd Inst-S-5153193369.job 2014-04-18 19:01 - 2014-04-18 19:01 - 00000000 ____D () C:\ProgramData\SuperbApp 2014-04-18 19:01 - 2013-12-30 20:38 - 00000000 ____D () C:\ProgramData\InstallMate 2014-04-18 18:49 - 2009-07-14 06:45 - 00020720 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-18 18:49 - 2009-07-14 06:45 - 00020720 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-18 18:35 - 2014-04-18 18:17 - 56909952 _____ () C:\Users\Daniel\Documents\Pack_Portalkran_und_Mitnahmestapler.zip 2014-04-18 18:30 - 2013-10-06 10:50 - 00000000 ____D () C:\Users\Daniel\AppData\Local\CrashDumps 2014-04-18 18:10 - 2013-12-14 11:26 - 00003942 _____ () C:\windows\System32\Tasks\User_Feed_Synchronization-{C30E1290-C35F-46AA-B4E5-269D71B65FAD} 2014-04-18 17:39 - 2014-04-18 17:39 - 01512321 _____ () C:\Users\Daniel\Desktop\Savegame_Editor.rar 2014-04-18 17:22 - 2013-12-31 11:54 - 00000442 ____H () C:\windows\Tasks\GS-Enabler-S-960308484.job 2014-04-18 17:22 - 2013-01-03 20:39 - 00001106 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-18 17:22 - 2011-09-26 03:03 - 00000000 ____D () C:\Program Files (x86)\Dell DataSafe Local Backup 2014-04-18 17:22 - 2011-09-26 02:29 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-04-18 17:22 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2014-04-18 17:22 - 2009-07-14 06:51 - 00109122 _____ () C:\windows\setupact.log 2014-04-17 21:11 - 2014-04-17 20:36 - 00780075 _____ () C:\windows\SysWOW64\winmodule.exe 2014-04-13 17:05 - 2014-04-13 17:05 - 00000000 ____D () C:\ProgramData\DeaalExpREss 2014-04-13 17:05 - 2013-12-30 20:40 - 00000000 ____D () C:\ProgramData\4d09ce8d5400296d 2014-04-13 14:17 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\rescache 2014-04-12 20:29 - 2013-07-24 10:01 - 00000000 ____D () C:\windows\system32\MRT 2014-04-12 20:27 - 2011-12-21 23:48 - 90655440 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2014-04-09 13:32 - 2013-05-24 15:37 - 00003440 _____ () C:\windows\System32\Tasks\PCDEventLauncherTask 2014-04-09 13:31 - 2011-12-12 22:00 - 00000000 ____D () C:\ProgramData\PCDr 2014-04-09 12:27 - 2014-01-31 18:37 - 00000306 __RSH () C:\ProgramData\ntuser.pol 2014-04-06 10:04 - 2011-12-24 17:03 - 00000000 ____D () C:\windows\System32\Tasks\Games 2014-04-05 18:19 - 2013-11-23 11:49 - 00000000 ____D () C:\Users\Daniel\Documents\Euro Truck Simulator 2 2014-04-05 17:43 - 2012-05-19 23:16 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\Grand Ages Rome 2014-04-05 02:13 - 2014-01-26 11:40 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\.minecraft 2014-04-04 14:13 - 2013-03-27 19:26 - 00000000 ____D () C:\Users\Daniel\Desktop\alles ordner 2014-04-04 13:59 - 2014-04-04 13:59 - 00000000 ____D () C:\ProgramData\Assistant 2014-04-04 13:59 - 2013-12-30 20:47 - 00000000 ____D () C:\Program Files (x86)\GS-Enabler 2014-04-03 16:28 - 2014-04-03 16:28 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\Ubisoft 2014-04-03 16:28 - 2014-04-03 16:28 - 00000000 ____D () C:\ProgramData\Ubisoft 2014-04-03 16:12 - 2014-04-03 16:12 - 00000000 ____D () C:\Program Files (x86)\Black_Box 2014-04-03 16:05 - 2011-09-26 02:50 - 00000000 ____D () C:\ProgramData\Sonic 2014-03-31 09:35 - 2010-11-21 05:27 - 00270496 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe 2014-03-31 03:16 - 2014-04-12 18:59 - 23134208 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-12 18:59 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-12 18:59 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-12 18:59 - 17073152 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2014-03-23 20:43 - 2013-09-01 11:11 - 00000000 ____D () C:\Users\Daniel\Desktop\mods ordener 2014-03-23 15:21 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\system32\NDF Files to move or delete: ==================== C:\ProgramData\3lwtrfh.dss C:\ProgramData\hfrtwl3.bxx C:\ProgramData\hfrtwl3.fvv C:\ProgramData\hfrtwl3.pss Some content of TEMP: ==================== C:\Users\Daniel\AppData\Local\Temp\amazonicon_v3.exe C:\Users\Daniel\AppData\Local\Temp\amazoninstallernircmdc.exe C:\Users\Daniel\AppData\Local\Temp\ApnStub.exe C:\Users\Daniel\AppData\Local\Temp\AutoRun.exe C:\Users\Daniel\AppData\Local\Temp\AutoRunGUI.dll C:\Users\Daniel\AppData\Local\Temp\BundleSweetIMSetup.exe C:\Users\Daniel\AppData\Local\Temp\chatzum_softonic_yahoo_62_v5.exe C:\Users\Daniel\AppData\Local\Temp\comver.dll C:\Users\Daniel\AppData\Local\Temp\DeltaTB.exe C:\Users\Daniel\AppData\Local\Temp\down.5576.helper_setup.exe C:\Users\Daniel\AppData\Local\Temp\EAD5244.exe C:\Users\Daniel\AppData\Local\Temp\EAD8E5.exe C:\Users\Daniel\AppData\Local\Temp\EADBD07.exe C:\Users\Daniel\AppData\Local\Temp\EADC1F7.exe C:\Users\Daniel\AppData\Local\Temp\EADCA8E.exe C:\Users\Daniel\AppData\Local\Temp\EADD72B.exe C:\Users\Daniel\AppData\Local\Temp\EADDAA5.exe C:\Users\Daniel\AppData\Local\Temp\EADE5BC.exe C:\Users\Daniel\AppData\Local\Temp\EADF6DC.exe C:\Users\Daniel\AppData\Local\Temp\farcry3_1.02.exe C:\Users\Daniel\AppData\Local\Temp\filebulldogTb_1.0.0.8.exe C:\Users\Daniel\AppData\Local\Temp\htmlayout.dll C:\Users\Daniel\AppData\Local\Temp\i4jdel0.exe C:\Users\Daniel\AppData\Local\Temp\i4jdel1.exe C:\Users\Daniel\AppData\Local\Temp\iMesh_setup.exe C:\Users\Daniel\AppData\Local\Temp\installerdll781175.dll C:\Users\Daniel\AppData\Local\Temp\installerdll801345.dll C:\Users\Daniel\AppData\Local\Temp\Installhelper.dll C:\Users\Daniel\AppData\Local\Temp\iupdate.exe C:\Users\Daniel\AppData\Local\Temp\jre-6u38-windows-i586-iftw.exe C:\Users\Daniel\AppData\Local\Temp\jre-7u40-windows-i586-iftw.exe C:\Users\Daniel\AppData\Local\Temp\LiveSupport_setup.exe C:\Users\Daniel\AppData\Local\Temp\mgsqlite3.dll C:\Users\Daniel\AppData\Local\Temp\Minecraft_1.7.2.dl.exe C:\Users\Daniel\AppData\Local\Temp\MSND931.exe C:\Users\Daniel\AppData\Local\Temp\MybabylonTB.exe C:\Users\Daniel\AppData\Local\Temp\nsiB06C.tmp.tbFile.dll C:\Users\Daniel\AppData\Local\Temp\nskB3CC.exe C:\Users\Daniel\AppData\Local\Temp\nskB63D.exe C:\Users\Daniel\AppData\Local\Temp\nsp8F59.exe C:\Users\Daniel\AppData\Local\Temp\nsp9218.exe C:\Users\Daniel\AppData\Local\Temp\nsuDD77.exe C:\Users\Daniel\AppData\Local\Temp\OptimizerPro.exe C:\Users\Daniel\AppData\Local\Temp\pricepeep_130001_1001.exe C:\Users\Daniel\AppData\Local\Temp\propsys.dll C:\Users\Daniel\AppData\Local\Temp\QuickShare1.exe C:\Users\Daniel\AppData\Local\Temp\rootsupd.exe C:\Users\Daniel\AppData\Local\Temp\sdanircmdc.exe C:\Users\Daniel\AppData\Local\Temp\sdapskill.exe C:\Users\Daniel\AppData\Local\Temp\Setup.exe C:\Users\Daniel\AppData\Local\Temp\setup__3862.exe C:\Users\Daniel\AppData\Local\Temp\Shortcut_sweetim_0711-adf025c2.exe C:\Users\Daniel\AppData\Local\Temp\SIMEEI2Installer.exe C:\Users\Daniel\AppData\Local\Temp\SIMEEIInstaller.exe C:\Users\Daniel\AppData\Local\Temp\SmartbarExeInstaller.exe C:\Users\Daniel\AppData\Local\Temp\softonic_chr_1-8-16-10.exe C:\Users\Daniel\AppData\Local\Temp\SRAssetsHelper.dll C:\Users\Daniel\AppData\Local\Temp\swt-win32-3740.dll C:\Users\Daniel\AppData\Local\Temp\tbedrs.dll C:\Users\Daniel\AppData\Local\Temp\tbGam0.dll C:\Users\Daniel\AppData\Local\Temp\TB_A68D.exe C:\Users\Daniel\AppData\Local\Temp\TB_A69D.exe C:\Users\Daniel\AppData\Local\Temp\TB_AA35.exe C:\Users\Daniel\AppData\Local\Temp\toolbar4579939.exe C:\Users\Daniel\AppData\Local\Temp\toolbar4582123.exe C:\Users\Daniel\AppData\Local\Temp\TorchSetupFull.exe C:\Users\Daniel\AppData\Local\Temp\Tsu0902B453.dll C:\Users\Daniel\AppData\Local\Temp\Tsu15BB0748.dll C:\Users\Daniel\AppData\Local\Temp\Tsu19DC5FEA.dll C:\Users\Daniel\AppData\Local\Temp\Tsu1E81743A.dll C:\Users\Daniel\AppData\Local\Temp\Tsu30205790.dll C:\Users\Daniel\AppData\Local\Temp\Tsu9A81099F.dll C:\Users\Daniel\AppData\Local\Temp\TsuFBB58280.dll C:\Users\Daniel\AppData\Local\Temp\TuneUpUtilities2013_de-DE.exe C:\Users\Daniel\AppData\Local\Temp\TuneUpUtilities2013_de-DE[1].exe C:\Users\Daniel\AppData\Local\Temp\ubi9F7A.tmp.exe C:\Users\Daniel\AppData\Local\Temp\uninst1.exe C:\Users\Daniel\AppData\Local\Temp\uninstall65697184.exe C:\Users\Daniel\AppData\Local\Temp\UninstallEADM.dll C:\Users\Daniel\AppData\Local\Temp\vcredist_x64.exe C:\Users\Daniel\AppData\Local\Temp\vcredist_x86.exe C:\Users\Daniel\AppData\Local\Temp\wajam_download.exe C:\Users\Daniel\AppData\Local\Temp\WindowsInstaller-KB893803-v2-x86.exe C:\Users\Daniel\AppData\Local\Temp\_4FB4.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-13 14:08 ==================== End Of Log ============================ |
19.04.2014, 19:32 | #5 |
/// the machine /// TB-Ausbilder | Viel Werbung bei internet explorer Revo Uninstaller - Download - Filepony Damit alles deinstallieren was Du in der Additional.txt findest mit dem Zusatz <== ATTENTION Mit Revo auch Moderat die Reste entfernen lassen. Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Viel Werbung bei internet explorer |
explore, explorer, inter, interne, internet, internet explorer, problem, viel werbung, werbung, werbung auf jeder internetseite |