|
Log-Analyse und Auswertung: Windows 8 - Sound funktioniert nicht richtig/Youtube(andere Musikmöglichkeiten) funktionieren auch nicht!Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
11.07.2014, 11:28 | #1 |
| Windows 8 - Sound funktioniert nicht richtig/Youtube(andere Musikmöglichkeiten) funktionieren auch nicht! Hallo erstmal! Hab alle Schritte versucht durchzuarbeiten, alles was ich bekam war leider nur das Frst.txt und das Addtion.txt. Bei dem GMER ist mein Laptop abgestürzt. Könnt ihr bitte helfen? Addition.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-07-2014 Ran by Muhammed at 2014-07-11 11:50:47 Running from C:\Users\Muhammed\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated) Adobe Reader XI (11.0.07) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated) Amazon Music (HKCU\...\Amazon Amazon Music) (Version: 3.0.0.564 - Amazon Services LLC) ASUS InstantOn (HKLM-x32\...\{749F674B-2674-47E8-879C-5626A06B2A91}) (Version: 3.0.5 - ASUS) ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.1.9 - ASUS) ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.1.9 - ASUS) ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 2.1.7 - ASUS) ASUS Screen Saver (HKLM\...\{0FBEEDF8-30FA-4FA3-B31F-C9C7E7E8DFA2}) (Version: 1.0.1 - ASUS) ASUS Smart Gesture (HKLM-x32\...\{4D3286A6-F6AB-498A-82A4-E4F040529F3D}) (Version: 2.2.0 - ASUS) ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 2.01.0005 - ASUS) ASUS USB Charger Plus (HKLM-x32\...\{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}) (Version: 2.1.5 - ASUS) ASUS WebStorage Sync Agent (HKLM-x32\...\ASUS WebStorage) (Version: 1.1.18.159 - ASUS Cloud Corporation) ASUSDVD (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.4126.52 - CyberLink Corp.) ASUSDVD (x32 Version: 10.0.4126.52 - CyberLink Corp.) Hidden AsusVibe2.0 (HKLM-x32\...\Asus Vibe2.0) (Version: 2.0.12.309 - ASUSTEK) Automation Software Updater (x32 Version: 01.00.0000 - Siemens AG) Hidden Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.5.464 - Avira) Borderlands 2 (HKLM-x32\...\Steam App 49520) (Version: - Gearbox Software) CCleaner (HKLM\...\CCleaner) (Version: 4.08 - Piriform) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Dropbox (HKCU\...\Dropbox) (Version: 2.8.2 - Dropbox, Inc.) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - ) EPSON-Drucker-Software (HKLM\...\EPSON Printer and Utilities) (Version: - SEIKO EPSON Corporation) Far Cry® 3 (HKLM-x32\...\Steam App 220240) (Version: - Ubisoft Montreal, Massive Entertainment, and Ubisoft Shanghai) FileZilla Client 3.8.1 (HKCU\...\FileZilla Client) (Version: 3.8.1 - Tim Kosse) Fotogalerie (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Free YouTube to MP3 Converter version 3.12.17.1127 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.17.1127 - DVDVideoSoft Ltd.) Galerie de photos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 35.0.1916.153 - Google Inc.) Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2932 - Intel Corporation) Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation) Intel® Trusted Connect Service Client (Version: 1.24.388.1 - Intel Corporation) Hidden League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games ) League of Legends (x32 Version: 3.0.1 - Riot Games ) Hidden Malwarebytes Anti-Malware Version 1.75.0.1300 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation) Math-Kernel-Bibliotheken (64 Bit) (Version: 1.0.31.0 - National Instruments) Hidden Math-Kernel-Bibliotheken (64 Bit) (Version: 13.0.13 - National Instruments) Hidden Math-Kernel-Bibliotheken (x32 Version: 1.0.31.0 - National Instruments) Hidden Math-Kernel-Bibliotheken (x32 Version: 13.0.13 - National Instruments) Hidden Microsoft App Update for microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe (x64) (Version: 1.0.0.0 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation) Microsoft Primary Interoperability Assemblies 2005 (HKLM-x32\...\{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft Silverlight 5.1 (x32 Version: 5.1.4001 - National Instruments) Hidden Microsoft SkyDrive (HKCU\...\SkyDriveSetup.exe) (Version: 17.0.2015.0811 - Microsoft Corporation) Microsoft SOAP Toolkit 3.0 (HKLM-x32\...\{BCB4C18A-ACA6-4383-8688-E19933A705DD}) (Version: 3.0.1325.4 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Mozilla Firefox 30.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 30.0 (x86 de)) (Version: 30.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden MyBitCast 2.0 (HKLM-x32\...\MyBitCast) (Version: 2.0 - ASUS) National Instruments - Software (HKLM-x32\...\NI Uninstaller) (Version: - National Instruments) NCM GPRS 64 (Version: 01.01.0000 - Siemens AG) Hidden NI .NET Framework 4.0 (x32 Version: 4.01.49152 - National Instruments) Hidden NI Assistant Framework (x32 Version: 9.0.143 - National Instruments) Hidden NI Assistant Framework 64-bit (Version: 9.0.143 - National Instruments) Hidden NI Assistant Framework LabVIEW 2013 Support (x32 Version: 9.0.107 - National Instruments) Hidden NI Assistant Framework LabVIEW Code Generator 2013 (x32 Version: 9.0.107 - National Instruments) Hidden NI Authentication 13.0.0 (64-bit) (Version: 13.0.326 - National Instruments) Hidden NI Authentication 13.0.0 (x32 Version: 13.0.326 - National Instruments) Hidden NI CodeSignAPI (x32 Version: 2.70.346 - National Instruments) Hidden NI Curl 13.0.0 (64-bit) (Version: 13.0.324 - National Instruments) Hidden NI Curl 13.0.0 (x32 Version: 13.0.324 - National Instruments) Hidden NI DataSocket 5.1 (64 Bit) (Version: 5.1.227 - National Instruments) Hidden NI DataSocket 5.1 (x32 Version: 5.1.227 - National Instruments) Hidden NI Error Reporting Interface Installer 5.5 (x32 Version: 5.50.49152 - National Instruments) Hidden NI Error Reporting Interface Installer 5.5 for Windows 64-bit (Version: 5.50.49152 - National Instruments) Hidden NI EulaDepot (x32 Version: 3.20.361 - National Instruments) Hidden NI Example Finder 13.0 (x32 Version: 13.0.324 - National Instruments) Hidden NI GMP Windows 32-bit Installer 13.0.0 (x32 Version: 13.0.45.0 - National Instruments) Hidden NI GMP Windows 64-bit Installer 13.0.0 (Version: 13.0.45.0 - National Instruments) Hidden NI Help Assistant 2.0 (64bit) (Version: 2.0.3 - National Instruments) Hidden NI Help Assistant 2.0 (x32 Version: 2.0.3 - National Instruments) Hidden NI Instrument IO Assistant for LabVIEW 2013 32-bit (x32 Version: 1.0.14.0 - National Instruments) Hidden NI LabVIEW 2011 Real-Time NBFifo (x32 Version: 11.0.250.0 - National Instruments) Hidden NI LabVIEW 2012 Real-Time NBFifo (x32 Version: 12.0.219.0 - National Instruments) Hidden NI LabVIEW 2012 Real-Time NBFifo (x32 Version: 13.0.336 - National Instruments) Hidden NI LabVIEW 2013 (32 Bit) (x32 Version: 13.0.105 - National Instruments) Hidden NI LabVIEW 2013 Deployable License (x32 Version: 13.0.303 - National Instruments) Hidden NI LabVIEW 2013 Deployment Framework (x32 Version: 13.0.330 - National Instruments) Hidden NI LabVIEW 2013 f2 (x32 Version: 13.0.339 - National Instruments) Hidden NI LabVIEW 2013 Help (x32 Version: 13.0.106 - National Instruments) Hidden NI LabVIEW 2013 Help File (x32 Version: 13.0.299 - National Instruments) Hidden NI LabVIEW 2013 License (x32 Version: 13.0.342 - National Instruments) Hidden NI LabVIEW 2013 Manuals (x32 Version: 13.0.105 - National Instruments) Hidden NI LabVIEW 2013 MeasAppChm File (x32 Version: 13.0.299 - National Instruments) Hidden NI LabVIEW 2013 Real-Time Error Dialog (x32 Version: 13.0.123 - National Instruments) Hidden NI LabVIEW 2013 Scripting Code Generator (x32 Version: 9.0.172 - National Instruments) Hidden NI LabVIEW 2013 Search (x32 Version: 13.0.16 - National Instruments) Hidden NI LabVIEW 2013 Simulation (x32 Version: 13.0.327 - National Instruments) Hidden NI LabVIEW 2013 Variable Web Service (x32 Version: 13.0.326 - National Instruments) Hidden NI LabVIEW 2013 Web Server (x32 Version: 13.0.327 - National Instruments) Hidden NI LabVIEW Broker (64 bit) (Version: 6.8.10.0 - National Instruments) Hidden NI LabVIEW Broker (x32 Version: 6.8.10.0 - National Instruments) Hidden NI LabVIEW C Interface (x32 Version: 1.0.1 - National Instruments) Hidden NI LabVIEW Compare Utility 13.0.0 (x32 Version: 13.0.340 - National Instruments) Hidden NI LabVIEW MAX XML (x32 Version: 9.0.6.0 - National Instruments) Hidden NI LabVIEW Merge Utility 13.0.0 (x32 Version: 13.0.339 - National Instruments) Hidden NI LabVIEW Run-Time Engine 2011 SP1 (x32 Version: 11.0.448.0 - National Instruments) Hidden NI LabVIEW Run-Time Engine 2012 SP1 f3 (x32 Version: 12.1.58.0 - National Instruments) Hidden NI LabVIEW Run-Time Engine Interop 2011 (x32 Version: 11.0.449.0 - National Instruments) Hidden NI LabVIEW Run-Time Engine Interop 2012 SP1 (x32 Version: 12.1.58.0 - National Instruments) Hidden NI LabVIEW Run-Time Engine Interop 2013 (x32 Version: 13.0.337 - National Instruments) Hidden NI LabVIEW Run-Time Engine Webserver 2012 (x32 Version: 12.5.198.0 - National Instruments) Hidden NI LabVIEW Run-Time Engine Webserver 2013 (x32 Version: 13.0.321 - National Instruments) Hidden NI LabVIEW Runtime-Engine 2013 f2 (x32 Version: 13.0.337 - National Instruments) Hidden NI LabVIEW Web Server for Run-Time Engine (x32 Version: 11.0.375.0 - National Instruments) Hidden NI LabVIEW Web Services Runtime (x32 Version: 13.0.314 - National Instruments) Hidden NI LabWindows/CVI 2010 SP1 Analysis Library (64-bit) (Version: 10.0.1434 - National Instruments) Hidden NI LabWindows/CVI 2010 SP1 Analysis Library (x32 Version: 10.0.1434 - National Instruments) Hidden NI LabWindows/CVI 2010 SP1 Code Generator (x32 Version: 10.0.1434 - National Instruments) Hidden NI LabWindows/CVI 2010 SP1 Low-Level Driver (Original) (x32 Version: 10.0.1434 - National Instruments) Hidden NI LabWindows/CVI 2010 SP1 Low-Level Driver (Updated) (x32 Version: 10.0.1434 - National Instruments) Hidden NI LabWindows/CVI 2010 SP1 Network Variable Library (64-bit) (Version: 10.0.1434 - National Instruments) Hidden NI LabWindows/CVI 2010 SP1 Network Variable Library (x32 Version: 10.0.1434 - National Instruments) Hidden NI LabWindows/CVI 2010 SP1 Run-Time Engine (64-bit) (Version: 10.0.1434 - National Instruments) Hidden NI LabWindows/CVI 2010 SP1 TDM Streaming Library (64-bit) (Version: 10.0.1434 - National Instruments) Hidden NI LabWindows/CVI 2010 SP1 TDM Streaming Library (x32 Version: 10.0.1434 - National Instruments) Hidden NI LabWindows/CVI 2012 LabVIEW DLL Builder (x32 Version: 12.0.0422 - National Instruments) Hidden NI LabWindows/CVI Run-Time Engine 2010 SP1 (Updated) (x32 Version: 10.0.1434 - National Instruments) Hidden NI LabWindows/CVI Run-Time Engine 2010 SP1 (x32 Version: 10.0.1434 - National Instruments) Hidden NI Launcher (x32 Version: 3.20.351 - National Instruments) Hidden NI License Manager (x32 Version: 3.7.53 - National Instruments) Hidden NI Logos 5.5 (64 Bit) (Version: 5.5.293 - National Instruments) Hidden NI Logos 5.5 (x32 Version: 5.5.293 - National Instruments) Hidden NI Logos LabVIEW 2013 Support (x32 Version: 13.0.106 - National Instruments) Hidden NI Logos XT Support (x32 Version: 5.5.294 - National Instruments) Hidden NI Logos64 XT Support (Version: 5.5.294 - National Instruments) Hidden NI Math Kernel Libraries (64-bit) (Version: 1.0.10.0 - National Instruments) Hidden NI Math Kernel Libraries (x32 Version: 1.0.10.0 - National Instruments) Hidden NI MAX Remote Configuration 64-bit Installer 5.5 (Version: 5.50.49152 - National Instruments) Hidden NI MAX Remote Configuration Installer 5.5 (x32 Version: 5.50.49152 - National Instruments) Hidden NI MAX Support for 64 Bit Windows (Version: 5.50.49152 - National Instruments) Hidden NI MDF Support (x32 Version: 3.20.361 - National Instruments) Hidden NI mDNS Responder 2.2 for Windows 64-bit (Version: 2.20.49152 - National Instruments) Hidden NI mDNS Responder 2.2.0 (x32 Version: 2.20.49152 - National Instruments) Hidden NI Measurement & Automation Explorer 5.5.0 (x32 Version: 5.50.49152 - National Instruments) Hidden NI Measurement Studio ComponentWorks 3D Graph (x32 Version: 8.6.10603 - National Instruments) Hidden NI Measurement Studio ComponentWorks UI (x32 Version: 8.6.10603 - National Instruments) Hidden NI Measurement Studio Recipe Processor (x32 Version: 8.0.0101 - National Instruments) Hidden NI MetaSuite Installer (x32 Version: 3.20.351 - National Instruments) Hidden NI MXS 5.5.0 (x32 Version: 5.50.49152 - National Instruments) Hidden NI MXS 5.5.0 for 64 Bit Windows (Version: 5.50.49152 - National Instruments) Hidden NI Network Discovery 5.5 (x32 Version: 5.50.49152 - National Instruments) Hidden NI Network Discovery 5.5 for Windows 64-bit (Version: 5.50.49152 - National Instruments) Hidden NI OPC Support (x32 Version: 13.0.296 - National Instruments) Hidden NI OPCEnum Shared (x32 Version: 5.5.2018 - National Instruments) Hidden NI Portable Configuration 5.5.0 (x32 Version: 5.50.49152 - National Instruments) Hidden NI Portable Configuration for 64 Bit Windows 5.5.0 (Version: 5.50.49152 - National Instruments) Hidden NI Registration Wizard (x32 Version: 1.3.97.0 - National Instruments) Hidden NI Remote Provider for MAX 5.5.0 (x32 Version: 5.50.49152 - National Instruments) Hidden NI Remote PXI Provider for MAX 5.5.0 (x32 Version: 5.50.49152 - National Instruments) Hidden NI Search Shared (x32 Version: 13.0.13 - National Instruments) Hidden NI Security Update (KB 67L8LCQW) (64-bit) (Version: 1.0.29.0 - National Instruments) Hidden NI Security Update (KB 67L8LCQW) (x32 Version: 1.0.29.0 - National Instruments) Hidden NI Service Locator 13.0 (x32 Version: 13.0.307 - National Instruments) Hidden NI SLCP 2.0 (x32 Version: 2.0.27 - National Instruments) Hidden NI Software Provider for MAX 5.5.0 (x32 Version: 5.50.49152 - National Instruments) Hidden NI SSL LabVIEW 2013 Support (x32 Version: 13.0.328 - National Instruments) Hidden NI SSL LabVIEW RTE 2012 SP1 Support (x32 Version: 12.5.8.0 - National Instruments) Hidden NI SSL LabVIEW RTE 2013 Support (x32 Version: 13.0.317 - National Instruments) Hidden NI System API .NET 5.5.0 (x32 Version: 5.50.157 - National Instruments) Hidden NI System API Client for WIF 5.5.0 (x32 Version: 5.50.419 - National Instruments) Hidden NI System API Web-Service 32-bit 5.5.0 (x32 Version: 5.50.405 - National Instruments) Hidden NI System API Windows 32-bit 5.5.0 (x32 Version: 5.50.589 - National Instruments) Hidden NI System API Windows 64-bit 5.5.0 (Version: 5.50.588 - National Instruments) Hidden NI System Configuration 5.5.0 LabVIEW Support (x32 Version: 5.50.186 - National Instruments) Hidden NI System Configuration LV2013 Support 5.5.0 (x32 Version: 5.50.178 - National Instruments) Hidden NI System Configuration Runtime 5.5.0 for Windows 64-bit (Version: 5.50.226 - National Instruments) Hidden NI System State Publisher (64-bit) (Version: 13.0.299 - National Instruments) Hidden NI System State Publisher (x32 Version: 13.0.304 - National Instruments) Hidden NI System Web Server 13.0 (x32 Version: 13.0.333 - National Instruments) Hidden NI System Web Server Base 13.0.0 (64-bit) (Version: 13.0.324 - National Instruments) Hidden NI System Web Server Base 13.0.0 (x32 Version: 13.0.324 - National Instruments) Hidden NI TDM Excel Add-In 3.5 (x32 Version: 3.5.9 - National Instruments) Hidden NI TDM Excel Add-In 3.5 64-bit (Version: 3.5.9 - National Instruments) Hidden NI TDM Streaming 2.5 (64 Bit) (Version: 2.5.36 - National Instruments) Hidden NI TDM Streaming 2.5 (x32 Version: 2.5.36 - National Instruments) Hidden NI Trace Engine (64-bit) (Version: 13.0.324 - National Instruments) Hidden NI Trace Engine (x32 Version: 13.0.324 - National Instruments) Hidden NI Uninstaller (x32 Version: 3.20.361 - National Instruments) Hidden NI Unterstützung für nicht englische Versionen der Runtime-Engine von LabVIEW 2011 SP1 (x32 Version: 11.0.302.0 - National Instruments) Hidden NI Update Service 2.3 (64-bit) (Version: 2.30.53 - National Instruments) Hidden NI USI 2.0.1 (x32 Version: 2.0.15249 - National Instruments) Hidden NI USI 2.0.1 64-Bit (Version: 2.0.15249 - National Instruments) Hidden NI Variable Engine (64-bit) (Version: 2.7.297 - National Instruments) Hidden NI Variable Engine 2.6.0 (x32 Version: 2.7.297 - National Instruments) Hidden NI Variable Engine LabVIEW 2013 Support (x32 Version: 13.0.106 - National Instruments) Hidden NI VC2005MSMs x64 (Version: 8.05.0 - National Instruments) Hidden NI VC2005MSMs x86 (x32 Version: 8.05.0 - National Instruments) Hidden NI VC2008MSMs x64 (Version: 9.0.401 - National Instruments) Hidden NI VC2008MSMs x86 (x32 Version: 9.0.401 - National Instruments) Hidden NI VC2010SP1MSMs x64 (Version: 10.0.100 - National Instruments) Hidden NI VC2010SP1MSMs x86 (x32 Version: 10.0.100 - National Instruments) Hidden NI VIPM Helper 2013 (x32 Version: 13.0.339 - National Instruments) Hidden NI Web Application Server 13.0 (64 Bit) (Version: 13.0.319 - National Instruments) Hidden NI Web Application Server 13.0 (x32 Version: 13.0.324 - National Instruments) Hidden NI Web Pipeline 3.3 (64-bit) (Version: 3.30.24 - National Instruments) Hidden NI Web Pipeline 3.3 (x32 Version: 3.30.24 - National Instruments) Hidden NI Xalan Delay Load 1.10.2 (x32 Version: 1.10.72.0 - National Instruments) Hidden NI Xalan Delay Load 1.10.2 64-bit (Version: 1.10.73.0 - National Instruments) Hidden NI Xerces Delay Load 2.7.3 (x32 Version: 2.7.180.0 - National Instruments) Hidden NI Xerces Delay Load 2.7.3 64-bit (Version: 2.7.190.0 - National Instruments) Hidden NI-ActiveX-Container (64-bit) (Version: 13.0.4 - National Instruments) Hidden NI-ActiveX-Container (x32 Version: 13.0.4 - National Instruments) Hidden NI-DAQmx/LabVIEW shared documentation 9.7.5 (x32 Version: 9.75.49152 - National Instruments) Hidden NI-DAQmx/LabVIEW shared documentation for 64 Bit Windows 9.7.5 (Version: 9.75.49152 - National Instruments) Hidden NI-DSM 2013 (x32 Version: 13.0.338 - National Instruments) Hidden NI-Fehlerprotokolle 2013 (x32 Version: 13.0.324 - National Instruments) Hidden NI-Mesa (Version: 12.0.7.0 - National Instruments) Hidden NI-Mesa (x32 Version: 12.0.7.0 - National Instruments) Hidden NI-Qualitätssteigerungsprogramm (x32 Version: 2.0.77 - National Instruments) Hidden NI-RPC 4.4.0f0 (x32 Version: 4.40.49152 - National Instruments) Hidden NI-RPC 4.4.0f0 for 64 Bit Windows (Version: 4.40.49152 - National Instruments) Hidden NI-RPC 4.4.0f0 for Phar Lap ETS (x32 Version: 4.40.49152 - National Instruments) Hidden NI-Update-Dienst 2.3 (x32 Version: 2.30.65 - National Instruments) Hidden NI-Webkonfiguration und Überwachung 2013 (x32 Version: 13.0.306 - National Instruments) Hidden NVIDIA Control Panel 311.93 (Version: 311.93 - NVIDIA Corporation) Hidden NVIDIA Graphics Driver 311.93 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 311.93 - NVIDIA Corporation) NVIDIA HD Audio Driver 1.3.24.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.24.2 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.124.810 - NVIDIA Corporation) Hidden NVIDIA Optimus 4.11.9 (Version: 4.11.9 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.13.0604 - NVIDIA Corporation) Hidden NVIDIA PhysX System Software 9.13.0604 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0604 - NVIDIA Corporation) NVIDIA Update 4.11.9 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 4.11.9 - NVIDIA Corporation) NVIDIA Update Components (Version: 4.11.9 - NVIDIA Corporation) Hidden OpenOffice 4.0.1 (HKLM-x32\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation) Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.7 - Pando Networks Inc.) Photo Common (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Photo Gallery (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.) Qualcomm Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros) Raccolta foto (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.7.1025.2012 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6937 - Realtek Semiconductor Corp.) Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.2.9200.27030 - Realtek Semiconductor Corp.) Reset NI Config 5.5.0 (x32 Version: 5.50.227 - National Instruments) Hidden Runtime für den NI-Systemkonfigurator 5.5.0 (x32 Version: 5.50.226 - National Instruments) Hidden Samsung_MonSetup (HKLM-x32\...\{8EA79DBF-D637-448A-89D6-410A087A4493}) (Version: 1.00.0000 - Samsung) SeCon (x32 Version: 02.01.0000 - Siemens AG) Hidden Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee) Siemens Totally Integrated Automation Portal V13 - Hardware Support Base Package 0 V13.0 (x32 Version: 13.00.0000 - Siemens AG) Hidden Siemens Totally Integrated Automation Portal V13 - Hardware Support Base Package 02 V13.0 (x32 Version: 13.00.0000 - Siemens AG) Hidden Siemens Totally Integrated Automation Portal V13 - Hardware Support Base Package 03 V13.0 (x32 Version: 13.00.0000 - Siemens AG) Hidden Siemens Totally Integrated Automation Portal V13 - Hardware Support Base Package WCF-01 V13.0 (x32 Version: 13.00.0000 - Siemens AG) Hidden Siemens Totally Integrated Automation Portal V13 - HM All Editions Single SetupPackage V13.0 (x32 Version: 13.00.0000 - Siemens AG) Hidden Siemens Totally Integrated Automation Portal V13 - HM NoBasic Single SetupPackage V13.0 (x32 Version: 13.00.0000 - Siemens AG) Hidden Siemens Totally Integrated Automation Portal V13 - Simatic Single SetupPackage V13.0 (x32 Version: 13.00.0000 - Siemens AG) Hidden Siemens Totally Integrated Automation Portal V13 - STEP 7 Single SetupPackage V13.0 (x32 Version: 13.00.0000 - Siemens AG) Hidden Siemens Totally Integrated Automation Portal V13 - Support Base Package TO-01 V13.0 (x32 Version: 13.00.0000 - Siemens AG) Hidden Siemens Totally Integrated Automation Portal V13 - Support Base Package TO-02 V13.0 (x32 Version: 13.00.0000 - Siemens AG) Hidden Siemens Totally Integrated Automation Portal V13 - TIACOMPCHECK Single SetupPackage V13.0 (x32 Version: 13.00.0000 - Siemens AG) Hidden Siemens Totally Integrated Automation Portal V13 - WinCC Single SetupPackage V13.0 (x32 Version: 13.00.0000 - Siemens AG) Hidden Siemens Automation License Manager (Version: 05.03.0001 - Siemens AG) Hidden Siemens Automation License Manager V5.3 + Upd1 (HKLM\...\{34A9817D-BA56-4688-A810-C76ECB118DB4}LicenseManager) (Version: 05.03.0001 - Siemens AG) SIMATIC Device Drivers (Version: 01.02.0300 - Siemens AG) Hidden SIMATIC Device Drivers WoW (x32 Version: 20.02.0300 - Siemens AG) Hidden SIMATIC Event Database (x32 Version: 05.05.0300 - Siemens AG) Hidden SIMATIC HMI License Manager Panel Plugin (x64) (Version: 13.00.0000 - Siemens AG) Hidden SIMATIC HMI Symbol Library (x32 Version: 13.00.0000 - Siemens AG) Hidden SIMATIC NCM FWL 64 (Version: 05.05.0400 - Siemens AG) Hidden SIMATIC PLCSIM 64 (Version: 01.00.0003 - Siemens AG) Hidden SIMATIC Prosave (x32 Version: 13.00.0000 - Siemens AG) Hidden SIMATIC Prosave V13.0 (HKLM-x32\...\{8E912B95-EDFE-457C-88C3-C8E4062A9C3A}Prosave) (Version: 13.00.0000 - Siemens AG) SIMATIC S7-PLCSIM (x32 Version: 5.4.0503 - Siemens AG) Hidden SIMATIC S7-PLCSIM V5.4 + SP5 + Upd3 (HKLM-x32\...\{57ABCC6B-F570-49CC-A45E-95155A9423DD}PLCSim) (Version: 5.4.0503 - Siemens AG) Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation) TeamSpeak 3 Client (HKCU\...\TeamSpeak 3 Client) (Version: 3.0.15 - TeamSpeak Systems GmbH) The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version: - Bethesda Game Studios) Totally Integrated Automation Portal V13 - TIA Portal Single SetupPackage V13.0 (x32 Version: 13.00.0000 - Siemens AG) Hidden Unterstützung für NI SSL (64 Bit) (Version: 13.0.319 - National Instruments) Hidden Unterstützung für NI SSL (x32 Version: 13.0.324 - National Instruments) Hidden Unterstützung für nicht englische Versionen der Runtime-Engine von LabVIEW 2012 SP1. (x32 Version: 12.1.52.0 - National Instruments) Hidden Unterstützung für nicht englische Versionen der Runtime-Engine von LabVIEW 2013. (x32 Version: 13.0.329 - National Instruments) Hidden Uplay (HKLM-x32\...\Uplay) (Version: 2.0 - Ubisoft) VC User 71 RTL X86 --- (x32 Version: 1.0 - redistributed from Microsoft Corporation merge modules) Hidden VI Package Manager 2013 (HKLM-x32\...\{D50AD7A0-1F67-4007-825B-CA784852A341}) (Version: 13.1.1905 - JKI) VI Package Manager 2013 (x32 Version: 13.0.0 - National Instruments) Hidden WIF Core Dependencies Windows 5.5.0 (x32 Version: 5.50.155 - National Instruments) Hidden WinCC Runtime Advanced Simulator (x32 Version: 13.00.0000 - Siemens AG) Hidden Windows Driver Package - ASUS (ATP) Mouse (05/09/2013 1.0.0.173) (HKLM\...\1016059FBF327ED9E3BAE758BD08CF10D3C6252D) (Version: 05/09/2013 1.0.0.173 - ASUS) Windows Live (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Communications Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation) Windows Live Essentials (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.42.0 - ASUS) WinRAR 5.10 beta 4 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.10.4 - win.rar GmbH) ==================== Restore Points ========================= 22-06-2014 20:25:35 Geplanter Prüfpunkt 01-07-2014 08:41:20 Geplanter Prüfpunkt 06-07-2014 17:30:47 Windows Update ==================== Hosts content: ========================== 2012-07-26 07:26 - 2013-12-13 11:43 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList Task: {415AD014-0F27-4952-AE56-B386AF59484E} - System32\Tasks\ContinueAfterReboot_STEP_7_Professional_V13.0_13.0.0 => C:\Program Files (x86)\Common Files\Siemens\Automation\Siemens Installer Assistant\305\Start.exe [2014-06-03] (SIEMENS AG) Task: {5AE1A1B7-A88C-466B-AF7B-32F2B53A6CC1} - System32\Tasks\Microsoft\Windows\Setup\Pre-staged GDR Notification => C:\Windows\system32\NotificationUI.exe [2014-04-19] (Microsoft Corporation) Task: {5C5F965A-5EDE-4A4F-84B5-03AB3DD4FC2D} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2012-08-22] (ASUSTeK Computer Inc.) Task: {6DD106DA-8796-47B8-B383-28CBAF557584} - System32\Tasks\ASUS InstantOn Config => C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnCfg.exe [2012-10-24] (ASUS) Task: {75AB77F8-E850-4C89-85BE-AEDCA68C734C} - System32\Tasks\AsusVibeSchedule => C:\Program Files (x86)\Asus\AsusVibe\AsusVibeLauncher.exe [2013-01-04] () Task: {7B8A02FD-FD3F-410D-AECE-6D3864176B05} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-02] (Google Inc.) Task: {7F25D845-4750-4380-A86C-B581E46B279F} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2014-07-09] (Microsoft Corporation) Task: {8F05E638-1904-4A78-A660-08C74FE456FE} - System32\Tasks\NIUpdateServiceCheckTask => D:\Labview\Shared\Update Service\NIUpdateService.exe [2013-05-28] (National Instruments) Task: {8F72176A-8DE5-46A5-8FEF-37C5FC211056} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-02] (Google Inc.) Task: {99F0E240-FA85-4831-B2D9-F7DBBA2C6F06} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [2012-08-24] (ASUS) Task: {A52E581E-2E5E-4E4E-9F45-00396A18669E} - System32\Tasks\ASUS Splendid ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2012-11-28] (ASUS) Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing Task: {A939C099-471B-4510-82F4-2CBE48D662C1} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2012-09-18] (ASUSTek Computer Inc.) Task: {C325D06D-73BF-459A-BF1A-A36EF4002886} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-11-22] (Piriform Ltd) Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState Task: {C8D49281-703D-4715-A38D-61D14DE6EA2A} - System32\Tasks\JKIUpdateTask => C:\Program Files (x86)\JKI\VI Package Manager\support\JKIUpdate.exe [2013-12-05] (JKI) Task: {D0C6D4BF-5023-4F1F-A147-3459FF53D233} - System32\Tasks\ASUS Splendid ColorU => C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe [2013-02-26] (ASUSTeK Computer Inc.) Task: {D9055DFA-E841-4C88-AD5F-A7D558D2778B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-08] (Adobe Systems Incorporated) Task: {E805C5C7-E900-4BA4-9020-F65F830A84DB} - System32\Tasks\ASUS Smart Gesture Launcher => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [2013-06-28] (AsusTek) Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2014-01-13 10:00 - 2014-01-13 10:00 - 00774144 _____ () C:\Program Files\Common Files\Siemens\SWS\PlugIns\SCP\Scpwin64.dll 2012-12-19 08:10 - 2012-12-19 08:10 - 00072192 _____ () C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe 2014-04-10 20:08 - 2014-04-10 20:08 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2013-07-04 19:27 - 2013-07-04 19:27 - 00848096 _____ () C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\sn_regbase.dll 2014-06-14 00:56 - 2014-06-05 00:18 - 03162944 _____ () C:\Users\Muhammed\AppData\Local\Amazon Music\Amazon Music Helper.exe 2013-07-22 04:52 - 2012-12-14 00:14 - 00094208 _____ () C:\Windows\system32\IccLibDll_x64.dll 2013-10-09 14:11 - 2013-10-09 14:11 - 02214912 _____ () D:\Labview\Shared\LabVIEW Run-Time\2013\NIQtCore_2013.dll 2013-10-09 14:11 - 2013-10-09 14:11 - 08044544 _____ () D:\Labview\Shared\LabVIEW Run-Time\2013\NIQtGui_2013.dll 2012-01-26 11:36 - 2012-01-26 11:36 - 00278528 ____R () D:\Labview\Shared\License Manager\Bin\xerces-depdom_2_6.dll 2013-06-07 11:59 - 2013-06-07 11:59 - 01958560 _____ () D:\Labview\Shared\NI Error Reporting\niwsrp.dll 2014-07-11 10:53 - 2014-07-11 10:53 - 00043008 _____ () c:\users\muhammed\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpkd0lj9.dll 2013-08-23 21:01 - 2013-08-23 21:01 - 25100288 _____ () C:\Users\Muhammed\AppData\Roaming\Dropbox\bin\libcef.dll 2013-10-08 10:12 - 2012-06-25 11:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll 2013-09-20 14:50 - 2013-09-20 14:50 - 00988160 _____ () C:\Program Files (x86)\OpenOffice 4\program\libxml2.dll 2013-09-17 05:54 - 2013-09-17 05:54 - 00170496 _____ () C:\Program Files (x86)\OpenOffice 4\program\libxslt.dll 2014-06-19 00:34 - 2014-06-19 00:34 - 03852912 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" ==================== EXE Association (whitelisted) ============= ==================== MSCONFIG/TASK MANAGER disabled items ========= ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (07/11/2014 11:25:19 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2486) (User: Muhi-PC) Description: Die App „microsoft.windowsphotos_8wekyb3d8bbwe!Microsoft.WindowsLive.ModernPhotos“ wurde nicht innerhalb der vorgesehenen Zeit gestartet. Error: (07/10/2014 03:05:28 PM) (Source: SideBySide) (EventID: 35) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Siemens.Automation.Portal.Com,processorArchitecture="AMD64",type="win32",version="1.0.0.0"1". Fehler in Manifest- oder Richtliniendatei "Siemens.Automation.Portal.Com,processorArchitecture="AMD64",type="win32",version="1.0.0.0"2" in Zeile Siemens.Automation.Portal.Com,processorArchitecture="AMD64",type="win32",version="1.0.0.0"3. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: Siemens.Automation.Portal.Com,processorArchitecture="AMD64",type="win32",version="1.0.0.0". Definition: Siemens.Automation.Portal.Com,processorArchitecture="x86",type="win32",version="1.0.0.0". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (07/09/2014 07:24:53 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Muhi-PC) Description: Bei der Aktivierung der App „Microsoft.SkypeApp_kzf8qxf38zg5c!App“ ist folgender Fehler aufgetreten: -2144927141. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“. Error: (07/09/2014 00:57:52 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: LolClient.exe, Version: 0.0.0.0, Zeitstempel: 0x515663e0 Name des fehlerhaften Moduls: Adobe AIR.dll, Version: 3.7.0.1530, Zeitstempel: 0x5156646c Ausnahmecode: 0xc0000005 Fehleroffset: 0x0006dd76 ID des fehlerhaften Prozesses: 0x196c Startzeit der fehlerhaften Anwendung: 0xLolClient.exe0 Pfad der fehlerhaften Anwendung: LolClient.exe1 Pfad des fehlerhaften Moduls: LolClient.exe2 Berichtskennung: LolClient.exe3 Vollständiger Name des fehlerhaften Pakets: LolClient.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: LolClient.exe5 Error: (07/08/2014 09:50:08 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: ) Description: 80070005 Error: (07/07/2014 02:48:01 PM) (Source: SideBySide) (EventID: 35) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Siemens.Automation.Portal.Com,processorArchitecture="AMD64",type="win32",version="1.0.0.0"1". Fehler in Manifest- oder Richtliniendatei "Siemens.Automation.Portal.Com,processorArchitecture="AMD64",type="win32",version="1.0.0.0"2" in Zeile Siemens.Automation.Portal.Com,processorArchitecture="AMD64",type="win32",version="1.0.0.0"3. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: Siemens.Automation.Portal.Com,processorArchitecture="AMD64",type="win32",version="1.0.0.0". Definition: Siemens.Automation.Portal.Com,processorArchitecture="x86",type="win32",version="1.0.0.0". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (07/07/2014 02:46:25 PM) (Source: SideBySide) (EventID: 35) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Siemens.Automation.Portal.Com,processorArchitecture="AMD64",type="win32",version="1.0.0.0"1". Fehler in Manifest- oder Richtliniendatei "Siemens.Automation.Portal.Com,processorArchitecture="AMD64",type="win32",version="1.0.0.0"2" in Zeile Siemens.Automation.Portal.Com,processorArchitecture="AMD64",type="win32",version="1.0.0.0"3. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: Siemens.Automation.Portal.Com,processorArchitecture="AMD64",type="win32",version="1.0.0.0". Definition: Siemens.Automation.Portal.Com,processorArchitecture="x86",type="win32",version="1.0.0.0". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (07/07/2014 00:10:53 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm sia2.exe, Version 305.0.113.3 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: fc4 Startzeit: 01cf99cb7ceaead0 Endzeit: 4294967295 Anwendungspfad: C:\PROGRAM FILES (X86)\COMMON FILES\SIEMENS\AUTOMATION\SIEMENS INSTALLER ASSISTANT\305\sia2.exe Berichts-ID: f94ea0fd-05be-11e4-bf4f-d850e61e2d4e Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (07/04/2014 00:57:50 PM) (Source: SideBySide) (EventID: 35) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Siemens.Automation.Portal.Com,processorArchitecture="AMD64",type="win32",version="1.0.0.0"1". Fehler in Manifest- oder Richtliniendatei "Siemens.Automation.Portal.Com,processorArchitecture="AMD64",type="win32",version="1.0.0.0"2" in Zeile Siemens.Automation.Portal.Com,processorArchitecture="AMD64",type="win32",version="1.0.0.0"3. Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein. Verweis: Siemens.Automation.Portal.Com,processorArchitecture="AMD64",type="win32",version="1.0.0.0". Definition: Siemens.Automation.Portal.Com,processorArchitecture="x86",type="win32",version="1.0.0.0". Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose. Error: (07/01/2014 06:54:23 PM) (Source: OpenVPNService) (EventID: 0) (User: ) Description: OpenVPNService error: 0StartServiceCtrlDispatcher failed. System errors: ============= Error: (07/11/2014 10:52:44 AM) (Source: DCOM) (EventID: 10016) (User: Muhi-PC) Description: AnwendungsspezifischLokalStart{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}Muhi-PCMuhammedS-1-5-21-529104025-161939068-2471084440-1002LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar Error: (07/09/2014 07:24:53 PM) (Source: DCOM) (EventID: 10010) (User: Muhi-PC) Description: App.AppX6yygnwabebypxjc6bx7wvtens09wztyw.wwa Error: (07/07/2014 00:51:28 AM) (Source: DCOM) (EventID: 10010) (User: Muhi-PC) Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39} Error: (07/07/2014 00:51:28 AM) (Source: DCOM) (EventID: 10010) (User: Muhi-PC) Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39} Error: (07/04/2014 01:29:31 AM) (Source: Service Control Manager) (EventID: 7043) (User: ) Description: Der Dienst Gruppenrichtlinienclient konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden. Error: (06/22/2014 07:59:41 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "SIMATIC S7DOS Help Service" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts. Error: (06/15/2014 05:19:13 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Steam Client Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (06/15/2014 05:19:13 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Steam Client Service erreicht. Error: (06/05/2014 08:04:23 PM) (Source: Service Control Manager) (EventID: 7043) (User: ) Description: Der Dienst Gruppenrichtlinienclient konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden. Error: (06/03/2014 07:21:03 PM) (Source: DCOM) (EventID: 10016) (User: Muhi-PC) Description: AnwendungsspezifischLokalStart{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}Muhi-PCMuhammedS-1-5-21-529104025-161939068-2471084440-1002LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar Microsoft Office Sessions: ========================= Error: (07/11/2014 11:25:19 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2486) (User: Muhi-PC) Description: microsoft.windowsphotos_8wekyb3d8bbwe!Microsoft.WindowsLive.ModernPhotos Error: (07/10/2014 03:05:28 PM) (Source: SideBySide) (EventID: 35) (User: ) Description: Siemens.Automation.Portal.Com,processorArchitecture="AMD64",type="win32",version="1.0.0.0"Siemens.Automation.Portal.Com,processorArchitecture="x86",type="win32",version="1.0.0.0"D:\Siemens\Automation\Portal V13\Bin\Siemens.Automation.Portal.exeD:\Siemens\Automation\Portal V13\Bin\Siemens.Automation.Portal.Com.DLL1 Error: (07/09/2014 07:24:53 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Muhi-PC) Description: Microsoft.SkypeApp_kzf8qxf38zg5c!App-2144927141 Error: (07/09/2014 00:57:52 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: LolClient.exe0.0.0.0515663e0Adobe AIR.dll3.7.0.15305156646cc00000050006dd76196c01cf9a9865d99ee9C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.99\deploy\LolClient.exeC:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.99\deploy\Adobe AIR\Versions\1.0\Adobe AIR.dll4a06ecbc-06f3-11e4-bf50-d850e61e2d4e Error: (07/08/2014 09:50:08 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: ) Description: 80070005 Error: (07/07/2014 02:48:01 PM) (Source: SideBySide) (EventID: 35) (User: ) Description: Siemens.Automation.Portal.Com,processorArchitecture="AMD64",type="win32",version="1.0.0.0"Siemens.Automation.Portal.Com,processorArchitecture="x86",type="win32",version="1.0.0.0"D:\Siemens\Automation\Portal V13\Bin\Siemens.Automation.Portal.exeD:\Siemens\Automation\Portal V13\Bin\Siemens.Automation.Portal.Com.DLL1 Error: (07/07/2014 02:46:25 PM) (Source: SideBySide) (EventID: 35) (User: ) Description: Siemens.Automation.Portal.Com,processorArchitecture="AMD64",type="win32",version="1.0.0.0"Siemens.Automation.Portal.Com,processorArchitecture="x86",type="win32",version="1.0.0.0"D:\Siemens\Automation\Portal V13\Bin\Siemens.Automation.Portal.exeD:\Siemens\Automation\Portal V13\Bin\Siemens.Automation.Portal.Com.DLL1 Error: (07/07/2014 00:10:53 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: sia2.exe305.0.113.3fc401cf99cb7ceaead04294967295C:\PROGRAM FILES (X86)\COMMON FILES\SIEMENS\AUTOMATION\SIEMENS INSTALLER ASSISTANT\305\sia2.exef94ea0fd-05be-11e4-bf4f-d850e61e2d4e Error: (07/04/2014 00:57:50 PM) (Source: SideBySide) (EventID: 35) (User: ) Description: Siemens.Automation.Portal.Com,processorArchitecture="AMD64",type="win32",version="1.0.0.0"Siemens.Automation.Portal.Com,processorArchitecture="x86",type="win32",version="1.0.0.0"D:\Siemens\Automation\Portal V13\Bin\Siemens.Automation.Portal.exeD:\Siemens\Automation\Portal V13\Bin\Siemens.Automation.Portal.Com.DLL1 Error: (07/01/2014 06:54:23 PM) (Source: OpenVPNService) (EventID: 0) (User: ) Description: OpenVPNService error: 0StartServiceCtrlDispatcher failed. CodeIntegrity Errors: =================================== Date: 2013-12-13 10:43:37.450 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Memory info =========================== Percentage of memory in use: 31% Total physical RAM: 8077.68 MB Available physical RAM: 5567.75 MB Total Pagefile: 9293.68 MB Available Pagefile: 6723.49 MB Total Virtual: 8192 MB Available Virtual: 8191.78 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:279.45 GB) (Free:202.08 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (DATA) (Fixed) (Total:398.07 GB) (Free:369.65 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 699 GB) (Disk ID: 568814A2) Partition: GPT Partition Type. ==================== End Of Log ============================ Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-07-2014 Ran by Muhammed (administrator) on MUHI-PC on 11-07-2014 11:49:35 Running from C:\Users\Muhammed\Downloads Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 10 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (SIEMENS AG) C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe (Siemens AG) C:\Program Files\Common Files\Siemens\AlmPanelPlugin\ALMPanelPlugin.exe () C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (National Instruments Corporation) C:\Windows\SysWOW64\lkads.exe (National Instruments Corporation) D:\Labview\MAX\nimxs.exe (National Instruments Corporation) D:\Labview\Shared\Security\nidmsrv.exe (National Instruments Corporation) D:\Labview\Shared\nisvcloc\nisvcloc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Siemens AG) C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7oiehsx64.exe (Siemens AG) C:\Program Files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceService64x.exe (National Instruments, Inc.) C:\Windows\SysWOW64\lkcitdl.exe (National Instruments Corporation) C:\Windows\SysWOW64\lktsrv.exe (National Instruments Corporation) D:\Labview\Shared\mDNS Responder\nimdnsResponder.exe (National Instruments Corporation) D:\Labview\Shared\NI WebServer\SystemWebServer.exe (National Instruments Corporation) D:\Labview\Shared\Tagger\tagsrv.exe (National Instruments Corporation) D:\Labview\Shared\NI Network Discovery\niDiscSvc.exe (Siemens AG) C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7epasrv64x.exe (National Instruments Corporation) D:\Labview\Shared\NI WebServer\ApplicationWebServer.exe (Siemens AG) C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\pniomgr.exe (Siemens AG) C:\Windows\SysWOW64\pniopcac.exe (Siemens AG) C:\Windows\SysWOW64\pniopcac.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe () C:\Users\Muhammed\AppData\Local\Amazon Music\Amazon Music Helper.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe (National Instruments Corporation) D:\Labview\Shared\NI Error Reporting\nierserver.exe (Dropbox, Inc.) C:\Users\Muhammed\AppData\Roaming\Dropbox\bin\Dropbox.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Apache Software Foundation) C:\Program Files (x86)\OpenOffice 4\program\swriter.exe (Apache Software Foundation) C:\Program Files (x86)\OpenOffice 4\program\soffice.exe (Apache Software Foundation) C:\Program Files (x86)\OpenOffice 4\program\soffice.bin (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13550152 2013-05-30] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1308232 2013-05-20] (Realtek Semiconductor) HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3187360 2013-04-26] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSPanel.exe [3576784 2012-12-19] (ASUS Cloud Corporation) HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [750160 2014-07-01] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [NI Update Service] => D:\Labview\Shared\Update Service\NIUpdateService.exe [857888 2013-05-28] (National Instruments) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SiemensAutomationFileStorage_TIAP13] => D:\Siemens\Automation\Portal V13\Bin\Siemens.Automation.ObjectFrame.FileStorage.Server.exe [1022464 2014-02-12] (Siemens AG) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-529104025-161939068-2471084440-1002\...\Run: [NIRegistrationWizard] => D:\Labview\Shared\RegistrationWizard\Bin\RegistrationWizard.exe [847000 2013-04-19] () HKU\S-1-5-21-529104025-161939068-2471084440-1002\...\Run: [EPSON Stylus DX7400] => C:\Windows\system32\spool\DRIVERS\x64\3\E_IATICDE.EXE [213504 2007-04-12] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-529104025-161939068-2471084440-1002\...\Run: [Amazon Music] => C:\Users\Muhammed\AppData\Local\Amazon Music\Amazon Music Helper.exe [3162944 2014-06-05] () AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [245872 2013-07-08] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [201576 2013-07-08] (NVIDIA Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NI Error Reporting.lnk ShortcutTarget: NI Error Reporting.lnk -> D:\Labview\Shared\NI Error Reporting\nierserver.exe (National Instruments Corporation) Startup: C:\Users\Muhammed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Muhammed\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ShellIconOverlayIdentifiers: !AsusWSShellExt_B -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\ASUSWSShellExt64.dll (ASUS Cloud Corporation.) ShellIconOverlayIdentifiers: !AsusWSShellExt_O -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\ASUSWSShellExt64.dll (ASUS Cloud Corporation.) ShellIconOverlayIdentifiers: !AsusWSShellExt_U -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4D} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\ASUSWSShellExt64.dll (ASUS Cloud Corporation.) ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers-x32: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers-x32: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers-x32: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ShellIconOverlayIdentifiers-x32: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers-x32: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers-x32: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus13.msn.com StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS SearchScopes: HKLM-x32 - DefaultScope value is missing. SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = Winsock: Catalog5 08 D:\Labview\Shared\mDNS Responder\nimdnsNSP.dll [26512] (National Instruments Corporation) Winsock: Catalog5-x64 08 C:\Program Files\National Instruments\Shared\mDNS Responder\nimdnsNSP.dll [28560] (National Instruments Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Muhammed\AppData\Roaming\Mozilla\Firefox\Profiles\n6xal7me.default FF Homepage: www.google.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: NoScript - C:\Users\Muhammed\AppData\Roaming\Mozilla\Firefox\Profiles\n6xal7me.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-12-17] FF Extension: Adblock Plus - C:\Users\Muhammed\AppData\Roaming\Mozilla\Firefox\Profiles\n6xal7me.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-12-17] FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK Chrome: ======= CHR Extension: (Adblock Plus) - C:\Users\Muhammed\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-03-04] CHR Extension: (Google Wallet) - C:\Users\Muhammed\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-02] ==================== Services (Whitelisted) ================= R2 almservice; C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe [1563968 2014-01-13] (SIEMENS AG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-07-01] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-07-01] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1030224 2014-07-10] (Avira Operations GmbH & Co. KG) R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS) R2 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe [72192 2012-12-19] () [File not signed] R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation) R2 LkCitadelServer; C:\Windows\SysWOW64\lkcitdl.exe [695136 2010-10-27] (National Instruments, Inc.) R2 lkClassAds; C:\Windows\SysWOW64\lkads.exe [53544 2013-06-12] (National Instruments Corporation) R2 lkTimeSync; C:\Windows\SysWOW64\lktsrv.exe [63792 2013-06-12] (National Instruments Corporation) R2 mxssvr; D:\Labview\MAX\nimxs.exe [83768 2013-06-11] (National Instruments Corporation) R2 NIApplicationWebServer; D:\Labview\Shared\NI WebServer\ApplicationWebServer.exe [57696 2013-06-08] (National Instruments Corporation) S4 NIApplicationWebServer64; C:\Program Files\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [81248 2013-06-08] (National Instruments Corporation) R2 NIDomainService; D:\Labview\Shared\Security\nidmsrv.exe [380720 2013-06-12] (National Instruments Corporation) S3 NILM License Manager; D:\Labview\Shared\License Manager\Bin\lmgrd.exe [1427688 2010-08-02] (Macrovision Corporation) R2 nimDNSResponder; D:\Labview\Shared\mDNS Responder\nimdnsResponder.exe [260976 2013-05-11] (National Instruments Corporation) R2 NINetworkDiscovery; D:\Labview\Shared\NI Network Discovery\niDiscSvc.exe [176512 2013-06-19] (National Instruments Corporation) R2 NiSvcLoc; D:\Labview\Shared\niSvcLoc\nisvcloc.exe [90440 2013-06-07] (National Instruments Corporation) R2 NISystemWebServer; D:\Labview\Shared\NI WebServer\SystemWebServer.exe [57680 2013-06-08] (National Instruments Corporation) R2 NITaggerService; D:\Labview\Shared\Tagger\tagsrv.exe [687944 2013-06-15] (National Instruments Corporation) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-04-10] () R2 s7oiehsx64; C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7oiehsx64.exe [144608 2014-01-16] (Siemens AG) R2 S7TraceServiceX; C:\Program Files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceService64X.exe [472288 2014-01-16] (Siemens AG) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== U5 AppMgmt; C:\Windows\system32\svchost.exe [29696 2013-04-26] (Microsoft Corporation) R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [65784 2013-06-28] (ASUS Corporation) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-07-01] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [130584 2014-05-20] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-10-10] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [42040 2014-07-10] (Avira Operations GmbH & Co. KG) R3 dpmconv; C:\Windows\System32\drivers\dpmconv.sys [259584 2013-08-07] (Siemens AG) R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( ) R3 s7odpx2x64; C:\Windows\System32\drivers\s7odpx2x64.sys [71168 2012-12-19] (SIEMENS AG) R3 s7oppinx64; C:\Windows\System32\drivers\s7oppinx64.sys [107520 2012-07-24] (SIEMENS AG) R3 s7oserix64; C:\Windows\System32\Drivers\s7oserix64.sys [121856 2012-07-24] (SIEMENS AG) R3 s7osmcax64; C:\Windows\System32\drivers\s7osmcax64.sys [199680 2012-07-24] (SIEMENS AG) R3 s7osobux64; C:\Windows\System32\drivers\s7osobux64.sys [153600 2012-07-24] (SIEMENS AG) R3 s7otmcd64x; C:\Windows\System32\Drivers\s7otmcd64x.sys [199680 2012-07-24] (SIEMENS AG) R3 s7otranx64; C:\Windows\System32\drivers\s7otranx64.sys [260608 2013-12-02] (Siemens AG) R3 s7otsadx64; C:\Windows\System32\drivers\s7otsadx64.sys [196096 2012-07-24] (SIEMENS AG) R2 s7ousbu64x; C:\Windows\System32\drivers\s7ousbu64x.sys [137216 2013-12-17] (Siemens AG) R2 s7sn2srtx; C:\Windows\system32\DRIVERS\s7sn2srtx.sys [83032 2012-05-09] (SIEMENS AG) R2 SNTIE; C:\Windows\system32\DRIVERS\sntie.sys [359648 2013-10-28] (Siemens AG) R3 vsnl2ada; C:\Windows\System32\drivers\vsnl2ada.sys [128000 2013-08-07] (SIEMENS AG) S3 catchme; \??\C:\ComboFix\catchme.sys [X] U0 msahci; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-11 11:49 - 2014-07-11 11:49 - 00019995 _____ () C:\Users\Muhammed\Downloads\FRST.txt 2014-07-11 11:49 - 2014-07-11 11:49 - 00000000 ____D () C:\FRST 2014-07-11 11:48 - 2014-07-11 11:48 - 02084864 _____ (Farbar) C:\Users\Muhammed\Downloads\FRST64.exe 2014-07-11 11:47 - 2014-07-11 11:47 - 00050477 _____ () C:\Users\Muhammed\Downloads\Defogger.exe 2014-07-11 11:47 - 2014-07-11 11:47 - 00000478 _____ () C:\Users\Muhammed\Downloads\defogger_disable.log 2014-07-11 11:47 - 2014-07-11 11:47 - 00000000 _____ () C:\Users\Muhammed\defogger_reenable 2014-07-11 10:30 - 2014-07-11 10:30 - 00338240 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-07-10 01:43 - 2014-07-10 01:43 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-07-09 12:25 - 2014-07-01 00:42 - 00702464 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-07-09 12:25 - 2014-07-01 00:42 - 00394240 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2014-07-09 12:25 - 2014-07-01 00:42 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2014-07-09 12:25 - 2014-06-28 05:35 - 00556544 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-07-09 12:25 - 2014-06-19 04:12 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-07-09 12:25 - 2014-06-19 04:12 - 01366528 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-07-09 12:25 - 2014-06-19 04:12 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2014-07-09 12:25 - 2014-06-19 04:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll 2014-07-09 12:25 - 2014-06-19 04:12 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-07-09 12:25 - 2014-06-19 04:11 - 19277312 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-07-09 12:25 - 2014-06-19 04:11 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-07-09 12:25 - 2014-06-19 04:11 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 15369728 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 02650624 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-07-09 12:25 - 2014-06-19 04:09 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-07-09 12:25 - 2014-06-19 02:53 - 14368768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-07-09 12:25 - 2014-06-19 02:53 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-07-09 12:25 - 2014-06-19 02:53 - 01141760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-07-09 12:25 - 2014-06-19 02:53 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-07-09 12:25 - 2014-06-19 02:53 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-07-09 12:25 - 2014-06-19 02:53 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-07-09 12:25 - 2014-06-19 02:53 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2014-07-09 12:25 - 2014-06-19 02:52 - 13732352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-07-09 12:25 - 2014-06-19 02:52 - 02863616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-07-09 12:25 - 2014-06-19 02:52 - 02051072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-07-09 12:25 - 2014-06-19 02:52 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-07-09 12:25 - 2014-06-19 02:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-07-09 12:25 - 2014-06-19 02:52 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-07-09 12:25 - 2014-06-19 02:52 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-07-09 12:25 - 2014-06-19 02:52 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-07-09 12:25 - 2014-06-19 02:52 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-07-09 12:25 - 2014-06-19 02:52 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-07-09 12:25 - 2014-06-19 02:52 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-07-09 12:25 - 2014-06-19 02:52 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-07-09 12:25 - 2014-06-19 02:33 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-07-09 12:25 - 2014-06-19 02:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-07-09 12:25 - 2014-06-19 00:05 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll 2014-07-09 12:25 - 2014-06-18 01:27 - 01440256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe 2014-07-09 12:25 - 2014-06-18 01:24 - 01557504 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe 2014-07-09 12:25 - 2014-06-11 06:18 - 04038144 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-07-09 12:25 - 2014-06-06 16:06 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-07-09 12:25 - 2014-06-06 12:17 - 00497152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-07-09 12:25 - 2014-06-03 00:33 - 00265216 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll 2014-07-09 12:25 - 2014-05-30 01:31 - 00452608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll 2014-07-09 12:25 - 2014-05-30 01:03 - 00588288 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll 2014-07-09 12:25 - 2014-05-30 01:02 - 01281536 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-07-09 12:25 - 2014-05-30 01:02 - 00439808 _____ (Microsoft Corporation) C:\Windows\system32\lsm.dll 2014-07-09 12:25 - 2014-05-30 00:24 - 00576512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2014-07-09 12:25 - 2014-05-03 08:34 - 06974808 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-07-09 12:25 - 2014-05-03 08:33 - 01824808 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2014-07-09 12:25 - 2014-05-03 06:51 - 01408976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2014-07-09 12:25 - 2014-05-02 00:37 - 01023488 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll 2014-07-09 12:25 - 2014-04-30 00:32 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\Robocopy.exe 2014-07-09 12:25 - 2014-04-30 00:32 - 00106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Robocopy.exe 2014-07-09 12:25 - 2014-04-24 01:51 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll 2014-07-09 12:25 - 2014-04-24 01:51 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2014-07-09 12:25 - 2014-04-24 01:38 - 00693760 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll 2014-07-09 12:25 - 2014-04-24 01:38 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2014-07-09 12:25 - 2014-02-08 06:34 - 00071168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hdaudbus.sys 2014-07-06 19:45 - 2014-05-03 07:47 - 03246592 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2014-07-06 19:45 - 2014-05-03 05:34 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2014-07-06 19:45 - 2014-04-03 13:19 - 00328024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys 2014-07-06 19:45 - 2014-04-03 05:44 - 00619008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2014-07-06 19:45 - 2014-04-01 00:08 - 00387268 _____ () C:\Windows\system32\ApnDatabase.xml 2014-07-06 19:45 - 2014-03-25 01:42 - 00305152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wusa.exe 2014-07-06 19:45 - 2014-03-25 00:56 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\wusa.exe 2014-07-06 19:44 - 2014-04-30 00:32 - 01301504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-07-06 19:44 - 2014-04-30 00:22 - 01023488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-07-06 19:40 - 2014-04-03 13:22 - 02233176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-07-06 19:40 - 2014-03-07 02:47 - 01419264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-07-06 19:40 - 2014-03-07 02:08 - 01845760 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-07-06 19:31 - 2014-05-20 04:33 - 00059416 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2014-07-06 19:31 - 2014-05-20 01:45 - 00629248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2014-07-06 19:31 - 2014-05-20 01:45 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2014-07-06 19:31 - 2014-05-20 01:24 - 03286528 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2014-07-06 19:31 - 2014-05-20 01:24 - 01623040 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2014-07-06 19:31 - 2014-05-20 01:24 - 00773632 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2014-07-06 19:31 - 2014-05-20 01:24 - 00253440 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll 2014-07-06 19:31 - 2014-05-20 01:24 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll 2014-07-06 19:31 - 2014-05-20 01:24 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2014-07-06 19:31 - 2014-05-15 00:43 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2014-07-06 19:31 - 2014-05-15 00:43 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2014-07-06 19:31 - 2014-05-15 00:42 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2014-07-06 19:31 - 2014-05-15 00:42 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2014-07-01 18:49 - 2014-07-01 18:52 - 00000000 ____D () C:\Users\Muhammed\Downloads\openvpn-2.3.3.I001-64Bit 2014-07-01 18:48 - 2014-07-01 18:51 - 02882999 _____ () C:\Users\Muhammed\Downloads\openvpn-2.3.3.I001-64Bit.zip 2014-06-28 15:24 - 2014-06-28 15:28 - 24901341 _____ () C:\Users\Muhammed\Downloads\Hibbeler.Mechanik3.Dynamik.rar 2014-06-22 20:39 - 2014-06-22 20:39 - 00000000 ____D () C:\Program Files (x86)\GUMEDA7.tmp 2014-06-19 00:34 - 2014-06-19 00:34 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-14 00:56 - 2014-06-15 13:34 - 00001142 _____ () C:\Users\Muhammed\Desktop\Amazon Music.lnk 2014-06-13 13:36 - 2014-06-13 13:36 - 00000000 ____D () C:\Users\Muhammed\AppData\Local\Adobe ==================== One Month Modified Files and Folders ======= 2014-07-11 11:49 - 2014-07-11 11:49 - 00019995 _____ () C:\Users\Muhammed\Downloads\FRST.txt 2014-07-11 11:49 - 2014-07-11 11:49 - 00000000 ____D () C:\FRST 2014-07-11 11:48 - 2014-07-11 11:48 - 02084864 _____ (Farbar) C:\Users\Muhammed\Downloads\FRST64.exe 2014-07-11 11:47 - 2014-07-11 11:47 - 00050477 _____ () C:\Users\Muhammed\Downloads\Defogger.exe 2014-07-11 11:47 - 2014-07-11 11:47 - 00000478 _____ () C:\Users\Muhammed\Downloads\defogger_disable.log 2014-07-11 11:47 - 2014-07-11 11:47 - 00000000 _____ () C:\Users\Muhammed\defogger_reenable 2014-07-11 11:47 - 2013-11-02 16:59 - 00000000 ____D () C:\Users\Muhammed 2014-07-11 11:44 - 2013-11-02 19:01 - 00000000 ____D () C:\Users\Muhammed\AppData\Roaming\TS3Client 2014-07-11 11:44 - 2013-11-02 17:07 - 00001130 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-07-11 11:20 - 2012-08-03 01:02 - 00753134 _____ () C:\Windows\system32\perfh007.dat 2014-07-11 11:20 - 2012-08-03 01:02 - 00155826 _____ () C:\Windows\system32\perfc007.dat 2014-07-11 11:20 - 2012-07-26 09:28 - 01745416 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-07-11 11:10 - 2013-12-17 18:31 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-07-11 11:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru 2014-07-11 10:54 - 2013-11-03 11:29 - 00000000 ____D () C:\Users\Muhammed\AppData\Roaming\Dropbox 2014-07-11 10:53 - 2014-05-03 13:03 - 00000000 ____D () C:\Users\Muhammed\AppData\Roaming\DropboxMaster 2014-07-11 10:53 - 2013-11-03 11:31 - 00000000 ___RD () C:\Users\Muhammed\Dropbox 2014-07-11 10:52 - 2013-11-02 17:07 - 00001126 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-07-11 10:52 - 2013-11-02 17:02 - 00000062 _____ () C:\Users\Muhammed\AppData\Roaming\sp_data.sys 2014-07-11 10:51 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-11 10:30 - 2014-07-11 10:30 - 00338240 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-07-10 21:19 - 2013-11-02 17:13 - 00000000 ____D () C:\Users\Muhammed\AppData\Local\PMB Files 2014-07-10 20:42 - 2014-03-02 16:51 - 01824004 _____ () C:\Windows\WindowsUpdate.log 2014-07-10 16:46 - 2013-11-17 22:38 - 00000391 _____ () C:\Users\Muhammed\Desktop\Series.txt 2014-07-10 12:51 - 2013-11-02 19:35 - 00042040 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2014-07-10 01:44 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI 2014-07-10 01:43 - 2014-07-10 01:43 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-07-10 01:43 - 2012-07-26 11:45 - 00000000 ____D () C:\Program Files\Windows Journal 2014-07-10 01:43 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-10 01:43 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-10 01:43 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\WinStore 2014-07-09 12:52 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp 2014-07-09 12:51 - 2013-11-02 22:55 - 00000000 ____D () C:\Windows\system32\MRT 2014-07-09 12:50 - 2013-11-02 22:55 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-07-09 12:50 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM 2014-07-08 19:10 - 2013-12-17 18:31 - 00003772 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-07-07 14:56 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache 2014-07-06 19:48 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent 2014-07-03 23:49 - 2014-05-17 12:19 - 00000000 ____D () C:\Users\Muhammed\Documents\BabaAnne 2014-07-02 13:11 - 2013-11-02 17:13 - 00000000 ____D () C:\ProgramData\PMB Files 2014-07-02 10:31 - 2013-11-02 17:07 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-529104025-161939068-2471084440-1002 2014-07-02 09:34 - 2014-06-04 08:12 - 00000774 _____ () C:\Windows\PFRO.log 2014-07-01 18:52 - 2014-07-01 18:49 - 00000000 ____D () C:\Users\Muhammed\Downloads\openvpn-2.3.3.I001-64Bit 2014-07-01 18:51 - 2014-07-01 18:48 - 02882999 _____ () C:\Users\Muhammed\Downloads\openvpn-2.3.3.I001-64Bit.zip 2014-07-01 18:48 - 2014-06-02 08:39 - 00000000 ____D () C:\Users\Muhammed\AppData\Roaming\FileZilla 2014-07-01 16:58 - 2014-05-06 15:18 - 00000000 ____D () C:\Users\Muhammed\Documents\BEWERBUNGEN 2014-07-01 15:02 - 2013-11-02 19:35 - 00117712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-07-01 00:42 - 2014-07-09 12:25 - 00702464 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-07-01 00:42 - 2014-07-09 12:25 - 00394240 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2014-07-01 00:42 - 2014-07-09 12:25 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2014-06-28 15:28 - 2014-06-28 15:24 - 24901341 _____ () C:\Users\Muhammed\Downloads\Hibbeler.Mechanik3.Dynamik.rar 2014-06-28 05:35 - 2014-07-09 12:25 - 00556544 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-06-26 22:53 - 2013-11-05 10:32 - 00703968 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-06-26 22:53 - 2013-11-05 10:32 - 00105440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-06-24 21:43 - 2013-11-02 18:59 - 00000000 ____D () C:\Users\Muhammed\AppData\Local\TeamSpeak 3 Client 2014-06-22 20:39 - 2014-06-22 20:39 - 00000000 ____D () C:\Program Files (x86)\GUMEDA7.tmp 2014-06-22 20:39 - 2013-11-02 17:07 - 00004102 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-06-22 20:39 - 2013-11-02 17:07 - 00003866 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-06-22 19:58 - 2013-12-17 17:59 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-06-20 20:33 - 2014-03-17 18:56 - 00000000 ____D () C:\Users\Muhammed\Desktop\HTW-F3 2014-06-19 04:12 - 2014-07-09 12:25 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-06-19 04:12 - 2014-07-09 12:25 - 01366528 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-06-19 04:12 - 2014-07-09 12:25 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2014-06-19 04:12 - 2014-07-09 12:25 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll 2014-06-19 04:12 - 2014-07-09 12:25 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-06-19 04:11 - 2014-07-09 12:25 - 19277312 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-06-19 04:11 - 2014-07-09 12:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-06-19 04:11 - 2014-07-09 12:25 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 15369728 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 02650624 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-06-19 04:09 - 2014-07-09 12:25 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-06-19 02:53 - 2014-07-09 12:25 - 14368768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-06-19 02:53 - 2014-07-09 12:25 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-06-19 02:53 - 2014-07-09 12:25 - 01141760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-06-19 02:53 - 2014-07-09 12:25 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-06-19 02:53 - 2014-07-09 12:25 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-06-19 02:53 - 2014-07-09 12:25 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-06-19 02:53 - 2014-07-09 12:25 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2014-06-19 02:52 - 2014-07-09 12:25 - 13732352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-06-19 02:52 - 2014-07-09 12:25 - 02863616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-06-19 02:52 - 2014-07-09 12:25 - 02051072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-06-19 02:52 - 2014-07-09 12:25 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-06-19 02:52 - 2014-07-09 12:25 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-06-19 02:52 - 2014-07-09 12:25 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-06-19 02:52 - 2014-07-09 12:25 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-06-19 02:52 - 2014-07-09 12:25 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-06-19 02:52 - 2014-07-09 12:25 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-06-19 02:52 - 2014-07-09 12:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-06-19 02:52 - 2014-07-09 12:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-06-19 02:52 - 2014-07-09 12:25 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-06-19 02:33 - 2014-07-09 12:25 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-06-19 02:30 - 2014-07-09 12:25 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-06-19 00:34 - 2014-06-19 00:34 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-19 00:05 - 2014-07-09 12:25 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll 2014-06-18 01:27 - 2014-07-09 12:25 - 01440256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe 2014-06-18 01:24 - 2014-07-09 12:25 - 01557504 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe 2014-06-16 16:53 - 2014-05-27 15:20 - 00013824 ___SH () C:\Users\Muhammed\Desktop\Thumbs.db 2014-06-15 13:35 - 2014-05-10 14:03 - 00000000 ____D () C:\Users\Muhammed\AppData\Local\Amazon Cloud Player 2014-06-15 13:34 - 2014-06-14 00:56 - 00001142 _____ () C:\Users\Muhammed\Desktop\Amazon Music.lnk 2014-06-13 13:36 - 2014-06-13 13:36 - 00000000 ____D () C:\Users\Muhammed\AppData\Local\Adobe 2014-06-11 11:23 - 2014-05-27 15:20 - 00011710 _____ () C:\Users\Muhammed\Desktop\Lernplan.ods 2014-06-11 06:18 - 2014-07-09 12:25 - 04038144 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys Files to move or delete: ==================== C:\ProgramData\SetStretch.exe Some content of TEMP: ==================== C:\Users\Muhammed\AppData\Local\Temp\avgnt.exe C:\Users\Muhammed\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpkd0lj9.dll C:\Users\Muhammed\AppData\Local\Temp\msvcr100.dll C:\Users\Muhammed\AppData\Local\Temp\pimuninstall.exe C:\Users\Muhammed\AppData\Local\Temp\rochj3ow.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-07 14:46 ==================== End Of Log ========================= |
11.07.2014, 12:27 | #2 |
/// the machine /// TB-Ausbilder | Windows 8 - Sound funktioniert nicht richtig/Youtube(andere Musikmöglichkeiten) funktionieren auch nicht! hi,
__________________Scan mit Combofix
__________________ |
11.07.2014, 13:11 | #3 |
| Windows 8 - Sound funktioniert nicht richtig/Youtube(andere Musikmöglichkeiten) funktionieren auch nicht! hey Schrauber!
__________________danke für die schnelle Antwort! Ich hatte Antivir deaktiviert, aber es kam, als Combofix gestartet wurde, trotzdem eine Fehlermeldung dass in der Registry rumgepfuscht wird. Ich hoffe ich habe es dennoch richtig gemacht! Gruß Combofix: Code:
ATTFilter ComboFix 14-07-11.03 - Muhammed 11.07.2014 14:02:30.1.4 - x64 Microsoft Windows 8 6.2.9200.0.1252.49.1031.18.8078.5437 [GMT 2:00] ausgeführt von:: c:\users\Muhammed\Desktop\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859} AV: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Avira Desktop *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\SetStretch.exe . . ((((((((((((((((((((((( Dateien erstellt von 2014-06-11 bis 2014-07-11 )))))))))))))))))))))))))))))) . . 2014-07-11 12:07 . 2014-07-11 12:07 -------- d-----w- c:\users\Muhammed\AppData\Local\temp 2014-07-11 10:31 . 2014-06-05 01:54 10779000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{87F28461-8BE7-41E4-B2AE-89ECC9D903D7}\mpengine.dll 2014-07-11 09:49 . 2014-07-11 09:51 -------- d-----w- C:\FRST 2014-07-09 23:43 . 2014-07-09 23:43 -------- d-s---w- c:\windows\system32\CompatTel 2014-07-06 17:45 . 2014-05-03 05:47 3246592 ----a-w- c:\windows\system32\rdpcorets.dll 2014-07-06 17:45 . 2014-05-03 03:34 235520 ----a-w- c:\windows\system32\rdpudd.dll 2014-07-06 17:45 . 2014-04-03 03:44 619008 ----a-w- c:\windows\system32\drivers\srv2.sys 2014-07-06 17:45 . 2014-04-03 11:19 328024 ----a-w- c:\windows\system32\drivers\Classpnp.sys 2014-07-06 17:45 . 2014-03-24 23:42 305152 ----a-w- c:\windows\SysWow64\wusa.exe 2014-07-06 17:45 . 2014-03-24 22:56 309760 ----a-w- c:\windows\system32\wusa.exe 2014-07-06 17:44 . 2014-04-29 22:32 1301504 ----a-w- c:\windows\system32\gdi32.dll 2014-07-06 17:44 . 2014-04-29 22:22 1023488 ----a-w- c:\windows\SysWow64\gdi32.dll 2014-07-06 17:40 . 2014-04-03 11:22 2233176 ----a-w- c:\windows\system32\drivers\tcpip.sys 2014-07-06 17:40 . 2014-03-07 00:47 1419264 ----a-w- c:\windows\SysWow64\msxml3.dll 2014-07-06 17:40 . 2014-03-07 00:08 1845760 ----a-w- c:\windows\system32\msxml3.dll 2014-07-01 08:31 . 2014-07-01 08:31 257704 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10243.bin 2014-06-22 18:39 . 2014-06-22 18:39 -------- d-----w- c:\program files (x86)\GUMEDA7.tmp 2014-06-13 22:56 . 2014-06-15 11:35 -------- d-----w- c:\users\Muhammed\AppData\Local\Amazon Music 2014-06-13 11:36 . 2014-06-13 11:36 -------- d-----w- c:\users\Muhammed\AppData\Local\Adobe . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-07-11 10:17 . 2013-11-02 15:02 62 ----a-w- c:\users\Muhammed\AppData\Roaming\sp_data.sys 2014-07-10 10:51 . 2013-11-02 17:35 42040 ----a-w- c:\windows\system32\drivers\avnetflt.sys 2014-07-09 10:50 . 2013-11-02 20:55 96441528 ----a-w- c:\windows\system32\MRT.exe 2014-07-01 13:02 . 2013-11-02 17:35 117712 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2014-06-26 20:53 . 2013-11-05 08:32 703968 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2014-06-26 20:53 . 2013-11-05 08:32 105440 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2014-05-20 08:47 . 2013-11-02 17:35 130584 ----a-w- c:\windows\system32\drivers\avipbb.sys 2014-05-14 16:00 . 2014-05-14 16:00 17536 ----a-w- c:\programdata\Microsoft\windowssampling\Sqm\Manifest\Sqm3.bin 2014-04-19 09:39 . 2014-05-31 10:22 628024 ----a-w- c:\windows\system32\NotificationUI.exe 2014-04-13 09:52 . 2014-04-10 18:15 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr 2014-04-13 09:52 . 2014-04-10 18:08 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.exe 2014-04-12 18:21 . 2014-04-10 18:08 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0 . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1] @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}] 2013-11-02 15:17 222832 ----a-w- c:\users\Muhammed\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2] @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}] 2013-11-02 15:17 222832 ----a-w- c:\users\Muhammed\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3] @="{BBACC218-34EA-4666-9D7A-C78F2274A524}" [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}] 2013-11-02 15:17 222832 ----a-w- c:\users\Muhammed\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-11 02:09 131248 ----a-w- c:\users\Muhammed\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-11 02:09 131248 ----a-w- c:\users\Muhammed\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-11 02:09 131248 ----a-w- c:\users\Muhammed\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NIRegistrationWizard"="d:\labview\Shared\RegistrationWizard\Bin\RegistrationWizard.exe" [2013-04-19 847000] "Amazon Music"="c:\users\Muhammed\AppData\Local\Amazon Music\Amazon Music Helper.exe" [2014-06-04 3162944] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "ASUSPRP"="c:\program files (x86)\ASUS\APRP\APRP.EXE" [2013-04-25 3187360] "ASUSWebStorage"="c:\program files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSPanel.exe" [2012-12-19 3576784] "RemoteControl10"="c:\program files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" [2012-03-28 91432] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2014-07-01 750160] "NI Update Service"="d:\labview\Shared\Update Service\NIUpdateService.exe" [2013-05-28 857888] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904] "SiemensAutomationFileStorage_TIAP13"="d:\siemens\Automation\Portal V13\Bin\Siemens.Automation.ObjectFrame.FileStorage.Server.exe" [2014-02-12 1022464] . c:\users\Muhammed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Muhammed\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2014-5-20 33322312] . c:\programdata\Microsoft\Windows\Start Menu\Programs\StartUp\ NI Error Reporting.lnk - d:\labview\Shared\NI Error Reporting\nierserver.exe [2013-6-7 663896] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "PromptOnSecureDesktop"= 0 (0x0) "ConsentPromptBehaviorAdmin"= 5 (0x5) "EnableUIADesktopToggle"= 0 (0x0) "EnableCursorSuppression"= 1 (0x1) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableSecureUIAPath"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "Userinit"="userinit.exe" . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) "AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc] @="" . R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x] R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x] R3 WUDFWpdMtp;WUDFWpdMtp;c:\windows\system32\DRIVERS\WUDFRd.sys;c:\windows\SYSNATIVE\DRIVERS\WUDFRd.sys [x] R4 NIApplicationWebServer64;NI Application Web Server (64-bit);c:\program files\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe;c:\program files\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [x] S0 iaStorA;iaStorA;c:\windows\System32\drivers\iaStorA.sys;c:\windows\SYSNATIVE\drivers\iaStorA.sys [x] S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x] S2 almservice;Automation License Manager Service;c:\program files\Common Files\Siemens\sws\almsrv\almsrv64x.exe;c:\program files\Common Files\Siemens\sws\almsrv\almsrv64x.exe [x] S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x] S2 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe [x] S2 ASUS InstantOn;ASUS InstantOn Service;c:\program files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe;c:\program files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [x] S2 Asus WebStorage Windows Service;Asus WebStorage Windows Service;c:\program files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe;c:\program files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe [x] S2 avnetflt;avnetflt;c:\windows\system32\DRIVERS\avnetflt.sys;c:\windows\SYSNATIVE\DRIVERS\avnetflt.sys [x] S2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [x] S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x] S2 Intel(R) ME Service;Intel(R) ME Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [x] S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x] S2 NIApplicationWebServer;NI Application Web Server;d:\labview\Shared\NI WebServer\ApplicationWebServer.exe;d:\labview\Shared\NI WebServer\ApplicationWebServer.exe [x] S2 nimDNSResponder;NI mDNS Responder Service;d:\labview\Shared\mDNS Responder\nimdnsResponder.exe;d:\labview\Shared\mDNS Responder\nimdnsResponder.exe [x] S2 NINetworkDiscovery;NI Network Discovery;d:\labview\Shared\NI Network Discovery\niDiscSvc.exe;d:\labview\Shared\NI Network Discovery\niDiscSvc.exe [x] S2 NISystemWebServer;NI System Web Server;d:\labview\Shared\NI WebServer\SystemWebServer.exe;d:\labview\Shared\NI WebServer\SystemWebServer.exe [x] S2 s7oiehsx64;SIMATIC S7DOS Help Service;c:\program files\Common Files\Siemens\Automation\Simatic OAM\bin\s7oiehsx64.exe;c:\program files\Common Files\Siemens\Automation\Simatic OAM\bin\s7oiehsx64.exe [x] S2 s7ousbu64x;SIMATIC USB Service;c:\windows\System32\drivers\s7ousbu64x.sys;c:\windows\SYSNATIVE\drivers\s7ousbu64x.sys [x] S2 s7sn2srtx;PROFINET IO RT-Protocol V2.0;c:\windows\system32\DRIVERS\s7sn2srtx.sys;c:\windows\SYSNATIVE\DRIVERS\s7sn2srtx.sys [x] S2 S7TraceServiceX;S7TraceServiceX;c:\program files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceService64X.exe;c:\program files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceService64X.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S3 AiCharger;ASUS Charger Driver;c:\windows\system32\DRIVERS\AiCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AiCharger.sys [x] S3 ATP;ASUS Input Device;c:\windows\System32\drivers\AsusTP.sys;c:\windows\SYSNATIVE\drivers\AsusTP.sys [x] S3 dpmconv;SIMATIC NET DP Driver;c:\windows\System32\drivers\dpmconv.sys;c:\windows\SYSNATIVE\drivers\dpmconv.sys [x] S3 HIDSwitch;ASUS Wireless Radio Control;c:\windows\System32\drivers\AsHIDSwitch64.sys;c:\windows\SYSNATIVE\drivers\AsHIDSwitch64.sys [x] S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [x] S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 RSBASTOR;Realtek PCIE CardReader Driver - BA;c:\windows\system32\DRIVERS\RtsBaStor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsBaStor.sys [x] S3 RTL8168;Realtek 8168 NT Driver;c:\windows\system32\DRIVERS\Rt630x64.sys;c:\windows\SYSNATIVE\DRIVERS\Rt630x64.sys [x] S3 s7odpx2x64;SIMATIC Knotentaufe;c:\windows\System32\drivers\s7odpx2x64.sys;c:\windows\SYSNATIVE\drivers\s7odpx2x64.sys [x] S3 s7oppinx64;SIMATIC PPI Transport;c:\windows\System32\drivers\s7oppinx64.sys;c:\windows\SYSNATIVE\drivers\s7oppinx64.sys [x] S3 s7oserix64;Siemens PC Serial Cable;c:\windows\System32\Drivers\s7oserix64.sys;c:\windows\SYSNATIVE\Drivers\s7oserix64.sys [x] S3 s7osmcax64;SIMATIC PC Adapter RS232;c:\windows\System32\drivers\s7osmcax64.sys;c:\windows\SYSNATIVE\drivers\s7osmcax64.sys [x] S3 s7osobux64;SIMATIC SoftBus;c:\windows\System32\drivers\s7osobux64.sys;c:\windows\SYSNATIVE\drivers\s7osobux64.sys [x] S3 s7otmcd64x;SIMATIC Memory Cards;c:\windows\System32\Drivers\s7otmcd64x.sys;c:\windows\SYSNATIVE\Drivers\s7otmcd64x.sys [x] S3 s7otranx64;SIMATIC Transport;c:\windows\System32\drivers\s7otranx64.sys;c:\windows\SYSNATIVE\drivers\s7otranx64.sys [x] S3 s7otsadx64;SIMATIC TS Adapter RS232;c:\windows\System32\drivers\s7otsadx64.sys;c:\windows\SYSNATIVE\drivers\s7otsadx64.sys [x] S3 vsnl2ada;SIMATIC NET FDL Driver;c:\windows\System32\drivers\vsnl2ada.sys;c:\windows\SYSNATIVE\drivers\vsnl2ada.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2014-06-13 19:41 1091912 ----a-w- c:\program files (x86)\Google\Chrome\Application\35.0.1916.153\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2014-07-11 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-17 17:10] . 2014-07-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-11-02 15:07] . 2014-07-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-11-02 15:07] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1] @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}] 2013-11-02 15:17 261744 ----a-w- c:\users\Muhammed\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2] @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}] 2013-11-02 15:17 261744 ----a-w- c:\users\Muhammed\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3] @="{BBACC218-34EA-4666-9D7A-C78F2274A524}" [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}] 2013-11-02 15:17 261744 ----a-w- c:\users\Muhammed\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\!AsusWSShellExt_B] @="{6D4133E5-0742-4ADC-8A8C-9303440F7190}" [HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}] 2012-09-27 07:15 1472512 ----a-w- c:\program files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSShellExt64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\!AsusWSShellExt_O] @="{64174815-8D98-4CE6-8646-4C039977D808}" [HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}] 2012-09-27 07:15 1472512 ----a-w- c:\program files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSShellExt64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\!AsusWSShellExt_U] @="{1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4D}" [HKEY_CLASSES_ROOT\CLSID\{1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4D}] 2012-09-27 07:15 1472512 ----a-w- c:\program files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSShellExt64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-11 02:09 164016 ----a-w- c:\users\Muhammed\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-11 02:09 164016 ----a-w- c:\users\Muhammed\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-11 02:09 164016 ----a-w- c:\users\Muhammed\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2013-09-11 02:09 164016 ----a-w- c:\users\Muhammed\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-12-13 172144] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-12-13 399984] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2013-05-30 13550152] "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2013-05-20 1308232] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=c:\windows\System32\nvinitx.dll . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://asus13.msn.com mLocal Page = c:\windows\SysWOW64\blank.htm TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\Muhammed\AppData\Roaming\Mozilla\Firefox\Profiles\n6xal7me.default\ FF - prefs.js: browser.startup.homepage - www.google.de . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Toolbar-Locked - (no file) . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\McAfee] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) @SACL=(02 0000) . Zeit der Fertigstellung: 2014-07-11 14:09:21 ComboFix-quarantined-files.txt 2014-07-11 12:09 . Vor Suchlauf: 14 Verzeichnis(se), 208.825.040.896 Bytes frei Nach Suchlauf: 15 Verzeichnis(se), 208.858.406.912 Bytes frei . - - End Of File - - 6B15408404CC8FD3DA14D0C434C0665B |
12.07.2014, 07:41 | #4 |
/// the machine /// TB-Ausbilder | Windows 8 - Sound funktioniert nicht richtig/Youtube(andere Musikmöglichkeiten) funktionieren auch nicht! Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
13.07.2014, 15:04 | #5 |
| Windows 8 - Sound funktioniert nicht richtig/Youtube(andere Musikmöglichkeiten) funktionieren auch nicht! Hey! mbam.txt Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 13.07.2014 Suchlauf-Zeit: 15:31:36 Logdatei: mbam.txt Administrator: Ja Version: 2.00.2.1012 Malware Datenbank: v2014.07.13.04 Rootkit Datenbank: v2014.07.09.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Self-protection: Deaktiviert Betriebssystem: Windows 8 CPU: x64 Dateisystem: NTFS Benutzer: Muhammed Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 353062 Verstrichene Zeit: 8 Min, 53 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristics: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 1 PUP.Optional.Softonic.A, HKU\S-1-5-21-529104025-161939068-2471084440-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, In Quarantäne, [45c38c13ea91d4627f5a2ba4d42e59a7], Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 0 (No malicious items detected) Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter # AdwCleaner v3.215 - Bericht erstellt am 13/07/2014 um 15:45:38 # Aktualisiert 09/07/2014 von Xplode # Betriebssystem : Windows 8 (64 bits) # Benutzername : Muhammed - MUHI-PC # Gestartet von : C:\Users\Muhammed\Downloads\adwcleaner_3.215.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKCU\Software\Softonic ***** [ Browser ] ***** -\\ Internet Explorer v10.0.9200.17028 -\\ Mozilla Firefox v30.0 (de) [ Datei : C:\Users\Muhammed\AppData\Roaming\Mozilla\Firefox\Profiles\n6xal7me.default\prefs.js ] -\\ Google Chrome v35.0.1916.153 [ Datei : C:\Users\Muhammed\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [1104 octets] - [13/07/2014 15:44:37] AdwCleaner[S0].txt - [929 octets] - [13/07/2014 15:45:38] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [988 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 8 x64 Ran by Muhammed on 13.07.2014 at 15:52:55,93 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin" ~~~ FireFox Emptied folder: C:\Users\Muhammed\AppData\Roaming\mozilla\firefox\profiles\n6xal7me.default\minidumps [20 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 13.07.2014 at 15:56:33,38 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-07-2014 Ran by Muhammed (administrator) on MUHI-PC on 13-07-2014 15:58:08 Running from C:\Users\Muhammed\Downloads Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (SIEMENS AG) C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe () C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe (Siemens AG) C:\Program Files\Common Files\Siemens\AlmPanelPlugin\ALMPanelPlugin.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (National Instruments Corporation) C:\Windows\SysWOW64\lkads.exe (National Instruments Corporation) D:\Labview\MAX\nimxs.exe (National Instruments Corporation) D:\Labview\Shared\Security\nidmsrv.exe (National Instruments Corporation) D:\Labview\Shared\nisvcloc\nisvcloc.exe (ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Siemens AG) C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7oiehsx64.exe (Siemens AG) C:\Program Files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceService64x.exe (National Instruments, Inc.) C:\Windows\SysWOW64\lkcitdl.exe (National Instruments Corporation) C:\Windows\SysWOW64\lktsrv.exe (National Instruments Corporation) D:\Labview\Shared\mDNS Responder\nimdnsResponder.exe (National Instruments Corporation) D:\Labview\Shared\NI WebServer\SystemWebServer.exe (National Instruments Corporation) D:\Labview\Shared\Tagger\tagsrv.exe (Siemens AG) C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7epasrv64x.exe (National Instruments Corporation) D:\Labview\Shared\NI WebServer\ApplicationWebServer.exe (National Instruments Corporation) D:\Labview\Shared\NI Network Discovery\niDiscSvc.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe (Siemens AG) C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\pniomgr.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe (Siemens AG) C:\Windows\SysWOW64\pniopcac.exe (Siemens AG) C:\Windows\SysWOW64\pniopcac.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe () C:\Users\Muhammed\AppData\Local\Amazon Music\Amazon Music Helper.exe (National Instruments Corporation) D:\Labview\Shared\NI Error Reporting\nierserver.exe (Dropbox, Inc.) C:\Users\Muhammed\AppData\Roaming\Dropbox\bin\Dropbox.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13550152 2013-05-30] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1308232 2013-05-20] (Realtek Semiconductor) HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3187360 2013-04-26] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSPanel.exe [3576784 2012-12-19] (ASUS Cloud Corporation) HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [750160 2014-07-01] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [NI Update Service] => D:\Labview\Shared\Update Service\NIUpdateService.exe [857888 2013-05-28] (National Instruments) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SiemensAutomationFileStorage_TIAP13] => D:\Siemens\Automation\Portal V13\Bin\Siemens.Automation.ObjectFrame.FileStorage.Server.exe [1022464 2014-02-12] (Siemens AG) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-529104025-161939068-2471084440-1002\...\Run: [NIRegistrationWizard] => D:\Labview\Shared\RegistrationWizard\Bin\RegistrationWizard.exe [847000 2013-04-19] () HKU\S-1-5-21-529104025-161939068-2471084440-1002\...\Run: [Amazon Music] => C:\Users\Muhammed\AppData\Local\Amazon Music\Amazon Music Helper.exe [3162944 2014-06-05] () AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [245872 2013-07-08] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [201576 2013-07-08] (NVIDIA Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NI Error Reporting.lnk ShortcutTarget: NI Error Reporting.lnk -> D:\Labview\Shared\NI Error Reporting\nierserver.exe (National Instruments Corporation) Startup: C:\Users\Muhammed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Muhammed\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ShellIconOverlayIdentifiers: !AsusWSShellExt_B -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\ASUSWSShellExt64.dll (ASUS Cloud Corporation.) ShellIconOverlayIdentifiers: !AsusWSShellExt_O -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\ASUSWSShellExt64.dll (ASUS Cloud Corporation.) ShellIconOverlayIdentifiers: !AsusWSShellExt_U -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4D} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\ASUSWSShellExt64.dll (ASUS Cloud Corporation.) ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers-x32: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers-x32: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers-x32: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ShellIconOverlayIdentifiers-x32: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers-x32: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers-x32: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus13.msn.com StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS SearchScopes: HKLM-x32 - DefaultScope value is missing. SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = Winsock: Catalog5 08 D:\Labview\Shared\mDNS Responder\nimdnsNSP.dll [26512] (National Instruments Corporation) Winsock: Catalog5-x64 08 C:\Program Files\National Instruments\Shared\mDNS Responder\nimdnsNSP.dll [28560] (National Instruments Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Muhammed\AppData\Roaming\Mozilla\Firefox\Profiles\n6xal7me.default FF Homepage: www.google.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: NoScript - C:\Users\Muhammed\AppData\Roaming\Mozilla\Firefox\Profiles\n6xal7me.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-12-17] FF Extension: Adblock Plus - C:\Users\Muhammed\AppData\Roaming\Mozilla\Firefox\Profiles\n6xal7me.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-12-17] FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK Chrome: ======= CHR HomePage: CHR Extension: (Adblock Plus) - C:\Users\Muhammed\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-03-04] CHR Extension: (Google Wallet) - C:\Users\Muhammed\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-02] ==================== Services (Whitelisted) ================= R2 almservice; C:\Program Files\Common Files\Siemens\sws\almsrv\almsrv64x.exe [1563968 2014-01-13] (SIEMENS AG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-07-01] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-07-01] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1030224 2014-07-10] (Avira Operations GmbH & Co. KG) R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS) R2 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe [72192 2012-12-19] () [File not signed] R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation) R2 LkCitadelServer; C:\Windows\SysWOW64\lkcitdl.exe [695136 2010-10-27] (National Instruments, Inc.) R2 lkClassAds; C:\Windows\SysWOW64\lkads.exe [53544 2013-06-12] (National Instruments Corporation) R2 lkTimeSync; C:\Windows\SysWOW64\lktsrv.exe [63792 2013-06-12] (National Instruments Corporation) R2 mxssvr; D:\Labview\MAX\nimxs.exe [83768 2013-06-11] (National Instruments Corporation) R2 NIApplicationWebServer; D:\Labview\Shared\NI WebServer\ApplicationWebServer.exe [57696 2013-06-08] (National Instruments Corporation) S4 NIApplicationWebServer64; C:\Program Files\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [81248 2013-06-08] (National Instruments Corporation) R2 NIDomainService; D:\Labview\Shared\Security\nidmsrv.exe [380720 2013-06-12] (National Instruments Corporation) S3 NILM License Manager; D:\Labview\Shared\License Manager\Bin\lmgrd.exe [1427688 2010-08-02] (Macrovision Corporation) R2 nimDNSResponder; D:\Labview\Shared\mDNS Responder\nimdnsResponder.exe [260976 2013-05-11] (National Instruments Corporation) R2 NINetworkDiscovery; D:\Labview\Shared\NI Network Discovery\niDiscSvc.exe [176512 2013-06-19] (National Instruments Corporation) R2 NiSvcLoc; D:\Labview\Shared\niSvcLoc\nisvcloc.exe [90440 2013-06-07] (National Instruments Corporation) R2 NISystemWebServer; D:\Labview\Shared\NI WebServer\SystemWebServer.exe [57680 2013-06-08] (National Instruments Corporation) R2 NITaggerService; D:\Labview\Shared\Tagger\tagsrv.exe [687944 2013-06-15] (National Instruments Corporation) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-04-10] () R2 s7oiehsx64; C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7oiehsx64.exe [144608 2014-01-16] (Siemens AG) R2 S7TraceServiceX; C:\Program Files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceService64X.exe [472288 2014-01-16] (Siemens AG) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== U5 AppMgmt; C:\Windows\system32\svchost.exe [29696 2013-04-26] (Microsoft Corporation) R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [65784 2013-06-28] (ASUS Corporation) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-07-01] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [130584 2014-05-20] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-10-10] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [42040 2014-07-10] (Avira Operations GmbH & Co. KG) R3 dpmconv; C:\Windows\System32\drivers\dpmconv.sys [259584 2013-08-07] (Siemens AG) R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( ) S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-07-13] (Malwarebytes Corporation) R3 s7odpx2x64; C:\Windows\System32\drivers\s7odpx2x64.sys [71168 2012-12-19] (SIEMENS AG) R3 s7oppinx64; C:\Windows\System32\drivers\s7oppinx64.sys [107520 2012-07-24] (SIEMENS AG) R3 s7oserix64; C:\Windows\System32\Drivers\s7oserix64.sys [121856 2012-07-24] (SIEMENS AG) R3 s7osmcax64; C:\Windows\System32\drivers\s7osmcax64.sys [199680 2012-07-24] (SIEMENS AG) R3 s7osobux64; C:\Windows\System32\drivers\s7osobux64.sys [153600 2012-07-24] (SIEMENS AG) R3 s7otmcd64x; C:\Windows\System32\Drivers\s7otmcd64x.sys [199680 2012-07-24] (SIEMENS AG) R3 s7otranx64; C:\Windows\System32\drivers\s7otranx64.sys [260608 2013-12-02] (Siemens AG) R3 s7otsadx64; C:\Windows\System32\drivers\s7otsadx64.sys [196096 2012-07-24] (SIEMENS AG) R2 s7ousbu64x; C:\Windows\System32\drivers\s7ousbu64x.sys [137216 2013-12-17] (Siemens AG) R2 s7sn2srtx; C:\Windows\system32\DRIVERS\s7sn2srtx.sys [83032 2012-05-09] (SIEMENS AG) R2 SNTIE; C:\Windows\system32\DRIVERS\sntie.sys [359648 2013-10-28] (Siemens AG) R3 vsnl2ada; C:\Windows\System32\drivers\vsnl2ada.sys [128000 2013-08-07] (SIEMENS AG) S3 catchme; \??\C:\ComboFix\catchme.sys [X] U0 msahci; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-13 15:58 - 2014-07-13 15:58 - 00000000 ____D () C:\Users\Muhammed\Downloads\FRST-OlderVersion 2014-07-13 15:56 - 2014-07-13 15:56 - 00000820 _____ () C:\Users\Muhammed\Desktop\JRT.txt 2014-07-13 15:52 - 2014-07-13 15:52 - 01016261 _____ (Thisisu) C:\Users\Muhammed\Downloads\JRT.exe 2014-07-13 15:49 - 2014-07-13 15:49 - 00001067 _____ () C:\Users\Muhammed\Desktop\AdwCleaner[S0].txt 2014-07-13 15:45 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-07-13 15:43 - 2014-07-13 15:45 - 00000000 ____D () C:\AdwCleaner 2014-07-13 15:43 - 2014-07-13 15:43 - 01348263 _____ () C:\Users\Muhammed\Downloads\adwcleaner_3.215.exe 2014-07-13 15:42 - 2014-07-13 15:42 - 00001323 _____ () C:\Users\Muhammed\Desktop\mbam.txt 2014-07-13 15:28 - 2014-07-13 15:29 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-13 15:28 - 2014-07-13 15:28 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-07-13 15:28 - 2014-07-13 15:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-13 15:28 - 2014-07-13 15:28 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-07-13 15:28 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-07-13 15:28 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-07-13 15:28 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-07-13 15:27 - 2014-07-13 15:28 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Muhammed\Downloads\mbam-setup-2.0.2.1012.exe 2014-07-11 14:09 - 2014-07-11 14:09 - 00021381 _____ () C:\ComboFix.txt 2014-07-11 14:00 - 2014-07-11 14:09 - 00000000 ____D () C:\Qoobox 2014-07-11 14:00 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-07-11 14:00 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-07-11 14:00 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-07-11 14:00 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-07-11 14:00 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-07-11 14:00 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe 2014-07-11 14:00 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-07-11 14:00 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-07-11 14:00 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-07-11 13:58 - 2014-07-11 13:58 - 05218294 ____R (Swearware) C:\Users\Muhammed\Desktop\ComboFix.exe 2014-07-11 12:00 - 2014-07-11 12:01 - 00301064 _____ () C:\Windows\Minidump\071114-67031-01.dmp 2014-07-11 11:55 - 2014-07-11 12:00 - 543916582 _____ () C:\Windows\MEMORY.DMP 2014-07-11 11:55 - 2014-07-11 12:00 - 00000000 ____D () C:\Windows\Minidump 2014-07-11 11:55 - 2014-07-11 11:55 - 00301064 _____ () C:\Windows\Minidump\071114-70218-01.dmp 2014-07-11 11:52 - 2014-07-11 11:52 - 00380416 _____ () C:\Users\Muhammed\Downloads\d26u31wd.exe 2014-07-11 11:52 - 2014-07-11 11:52 - 00049401 _____ () C:\Users\Muhammed\Desktop\Addition.txt 2014-07-11 11:52 - 2014-07-11 11:52 - 00045070 _____ () C:\Users\Muhammed\Desktop\FRST.txt 2014-07-11 11:50 - 2014-07-11 11:51 - 00049401 _____ () C:\Users\Muhammed\Downloads\Addition.txt 2014-07-11 11:49 - 2014-07-13 15:58 - 00019475 _____ () C:\Users\Muhammed\Downloads\FRST.txt 2014-07-11 11:49 - 2014-07-13 15:58 - 00000000 ____D () C:\FRST 2014-07-11 11:48 - 2014-07-13 15:58 - 02086912 _____ (Farbar) C:\Users\Muhammed\Downloads\FRST64.exe 2014-07-11 11:47 - 2014-07-11 11:47 - 00050477 _____ () C:\Users\Muhammed\Downloads\Defogger.exe 2014-07-11 11:47 - 2014-07-11 11:47 - 00000478 _____ () C:\Users\Muhammed\Downloads\defogger_disable.log 2014-07-11 11:47 - 2014-07-11 11:47 - 00000000 _____ () C:\Users\Muhammed\defogger_reenable 2014-07-11 10:30 - 2014-07-11 10:30 - 00338240 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-07-10 01:43 - 2014-07-10 01:43 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-07-09 12:25 - 2014-07-01 00:42 - 00702464 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-07-09 12:25 - 2014-07-01 00:42 - 00394240 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2014-07-09 12:25 - 2014-07-01 00:42 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2014-07-09 12:25 - 2014-06-28 05:35 - 00556544 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-07-09 12:25 - 2014-06-19 04:12 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-07-09 12:25 - 2014-06-19 04:12 - 01366528 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-07-09 12:25 - 2014-06-19 04:12 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2014-07-09 12:25 - 2014-06-19 04:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll 2014-07-09 12:25 - 2014-06-19 04:12 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-07-09 12:25 - 2014-06-19 04:11 - 19277312 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-07-09 12:25 - 2014-06-19 04:11 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-07-09 12:25 - 2014-06-19 04:11 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 15369728 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 02650624 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-07-09 12:25 - 2014-06-19 04:09 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-07-09 12:25 - 2014-06-19 02:53 - 14368768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-07-09 12:25 - 2014-06-19 02:53 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-07-09 12:25 - 2014-06-19 02:53 - 01141760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-07-09 12:25 - 2014-06-19 02:53 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-07-09 12:25 - 2014-06-19 02:53 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-07-09 12:25 - 2014-06-19 02:53 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-07-09 12:25 - 2014-06-19 02:53 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2014-07-09 12:25 - 2014-06-19 02:52 - 13732352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-07-09 12:25 - 2014-06-19 02:52 - 02863616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-07-09 12:25 - 2014-06-19 02:52 - 02051072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-07-09 12:25 - 2014-06-19 02:52 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-07-09 12:25 - 2014-06-19 02:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-07-09 12:25 - 2014-06-19 02:52 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-07-09 12:25 - 2014-06-19 02:52 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-07-09 12:25 - 2014-06-19 02:52 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-07-09 12:25 - 2014-06-19 02:52 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-07-09 12:25 - 2014-06-19 02:52 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-07-09 12:25 - 2014-06-19 02:52 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-07-09 12:25 - 2014-06-19 02:52 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-07-09 12:25 - 2014-06-19 02:33 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-07-09 12:25 - 2014-06-19 02:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-07-09 12:25 - 2014-06-19 00:05 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll 2014-07-09 12:25 - 2014-06-18 01:27 - 01440256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe 2014-07-09 12:25 - 2014-06-18 01:24 - 01557504 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe 2014-07-09 12:25 - 2014-06-11 06:18 - 04038144 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-07-09 12:25 - 2014-06-06 16:06 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-07-09 12:25 - 2014-06-06 12:17 - 00497152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-07-09 12:25 - 2014-06-03 00:33 - 00265216 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll 2014-07-09 12:25 - 2014-05-30 01:31 - 00452608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll 2014-07-09 12:25 - 2014-05-30 01:03 - 00588288 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll 2014-07-09 12:25 - 2014-05-30 01:02 - 01281536 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-07-09 12:25 - 2014-05-30 01:02 - 00439808 _____ (Microsoft Corporation) C:\Windows\system32\lsm.dll 2014-07-09 12:25 - 2014-05-30 00:24 - 00576512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2014-07-09 12:25 - 2014-05-03 08:34 - 06974808 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-07-09 12:25 - 2014-05-03 08:33 - 01824808 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2014-07-09 12:25 - 2014-05-03 06:51 - 01408976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2014-07-09 12:25 - 2014-05-02 00:37 - 01023488 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll 2014-07-09 12:25 - 2014-04-30 00:32 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\Robocopy.exe 2014-07-09 12:25 - 2014-04-30 00:32 - 00106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Robocopy.exe 2014-07-09 12:25 - 2014-04-24 01:51 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll 2014-07-09 12:25 - 2014-04-24 01:51 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2014-07-09 12:25 - 2014-04-24 01:38 - 00693760 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll 2014-07-09 12:25 - 2014-04-24 01:38 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2014-07-09 12:25 - 2014-02-08 06:34 - 00071168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hdaudbus.sys 2014-07-06 19:45 - 2014-05-03 07:47 - 03246592 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2014-07-06 19:45 - 2014-05-03 05:34 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2014-07-06 19:45 - 2014-04-03 13:19 - 00328024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys 2014-07-06 19:45 - 2014-04-03 05:44 - 00619008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2014-07-06 19:45 - 2014-04-01 00:08 - 00387268 _____ () C:\Windows\system32\ApnDatabase.xml 2014-07-06 19:45 - 2014-03-25 01:42 - 00305152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wusa.exe 2014-07-06 19:45 - 2014-03-25 00:56 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\wusa.exe 2014-07-06 19:44 - 2014-04-30 00:32 - 01301504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-07-06 19:44 - 2014-04-30 00:22 - 01023488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-07-06 19:40 - 2014-04-03 13:22 - 02233176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-07-06 19:40 - 2014-03-07 02:47 - 01419264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-07-06 19:40 - 2014-03-07 02:08 - 01845760 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-07-06 19:31 - 2014-05-20 04:33 - 00059416 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2014-07-06 19:31 - 2014-05-20 01:45 - 00629248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2014-07-06 19:31 - 2014-05-20 01:45 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2014-07-06 19:31 - 2014-05-20 01:24 - 03286528 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2014-07-06 19:31 - 2014-05-20 01:24 - 01623040 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2014-07-06 19:31 - 2014-05-20 01:24 - 00773632 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2014-07-06 19:31 - 2014-05-20 01:24 - 00253440 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll 2014-07-06 19:31 - 2014-05-20 01:24 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll 2014-07-06 19:31 - 2014-05-20 01:24 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2014-07-06 19:31 - 2014-05-15 00:43 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2014-07-06 19:31 - 2014-05-15 00:43 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2014-07-06 19:31 - 2014-05-15 00:42 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2014-07-06 19:31 - 2014-05-15 00:42 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2014-07-01 18:49 - 2014-07-01 18:52 - 00000000 ____D () C:\Users\Muhammed\Downloads\openvpn-2.3.3.I001-64Bit 2014-07-01 18:48 - 2014-07-01 18:51 - 02882999 _____ () C:\Users\Muhammed\Downloads\openvpn-2.3.3.I001-64Bit.zip 2014-06-28 15:24 - 2014-06-28 15:28 - 24901341 _____ () C:\Users\Muhammed\Downloads\Hibbeler.Mechanik3.Dynamik.rar 2014-06-22 20:39 - 2014-06-22 20:39 - 00000000 ____D () C:\Program Files (x86)\GUMEDA7.tmp 2014-06-19 00:34 - 2014-06-19 00:34 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-14 00:56 - 2014-06-15 13:34 - 00001142 _____ () C:\Users\Muhammed\Desktop\Amazon Music.lnk 2014-06-13 13:36 - 2014-06-13 13:36 - 00000000 ____D () C:\Users\Muhammed\AppData\Local\Adobe ==================== One Month Modified Files and Folders ======= 2014-07-13 15:58 - 2014-07-13 15:58 - 00000000 ____D () C:\Users\Muhammed\Downloads\FRST-OlderVersion 2014-07-13 15:58 - 2014-07-11 11:49 - 00019475 _____ () C:\Users\Muhammed\Downloads\FRST.txt 2014-07-13 15:58 - 2014-07-11 11:49 - 00000000 ____D () C:\FRST 2014-07-13 15:58 - 2014-07-11 11:48 - 02086912 _____ (Farbar) C:\Users\Muhammed\Downloads\FRST64.exe 2014-07-13 15:56 - 2014-07-13 15:56 - 00000820 _____ () C:\Users\Muhammed\Desktop\JRT.txt 2014-07-13 15:52 - 2014-07-13 15:52 - 01016261 _____ (Thisisu) C:\Users\Muhammed\Downloads\JRT.exe 2014-07-13 15:52 - 2013-11-02 17:07 - 00003594 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-529104025-161939068-2471084440-1002 2014-07-13 15:51 - 2014-03-02 16:51 - 01939083 _____ () C:\Windows\WindowsUpdate.log 2014-07-13 15:51 - 2013-11-02 17:02 - 00000062 _____ () C:\Users\Muhammed\AppData\Roaming\sp_data.sys 2014-07-13 15:50 - 2013-11-03 11:29 - 00000000 ____D () C:\Users\Muhammed\AppData\Roaming\Dropbox 2014-07-13 15:49 - 2014-07-13 15:49 - 00001067 _____ () C:\Users\Muhammed\Desktop\AdwCleaner[S0].txt 2014-07-13 15:49 - 2014-05-03 13:03 - 00000000 ____D () C:\Users\Muhammed\AppData\Roaming\DropboxMaster 2014-07-13 15:49 - 2013-11-03 11:31 - 00000000 ___RD () C:\Users\Muhammed\Dropbox 2014-07-13 15:47 - 2013-11-02 17:07 - 00001126 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-07-13 15:47 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-13 15:46 - 2014-06-04 08:12 - 00001640 _____ () C:\Windows\PFRO.log 2014-07-13 15:45 - 2014-07-13 15:43 - 00000000 ____D () C:\AdwCleaner 2014-07-13 15:44 - 2013-11-02 17:07 - 00001130 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-07-13 15:43 - 2014-07-13 15:43 - 01348263 _____ () C:\Users\Muhammed\Downloads\adwcleaner_3.215.exe 2014-07-13 15:43 - 2013-11-02 19:01 - 00000000 ____D () C:\Users\Muhammed\AppData\Roaming\TS3Client 2014-07-13 15:42 - 2014-07-13 15:42 - 00001323 _____ () C:\Users\Muhammed\Desktop\mbam.txt 2014-07-13 15:29 - 2014-07-13 15:28 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-13 15:28 - 2014-07-13 15:28 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-07-13 15:28 - 2014-07-13 15:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-13 15:28 - 2014-07-13 15:28 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-07-13 15:28 - 2014-07-13 15:27 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Muhammed\Downloads\mbam-setup-2.0.2.1012.exe 2014-07-13 15:28 - 2013-12-14 22:29 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-12 02:10 - 2013-12-17 18:31 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-07-12 01:02 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru 2014-07-11 22:57 - 2013-11-02 17:13 - 00000000 ____D () C:\Users\Muhammed\AppData\Local\PMB Files 2014-07-11 15:49 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache 2014-07-11 14:09 - 2014-07-11 14:09 - 00021381 _____ () C:\ComboFix.txt 2014-07-11 14:09 - 2014-07-11 14:00 - 00000000 ____D () C:\Qoobox 2014-07-11 14:07 - 2012-07-26 07:26 - 00000215 _____ () C:\Windows\system.ini 2014-07-11 13:59 - 2013-12-13 11:38 - 00000000 ____D () C:\Windows\erdnt 2014-07-11 13:58 - 2014-07-11 13:58 - 05218294 ____R (Swearware) C:\Users\Muhammed\Desktop\ComboFix.exe 2014-07-11 12:31 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM 2014-07-11 12:01 - 2014-07-11 12:00 - 00301064 _____ () C:\Windows\Minidump\071114-67031-01.dmp 2014-07-11 12:00 - 2014-07-11 11:55 - 543916582 _____ () C:\Windows\MEMORY.DMP 2014-07-11 12:00 - 2014-07-11 11:55 - 00000000 ____D () C:\Windows\Minidump 2014-07-11 11:55 - 2014-07-11 11:55 - 00301064 _____ () C:\Windows\Minidump\071114-70218-01.dmp 2014-07-11 11:52 - 2014-07-11 11:52 - 00380416 _____ () C:\Users\Muhammed\Downloads\d26u31wd.exe 2014-07-11 11:52 - 2014-07-11 11:52 - 00049401 _____ () C:\Users\Muhammed\Desktop\Addition.txt 2014-07-11 11:52 - 2014-07-11 11:52 - 00045070 _____ () C:\Users\Muhammed\Desktop\FRST.txt 2014-07-11 11:51 - 2014-07-11 11:50 - 00049401 _____ () C:\Users\Muhammed\Downloads\Addition.txt 2014-07-11 11:47 - 2014-07-11 11:47 - 00050477 _____ () C:\Users\Muhammed\Downloads\Defogger.exe 2014-07-11 11:47 - 2014-07-11 11:47 - 00000478 _____ () C:\Users\Muhammed\Downloads\defogger_disable.log 2014-07-11 11:47 - 2014-07-11 11:47 - 00000000 _____ () C:\Users\Muhammed\defogger_reenable 2014-07-11 11:47 - 2013-11-02 16:59 - 00000000 ____D () C:\Users\Muhammed 2014-07-11 11:20 - 2012-08-03 01:02 - 00753134 _____ () C:\Windows\system32\perfh007.dat 2014-07-11 11:20 - 2012-08-03 01:02 - 00155826 _____ () C:\Windows\system32\perfc007.dat 2014-07-11 11:20 - 2012-07-26 09:28 - 01745416 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-07-11 10:30 - 2014-07-11 10:30 - 00338240 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-07-10 16:46 - 2013-11-17 22:38 - 00000391 _____ () C:\Users\Muhammed\Desktop\Series.txt 2014-07-10 12:51 - 2013-11-02 19:35 - 00042040 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2014-07-10 01:44 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI 2014-07-10 01:43 - 2014-07-10 01:43 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-07-10 01:43 - 2012-07-26 11:45 - 00000000 ____D () C:\Program Files\Windows Journal 2014-07-10 01:43 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-10 01:43 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-10 01:43 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\WinStore 2014-07-09 12:52 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp 2014-07-09 12:51 - 2013-11-02 22:55 - 00000000 ____D () C:\Windows\system32\MRT 2014-07-09 12:50 - 2013-11-02 22:55 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-07-08 19:10 - 2013-12-17 18:31 - 00003772 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-07-06 19:48 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent 2014-07-03 23:49 - 2014-05-17 12:19 - 00000000 ____D () C:\Users\Muhammed\Documents\BabaAnne 2014-07-02 13:11 - 2013-11-02 17:13 - 00000000 ____D () C:\ProgramData\PMB Files 2014-07-01 18:52 - 2014-07-01 18:49 - 00000000 ____D () C:\Users\Muhammed\Downloads\openvpn-2.3.3.I001-64Bit 2014-07-01 18:51 - 2014-07-01 18:48 - 02882999 _____ () C:\Users\Muhammed\Downloads\openvpn-2.3.3.I001-64Bit.zip 2014-07-01 18:48 - 2014-06-02 08:39 - 00000000 ____D () C:\Users\Muhammed\AppData\Roaming\FileZilla 2014-07-01 16:58 - 2014-05-06 15:18 - 00000000 ____D () C:\Users\Muhammed\Documents\BEWERBUNGEN 2014-07-01 15:02 - 2013-11-02 19:35 - 00117712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-07-01 00:42 - 2014-07-09 12:25 - 00702464 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-07-01 00:42 - 2014-07-09 12:25 - 00394240 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2014-07-01 00:42 - 2014-07-09 12:25 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2014-06-28 15:28 - 2014-06-28 15:24 - 24901341 _____ () C:\Users\Muhammed\Downloads\Hibbeler.Mechanik3.Dynamik.rar 2014-06-28 05:35 - 2014-07-09 12:25 - 00556544 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-06-26 22:53 - 2013-11-05 10:32 - 00703968 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-06-26 22:53 - 2013-11-05 10:32 - 00105440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-06-24 21:43 - 2013-11-02 18:59 - 00000000 ____D () C:\Users\Muhammed\AppData\Local\TeamSpeak 3 Client 2014-06-22 20:39 - 2014-06-22 20:39 - 00000000 ____D () C:\Program Files (x86)\GUMEDA7.tmp 2014-06-22 20:39 - 2013-11-02 17:07 - 00004102 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-06-22 20:39 - 2013-11-02 17:07 - 00003866 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-06-22 19:58 - 2013-12-17 17:59 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-06-20 20:33 - 2014-03-17 18:56 - 00000000 ____D () C:\Users\Muhammed\Desktop\HTW-F3 2014-06-19 04:12 - 2014-07-09 12:25 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-06-19 04:12 - 2014-07-09 12:25 - 01366528 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-06-19 04:12 - 2014-07-09 12:25 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2014-06-19 04:12 - 2014-07-09 12:25 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll 2014-06-19 04:12 - 2014-07-09 12:25 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-06-19 04:11 - 2014-07-09 12:25 - 19277312 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-06-19 04:11 - 2014-07-09 12:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-06-19 04:11 - 2014-07-09 12:25 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 15369728 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 02650624 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-06-19 04:09 - 2014-07-09 12:25 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-06-19 02:53 - 2014-07-09 12:25 - 14368768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-06-19 02:53 - 2014-07-09 12:25 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-06-19 02:53 - 2014-07-09 12:25 - 01141760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-06-19 02:53 - 2014-07-09 12:25 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-06-19 02:53 - 2014-07-09 12:25 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-06-19 02:53 - 2014-07-09 12:25 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-06-19 02:53 - 2014-07-09 12:25 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2014-06-19 02:52 - 2014-07-09 12:25 - 13732352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-06-19 02:52 - 2014-07-09 12:25 - 02863616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-06-19 02:52 - 2014-07-09 12:25 - 02051072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-06-19 02:52 - 2014-07-09 12:25 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-06-19 02:52 - 2014-07-09 12:25 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-06-19 02:52 - 2014-07-09 12:25 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-06-19 02:52 - 2014-07-09 12:25 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-06-19 02:52 - 2014-07-09 12:25 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-06-19 02:52 - 2014-07-09 12:25 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-06-19 02:52 - 2014-07-09 12:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-06-19 02:52 - 2014-07-09 12:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-06-19 02:52 - 2014-07-09 12:25 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-06-19 02:33 - 2014-07-09 12:25 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-06-19 02:30 - 2014-07-09 12:25 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-06-19 00:34 - 2014-06-19 00:34 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-19 00:05 - 2014-07-09 12:25 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll 2014-06-18 01:27 - 2014-07-09 12:25 - 01440256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe 2014-06-18 01:24 - 2014-07-09 12:25 - 01557504 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe 2014-06-16 16:53 - 2014-05-27 15:20 - 00013824 ___SH () C:\Users\Muhammed\Desktop\Thumbs.db 2014-06-15 13:35 - 2014-05-10 14:03 - 00000000 ____D () C:\Users\Muhammed\AppData\Local\Amazon Cloud Player 2014-06-15 13:34 - 2014-06-14 00:56 - 00001142 _____ () C:\Users\Muhammed\Desktop\Amazon Music.lnk 2014-06-13 13:36 - 2014-06-13 13:36 - 00000000 ____D () C:\Users\Muhammed\AppData\Local\Adobe Some content of TEMP: ==================== C:\Users\Muhammed\AppData\Local\temp\avgnt.exe C:\Users\Muhammed\AppData\Local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp5hbzwa.dll C:\Users\Muhammed\AppData\Local\temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-07 14:46 ==================== End Of Log ============================ --- --- --- |
14.07.2014, 13:41 | #6 |
/// the machine /// TB-Ausbilder | Windows 8 - Sound funktioniert nicht richtig/Youtube(andere Musikmöglichkeiten) funktionieren auch nicht!ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> Windows 8 - Sound funktioniert nicht richtig/Youtube(andere Musikmöglichkeiten) funktionieren auch nicht! |
15.07.2014, 19:08 | #7 |
| Windows 8 - Sound funktioniert nicht richtig/Youtube(andere Musikmöglichkeiten) funktionieren auch nicht! Hey schrauber! habe jetzt zweimal den Eset Scan durchgeführt, es wurde aber leider kein logfile gemacht. Es war lediglich nur das logfile von einem ersten Scan, den ich sofort abgebrochen hatte, weil ich die falschen Einstellungen angeklickt hatte, drauf. Ich versuche es morgen mittag nach neuer Installation erneut! Gruß So, hinbekommen: Eset: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=ed8320f05bdfd542967a70742ecfc170 # engine=19187 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2014-07-15 04:59:57 # local_time=2014-07-15 06:59:57 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.2.9200 NT # compatibility_mode_1='Avira Desktop' # compatibility_mode=1810 16777213 100 100 85943 24014755 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 368900 9834486 0 0 # scanned=305028 # found=2 # cleaned=0 # scan_time=3193 sh=4B553651EF610C0614F8393D6C25ABA0A8F09ECA ft=1 fh=92ef1bb072edf568 vn="Variante von Win32/Bundled.Toolbar.Ask.D potenziell unsichere Anwendung" ac=I fn="C:\Program Files (x86)\Avira\AntiVir Desktop\offercast_avirav7_.exe" sh=8740FBC5E07E51D113E9F6D694A7F966D4AEE1B1 ft=1 fh=4d4a1d0560e83763 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Muhammed\Downloads\FileZilla - CHIP-Installer.exe" Code:
ATTFilter Results of screen317's Security Check version 0.99.85 x64 (UAC is enabled) Internet Explorer 10 Out of date! ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Windows Defender Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Adobe Flash Player 14.0.0.145 Adobe Reader XI Mozilla Firefox (30.0) Google Chrome 35.0.1916.114 Google Chrome 35.0.1916.153 ````````Process Check: objlist.exe by Laurent```````` Avira Antivir avgnt.exe Avira Antivir avguard.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-07-2014 Ran by Muhammed (administrator) on MUHI-PC on 15-07-2014 20:04:15 Running from C:\Users\Muhammed\Downloads Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe () C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (National Instruments Corporation) C:\Windows\SysWOW64\lkads.exe (National Instruments Corporation) D:\Labview\MAX\nimxs.exe (National Instruments Corporation) D:\Labview\Shared\Security\nidmsrv.exe (National Instruments Corporation) D:\Labview\Shared\nisvcloc\nisvcloc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Siemens AG) C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7oiehsx64.exe (Siemens AG) C:\Program Files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceService64x.exe (National Instruments, Inc.) C:\Windows\SysWOW64\lkcitdl.exe (National Instruments Corporation) C:\Windows\SysWOW64\lktsrv.exe (National Instruments Corporation) D:\Labview\Shared\mDNS Responder\nimdnsResponder.exe (National Instruments Corporation) D:\Labview\Shared\NI WebServer\SystemWebServer.exe (National Instruments Corporation) D:\Labview\Shared\Tagger\tagsrv.exe (National Instruments Corporation) D:\Labview\Shared\NI Network Discovery\niDiscSvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Siemens AG) C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7epasrv64x.exe (Siemens AG) C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\pniomgr.exe (Siemens AG) C:\Windows\SysWOW64\pniopcac.exe (Siemens AG) C:\Windows\SysWOW64\pniopcac.exe (National Instruments Corporation) D:\Labview\Shared\NI WebServer\ApplicationWebServer.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe () C:\Users\Muhammed\AppData\Local\Amazon Music\Amazon Music Helper.exe (National Instruments Corporation) D:\Labview\Shared\NI Error Reporting\nierserver.exe (Dropbox, Inc.) C:\Users\Muhammed\AppData\Roaming\Dropbox\bin\Dropbox.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13550152 2013-05-30] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1308232 2013-05-20] (Realtek Semiconductor) HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3187360 2013-04-26] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSPanel.exe [3576784 2012-12-19] (ASUS Cloud Corporation) HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [750160 2014-07-01] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [NI Update Service] => D:\Labview\Shared\Update Service\NIUpdateService.exe [857888 2013-05-28] (National Instruments) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SiemensAutomationFileStorage_TIAP13] => "D:\Siemens\Automation\Portal V13\Bin\Siemens.Automation.ObjectFrame.FileStorage.Server.exe" preload Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-529104025-161939068-2471084440-1002\...\Run: [NIRegistrationWizard] => D:\Labview\Shared\RegistrationWizard\Bin\RegistrationWizard.exe [847000 2013-04-19] () HKU\S-1-5-21-529104025-161939068-2471084440-1002\...\Run: [Amazon Music] => C:\Users\Muhammed\AppData\Local\Amazon Music\Amazon Music Helper.exe [3162944 2014-06-05] () AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [245872 2013-07-08] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [201576 2013-07-08] (NVIDIA Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NI Error Reporting.lnk ShortcutTarget: NI Error Reporting.lnk -> D:\Labview\Shared\NI Error Reporting\nierserver.exe (National Instruments Corporation) Startup: C:\Users\Muhammed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Muhammed\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ShellIconOverlayIdentifiers: !AsusWSShellExt_B -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\ASUSWSShellExt64.dll (ASUS Cloud Corporation.) ShellIconOverlayIdentifiers: !AsusWSShellExt_O -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\ASUSWSShellExt64.dll (ASUS Cloud Corporation.) ShellIconOverlayIdentifiers: !AsusWSShellExt_U -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4D} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\ASUSWSShellExt64.dll (ASUS Cloud Corporation.) ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers-x32: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers-x32: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers-x32: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ShellIconOverlayIdentifiers-x32: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers-x32: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers-x32: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus13.msn.com StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS SearchScopes: HKLM-x32 - DefaultScope value is missing. SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = Winsock: Catalog5 08 D:\Labview\Shared\mDNS Responder\nimdnsNSP.dll [26512] (National Instruments Corporation) Winsock: Catalog5-x64 08 C:\Program Files\National Instruments\Shared\mDNS Responder\nimdnsNSP.dll [28560] (National Instruments Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Muhammed\AppData\Roaming\Mozilla\Firefox\Profiles\n6xal7me.default FF Homepage: www.google.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: NoScript - C:\Users\Muhammed\AppData\Roaming\Mozilla\Firefox\Profiles\n6xal7me.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-12-17] FF Extension: Adblock Plus - C:\Users\Muhammed\AppData\Roaming\Mozilla\Firefox\Profiles\n6xal7me.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-12-17] FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK Chrome: ======= CHR HomePage: CHR Extension: (Adblock Plus) - C:\Users\Muhammed\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-03-04] CHR Extension: (Google Wallet) - C:\Users\Muhammed\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-02] ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-07-01] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-07-01] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1030224 2014-07-10] (Avira Operations GmbH & Co. KG) R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS) R2 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe [72192 2012-12-19] () [File not signed] R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation) R2 LkCitadelServer; C:\Windows\SysWOW64\lkcitdl.exe [695136 2010-10-27] (National Instruments, Inc.) R2 lkClassAds; C:\Windows\SysWOW64\lkads.exe [53544 2013-06-12] (National Instruments Corporation) R2 lkTimeSync; C:\Windows\SysWOW64\lktsrv.exe [63792 2013-06-12] (National Instruments Corporation) R2 mxssvr; D:\Labview\MAX\nimxs.exe [83768 2013-06-11] (National Instruments Corporation) R2 NIApplicationWebServer; D:\Labview\Shared\NI WebServer\ApplicationWebServer.exe [57696 2013-06-08] (National Instruments Corporation) S4 NIApplicationWebServer64; C:\Program Files\National Instruments\Shared\NI WebServer\ApplicationWebServer.exe [81248 2013-06-08] (National Instruments Corporation) R2 NIDomainService; D:\Labview\Shared\Security\nidmsrv.exe [380720 2013-06-12] (National Instruments Corporation) S3 NILM License Manager; D:\Labview\Shared\License Manager\Bin\lmgrd.exe [1427688 2010-08-02] (Macrovision Corporation) R2 nimDNSResponder; D:\Labview\Shared\mDNS Responder\nimdnsResponder.exe [260976 2013-05-11] (National Instruments Corporation) R2 NINetworkDiscovery; D:\Labview\Shared\NI Network Discovery\niDiscSvc.exe [176512 2013-06-19] (National Instruments Corporation) R2 NiSvcLoc; D:\Labview\Shared\niSvcLoc\nisvcloc.exe [90440 2013-06-07] (National Instruments Corporation) R2 NISystemWebServer; D:\Labview\Shared\NI WebServer\SystemWebServer.exe [57680 2013-06-08] (National Instruments Corporation) R2 NITaggerService; D:\Labview\Shared\Tagger\tagsrv.exe [687944 2013-06-15] (National Instruments Corporation) R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-04-10] () R2 s7oiehsx64; C:\Program Files\Common Files\Siemens\Automation\Simatic OAM\bin\s7oiehsx64.exe [144608 2014-01-16] (Siemens AG) R2 S7TraceServiceX; C:\Program Files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceService64X.exe [472288 2014-01-16] (Siemens AG) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== U5 AppMgmt; C:\Windows\system32\svchost.exe [29696 2013-04-26] (Microsoft Corporation) R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [65784 2013-06-28] (ASUS Corporation) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-07-01] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [130584 2014-05-20] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-10-10] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [42040 2014-07-10] (Avira Operations GmbH & Co. KG) R3 dpmconv; C:\Windows\System32\drivers\dpmconv.sys [259584 2013-08-07] (Siemens AG) R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( ) S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-07-13] (Malwarebytes Corporation) R3 s7odpx2x64; C:\Windows\System32\drivers\s7odpx2x64.sys [71168 2012-12-19] (SIEMENS AG) R3 s7oppinx64; C:\Windows\System32\drivers\s7oppinx64.sys [107520 2012-07-24] (SIEMENS AG) R3 s7oserix64; C:\Windows\System32\Drivers\s7oserix64.sys [121856 2012-07-24] (SIEMENS AG) R3 s7osmcax64; C:\Windows\System32\drivers\s7osmcax64.sys [199680 2012-07-24] (SIEMENS AG) R3 s7osobux64; C:\Windows\System32\drivers\s7osobux64.sys [153600 2012-07-24] (SIEMENS AG) R3 s7otmcd64x; C:\Windows\System32\Drivers\s7otmcd64x.sys [199680 2012-07-24] (SIEMENS AG) R3 s7otranx64; C:\Windows\System32\drivers\s7otranx64.sys [260608 2013-12-02] (Siemens AG) R3 s7otsadx64; C:\Windows\System32\drivers\s7otsadx64.sys [196096 2012-07-24] (SIEMENS AG) R2 s7ousbu64x; C:\Windows\System32\drivers\s7ousbu64x.sys [137216 2013-12-17] (Siemens AG) R2 s7sn2srtx; C:\Windows\system32\DRIVERS\s7sn2srtx.sys [83032 2012-05-09] (SIEMENS AG) R2 SNTIE; C:\Windows\system32\DRIVERS\sntie.sys [359648 2013-10-28] (Siemens AG) R3 vsnl2ada; C:\Windows\System32\drivers\vsnl2ada.sys [128000 2013-08-07] (SIEMENS AG) S3 catchme; \??\C:\ComboFix\catchme.sys [X] U0 msahci; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-15 20:03 - 2014-07-15 20:03 - 00000806 _____ () C:\Users\Muhammed\Desktop\checkup.txt 2014-07-15 20:02 - 2014-07-15 20:02 - 00854390 _____ () C:\Users\Muhammed\Desktop\SecurityCheck.exe 2014-07-15 17:53 - 2014-07-15 17:53 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-07-14 19:32 - 2014-07-14 19:32 - 02347384 _____ (ESET) C:\Users\Muhammed\Downloads\esetsmartinstaller_deu.exe 2014-07-14 19:07 - 2014-06-24 09:36 - 00703440 _____ (Microsoft Corporation) C:\Windows\system32\NotificationUI.exe 2014-07-14 19:07 - 2014-06-24 09:35 - 00010450 _____ () C:\Windows\system32\autoconfig.cab 2014-07-14 19:07 - 2014-06-24 08:41 - 10115584 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll 2014-07-14 19:07 - 2014-06-24 08:41 - 00694784 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll 2014-07-14 19:07 - 2014-06-24 08:41 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2014-07-14 19:07 - 2014-06-24 08:40 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2014-07-14 19:07 - 2014-06-24 08:39 - 02307072 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2014-07-14 19:07 - 2014-06-24 08:39 - 02146304 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll 2014-07-14 19:07 - 2014-06-24 06:08 - 08858624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll 2014-07-14 19:07 - 2014-06-24 06:08 - 00567808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll 2014-07-14 19:07 - 2014-06-24 06:08 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2014-07-14 19:07 - 2014-06-24 06:06 - 02037760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2014-07-14 19:07 - 2014-06-24 06:06 - 00754176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll 2014-07-13 15:58 - 2014-07-13 15:58 - 00000000 ____D () C:\Users\Muhammed\Downloads\FRST-OlderVersion 2014-07-13 15:56 - 2014-07-13 15:56 - 00000820 _____ () C:\Users\Muhammed\Desktop\JRT.txt 2014-07-13 15:52 - 2014-07-13 15:52 - 01016261 _____ (Thisisu) C:\Users\Muhammed\Downloads\JRT.exe 2014-07-13 15:49 - 2014-07-13 15:49 - 00001067 _____ () C:\Users\Muhammed\Desktop\AdwCleaner[S0].txt 2014-07-13 15:45 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-07-13 15:43 - 2014-07-13 15:45 - 00000000 ____D () C:\AdwCleaner 2014-07-13 15:43 - 2014-07-13 15:43 - 01348263 _____ () C:\Users\Muhammed\Downloads\adwcleaner_3.215.exe 2014-07-13 15:42 - 2014-07-13 15:42 - 00001323 _____ () C:\Users\Muhammed\Desktop\mbam.txt 2014-07-13 15:28 - 2014-07-13 15:29 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-13 15:28 - 2014-07-13 15:28 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-07-13 15:28 - 2014-07-13 15:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-13 15:28 - 2014-07-13 15:28 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-07-13 15:28 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-07-13 15:28 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-07-13 15:28 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-07-13 15:27 - 2014-07-13 15:28 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Muhammed\Downloads\mbam-setup-2.0.2.1012.exe 2014-07-11 14:09 - 2014-07-11 14:09 - 00021381 _____ () C:\ComboFix.txt 2014-07-11 14:00 - 2014-07-11 14:09 - 00000000 ____D () C:\Qoobox 2014-07-11 14:00 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-07-11 14:00 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-07-11 14:00 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-07-11 14:00 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-07-11 14:00 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-07-11 14:00 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe 2014-07-11 14:00 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-07-11 14:00 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-07-11 14:00 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-07-11 13:58 - 2014-07-11 13:58 - 05218294 ____R (Swearware) C:\Users\Muhammed\Desktop\ComboFix.exe 2014-07-11 12:00 - 2014-07-11 12:01 - 00301064 _____ () C:\Windows\Minidump\071114-67031-01.dmp 2014-07-11 11:55 - 2014-07-11 12:00 - 543916582 _____ () C:\Windows\MEMORY.DMP 2014-07-11 11:55 - 2014-07-11 12:00 - 00000000 ____D () C:\Windows\Minidump 2014-07-11 11:55 - 2014-07-11 11:55 - 00301064 _____ () C:\Windows\Minidump\071114-70218-01.dmp 2014-07-11 11:52 - 2014-07-13 16:00 - 00050123 _____ () C:\Users\Muhammed\Desktop\FRST.txt 2014-07-11 11:52 - 2014-07-11 11:52 - 00380416 _____ () C:\Users\Muhammed\Downloads\d26u31wd.exe 2014-07-11 11:52 - 2014-07-11 11:52 - 00049401 _____ () C:\Users\Muhammed\Desktop\Addition.txt 2014-07-11 11:50 - 2014-07-11 11:51 - 00049401 _____ () C:\Users\Muhammed\Downloads\Addition.txt 2014-07-11 11:49 - 2014-07-15 20:04 - 00019018 _____ () C:\Users\Muhammed\Downloads\FRST.txt 2014-07-11 11:49 - 2014-07-15 20:04 - 00000000 ____D () C:\FRST 2014-07-11 11:48 - 2014-07-13 15:58 - 02086912 _____ (Farbar) C:\Users\Muhammed\Downloads\FRST64.exe 2014-07-11 11:47 - 2014-07-11 11:47 - 00050477 _____ () C:\Users\Muhammed\Downloads\Defogger.exe 2014-07-11 11:47 - 2014-07-11 11:47 - 00000478 _____ () C:\Users\Muhammed\Downloads\defogger_disable.log 2014-07-11 11:47 - 2014-07-11 11:47 - 00000000 _____ () C:\Users\Muhammed\defogger_reenable 2014-07-11 10:30 - 2014-07-11 10:30 - 00338240 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-07-10 01:43 - 2014-07-10 01:43 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-07-09 12:25 - 2014-07-01 00:42 - 00702464 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-07-09 12:25 - 2014-07-01 00:42 - 00394240 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2014-07-09 12:25 - 2014-07-01 00:42 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2014-07-09 12:25 - 2014-06-28 05:35 - 00556544 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-07-09 12:25 - 2014-06-19 04:12 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-07-09 12:25 - 2014-06-19 04:12 - 01366528 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-07-09 12:25 - 2014-06-19 04:12 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2014-07-09 12:25 - 2014-06-19 04:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll 2014-07-09 12:25 - 2014-06-19 04:12 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-07-09 12:25 - 2014-06-19 04:11 - 19277312 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-07-09 12:25 - 2014-06-19 04:11 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-07-09 12:25 - 2014-06-19 04:11 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 15369728 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 02650624 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-07-09 12:25 - 2014-06-19 04:10 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-07-09 12:25 - 2014-06-19 04:09 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-07-09 12:25 - 2014-06-19 02:53 - 14368768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-07-09 12:25 - 2014-06-19 02:53 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-07-09 12:25 - 2014-06-19 02:53 - 01141760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-07-09 12:25 - 2014-06-19 02:53 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-07-09 12:25 - 2014-06-19 02:53 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-07-09 12:25 - 2014-06-19 02:53 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-07-09 12:25 - 2014-06-19 02:53 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2014-07-09 12:25 - 2014-06-19 02:52 - 13732352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-07-09 12:25 - 2014-06-19 02:52 - 02863616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-07-09 12:25 - 2014-06-19 02:52 - 02051072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-07-09 12:25 - 2014-06-19 02:52 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-07-09 12:25 - 2014-06-19 02:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-07-09 12:25 - 2014-06-19 02:52 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-07-09 12:25 - 2014-06-19 02:52 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-07-09 12:25 - 2014-06-19 02:52 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-07-09 12:25 - 2014-06-19 02:52 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-07-09 12:25 - 2014-06-19 02:52 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-07-09 12:25 - 2014-06-19 02:52 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-07-09 12:25 - 2014-06-19 02:52 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-07-09 12:25 - 2014-06-19 02:33 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-07-09 12:25 - 2014-06-19 02:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-07-09 12:25 - 2014-06-19 00:05 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll 2014-07-09 12:25 - 2014-06-18 01:27 - 01440256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe 2014-07-09 12:25 - 2014-06-18 01:24 - 01557504 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe 2014-07-09 12:25 - 2014-06-11 06:18 - 04038144 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-07-09 12:25 - 2014-06-06 16:06 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-07-09 12:25 - 2014-06-06 12:17 - 00497152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-07-09 12:25 - 2014-06-03 00:33 - 00265216 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll 2014-07-09 12:25 - 2014-05-30 01:31 - 00452608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll 2014-07-09 12:25 - 2014-05-30 01:03 - 00588288 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll 2014-07-09 12:25 - 2014-05-30 01:02 - 01281536 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-07-09 12:25 - 2014-05-30 01:02 - 00439808 _____ (Microsoft Corporation) C:\Windows\system32\lsm.dll 2014-07-09 12:25 - 2014-05-30 00:24 - 00576512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2014-07-09 12:25 - 2014-05-03 08:34 - 06974808 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-07-09 12:25 - 2014-05-03 08:33 - 01824808 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2014-07-09 12:25 - 2014-05-03 06:51 - 01408976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2014-07-09 12:25 - 2014-05-02 00:37 - 01023488 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll 2014-07-09 12:25 - 2014-04-30 00:32 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\Robocopy.exe 2014-07-09 12:25 - 2014-04-30 00:32 - 00106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Robocopy.exe 2014-07-09 12:25 - 2014-02-08 06:34 - 00071168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hdaudbus.sys 2014-07-06 19:45 - 2014-05-03 07:47 - 03246592 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2014-07-06 19:45 - 2014-05-03 05:34 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2014-07-06 19:45 - 2014-04-03 13:19 - 00328024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys 2014-07-06 19:45 - 2014-04-03 05:44 - 00619008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2014-07-06 19:45 - 2014-04-01 00:08 - 00387268 _____ () C:\Windows\system32\ApnDatabase.xml 2014-07-06 19:45 - 2014-03-25 01:42 - 00305152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wusa.exe 2014-07-06 19:45 - 2014-03-25 00:56 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\wusa.exe 2014-07-06 19:44 - 2014-04-30 00:32 - 01301504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-07-06 19:44 - 2014-04-30 00:22 - 01023488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-07-06 19:40 - 2014-04-03 13:22 - 02233176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-07-06 19:40 - 2014-03-07 02:47 - 01419264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-07-06 19:40 - 2014-03-07 02:08 - 01845760 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-07-06 19:31 - 2014-05-20 04:33 - 00059416 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2014-07-06 19:31 - 2014-05-20 01:45 - 00629248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2014-07-06 19:31 - 2014-05-20 01:45 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2014-07-06 19:31 - 2014-05-20 01:24 - 03286528 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2014-07-06 19:31 - 2014-05-20 01:24 - 01623040 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2014-07-06 19:31 - 2014-05-20 01:24 - 00773632 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2014-07-06 19:31 - 2014-05-20 01:24 - 00253440 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll 2014-07-06 19:31 - 2014-05-20 01:24 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll 2014-07-06 19:31 - 2014-05-20 01:24 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2014-07-06 19:31 - 2014-05-15 00:43 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2014-07-06 19:31 - 2014-05-15 00:43 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2014-07-06 19:31 - 2014-05-15 00:42 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2014-07-06 19:31 - 2014-05-15 00:42 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2014-07-01 18:49 - 2014-07-01 18:52 - 00000000 ____D () C:\Users\Muhammed\Downloads\openvpn-2.3.3.I001-64Bit 2014-07-01 18:48 - 2014-07-01 18:51 - 02882999 _____ () C:\Users\Muhammed\Downloads\openvpn-2.3.3.I001-64Bit.zip 2014-06-28 15:24 - 2014-06-28 15:28 - 24901341 _____ () C:\Users\Muhammed\Downloads\Hibbeler.Mechanik3.Dynamik.rar 2014-06-22 20:39 - 2014-06-22 20:39 - 00000000 ____D () C:\Program Files (x86)\GUMEDA7.tmp 2014-06-19 00:34 - 2014-06-19 00:34 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2014-07-15 20:04 - 2014-07-11 11:49 - 00019018 _____ () C:\Users\Muhammed\Downloads\FRST.txt 2014-07-15 20:04 - 2014-07-11 11:49 - 00000000 ____D () C:\FRST 2014-07-15 20:03 - 2014-07-15 20:03 - 00000806 _____ () C:\Users\Muhammed\Desktop\checkup.txt 2014-07-15 20:02 - 2014-07-15 20:02 - 00854390 _____ () C:\Users\Muhammed\Desktop\SecurityCheck.exe 2014-07-15 19:44 - 2014-03-02 16:51 - 02086801 _____ () C:\Windows\WindowsUpdate.log 2014-07-15 19:44 - 2013-11-02 17:07 - 00001130 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-07-15 19:10 - 2013-12-17 18:31 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-07-15 19:10 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache 2014-07-15 19:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru 2014-07-15 18:05 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp 2014-07-15 17:54 - 2012-08-03 01:02 - 00753134 _____ () C:\Windows\system32\perfh007.dat 2014-07-15 17:54 - 2012-08-03 01:02 - 00155826 _____ () C:\Windows\system32\perfc007.dat 2014-07-15 17:54 - 2012-07-26 09:28 - 01745416 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-07-15 17:53 - 2014-07-15 17:53 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-07-15 17:52 - 2013-11-03 11:29 - 00000000 ____D () C:\Users\Muhammed\AppData\Roaming\Dropbox 2014-07-15 17:52 - 2013-11-02 17:02 - 00000062 _____ () C:\Users\Muhammed\AppData\Roaming\sp_data.sys 2014-07-15 17:51 - 2014-05-03 13:03 - 00000000 ____D () C:\Users\Muhammed\AppData\Roaming\DropboxMaster 2014-07-15 17:51 - 2013-11-03 11:31 - 00000000 ___RD () C:\Users\Muhammed\Dropbox 2014-07-15 17:50 - 2013-11-02 17:07 - 00001126 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-07-15 17:48 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-14 23:13 - 2012-07-26 10:12 - 00000000 ___RD () C:\Windows\ToastData 2014-07-14 23:13 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\WinStore 2014-07-14 22:50 - 2013-11-02 19:01 - 00000000 ____D () C:\Users\Muhammed\AppData\Roaming\TS3Client 2014-07-14 19:32 - 2014-07-14 19:32 - 02347384 _____ (ESET) C:\Users\Muhammed\Downloads\esetsmartinstaller_deu.exe 2014-07-13 17:06 - 2013-11-02 17:13 - 00000000 ____D () C:\Users\Muhammed\AppData\Local\PMB Files 2014-07-13 16:30 - 2013-11-02 17:07 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-529104025-161939068-2471084440-1002 2014-07-13 16:09 - 2014-06-03 19:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Siemens Automation 2014-07-13 16:09 - 2014-06-03 19:25 - 00000000 ____D () C:\Program Files\Common Files\Siemens 2014-07-13 16:08 - 2014-06-03 19:32 - 00000000 ____D () C:\Program Files (x86)\SIEMENS 2014-07-13 16:00 - 2014-07-11 11:52 - 00050123 _____ () C:\Users\Muhammed\Desktop\FRST.txt 2014-07-13 15:58 - 2014-07-13 15:58 - 00000000 ____D () C:\Users\Muhammed\Downloads\FRST-OlderVersion 2014-07-13 15:58 - 2014-07-11 11:48 - 02086912 _____ (Farbar) C:\Users\Muhammed\Downloads\FRST64.exe 2014-07-13 15:56 - 2014-07-13 15:56 - 00000820 _____ () C:\Users\Muhammed\Desktop\JRT.txt 2014-07-13 15:52 - 2014-07-13 15:52 - 01016261 _____ (Thisisu) C:\Users\Muhammed\Downloads\JRT.exe 2014-07-13 15:49 - 2014-07-13 15:49 - 00001067 _____ () C:\Users\Muhammed\Desktop\AdwCleaner[S0].txt 2014-07-13 15:46 - 2014-06-04 08:12 - 00001640 _____ () C:\Windows\PFRO.log 2014-07-13 15:45 - 2014-07-13 15:43 - 00000000 ____D () C:\AdwCleaner 2014-07-13 15:43 - 2014-07-13 15:43 - 01348263 _____ () C:\Users\Muhammed\Downloads\adwcleaner_3.215.exe 2014-07-13 15:42 - 2014-07-13 15:42 - 00001323 _____ () C:\Users\Muhammed\Desktop\mbam.txt 2014-07-13 15:29 - 2014-07-13 15:28 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-13 15:28 - 2014-07-13 15:28 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-07-13 15:28 - 2014-07-13 15:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-13 15:28 - 2014-07-13 15:28 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-07-13 15:28 - 2014-07-13 15:27 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Muhammed\Downloads\mbam-setup-2.0.2.1012.exe 2014-07-13 15:28 - 2013-12-14 22:29 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-11 14:09 - 2014-07-11 14:09 - 00021381 _____ () C:\ComboFix.txt 2014-07-11 14:09 - 2014-07-11 14:00 - 00000000 ____D () C:\Qoobox 2014-07-11 14:07 - 2012-07-26 07:26 - 00000215 _____ () C:\Windows\system.ini 2014-07-11 13:59 - 2013-12-13 11:38 - 00000000 ____D () C:\Windows\erdnt 2014-07-11 13:58 - 2014-07-11 13:58 - 05218294 ____R (Swearware) C:\Users\Muhammed\Desktop\ComboFix.exe 2014-07-11 12:31 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM 2014-07-11 12:01 - 2014-07-11 12:00 - 00301064 _____ () C:\Windows\Minidump\071114-67031-01.dmp 2014-07-11 12:00 - 2014-07-11 11:55 - 543916582 _____ () C:\Windows\MEMORY.DMP 2014-07-11 12:00 - 2014-07-11 11:55 - 00000000 ____D () C:\Windows\Minidump 2014-07-11 11:55 - 2014-07-11 11:55 - 00301064 _____ () C:\Windows\Minidump\071114-70218-01.dmp 2014-07-11 11:52 - 2014-07-11 11:52 - 00380416 _____ () C:\Users\Muhammed\Downloads\d26u31wd.exe 2014-07-11 11:52 - 2014-07-11 11:52 - 00049401 _____ () C:\Users\Muhammed\Desktop\Addition.txt 2014-07-11 11:51 - 2014-07-11 11:50 - 00049401 _____ () C:\Users\Muhammed\Downloads\Addition.txt 2014-07-11 11:47 - 2014-07-11 11:47 - 00050477 _____ () C:\Users\Muhammed\Downloads\Defogger.exe 2014-07-11 11:47 - 2014-07-11 11:47 - 00000478 _____ () C:\Users\Muhammed\Downloads\defogger_disable.log 2014-07-11 11:47 - 2014-07-11 11:47 - 00000000 _____ () C:\Users\Muhammed\defogger_reenable 2014-07-11 11:47 - 2013-11-02 16:59 - 00000000 ____D () C:\Users\Muhammed 2014-07-11 10:30 - 2014-07-11 10:30 - 00338240 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-07-10 16:46 - 2013-11-17 22:38 - 00000391 _____ () C:\Users\Muhammed\Desktop\Series.txt 2014-07-10 12:51 - 2013-11-02 19:35 - 00042040 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2014-07-10 01:44 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI 2014-07-10 01:43 - 2014-07-10 01:43 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-07-10 01:43 - 2012-07-26 11:45 - 00000000 ____D () C:\Program Files\Windows Journal 2014-07-10 01:43 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-10 01:43 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-09 12:51 - 2013-11-02 22:55 - 00000000 ____D () C:\Windows\system32\MRT 2014-07-09 12:50 - 2013-11-02 22:55 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-07-08 19:10 - 2013-12-17 18:31 - 00003772 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-07-06 19:48 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent 2014-07-03 23:49 - 2014-05-17 12:19 - 00000000 ____D () C:\Users\Muhammed\Documents\BabaAnne 2014-07-02 13:11 - 2013-11-02 17:13 - 00000000 ____D () C:\ProgramData\PMB Files 2014-07-01 18:52 - 2014-07-01 18:49 - 00000000 ____D () C:\Users\Muhammed\Downloads\openvpn-2.3.3.I001-64Bit 2014-07-01 18:51 - 2014-07-01 18:48 - 02882999 _____ () C:\Users\Muhammed\Downloads\openvpn-2.3.3.I001-64Bit.zip 2014-07-01 18:48 - 2014-06-02 08:39 - 00000000 ____D () C:\Users\Muhammed\AppData\Roaming\FileZilla 2014-07-01 16:58 - 2014-05-06 15:18 - 00000000 ____D () C:\Users\Muhammed\Documents\BEWERBUNGEN 2014-07-01 15:02 - 2013-11-02 19:35 - 00117712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-07-01 00:42 - 2014-07-09 12:25 - 00702464 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-07-01 00:42 - 2014-07-09 12:25 - 00394240 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2014-07-01 00:42 - 2014-07-09 12:25 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2014-06-28 15:28 - 2014-06-28 15:24 - 24901341 _____ () C:\Users\Muhammed\Downloads\Hibbeler.Mechanik3.Dynamik.rar 2014-06-28 05:35 - 2014-07-09 12:25 - 00556544 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-06-26 22:53 - 2013-11-05 10:32 - 00703968 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-06-26 22:53 - 2013-11-05 10:32 - 00105440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-06-24 21:43 - 2013-11-02 18:59 - 00000000 ____D () C:\Users\Muhammed\AppData\Local\TeamSpeak 3 Client 2014-06-24 09:36 - 2014-07-14 19:07 - 00703440 _____ (Microsoft Corporation) C:\Windows\system32\NotificationUI.exe 2014-06-24 09:35 - 2014-07-14 19:07 - 00010450 _____ () C:\Windows\system32\autoconfig.cab 2014-06-24 08:41 - 2014-07-14 19:07 - 10115584 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll 2014-06-24 08:41 - 2014-07-14 19:07 - 00694784 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll 2014-06-24 08:41 - 2014-07-14 19:07 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2014-06-24 08:40 - 2014-07-14 19:07 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2014-06-24 08:39 - 2014-07-14 19:07 - 02307072 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2014-06-24 08:39 - 2014-07-14 19:07 - 02146304 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll 2014-06-24 06:08 - 2014-07-14 19:07 - 08858624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll 2014-06-24 06:08 - 2014-07-14 19:07 - 00567808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll 2014-06-24 06:08 - 2014-07-14 19:07 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2014-06-24 06:06 - 2014-07-14 19:07 - 02037760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2014-06-24 06:06 - 2014-07-14 19:07 - 00754176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll 2014-06-22 20:39 - 2014-06-22 20:39 - 00000000 ____D () C:\Program Files (x86)\GUMEDA7.tmp 2014-06-22 20:39 - 2013-11-02 17:07 - 00004102 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-06-22 20:39 - 2013-11-02 17:07 - 00003866 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-06-22 19:58 - 2013-12-17 17:59 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-06-20 20:33 - 2014-03-17 18:56 - 00000000 ____D () C:\Users\Muhammed\Desktop\HTW-F3 2014-06-19 04:12 - 2014-07-09 12:25 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-06-19 04:12 - 2014-07-09 12:25 - 01366528 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-06-19 04:12 - 2014-07-09 12:25 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll 2014-06-19 04:12 - 2014-07-09 12:25 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll 2014-06-19 04:12 - 2014-07-09 12:25 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-06-19 04:11 - 2014-07-09 12:25 - 19277312 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-06-19 04:11 - 2014-07-09 12:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-06-19 04:11 - 2014-07-09 12:25 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 15369728 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 02650624 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-06-19 04:10 - 2014-07-09 12:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-06-19 04:09 - 2014-07-09 12:25 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-06-19 02:53 - 2014-07-09 12:25 - 14368768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-06-19 02:53 - 2014-07-09 12:25 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-06-19 02:53 - 2014-07-09 12:25 - 01141760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-06-19 02:53 - 2014-07-09 12:25 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-06-19 02:53 - 2014-07-09 12:25 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-06-19 02:53 - 2014-07-09 12:25 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-06-19 02:53 - 2014-07-09 12:25 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll 2014-06-19 02:52 - 2014-07-09 12:25 - 13732352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-06-19 02:52 - 2014-07-09 12:25 - 02863616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-06-19 02:52 - 2014-07-09 12:25 - 02051072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-06-19 02:52 - 2014-07-09 12:25 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-06-19 02:52 - 2014-07-09 12:25 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-06-19 02:52 - 2014-07-09 12:25 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-06-19 02:52 - 2014-07-09 12:25 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-06-19 02:52 - 2014-07-09 12:25 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-06-19 02:52 - 2014-07-09 12:25 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-06-19 02:52 - 2014-07-09 12:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-06-19 02:52 - 2014-07-09 12:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-06-19 02:52 - 2014-07-09 12:25 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-06-19 02:33 - 2014-07-09 12:25 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-06-19 02:30 - 2014-07-09 12:25 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-06-19 00:34 - 2014-06-19 00:34 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-19 00:05 - 2014-07-09 12:25 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll 2014-06-18 01:27 - 2014-07-09 12:25 - 01440256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe 2014-06-18 01:24 - 2014-07-09 12:25 - 01557504 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe 2014-06-16 16:53 - 2014-05-27 15:20 - 00013824 ___SH () C:\Users\Muhammed\Desktop\Thumbs.db 2014-06-15 13:35 - 2014-05-10 14:03 - 00000000 ____D () C:\Users\Muhammed\AppData\Local\Amazon Cloud Player 2014-06-15 13:34 - 2014-06-14 00:56 - 00001142 _____ () C:\Users\Muhammed\Desktop\Amazon Music.lnk Some content of TEMP: ==================== C:\Users\Muhammed\AppData\Local\temp\avgnt.exe C:\Users\Muhammed\AppData\Local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp3oitc8.dll C:\Users\Muhammed\AppData\Local\temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-07 14:46 ==================== End Of Log ============================ --- --- --- --- --- --- |
16.07.2014, 17:25 | #8 |
/// the machine /// TB-Ausbilder | Windows 8 - Sound funktioniert nicht richtig/Youtube(andere Musikmöglichkeiten) funktionieren auch nicht! Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
16.07.2014, 21:52 | #9 |
| Windows 8 - Sound funktioniert nicht richtig/Youtube(andere Musikmöglichkeiten) funktionieren auch nicht! Ich habe keine Probleme mehr und/oder Fragen bezüglich Malware oder sonstiges! !! |
17.07.2014, 15:46 | #10 |
/// the machine /// TB-Ausbilder | Windows 8 - Sound funktioniert nicht richtig/Youtube(andere Musikmöglichkeiten) funktionieren auch nicht! Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Windows 8 - Sound funktioniert nicht richtig/Youtube(andere Musikmöglichkeiten) funktionieren auch nicht! |
antivirus, browser, combofix, computer, converter, desktop, dvdvideosoft ltd., firefox, flash player, homepage, iexplore.exe, installation, mp3, pup.optional.softonic.a, rundll, scan, server, software, svchost.exe, win32/bundled.toolbar.ask.d, win32/downloadsponsor.a, windows |