|
Alles rund um Windows: Nach Omiga startet Telekom Browser nicht mehrWindows 7 Hilfe zu allen Windows-Betriebssystemen: Windows XP, Windows Vista, Windows 7, Windows 8(.1) und Windows 10 / Windows 11- als auch zu sämtlicher Windows-Software. Alles zu Windows 10 ist auch gerne willkommen. Bitte benenne etwaige Fehler oder Bluescreens unter Windows mit dem Wortlaut der Fehlermeldung und Fehlercode. Erste Schritte für Hilfe unter Windows. |
16.07.2014, 19:11 | #1 |
| Problem: Nach Omiga startet Telekom Browser nicht mehr Der Telekom Browser 7.0 ließ sich nicht mehr öffnen (aber im TM sichtbar !). Als ich den IE versuchte, kam der Omiga Virus zum Vorschein. Habe nun die Anweisungn auf Eurer Seite befolgt, alles aktualisiert, Browser deinstalliert, Neustart wieder installiert, es geht nichts. IE funktioniert wieder ohne Probleme. Reicht der Auschnitt vom Logfile ? O1 HOSTS File: ([2013.08.22 15:25:41 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:64bit: - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ochelper.dll (Microsoft Corporation) O2:64bit: - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine64\21.4.0.13\coIEPlg.dll (Symantec Corporation) O2:64bit: - BHO: (Microsoft SkyDrive Pro Browser Helper) - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\grooveex.dll (Microsoft Corporation) O2:64bit: - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard) O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\coIEPlg.dll (Symantec Corporation) O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\IPS\IPSBHO.DLL (Symantec Corporation) O2 - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard) O3:64bit: - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine64\21.4.0.13\coIEPlg.dll (Symantec Corporation) O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\coIEPlg.dll (Symantec Corporation) O4:64bit: - HKLM..\Run: [OPBHOBroker] C:\Programme\Hewlett-Packard\SimplePass\OPBHOBroker.exe (Hewlett-Packard) O4:64bit: - HKLM..\Run: [OPBHOBrokerDesktop] C:\Programme\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe (Hewlett-Packard) O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4:64bit: - HKLM..\Run: [SimplePass] C:\Program Files\Hewlett-Packard\SimplePass\HPSmplPass.exe (Hewlett-Packard) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [BingDesktop] C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe (Microsoft Corp.) O4 - HKLM..\Run: [Reader Application Helper] C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe (Sony Corporation) O4 - HKLM..\Run: [StartCCC] c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKU\S-1-5-21-3508085089-3033536294-3423735549-1001..\Run: [Amazon Cloud Player] C:\Users\Christina\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe () O4 - HKU\S-1-5-21-3508085089-3033536294-3423735549-1001..\Run: [EPLTarget\P0000000000000000] C:\windows\system32\spool\DRIVERS\x64\3\E_IATIJCE.EXE /EPT "EPLTarget\P0000000000000000" /M "XP-600 Series" File not found O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE (Microsoft Corporation) O8:64bit: - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll (Microsoft Corporation) O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE (Microsoft Corporation) O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll (Microsoft Corporation) O9:64bit: - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard) O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard) O9:64bit: - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\onbttnie.dll (Microsoft Corporation) O9:64bit: - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\onbttnie.dll (Microsoft Corporation) O9:64bit: - Extra Button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ochelper.dll (Microsoft Corporation) O9:64bit: - Extra 'Tools' menuitem : Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ochelper.dll (Microsoft Corporation) O9:64bit: - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\onbttnielinkednotes.dll (Microsoft Corporation) O9:64bit: - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\onbttnielinkednotes.dll (Microsoft Corporation) O9 - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard) O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard) O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office 15\root\office15\onbttnie.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Programme\Microsoft Office 15\root\office15\onbttnie.dll (Microsoft Corporation) O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office 15\root\office15\onbttnielinkednotes.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Programme\Microsoft Office 15\root\office15\onbttnielinkednotes.dll (Microsoft Corporation) O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O1364bit: - gopher Prefix: missing O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6A888A8A-77BE-4025-A2C7-5B00B9A6F0D9}: DhcpNameServer = 192.168.2.1 O18:64bit: - Protocol\Handler\osf - No CLSID value found O18:64bit: - Protocol\Handler\wlpg - No CLSID value found O18 - Protocol\Handler\osf {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Programme\Microsoft Office 15\root\office15\msosb.dll (Microsoft Corporation) O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\windows\SysWow64\userinit.exe (Microsoft Corporation) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{35ffaafd-c4bf-11e3-8254-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{35ffaafd-c4bf-11e3-8254-806e6f6e6963}\Shell\AutoRun\command - "" = "E:\SETUP.EXE" O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) |
16.07.2014, 19:36 | #2 |
/// TB-Ausbilder | Nach Omiga startet Telekom Browser nicht mehr Anleitung / HilfeMein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen. Bitte beachte folgende Hinweise:
Bitte arbeite alle Schritte in der vorgegebenen Reihefolge nacheinander ab und poste alle Logdateien in CODE-Tags: So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert deinem Helfer massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu groß für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Danke für deine Mitarbeit! Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
|
17.07.2014, 07:49 | #3 |
| Nach Omiga startet Telekom Browser nicht mehr Details [CODEAdditional scan result of Farbar Recovery Scan Tool (x64) Version: 15-07-2014 01
__________________Ran by Christina at 2014-07-17 08:31:09 Running from C:\Users\Christina\AppData\Local\Microsoft\Windows\INetCache\IE\TKJF2TT1 Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Norton 360 Online (Disabled - Up to date) {D87FA2C0-F526-77B1-D6EC-0EDF3936CEDB} AS: Norton 360 Online (Enabled - Up to date) {631E4324-D31C-783F-EC5C-35AD42B18466} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Norton 360 Online (Enabled) {E04423E5-BF49-76E9-FDB3-A7EAC7E589A0} ==================== Installed Programs ====================== 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Absolute Uninstaller 2.9.0.722 (HKLM-x32\...\Absolute Uninstaller_is1) (Version: - Glarysoft.com) Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated) Alcor Micro USB Card Reader Driver (HKLM-x32\...\AmUStor) (Version: 20.21.3317.03861 - Alcor Micro Corp.) Alcor Micro USB Card Reader Driver (x32 Version: 20.21.3317.03861 - Alcor Micro Corp.) Hidden Amazon Cloud Player (HKCU\...\Amazon Amazon Cloud Player) (Version: 2.4.0.33 - Amazon Services LLC) AMD Catalyst Control Center (x32 Version: 2013.0910.2222.38361 - Advanced Micro Devices, Inc.) Hidden AMD Catalyst Install Manager (HKLM\...\{B38CC495-7657-3D5A-80C2-8D6E0ED8E638}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.) Bing-Desktop (HKLM-x32\...\{7D095455-D971-4D4C-9EFD-9AF6A6584F3A}) (Version: 1.3.466.0 - Microsoft Corporation) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Browser 7 der Telekom (HKLM-x32\...\Browser 7 der Telekom 29.0.40 (x86 de)) (Version: 29.0.40 - Deutsche Telekom AG) Browser 7 Maintenance Service (HKLM-x32\...\Browser7MaintenanceService) (Version: 29.0.40 - Deutsche Telekom AG) Canon Utilities Digital Photo Professional (HKLM-x32\...\Digital Photo Professional) (Version: 3.13.10.0 - Canon Inc.) Canon Utilities EOS Sample Music (HKLM-x32\...\EOS Sample Music) (Version: 1.0.1.1 - Canon Inc.) Canon Utilities EOS Utility (HKLM-x32\...\EOS Utility) (Version: 2.13.10.0 - Canon Inc.) Canon Utilities ImageBrowser EX (HKLM-x32\...\ImageBrowser EX) (Version: 1.4.0.5 - Canon Inc.) Canon Utilities PhotoStitch (HKLM-x32\...\PhotoStitch) (Version: 3.1.23.47 - Canon Inc.) Canon Utilities Picture Style Editor (HKLM-x32\...\Picture Style Editor) (Version: 1.13.10.0 - Canon Inc.) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2013.0910.2222.38361 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2013.0910.2222.38361 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2013.0910.2222.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2013.0910.2222.38361 - Advanced Micro Devices, Inc.) Hidden Content Transfer (HKLM-x32\...\{CFADE4AF-C0CF-4A04-A776-741318F1658F}) (Version: 1.3.0.23190 - Sony Corporation) CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.5.6805 - CyberLink Corp.) CyberLink LabelPrint (x32 Version: 2.5.5.6805 - CyberLink Corp.) Hidden CyberLink Media Suite 10 (HKLM-x32\...\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.5.3103 - CyberLink Corp.) CyberLink Media Suite 10 (x32 Version: 10.0.5.3103 - CyberLink Corp.) Hidden CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.5.3215 - CyberLink Corp.) CyberLink Power2Go 8 (x32 Version: 8.0.5.3215 - CyberLink Corp.) Hidden CyberLink PowerDVD 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.2.3212 - CyberLink Corp.) CyberLink PowerDVD 12 (x32 Version: 12.0.2.3212 - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Energy Star (HKLM-x32\...\{FC0ADA4D-8FA5-4452-8AFF-F0A0BAC97EF7}) (Version: 1.0.9 - Hewlett-Packard Company) EPSON XP-600 Series Printer Uninstall (HKLM\...\EPSON XP-600 Series) (Version: - SEIKO EPSON Corporation) Fotogalerie (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden HP Connected Music (Meridian - installer) (HKLM-x32\...\StartHPConnectedMusic) (Version: 1.0 - Meridian Audio Ltd) HP Customer Experience Enhancements (x32 Version: 6.0.1.7 - Hewlett-Packard) Hidden HP Documentation (HKLM-x32\...\{06600E94-1C34-40E2-AB09-D30AECF78172}) (Version: 1.1.0.0 - Hewlett-Packard) HP Postscript Converter (Version: 4.5.12202 - Hewlett-Packard) Hidden HP Registration Service (HKLM\...\{D1E8F2D7-7794-4245-B286-87ED86C1893C}) (Version: 1.2.7045.4591 - Hewlett-Packard) HP SimplePass (HKLM-x32\...\InstallShield_{314FAD12-F785-4471-BCE8-AB506642B9A1}) (Version: 8.00.51 - Hewlett-Packard) HP SimplePass (Version: 8.00.51 - Hewlett-Packard) Hidden HP Support Assistant (HKLM-x32\...\{390AD982-A331-4D4F-AFD1-64005BC7C99D}) (Version: 7.3.35.12 - Hewlett-Packard Company) HP Support Information (HKLM-x32\...\{B2B7B1C8-7C8B-476C-BE2C-049731C55992}) (Version: 13.00.0000 - Hewlett-Packard) Inst5675 (Version: 8.00.51 - Softex Inc.) Hidden Inst5676 (Version: 8.00.51 - Softex Inc.) Hidden Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office 365 - de-de (HKLM\...\O365HomePremRetail - de-de) (Version: 15.0.4631.1002 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SkyDrive (HKCU\...\SkyDriveSetup.exe) (Version: 16.4.6013.0910 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 (HKLM-x32\...\{6e8f74e0-43bd-4dce-8477-6ff6828acc07}) (Version: 11.0.51106.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (HKLM-x32\...\{8e70e4e1-06d7-470b-9f74-a51bef21088e}) (Version: 11.0.51106.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.51106 (Version: 11.0.51106 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.51106 (Version: 11.0.51106 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 (x32 Version: 11.0.51106 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 (x32 Version: 11.0.51106 - Microsoft Corporation) Hidden Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden Norton 360 (HKLM-x32\...\N360) (Version: 21.4.0.13 - Symantec Corporation) Office 15 Click-to-Run Licensing Component (Version: 15.0.4631.1002 - Microsoft Corporation) Hidden OpenOffice 4.1.0 (HKLM-x32\...\{E19483E2-6C18-494D-A307-D4498BCFD2C7}) (Version: 4.10.9764 - Apache Software Foundation) Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Photo Gallery (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Reader for PC (HKLM-x32\...\{71FB3127-E6B2-4058-ACEE-99813554FAB6}) (Version: 2.2.00.11270 - Sony Corporation) Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.30164 - Realtek Semiconductor Corp.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7135 - Realtek Semiconductor Corp.) Recovery Manager (x32 Version: 5.5.0.7001 - CyberLink Corp.) Hidden Windows Live Communications Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation) Windows Live Essentials (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden ==================== Restore Points ========================= 29-06-2014 07:25:16 Windows Update 02-07-2014 08:41:41 Windows Update 09-07-2014 05:24:36 Windows Update 16-07-2014 10:44:48 Norton 360 Registry Clean ==================== Hosts content: ========================== 2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____N C:\windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask Task: {084FB597-4DEE-4D9B-87F2-A694BC650D95} - System32\Tasks\CLVDLauncher => c:\Program Files (x86)\CyberLink\Power2Go8\CLVDLauncher.exe [2013-03-12] (CyberLink Corp.) Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList Task: {122A80BA-CC77-4E16-B7EF-253C86B8F029} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate Task: {2CCFB192-D944-4BD0-A76B-27817D9041A0} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-08] (Adobe Systems Incorporated) Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation) Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation) Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance Task: {64B5557F-DDA4-4C55-865D-432F16319B88} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\windows\system32\MRT.exe [2014-07-09] (Microsoft Corporation) Task: {654019A3-5547-45A9-B5C5-A4AD5731A436} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\WSCStub.exe [2014-06-27] (Symantec Corporation) Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task Task: {8C3F336C-E9A2-4CD6-A2A2-D20FCBF0A889} - System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup => C:\Windows\system32\cleanmgr.exe [2014-02-22] (Microsoft Corporation) Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask Task: {9D96B0A8-A606-4AE4-AADE-553BEDF1C423} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\SymErr.exe [2014-01-30] (Symantec Corporation) Task: {9E38C571-697B-4487-AE06-71CD50A305D0} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2012-11-29] (Hewlett-Packard Company) Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work Task: {A3210FCD-5162-45A3-9439-20672D90AE27} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Validation Task: {AAF95213-F4C9-4ADE-BF54-7A7A46A7C60F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2013-08-10] (Hewlett-Packard) Task: {C046D88A-C291-4F0D-81B2-DBA7C9C0A44F} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Management Task: {C3C7A1AA-FFD0-41F8-B42E-E1ADD3DB5063} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2013-08-10] (Hewlett-Packard) Task: {C7DCD301-3FE2-43DE-8AD0-9F875C802AC0} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-08-27] (Hewlett-Packard Company) Task: {CCF33DC8-C907-4573-83E3-A6F01015EB18} - System32\Tasks\CLMLSvc_P2G8 => c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2013-08-05] (CyberLink) Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing Task: {D8DAF26F-28D7-44F8-91BC-35FEF55A9B8D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-08-27] (Hewlett-Packard Company) Task: {D945C0F9-4076-4246-BA3D-791CAEBBF359} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network => Sc.exe start wuauserv Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization Task: {DDC99CD5-465B-4FD7-9A92-97E3528F4019} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics Task: {E56515ED-8129-4A90-994A-603694336AAD} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2014-06-10] (Microsoft Corporation) Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE Task: {F1130D9E-79EE-4CB4-BD6B-9A3EB903C278} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2014-06-19] (Microsoft Corporation) Task: {FF09418F-CBE7-4F76-8EDF-4C9C4029863D} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\SymErr.exe [2014-01-30] (Symantec Corporation) Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2013-09-05 13:22 - 2013-09-05 13:22 - 00109568 _____ () C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe 2013-09-05 13:24 - 2013-09-05 13:24 - 00627200 _____ () C:\Program Files\Hewlett-Packard\SimplePass\cachedrv.dll 2013-09-05 13:24 - 2013-09-05 13:24 - 02540544 _____ () C:\Program Files\Hewlett-Packard\SimplePass\autheng.dll 2013-09-05 13:21 - 2013-09-05 13:21 - 00035328 _____ () C:\Program Files\Hewlett-Packard\SimplePass\ssplogon.dll 2013-09-05 13:21 - 2013-09-05 13:21 - 00055296 _____ () C:\Program Files\Hewlett-Packard\SimplePass\RandomPass.dll 2013-09-05 13:21 - 2013-09-05 13:21 - 00021504 _____ () C:\Program Files\Hewlett-Packard\SimplePass\cryptodll.dll 2013-09-05 13:36 - 2013-09-05 13:36 - 00306064 _____ () C:\Program Files\Hewlett-Packard\SimplePass\mstrpwd.dll 2013-09-05 13:36 - 2013-09-05 13:36 - 01298832 _____ () C:\Program Files\Hewlett-Packard\SimplePass\GraphicalPwd.dll 2014-04-16 13:58 - 2014-05-20 09:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll 2013-09-05 13:31 - 2013-09-05 13:31 - 00064000 _____ () C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe 2014-05-30 17:58 - 2014-05-08 19:26 - 03145536 _____ () C:\Users\Christina\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe 2012-08-30 13:46 - 2013-10-03 10:42 - 00069120 _____ () C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe 2013-06-06 01:51 - 2013-06-06 01:51 - 00098304 _____ () c:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\BrandingNet4.dll 2014-07-16 18:51 - 2014-06-10 14:46 - 03654456 _____ () C:\Program Files (x86)\Deutsche Telekom AG\Browser 7\mozjs.dll 2012-08-30 13:39 - 2013-10-03 10:42 - 00112128 _____ () C:\Program Files (x86)\Canon\ImageBrowser EX\MFMFileSystemWatcher.dll 2013-11-27 20:48 - 2013-11-27 20:48 - 00880640 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\fsk.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00040264 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskMediaPlayers.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00239944 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\Fskin.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00026952 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskinLocalize.dll 2013-11-26 11:34 - 2013-11-26 11:34 - 00798720 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskSecurity.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00125256 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskDocumentViewer.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00016200 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskPower.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00024904 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskNetInterface.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00017224 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskMobileMediaDevice.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00015176 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskTimeHardware.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00034632 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ticket.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00018760 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ebookDeviceNotifier.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00092488 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ebookUsb.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00149832 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\readerAppHelper.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00178504 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\USBDetector.dll 2014-02-11 07:35 - 2013-08-05 09:49 - 00627672 _____ () c:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll 2013-08-06 01:48 - 2013-08-06 01:48 - 00016856 _____ () c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\Christina\Desktop\Cashback.jpeg:3or4kl4x13tuuug3Byamue2s4b AlternateDataStreams: C:\Users\Christina\Desktop\Cashback.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" ==================== EXE Association (whitelisted) ============= ==================== MSCONFIG/TASK MANAGER disabled items ========= ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (07/16/2014 07:48:18 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: ) Description: Subscription licensing service failed: -1073415161 Error: (07/16/2014 07:46:22 PM) (Source: Windows Search Service) (EventID: 10021) (User: ) Description: Die Registrierungsinformationen der Leistungsindikatoren für WSearchIdxPi für die Instanz konnten wegen des folgenden Fehlers nicht abgerufen werden: Der Vorgang wurde erfolgreich beendet. 0x0. Error: (07/16/2014 07:46:22 PM) (Source: Windows Search Service) (EventID: 3007) (User: ) Description: Die Leistungsüberwachung für den Gatherer-Dienst kann nicht initialisiert werden, da die Datenquellen nicht geladen sind oder das freigegebene Speicherobjekt nicht geöffnet werden konnte. Dies beeinträchtigt lediglich die Verfügbarkeit der Leistungsindikatoren. Starten Sie den Computer erneut. Kontext: Anwendung, SystemIndex Katalog Error: (07/16/2014 07:46:22 PM) (Source: Windows Search Service) (EventID: 3006) (User: ) Description: Die Leistungsüberwachung kann für den Gatherer-Dienst nicht initialisiert werden, da die Datenquellen nicht geladen sind oder das freigegebene Speicherobjekt nicht geöffnet werden konnte. Dies beeinträchtigt lediglich die Verfügbarkeit der Leistungsindikatoren. Starten Sie den Computer erneut. Error: (07/16/2014 06:42:24 PM) (Source: Windows Search Service) (EventID: 10021) (User: ) Description: Die Registrierungsinformationen der Leistungsindikatoren für WSearchIdxPi für die Instanz konnten wegen des folgenden Fehlers nicht abgerufen werden: Der Vorgang wurde erfolgreich beendet. 0x0. Error: (07/16/2014 06:42:23 PM) (Source: Windows Search Service) (EventID: 3007) (User: ) Description: Die Leistungsüberwachung für den Gatherer-Dienst kann nicht initialisiert werden, da die Datenquellen nicht geladen sind oder das freigegebene Speicherobjekt nicht geöffnet werden konnte. Dies beeinträchtigt lediglich die Verfügbarkeit der Leistungsindikatoren. Starten Sie den Computer erneut. Kontext: Anwendung, SystemIndex Katalog Error: (07/16/2014 06:42:21 PM) (Source: Windows Search Service) (EventID: 3006) (User: ) Description: Die Leistungsüberwachung kann für den Gatherer-Dienst nicht initialisiert werden, da die Datenquellen nicht geladen sind oder das freigegebene Speicherobjekt nicht geöffnet werden konnte. Dies beeinträchtigt lediglich die Verfügbarkeit der Leistungsindikatoren. Starten Sie den Computer erneut. Error: (07/16/2014 06:19:42 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest. Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest. Error: (07/16/2014 05:29:15 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest. Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest. System errors: ============= Error: (07/16/2014 09:49:32 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "CyberLink PowerDVD 12 Media Server Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (07/16/2014 07:45:49 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "McAfee Boot Delay Start Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (07/16/2014 06:40:16 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "McAfee Boot Delay Start Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (07/16/2014 06:39:22 PM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: Der Dienst "NPEService" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (07/16/2014 06:27:37 PM) (Source: DCOM) (EventID: 10010) (User: gebbisfirst) Description: {9AA46009-3CE0-458A-A354-715610A075E6} Error: (07/16/2014 06:27:07 PM) (Source: DCOM) (EventID: 10010) (User: gebbisfirst) Description: {9AA46009-3CE0-458A-A354-715610A075E6} Error: (07/16/2014 06:26:37 PM) (Source: DCOM) (EventID: 10010) (User: gebbisfirst) Description: {9AA46009-3CE0-458A-A354-715610A075E6} Error: (07/16/2014 06:26:07 PM) (Source: DCOM) (EventID: 10010) (User: gebbisfirst) Description: {9AA46009-3CE0-458A-A354-715610A075E6} Error: (07/16/2014 06:25:37 PM) (Source: DCOM) (EventID: 10010) (User: gebbisfirst) Description: {9AA46009-3CE0-458A-A354-715610A075E6} Error: (07/16/2014 06:25:06 PM) (Source: DCOM) (EventID: 10010) (User: gebbisfirst) Description: {9AA46009-3CE0-458A-A354-715610A075E6} Microsoft Office Sessions: ========================= Error: (07/16/2014 07:48:18 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: ) Description: Subscription licensing service failed: -1073415161 Error: (07/16/2014 07:46:22 PM) (Source: Windows Search Service) (EventID: 10021) (User: ) Description: WSearchIdxPiDer Vorgang wurde erfolgreich beendet. 0x0 Error: (07/16/2014 07:46:22 PM) (Source: Windows Search Service) (EventID: 3007) (User: ) Description: Kontext: Anwendung, SystemIndex Katalog Error: (07/16/2014 07:46:22 PM) (Source: Windows Search Service) (EventID: 3006) (User: ) Description: Error: (07/16/2014 06:42:24 PM) (Source: Windows Search Service) (EventID: 10021) (User: ) Description: WSearchIdxPiDer Vorgang wurde erfolgreich beendet. 0x0 Error: (07/16/2014 06:42:23 PM) (Source: Windows Search Service) (EventID: 3007) (User: ) Description: Kontext: Anwendung, SystemIndex Katalog Error: (07/16/2014 06:42:21 PM) (Source: Windows Search Service) (EventID: 3006) (User: ) Description: Error: (07/16/2014 06:19:42 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Users\Christina\Downloads\esetsmartinstaller_enu.exe Error: (07/16/2014 05:29:15 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Users\Christina\Downloads\esetsmartinstaller_enu.exe ==================== Memory info =========================== Percentage of memory in use: 68% Total physical RAM: 3531.63 MB Available physical RAM: 1110.09 MB Total Pagefile: 4235.63 MB Available Pagefile: 1770.5 MB Total Virtual: 131072 MB Available Virtual: 131071.8 MB ==================== Drives ================================ Drive c: (Windows) (Fixed) (Total:920.54 GB) (Free:801.57 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (Recovery Image) (Fixed) (Total:9.5 GB) (Free:1.11 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 932 GB) (Disk ID: 11D6C89C) Partition: GPT Partition Type. ==================== End Of Log ============================][/CODE] [CODE][/CO FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-07-2014 01 Ran by Christina (administrator) on GEBBISFIRST on 17-07-2014 08:29:28 Running from C:\Users\Christina\AppData\Local\Microsoft\Windows\INetCache\IE\TKJF2TT1 Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= () C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe (Softex Inc.) C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe (AMD) C:\Windows\System32\atiesrxx.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\n360.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (AMD) C:\Windows\System32\atieclxx.exe (Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe () C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\n360.exe (Deutsche Telekom AG) C:\Program Files (x86)\Deutsche Telekom AG\Browser 7\Browser7.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\HPSmplPass.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATIJCE.EXE () C:\Users\Christina\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe () C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Sony Corporation) C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BDExtHost.exe (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BDAppHost.exe (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BDRuntimeHost.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SimplePass] => C:\Program Files\Hewlett-Packard\SimplePass\HPSmplPass.exe [2793016 2013-09-05] (Hewlett-Packard) HKLM\...\Run: [OPBHOBroker] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe [154680 2013-09-05] (Hewlett-Packard) HKLM\...\Run: [OPBHOBrokerDesktop] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe [154680 2013-09-05] (Hewlett-Packard) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13663448 2014-01-13] (Realtek Semiconductor) HKLM-x32\...\Run: [StartCCC] => c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-09-11] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Reader Application Helper] => C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe [899400 2013-11-27] (Sony Corporation) HKLM-x32\...\Run: [BingDesktop] => C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe [2368728 2014-05-23] (Microsoft Corp.) HKU\S-1-5-21-3508085089-3033536294-3423735549-1001\...\Run: [EPLTarget\P0000000000000000] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATIJCE.EXE [283232 2012-10-01] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-3508085089-3033536294-3423735549-1001\...\Run: [Amazon Cloud Player] => C:\Users\Christina\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe [3145536 2014-05-08] () HKU\S-1-5-21-3508085089-3033536294-3423735549-1001\...\MountPoints2: {35ffaafd-c4bf-11e3-8254-806e6f6e6963} - "E:\SETUP.EXE" HKU\S-1-5-21-3508085089-3033536294-3423735549-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [EPLTarget\P0000000000000000] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATIJCE.EXE [283232 2012-10-01] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-3508085089-3033536294-3423735549-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Amazon Cloud Player] => C:\Users\Christina\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe [3145536 2014-05-08] () HKU\S-1-5-21-3508085089-3033536294-3423735549-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {35ffaafd-c4bf-11e3-8254-806e6f6e6963} - "E:\SETUP.EXE" Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ImageBrowser EX Agent.lnk ShortcutTarget: ImageBrowser EX Agent.lnk -> C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe () ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ShellIconOverlayIdentifiers: SkyDrivePro1 (ErrorConflict) -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: SkyDrivePro2 (SyncInProgress) -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: SkyDrivePro3 (InSync) -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: OverlayExcluded -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton 360\Engine64\21.4.0.13\buShell.dll (Symantec Corporation) ShellIconOverlayIdentifiers: OverlayPending -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton 360\Engine64\21.4.0.13\buShell.dll (Symantec Corporation) ShellIconOverlayIdentifiers: OverlayProtected -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton 360\Engine64\21.4.0.13\buShell.dll (Symantec Corporation) ShellIconOverlayIdentifiers-x32: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers-x32: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers-x32: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.t-online.de/ HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://isearch.glarysoft.com/?src=iehome HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://isearch.glarysoft.com/?src=iehome SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPDTDFJS SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPDTDFJS SearchScopes: HKLM - {A7ECAA6F-6CCA-49A8-B2A9-42C16E330BAF} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {c1d89ae7-449d-4929-b24b-fded04adbe06} URL = hxxp://isearch.glarysoft.com/?q={searchTerms}&src=iesearch SearchScopes: HKLM-x32 - {c1d89ae7-449d-4929-b24b-fded04adbe06} URL = hxxp://isearch.glarysoft.com/?q={searchTerms}&src=iesearch SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPDTDFJS SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPDTDFJS SearchScopes: HKCU - {c1d89ae7-449d-4929-b24b-fded04adbe06} URL = hxxp://isearch.glarysoft.com/?q={searchTerms}&src=iesearch SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine64\21.4.0.13\coIEPlg.dll (Symantec Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard) BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\coIEPlg.dll (Symantec Corporation) BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\IPS\IPSBHO.DLL (Symantec Corporation) BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard) Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine64\21.4.0.13\coIEPlg.dll (Symantec Corporation) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\coIEPlg.dll (Symantec Corporation) Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @sony.com/ReaderDesktop - C:\Program Files (x86)\Sony\ReaderDesktop\npreaderdetectmoz.dll (Sony Corporation) FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.0.1.3\coFFPlgn FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.0.1.3\coFFPlgn [2014-07-16] FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.0.1.3\IPSFF FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.0.1.3\IPSFF [2014-04-16] ==================== Services (Whitelisted) ================= R2 BingDesktopUpdate; C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [173784 2014-05-23] (Microsoft Corp.) S3 Browser7Maintenance; C:\Program Files (x86)\Browser 7 Maintenance Service\maintenanceservice.exe [117560 2014-06-10] (Deutsche Telekom AG) R2 Cachedrv server; C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe [109568 2013-09-05] () [File not signed] R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2356408 2014-06-19] (Microsoft Corporation) R2 CyberLink PowerDVD 12 Media Server Monitor Service; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [77576 2013-08-12] (CyberLink) R2 CyberLink PowerDVD 12 Media Server Service; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [298760 2013-08-12] (CyberLink) R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-08-27] (Hewlett-Packard Company) [File not signed] R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R2 N360; C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\N360.exe [265040 2014-06-27] (Symantec Corporation) R2 omniserv; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [87552 2013-09-05] (Softex Inc.) [File not signed] R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [290520 2014-01-13] (Realtek Semiconductor) S3 Sony SCSI Helper Service; C:\Program Files (x86)\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe [73728 2013-11-26] (Sony Corporation) [File not signed] S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2013-08-24] (Microsoft Corporation) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation) S2 0201921397581903mcinstcleanup; C:\windows\TEMP\020192~1.EXE -cleanup -nolog [X] S2 mcbootdelaystartsvc; "C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe" /McCoreSvc [X] ==================== Drivers (Whitelisted) ==================== R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36096 2013-05-22] (Advanced Micro Devices, Inc.) R1 BHDrvx64; C:\Program Files (x86)\Norton 360\NortonData\21.0.1.3\Definitions\BASHDefs\20140703.001\BHDrvx64.sys [1530160 2014-05-10] (Symantec Corporation) R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1504000.00D\ccSetx64.sys [162392 2014-02-25] (Symantec Corporation) R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-05] (CyberLink) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [486192 2014-06-21] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [142128 2014-06-21] (Symantec Corporation) R1 IDSVia64; C:\Program Files (x86)\Norton 360\NortonData\21.0.1.3\Definitions\IPSDefs\20140715.001\IDSvia64.sys [525016 2014-06-20] (Symantec Corporation) R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-07-17] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation) R3 NAVENG; C:\Program Files (x86)\Norton 360\NortonData\21.0.1.3\Definitions\VirusDefs\20140716.003\ENG64.SYS [126040 2014-06-21] (Symantec Corporation) R3 NAVEX15; C:\Program Files (x86)\Norton 360\NortonData\21.0.1.3\Definitions\VirusDefs\20140716.003\EX64.SYS [2099288 2014-06-21] (Symantec Corporation) R3 SRTSP; C:\Windows\System32\Drivers\N360x64\1504000.00D\SRTSP64.SYS [875736 2014-02-13] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1504000.00D\SRTSPX64.SYS [36952 2013-07-31] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\N360x64\1504000.00D\SYMDS64.SYS [493656 2013-08-01] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\N360x64\1504000.00D\SYMEFA64.SYS [1148120 2014-03-04] (Symantec Corporation) S0 SymELAM; C:\Windows\System32\drivers\N360x64\1504000.00D\SymELAM.sys [23568 2013-08-01] (Symantec Corporation) R3 SymEvent; C:\windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2014-04-15] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\N360x64\1504000.00D\Ironx64.SYS [264280 2013-07-31] (Symantec Corporation) R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1504000.00D\SYMNETS.SYS [593112 2014-02-18] (Symantec Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation) U3 McMPFSvc; U3 McNaiAnn; U3 mcpltsvc; U3 McProxy; U3 mfecore; U3 MSK80Service; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-17 08:29 - 2014-07-17 08:29 - 00000000 ____D () C:\FRST 2014-07-17 08:27 - 2014-07-17 08:27 - 01077248 _____ (Farbar) C:\Users\Christina\Downloads\FRST (2).exe 2014-07-17 08:25 - 2014-07-17 08:25 - 01077248 _____ (Farbar) C:\Users\Christina\Downloads\FRST.exe 2014-07-17 08:25 - 2014-07-17 08:25 - 01077248 _____ (Farbar) C:\Users\Christina\Downloads\FRST (1).exe 2014-07-16 20:00 - 2014-07-16 20:00 - 00602112 _____ (OldTimer Tools) C:\Users\Christina\Downloads\OTL.exe 2014-07-16 19:12 - 2014-07-16 19:12 - 00000000 ____D () C:\Program Files\AMD 2014-07-16 19:10 - 2014-06-05 16:13 - 00216368 _____ (Microsoft Corporation) C:\windows\system32\rsaenh.dll 2014-07-16 19:10 - 2014-06-05 15:14 - 00189016 _____ (Microsoft Corporation) C:\windows\SysWOW64\rsaenh.dll 2014-07-16 19:10 - 2014-06-02 04:10 - 00423768 _____ (Microsoft Corporation) C:\windows\system32\hal.dll 2014-07-16 19:10 - 2014-05-31 12:07 - 00467800 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBHUB3.SYS 2014-07-16 19:10 - 2014-05-31 12:07 - 00440664 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbport.sys 2014-07-16 19:10 - 2014-05-31 12:07 - 00419672 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbhub.sys 2014-07-16 19:10 - 2014-05-31 12:07 - 00089944 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbehci.sys 2014-07-16 19:10 - 2014-05-31 12:07 - 00027480 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbd.sys 2014-07-16 19:10 - 2014-05-31 08:30 - 00037376 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbuhci.sys 2014-07-16 19:10 - 2014-05-31 08:27 - 00206848 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys 2014-07-16 19:10 - 2014-05-31 08:27 - 00110592 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WUDFPf.sys 2014-07-16 19:10 - 2014-05-31 08:26 - 00227840 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WUDFRd.sys 2014-07-16 19:10 - 2014-05-31 06:01 - 00284672 _____ (Microsoft Corporation) C:\windows\system32\WUDFHost.exe 2014-07-16 19:10 - 2014-05-31 06:01 - 00209408 _____ (Microsoft Corporation) C:\windows\system32\WUDFPlatform.dll 2014-07-16 19:10 - 2014-05-31 06:01 - 00099840 _____ (Microsoft Corporation) C:\windows\system32\WUDFSvc.dll 2014-07-16 19:10 - 2014-05-27 17:53 - 02518360 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys 2014-07-16 19:10 - 2014-05-27 11:56 - 00323584 _____ (Microsoft Corporation) C:\windows\system32\DaOtpCredentialProvider.dll 2014-07-16 19:10 - 2014-05-27 11:53 - 00270848 _____ (Microsoft Corporation) C:\windows\SysWOW64\DaOtpCredentialProvider.dll 2014-07-16 19:10 - 2014-05-17 06:59 - 16871936 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Xaml.dll 2014-07-16 19:10 - 2014-05-17 06:13 - 12711424 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Xaml.dll 2014-07-16 19:10 - 2014-05-15 00:47 - 04720640 _____ (Microsoft Corporation) C:\windows\system32\SyncEngine.dll 2014-07-16 19:10 - 2014-05-13 09:01 - 00076800 _____ (Microsoft Corporation) C:\windows\system32\BulkOperationHost.exe 2014-07-16 19:10 - 2014-05-13 07:07 - 02844160 _____ (Microsoft Corporation) C:\windows\system32\actxprxy.dll 2014-07-16 19:10 - 2014-05-13 06:41 - 00118272 _____ (Microsoft Corporation) C:\windows\system32\winbici.dll 2014-07-16 19:10 - 2014-05-13 06:27 - 00716800 _____ (Microsoft Corporation) C:\windows\system32\SkyDriveTelemetry.dll 2014-07-16 19:10 - 2014-05-13 06:26 - 00285696 _____ (Microsoft Corporation) C:\windows\system32\SkyDriveShell.dll 2014-07-16 19:10 - 2014-05-13 05:59 - 01035264 _____ (Microsoft Corporation) C:\windows\SysWOW64\actxprxy.dll 2014-07-16 19:10 - 2014-05-13 05:41 - 01118720 _____ (Microsoft Corporation) C:\windows\system32\SkyDrive.exe 2014-07-16 19:10 - 2014-05-13 05:31 - 00265216 _____ (Microsoft Corporation) C:\windows\SysWOW64\SkyDriveShell.dll 2014-07-16 19:10 - 2014-05-03 13:29 - 01726224 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll 2014-07-16 19:10 - 2014-05-03 11:20 - 01473080 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll 2014-07-16 19:10 - 2014-05-03 07:36 - 00997888 _____ (Microsoft Corporation) C:\windows\system32\reseteng.dll 2014-07-16 19:10 - 2014-05-03 07:19 - 00071168 _____ (Microsoft Corporation) C:\windows\system32\ncobjapi.dll 2014-07-16 19:10 - 2014-05-03 07:08 - 00301056 _____ (Microsoft Corporation) C:\windows\system32\framedynos.dll 2014-07-16 19:10 - 2014-05-03 07:07 - 00262656 _____ (Microsoft Corporation) C:\windows\system32\framedyn.dll 2014-07-16 19:10 - 2014-05-03 06:46 - 00052736 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncobjapi.dll 2014-07-16 19:10 - 2014-05-03 06:37 - 00235008 _____ (Microsoft Corporation) C:\windows\SysWOW64\framedynos.dll 2014-07-16 19:10 - 2014-05-03 06:37 - 00207360 _____ (Microsoft Corporation) C:\windows\SysWOW64\framedyn.dll 2014-07-16 19:10 - 2014-05-03 05:30 - 02641920 _____ (Microsoft Corporation) C:\windows\system32\authui.dll 2014-07-16 19:10 - 2014-05-03 05:27 - 02317824 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll 2014-07-16 19:10 - 2014-05-03 01:26 - 00050745 _____ () C:\windows\system32\srms.dat 2014-07-16 19:10 - 2014-05-01 07:44 - 01025536 _____ (Microsoft Corporation) C:\windows\system32\localspl.dll 2014-07-16 19:10 - 2014-04-30 08:43 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\vwififlt.sys 2014-07-16 19:10 - 2014-04-30 08:41 - 00402432 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys 2014-07-16 19:10 - 2014-04-30 08:41 - 00096768 _____ (Microsoft Corporation) C:\windows\system32\Drivers\agilevpn.sys 2014-07-16 19:10 - 2014-04-30 08:41 - 00038912 _____ (Microsoft Corporation) C:\windows\system32\Drivers\vwifimp.sys 2014-07-16 19:10 - 2014-04-30 07:45 - 00123392 _____ (Microsoft Corporation) C:\windows\system32\Robocopy.exe 2014-07-16 19:10 - 2014-04-30 06:48 - 00106496 _____ (Microsoft Corporation) C:\windows\SysWOW64\Robocopy.exe 2014-07-16 19:10 - 2014-04-30 06:24 - 00065024 _____ (Microsoft Corporation) C:\windows\system32\dhcpcsvc6.dll 2014-07-16 19:10 - 2014-04-30 06:23 - 00353280 _____ (Microsoft Corporation) C:\windows\system32\dhcpcore.dll 2014-07-16 19:10 - 2014-04-30 06:23 - 00271872 _____ (Microsoft Corporation) C:\windows\system32\dhcpcore6.dll 2014-07-16 19:10 - 2014-04-30 06:23 - 00087552 _____ (Microsoft Corporation) C:\windows\system32\dhcpcsvc.dll 2014-07-16 19:10 - 2014-04-30 06:14 - 00827392 _____ (Microsoft Corporation) C:\windows\system32\BFE.DLL 2014-07-16 19:10 - 2014-04-30 05:59 - 01063424 _____ (Microsoft Corporation) C:\windows\system32\IKEEXT.DLL 2014-07-16 19:10 - 2014-04-30 05:46 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dhcpcore.dll 2014-07-16 19:10 - 2014-04-30 05:46 - 00229888 _____ (Microsoft Corporation) C:\windows\SysWOW64\dhcpcore6.dll 2014-07-16 19:10 - 2014-04-30 05:46 - 00056320 _____ (Microsoft Corporation) C:\windows\SysWOW64\dhcpcsvc6.dll 2014-07-16 19:10 - 2014-04-30 05:45 - 00062976 _____ (Microsoft Corporation) C:\windows\SysWOW64\dhcpcsvc.dll 2014-07-16 19:10 - 2014-04-30 05:42 - 00403968 _____ (Microsoft Corporation) C:\windows\system32\vpnike.dll 2014-07-16 19:10 - 2014-04-29 00:40 - 00721408 _____ (Microsoft Corporation) C:\windows\system32\fveapi.dll 2014-07-16 19:10 - 2014-04-27 00:03 - 02140888 _____ (Microsoft Corporation) C:\windows\system32\mfcore.dll 2014-07-16 19:10 - 2014-04-26 22:14 - 02144984 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfcore.dll 2014-07-16 19:10 - 2014-04-26 18:39 - 00339456 _____ (Microsoft Corporation) C:\windows\system32\bdesvc.dll 2014-07-16 19:10 - 2014-04-14 11:37 - 02125344 _____ (Microsoft Corporation) C:\windows\system32\d3d9.dll 2014-07-16 19:10 - 2014-04-14 10:08 - 01797896 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d9.dll 2014-07-16 19:10 - 2014-04-14 07:18 - 00011776 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d8thk.dll 2014-07-16 19:10 - 2014-04-09 08:11 - 00226816 _____ (Microsoft Corporation) C:\windows\system32\WebClnt.dll 2014-07-16 19:10 - 2014-04-09 07:20 - 00198656 _____ (Microsoft Corporation) C:\windows\SysWOW64\WebClnt.dll 2014-07-16 18:51 - 2014-07-16 18:51 - 00001359 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Browser 7 der Telekom.lnk 2014-07-16 18:51 - 2014-07-16 18:51 - 00001347 _____ () C:\Users\Public\Desktop\Browser 7 der Telekom.lnk 2014-07-16 18:51 - 2014-07-16 18:51 - 00000000 ____D () C:\Program Files (x86)\Browser 7 Maintenance Service 2014-07-16 18:48 - 2014-07-16 18:48 - 00362592 _____ (Deutsche Telekom AG) C:\Users\Christina\Downloads\browser7_setup (1).exe.hy7enp8.partial 2014-07-16 18:22 - 2014-07-16 18:27 - 00000000 ____D () C:\Users\Christina\AppData\Roaming\GlarySoft 2014-07-16 18:22 - 2014-07-16 18:22 - 00001129 _____ () C:\Users\Christina\Desktop\Absolute Uninstaller.lnk 2014-07-16 18:21 - 2014-07-16 18:21 - 02194784 _____ (Glarysoft.com ) C:\Users\Christina\Downloads\au29setup.exe 2014-07-16 18:21 - 2014-07-16 18:21 - 02194784 _____ (Glarysoft.com ) C:\Users\Christina\Downloads\au29setup (1).exe 2014-07-16 17:29 - 2014-07-16 17:29 - 02347384 _____ (ESET) C:\Users\Christina\Downloads\esetsmartinstaller_enu.exe 2014-07-16 17:28 - 2014-07-16 17:28 - 00441592 _____ (Bleeping Computer, LLC) C:\Users\Christina\Downloads\sc-cleaner.exe 2014-07-16 17:28 - 2014-07-16 17:28 - 00001770 _____ () C:\sc-cleaner.txt 2014-07-16 17:09 - 2014-07-16 17:09 - 00000911 _____ () C:\Users\Christina\Desktop\JRT.txt 2014-07-16 16:59 - 2014-07-16 16:59 - 00000000 ____D () C:\windows\ERUNT 2014-07-16 16:58 - 2014-07-16 16:58 - 01016261 _____ (Thisisu) C:\Users\Christina\Downloads\JRT.exe 2014-07-16 16:44 - 2014-07-16 16:47 - 00000000 ____D () C:\AdwCleaner 2014-07-16 16:43 - 2014-07-16 16:43 - 01348263 _____ () C:\Users\Christina\Downloads\adwcleaner_3.215.exe 2014-07-16 16:34 - 2014-07-16 18:43 - 00000000 ____D () C:\NPE 2014-07-16 16:28 - 2014-07-16 16:28 - 00010226 _____ () C:\Users\Christina\Downloads\hijackthis.log 2014-07-16 16:27 - 2014-07-16 16:27 - 00388608 _____ (Trend Micro Inc.) C:\Users\Christina\Downloads\HijackThis.exe 2014-07-16 16:21 - 2014-07-16 16:21 - 00304857 _____ () C:\Users\Christina\Downloads\HijackThis_205.zip 2014-07-16 15:46 - 2014-07-17 08:21 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-16 15:45 - 2014-07-16 15:45 - 00003190 _____ () C:\windows\System32\Tasks\{AD428E5A-001B-408D-97F0-5BBCB5C4A4C4} 2014-07-16 15:44 - 2014-07-16 15:44 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Christina\Downloads\mbam-setup-2.0.2.1012.exe 2014-07-16 15:44 - 2014-07-16 15:44 - 00001125 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-07-16 15:44 - 2014-07-16 15:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-16 15:44 - 2014-07-16 15:44 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-16 15:44 - 2014-07-16 15:44 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-07-16 15:44 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys 2014-07-16 15:44 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys 2014-07-16 15:44 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2014-07-16 15:22 - 2014-07-16 15:22 - 00362592 _____ (Deutsche Telekom AG) C:\Users\Christina\Downloads\browser7_setup.exe 2014-07-16 15:11 - 2014-07-16 15:11 - 01286520 _____ (Netviewer AG) C:\Users\Christina\Downloads\diagnose.exe 2014-07-16 14:03 - 2014-07-16 14:03 - 00000000 ____H () C:\windows\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf 2014-07-16 13:11 - 2014-07-16 13:11 - 00000000 ____D () C:\windows\System32\Tasks\Norton 360 2014-07-16 12:48 - 2014-07-16 12:48 - 00000000 ____D () C:\Users\Christina\Documents\Neuer Ordner 2014-07-14 16:28 - 2014-07-14 16:28 - 00001550 _____ () C:\Users\Christina\Downloads\URLLink(73).acsm 2014-07-14 16:27 - 2014-07-14 16:27 - 00001501 _____ () C:\Users\Christina\Downloads\URLLink(70).acsm 2014-07-14 16:27 - 2014-07-14 16:27 - 00001475 _____ () C:\Users\Christina\Downloads\URLLink(71).acsm 2014-07-14 16:27 - 2014-07-14 16:27 - 00001458 _____ () C:\Users\Christina\Downloads\URLLink(72).acsm 2014-07-09 07:30 - 2014-04-14 05:29 - 01018880 _____ (Microsoft Corporation) C:\windows\system32\termsrv.dll 2014-07-09 07:18 - 2014-06-17 00:26 - 00779264 _____ (Microsoft Corporation) C:\windows\SysWOW64\osk.exe 2014-07-09 07:18 - 2014-06-17 00:24 - 00834048 _____ (Microsoft Corporation) C:\windows\system32\osk.exe 2014-07-09 07:18 - 2014-06-06 16:20 - 04190720 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys 2014-07-09 07:18 - 2014-05-30 05:03 - 00563200 _____ (Microsoft Corporation) C:\windows\system32\Drivers\afd.sys 2014-07-09 07:18 - 2014-05-29 14:02 - 00565576 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys 2014-07-09 07:18 - 2014-05-29 09:55 - 00735232 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll 2014-07-09 07:18 - 2014-05-29 08:40 - 00735232 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll 2014-07-09 07:18 - 2014-05-29 08:37 - 00436224 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll 2014-07-09 07:18 - 2014-05-29 07:34 - 00318976 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll 2014-07-09 07:18 - 2014-05-29 07:27 - 01417216 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll 2014-07-09 07:17 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-07-09 07:17 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2014-07-09 07:17 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2014-07-09 07:17 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2014-07-09 07:17 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2014-07-09 07:17 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2014-07-09 07:17 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2014-07-09 07:17 - 2014-06-19 01:46 - 00250880 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll 2014-07-09 07:17 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2014-07-09 07:17 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2014-07-09 07:17 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll 2014-07-09 07:17 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2014-07-09 07:17 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll 2014-07-09 07:17 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll 2014-07-09 07:17 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2014-07-09 07:17 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll 2014-07-09 07:17 - 2014-06-19 00:57 - 00225280 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll 2014-07-09 07:17 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll 2014-07-09 07:17 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2014-07-09 07:17 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll 2014-07-09 07:17 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl 2014-07-09 07:17 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll 2014-07-09 07:17 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2014-07-09 07:17 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2014-07-09 07:17 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll 2014-07-09 07:17 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll 2014-07-09 07:17 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll 2014-07-09 07:17 - 2014-06-06 15:04 - 00586240 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll 2014-07-09 07:17 - 2014-06-06 14:18 - 00488960 _____ (Microsoft Corporation) C:\windows\SysWOW64\qedit.dll 2014-07-09 07:17 - 2014-05-31 05:40 - 13287936 _____ (Microsoft Corporation) C:\windows\system32\twinui.dll 2014-07-09 07:17 - 2014-05-31 04:36 - 00923136 _____ (Microsoft Corporation) C:\windows\system32\WSShared.dll 2014-07-09 07:17 - 2014-05-31 04:32 - 00756224 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSShared.dll 2014-07-09 07:16 - 2014-05-31 12:07 - 00054776 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe 2014-07-09 07:16 - 2014-05-31 12:06 - 00555736 _____ (Microsoft Corporation) C:\windows\system32\twinapi.appcore.dll 2014-07-09 07:16 - 2014-05-31 05:30 - 11792384 _____ (Microsoft Corporation) C:\windows\SysWOW64\twinui.dll 2014-07-09 07:16 - 2014-05-31 05:12 - 00249344 _____ (Microsoft Corporation) C:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2014-07-09 07:16 - 2014-05-31 05:06 - 00093696 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll 2014-07-09 07:16 - 2014-05-31 05:03 - 00827392 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll 2014-07-09 07:16 - 2014-05-31 05:01 - 00189952 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2014-07-09 07:16 - 2014-05-31 04:56 - 00080896 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll 2014-07-09 07:16 - 2014-05-31 04:54 - 00666624 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll 2014-07-09 07:16 - 2014-05-31 04:48 - 03463680 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll 2014-07-09 07:16 - 2014-05-31 04:37 - 01054208 _____ (Microsoft Corporation) C:\windows\system32\twinui.appcore.dll 2014-07-09 07:16 - 2014-05-31 04:35 - 00828928 _____ (Microsoft Corporation) C:\windows\SysWOW64\twinui.appcore.dll 2014-07-09 07:13 - 2014-07-09 07:13 - 00079872 _____ (Microsoft Corporation) C:\windows\system32\WSReset.exe 2014-07-08 14:22 - 2014-07-08 14:23 - 00001563 _____ () C:\Users\Christina\Downloads\URLLink(69).acsm 2014-07-08 09:03 - 2014-07-08 09:03 - 00001516 _____ () C:\Users\Christina\Downloads\URLLink(68).acsm 2014-07-02 09:56 - 2014-07-02 09:56 - 01058200 _____ (Adobe) C:\Users\Christina\Downloads\install_flashplayer14x32au_mssa_aaa_aih(1).exe 2014-06-29 19:11 - 2014-06-29 19:11 - 00001549 _____ () C:\Users\Christina\Downloads\URLLink(67).acsm 2014-06-29 19:10 - 2014-06-29 19:10 - 00001580 _____ () C:\Users\Christina\Downloads\URLLink(66).acsm 2014-06-29 19:10 - 2014-06-29 19:10 - 00001546 _____ () C:\Users\Christina\Downloads\URLLink(65).acsm 2014-06-29 19:10 - 2014-06-29 19:10 - 00001472 _____ () C:\Users\Christina\Downloads\URLLink(64).acsm 2014-06-29 19:10 - 2014-06-29 19:10 - 00001470 _____ () C:\Users\Christina\Downloads\URLLink(63).acsm 2014-06-29 19:10 - 2014-06-29 19:10 - 00001469 _____ () C:\Users\Christina\Downloads\URLLink(62).acsm 2014-06-27 14:25 - 2014-06-27 14:25 - 00001486 _____ () C:\Users\Christina\Downloads\URLLink(59).acsm 2014-06-27 14:25 - 2014-06-27 14:25 - 00001457 _____ () C:\Users\Christina\Downloads\URLLink(61).acsm 2014-06-27 14:25 - 2014-06-27 14:25 - 00001457 _____ () C:\Users\Christina\Downloads\URLLink(60).acsm 2014-06-26 20:01 - 2014-06-26 20:01 - 00025664 _____ () C:\Users\Christina\Documents\Elisa 12. Geburtstag.odt 2014-06-25 20:13 - 2014-06-25 20:13 - 05408139 _____ () C:\Users\Christina\Downloads\AmazonApps-release.apk 2014-06-23 20:46 - 2014-06-25 10:30 - 00014094 _____ () C:\Users\Christina\Documents\ADAC.odt 2014-06-23 17:07 - 2014-06-23 17:07 - 01058200 _____ (Adobe) C:\Users\Christina\Downloads\install_flashplayer14x32au_mssa_aaa_aih.exe 2014-06-22 19:53 - 2014-06-22 19:53 - 00001518 _____ () C:\Users\Christina\Downloads\URLLink(58).acsm 2014-06-22 19:52 - 2014-06-22 19:52 - 00001549 _____ () C:\Users\Christina\Downloads\URLLink(57).acsm 2014-06-22 19:44 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2014-06-22 19:44 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll 2014-06-22 19:44 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll 2014-06-22 19:44 - 2014-05-10 05:46 - 02151424 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll 2014-06-22 19:44 - 2014-05-10 05:22 - 01312256 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll 2014-06-22 19:44 - 2014-05-05 06:02 - 03360256 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll 2014-06-22 19:44 - 2014-04-30 13:16 - 01336648 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll 2014-06-22 19:44 - 2014-04-30 05:51 - 01064448 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll 2014-06-22 19:43 - 2014-07-16 19:07 - 00428888 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS 2014-06-22 19:43 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll 2014-06-22 19:43 - 2014-05-09 01:06 - 00295424 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ks.sys 2014-06-22 19:43 - 2014-04-18 16:57 - 00032600 _____ (Microsoft Corporation) C:\windows\system32\ploptin.dll 2014-06-22 19:43 - 2014-04-18 16:44 - 01466856 _____ (Microsoft Corporation) C:\windows\system32\propsys.dll 2014-06-22 19:43 - 2014-04-18 15:29 - 01200288 _____ (Microsoft Corporation) C:\windows\SysWOW64\propsys.dll 2014-06-22 19:43 - 2014-04-18 11:44 - 00055296 _____ (Microsoft Corporation) C:\windows\system32\energyprov.dll 2014-06-22 19:43 - 2014-04-18 10:32 - 00805376 _____ (Microsoft Corporation) C:\windows\system32\win32spl.dll 2014-06-22 19:43 - 2014-04-18 10:21 - 01126912 _____ (Microsoft Corporation) C:\windows\system32\SearchFolder.dll 2014-06-22 19:43 - 2014-04-18 10:09 - 08652800 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Search.dll 2014-06-22 19:43 - 2014-04-18 09:51 - 00836608 _____ (Microsoft Corporation) C:\windows\SysWOW64\SearchFolder.dll 2014-06-22 19:43 - 2014-04-18 09:49 - 05833216 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Search.dll 2014-06-22 19:43 - 2014-04-14 11:20 - 00324888 _____ (Microsoft Corporation) C:\windows\system32\MFCaptureEngine.dll 2014-06-22 19:43 - 2014-04-14 10:01 - 00285144 _____ (Microsoft Corporation) C:\windows\SysWOW64\MFCaptureEngine.dll 2014-06-22 19:43 - 2014-04-11 06:51 - 00250368 _____ (Microsoft Corporation) C:\windows\system32\rdpencom.dll 2014-06-22 19:43 - 2014-04-11 06:23 - 00209920 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdpencom.dll 2014-06-22 19:43 - 2014-04-11 05:30 - 00449536 _____ (Microsoft Corporation) C:\windows\system32\defragsvc.dll 2014-06-22 19:43 - 2014-04-09 13:53 - 00337240 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Classpnp.sys 2014-06-22 19:43 - 2014-04-09 08:39 - 00191488 _____ (Microsoft Corporation) C:\windows\system32\rpchttp.dll 2014-06-22 19:43 - 2014-04-09 07:44 - 00144384 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpchttp.dll 2014-06-22 19:43 - 2014-04-09 05:33 - 00135168 _____ (Microsoft Corporation) C:\windows\system32\wscsvc.dll 2014-06-22 19:43 - 2014-04-08 04:01 - 00589656 _____ (Microsoft Corporation) C:\windows\system32\Drivers\fvevol.sys 2014-06-22 19:43 - 2014-04-06 18:34 - 00372568 _____ (Microsoft Corporation) C:\windows\system32\Drivers\storport.sys 2014-06-22 19:43 - 2014-04-06 18:34 - 00275800 ____C (Microsoft Corporation) C:\windows\system32\Drivers\msiscsi.sys 2014-06-22 19:43 - 2014-04-06 18:32 - 00125496 _____ (Microsoft Corporation) C:\windows\system32\dwmapi.dll 2014-06-22 19:43 - 2014-04-06 18:31 - 21268952 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll 2014-06-22 19:43 - 2014-04-06 18:30 - 00201920 _____ (Microsoft Corporation) C:\windows\system32\MSVideoDSP.dll 2014-06-22 19:43 - 2014-04-06 18:24 - 00360792 _____ (Microsoft Corporation) C:\windows\system32\Drivers\fltMgr.sys 2014-06-22 19:43 - 2014-04-06 18:20 - 01403856 _____ (Microsoft Corporation) C:\windows\system32\winmde.dll 2014-06-22 19:43 - 2014-04-06 18:20 - 01379064 _____ (Microsoft Corporation) C:\windows\system32\wmpmde.dll 2014-06-22 19:43 - 2014-04-06 18:20 - 00881616 _____ (Microsoft Corporation) C:\windows\system32\mfplat.dll 2014-06-22 19:43 - 2014-04-06 18:20 - 00765408 _____ (Microsoft Corporation) C:\windows\system32\mfmpeg2srcsnk.dll 2014-06-22 19:43 - 2014-04-06 18:20 - 00609448 _____ (Microsoft Corporation) C:\windows\system32\mf.dll 2014-06-22 19:43 - 2014-04-06 18:20 - 00491744 _____ (Microsoft Corporation) C:\windows\system32\mfsvr.dll 2014-06-22 19:43 - 2014-04-06 18:20 - 00467496 _____ (Microsoft Corporation) C:\windows\system32\AudioSes.dll 2014-06-22 19:43 - 2014-04-06 18:20 - 00463256 _____ (Microsoft Corporation) C:\windows\system32\AudioEng.dll 2014-06-22 19:43 - 2014-04-06 18:20 - 00364640 _____ (Microsoft Corporation) C:\windows\system32\AUDIOKSE.dll 2014-06-22 19:43 - 2014-04-06 18:20 - 00244880 _____ (Microsoft Corporation) C:\windows\system32\audiodg.exe 2014-06-22 19:43 - 2014-04-06 18:20 - 00028408 _____ (Microsoft Corporation) C:\windows\system32\mfpmp.exe 2014-06-22 19:43 - 2014-04-06 17:23 - 00098584 _____ (Microsoft Corporation) C:\windows\SysWOW64\dwmapi.dll 2014-06-22 19:43 - 2014-04-06 17:22 - 18755672 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll 2014-06-22 19:43 - 2014-04-06 17:22 - 00178184 _____ (Microsoft Corporation) C:\windows\SysWOW64\MSVideoDSP.dll 2014-06-22 19:43 - 2014-04-06 17:16 - 01209616 _____ (Microsoft Corporation) C:\windows\SysWOW64\winmde.dll 2014-06-22 19:43 - 2014-04-06 17:16 - 00707048 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfplat.dll 2014-06-22 19:43 - 2014-04-06 17:16 - 00669856 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfmpeg2srcsnk.dll 2014-06-22 19:43 - 2014-04-06 17:16 - 00518544 _____ (Microsoft Corporation) C:\windows\SysWOW64\mf.dll 2014-06-22 19:43 - 2014-04-06 17:16 - 00406504 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioEng.dll 2014-06-22 19:43 - 2014-04-06 17:16 - 00387896 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfsvr.dll 2014-06-22 19:43 - 2014-04-06 17:16 - 00326024 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioSes.dll 2014-06-22 19:43 - 2014-04-06 17:16 - 00305768 _____ (Microsoft Corporation) C:\windows\SysWOW64\AUDIOKSE.dll 2014-06-22 19:43 - 2014-04-06 14:58 - 00070656 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll 2014-06-22 19:43 - 2014-04-06 14:51 - 00467968 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll 2014-06-22 19:43 - 2014-04-06 14:33 - 00335872 _____ (Microsoft Corporation) C:\windows\system32\MDEServer.exe 2014-06-22 19:43 - 2014-04-06 14:24 - 00271872 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe 2014-06-22 19:43 - 2014-04-06 14:06 - 00061440 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll 2014-06-22 19:43 - 2014-04-06 13:26 - 00143872 _____ (Microsoft Corporation) C:\windows\system32\BootMenuUX.dll 2014-06-22 19:43 - 2014-04-06 13:20 - 00201216 _____ (Microsoft Corporation) C:\windows\system32\AudioEndpointBuilder.dll 2014-06-22 19:43 - 2014-04-06 13:01 - 00834048 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll 2014-06-22 19:43 - 2014-04-06 12:52 - 00955904 _____ (Microsoft Corporation) C:\windows\system32\MFMediaEngine.dll 2014-06-22 19:43 - 2014-04-06 12:51 - 01230336 _____ (Microsoft Corporation) C:\windows\system32\Windows.Media.dll 2014-06-22 19:43 - 2014-04-06 12:37 - 00800768 _____ (Microsoft Corporation) C:\windows\SysWOW64\MFMediaEngine.dll 2014-06-22 19:43 - 2014-04-06 12:36 - 00888320 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Media.dll 2014-06-22 19:43 - 2014-04-06 12:05 - 01222656 _____ (Microsoft Corporation) C:\windows\system32\Windows.Media.Streaming.dll 2014-06-22 19:43 - 2014-04-06 11:59 - 00982016 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Media.Streaming.dll 2014-06-22 19:43 - 2014-04-03 10:12 - 00307304 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll 2014-06-22 19:43 - 2014-04-03 10:12 - 00130144 _____ (Microsoft Corporation) C:\windows\system32\gpapi.dll 2014-06-22 19:43 - 2014-04-03 06:03 - 00230808 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll 2014-06-22 19:43 - 2014-04-03 06:03 - 00111528 _____ (Microsoft Corporation) C:\windows\SysWOW64\gpapi.dll 2014-06-22 19:43 - 2014-04-03 04:53 - 00677376 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv2.sys 2014-06-22 19:43 - 2014-04-03 04:51 - 01584128 _____ (Microsoft Corporation) C:\windows\system32\workfolderssvc.dll 2014-06-22 19:43 - 2014-04-03 04:23 - 00046592 _____ (Microsoft Corporation) C:\windows\SysWOW64\tlscsp.dll 2014-06-22 19:43 - 2014-04-03 04:22 - 00047616 _____ (Microsoft Corporation) C:\windows\system32\tlscsp.dll 2014-06-22 19:43 - 2014-04-01 08:23 - 00384856 ____C (Microsoft Corporation) C:\windows\system32\Drivers\spaceport.sys 2014-06-22 19:43 - 2014-03-31 07:42 - 07425368 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe 2014-06-22 19:43 - 2014-03-31 02:01 - 00186880 _____ (Microsoft Corporation) C:\windows\system32\WorkFoldersShell.dll 2014-06-22 19:43 - 2014-03-31 01:43 - 00761856 _____ (Microsoft Corporation) C:\windows\system32\WorkfoldersControl.dll 2014-06-22 19:43 - 2014-03-31 00:54 - 01308160 _____ (Microsoft Corporation) C:\windows\system32\gpsvc.dll 2014-06-22 19:43 - 2014-03-31 00:49 - 01287168 _____ (Microsoft Corporation) C:\windows\system32\mispace.dll 2014-06-22 19:43 - 2014-03-31 00:35 - 01029120 _____ (Microsoft Corporation) C:\windows\SysWOW64\mispace.dll 2014-06-22 19:43 - 2014-03-28 17:58 - 00407016 _____ (Microsoft Corporation) C:\windows\system32\services.exe 2014-06-22 19:43 - 2014-03-27 08:16 - 00246272 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srvnet.sys 2014-06-22 19:43 - 2014-03-27 07:36 - 00281600 _____ (Microsoft Corporation) C:\windows\system32\resutils.dll 2014-06-22 19:43 - 2014-03-27 06:59 - 00426496 _____ (Microsoft Corporation) C:\windows\system32\clusapi.dll 2014-06-22 19:43 - 2014-03-27 06:48 - 00219136 _____ (Microsoft Corporation) C:\windows\SysWOW64\resutils.dll 2014-06-22 19:43 - 2014-03-27 06:19 - 00313344 _____ (Microsoft Corporation) C:\windows\SysWOW64\clusapi.dll 2014-06-22 19:43 - 2014-03-27 05:46 - 00323072 _____ (Microsoft Corporation) C:\windows\system32\srvsvc.dll 2014-06-22 19:43 - 2014-03-27 05:15 - 00718336 _____ (Microsoft Corporation) C:\windows\system32\swprv.dll 2014-06-22 19:43 - 2014-03-27 05:10 - 01436160 _____ (Microsoft Corporation) C:\windows\system32\VSSVC.exe 2014-06-22 19:43 - 2014-03-20 05:48 - 00263424 _____ (Microsoft Corporation) C:\windows\system32\SystemSettingsAdminFlows.exe 2014-06-22 19:43 - 2014-03-20 02:44 - 06645248 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll 2014-06-22 19:43 - 2014-03-20 01:33 - 05774848 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll 2014-06-22 19:43 - 2014-03-19 10:15 - 00011264 _____ (Microsoft Corporation) C:\windows\system32\wlanhlp.dll 2014-06-22 19:43 - 2014-03-19 10:07 - 00443904 _____ (Microsoft Corporation) C:\windows\system32\Drivers\nwifi.sys 2014-06-22 19:43 - 2014-03-19 09:24 - 00064512 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll 2014-06-22 19:43 - 2014-03-19 09:17 - 00011264 _____ (Microsoft Corporation) C:\windows\SysWOW64\wlanhlp.dll 2014-06-22 19:43 - 2014-03-19 08:36 - 01057280 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll 2014-06-22 19:43 - 2014-03-19 07:56 - 00855552 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdvidcrl.dll 2014-06-22 19:43 - 2014-03-19 07:45 - 00443904 _____ (Microsoft Corporation) C:\windows\system32\wlansec.dll 2014-06-22 19:43 - 2014-03-19 07:19 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\wlanapi.dll 2014-06-22 19:43 - 2014-03-19 07:07 - 00370176 _____ (Microsoft Corporation) C:\windows\system32\wlanmsm.dll 2014-06-22 19:43 - 2014-03-19 07:02 - 01527296 _____ (Microsoft Corporation) C:\windows\system32\wlansvc.dll 2014-06-22 19:43 - 2014-03-19 07:00 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\wlanapi.dll 2014-06-22 19:43 - 2014-03-19 06:51 - 00300544 _____ (Microsoft Corporation) C:\windows\SysWOW64\wlanmsm.dll 2014-06-22 19:43 - 2014-03-19 06:31 - 02100736 _____ (Microsoft Corporation) C:\windows\system32\SystemSettingsAdminFlowUI.dll 2014-06-22 19:43 - 2014-03-19 06:18 - 02688000 _____ (Microsoft Corporation) C:\windows\system32\SettingsHandlers.dll 2014-06-22 19:43 - 2014-03-18 10:19 - 00077312 ____C (Microsoft Corporation) C:\windows\system32\Drivers\hdaudbus.sys 2014-06-22 19:43 - 2014-03-18 07:00 - 07173120 _____ (Microsoft Corporation) C:\windows\system32\Windows.Data.Pdf.dll 2014-06-22 19:43 - 2014-03-18 06:52 - 05104640 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Data.Pdf.dll 2014-06-22 19:43 - 2014-03-17 07:09 - 00462336 _____ (Microsoft Corporation) C:\windows\system32\XpsGdiConverter.dll 2014-06-22 19:43 - 2014-03-17 06:11 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\XpsGdiConverter.dll 2014-06-22 19:43 - 2014-03-17 05:01 - 00486912 _____ (Microsoft Corporation) C:\windows\system32\winspool.drv 2014-06-22 19:43 - 2014-03-17 04:45 - 00370176 _____ (Microsoft Corporation) C:\windows\SysWOW64\winspool.drv 2014-06-22 19:43 - 2014-03-14 08:26 - 00491520 _____ (Microsoft Corporation) C:\windows\system32\GeofenceMonitorService.dll 2014-06-22 19:43 - 2014-03-14 08:10 - 00357376 _____ (Microsoft Corporation) C:\windows\SysWOW64\GeofenceMonitorService.dll 2014-06-22 19:43 - 2014-03-06 14:42 - 00310616 ____C (Microsoft Corporation) C:\windows\system32\Drivers\volsnap.sys 2014-06-22 19:42 - 2014-05-19 08:31 - 00057856 _____ (Microsoft Corporation) C:\windows\system32\drvcfg.exe 2014-06-22 19:42 - 2014-05-19 08:21 - 00110592 _____ (Microsoft Corporation) C:\windows\system32\drvinst.exe 2014-06-22 19:42 - 2014-05-19 07:23 - 00098816 _____ (Microsoft Corporation) C:\windows\SysWOW64\drvinst.exe 2014-06-22 19:42 - 2014-05-01 15:31 - 03048904 _____ (Microsoft Corporation) C:\windows\system32\WpcMon.exe 2014-06-22 19:42 - 2014-05-01 15:31 - 00055328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\wpcfltr.sys 2014-06-22 19:42 - 2014-05-01 09:14 - 03118080 _____ (Microsoft Corporation) C:\windows\system32\Wpc.dll 2014-06-22 19:42 - 2014-05-01 09:05 - 02861056 _____ (Microsoft Corporation) C:\windows\system32\WpcWebSync.dll 2014-06-22 19:42 - 2014-05-01 08:51 - 02344448 _____ (Microsoft Corporation) C:\windows\SysWOW64\Wpc.dll 2014-06-22 19:42 - 2014-05-01 07:24 - 02834944 _____ (Microsoft Corporation) C:\windows\system32\wpccpl.dll 2014-06-22 19:42 - 2014-04-30 06:43 - 01975296 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll 2014-06-22 19:42 - 2014-04-30 06:26 - 01345536 _____ (Microsoft Corporation) C:\windows\system32\FntCache.dll 2014-06-22 19:42 - 2014-04-30 05:47 - 01509888 _____ (Microsoft Corporation) C:\windows\SysWOW64\DWrite.dll 2014-06-22 19:41 - 2014-06-22 19:41 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsgqec.dll 2014-06-22 19:41 - 2014-06-22 19:41 - 00001549 _____ () C:\Users\Christina\Downloads\URLLink(56).acsm 2014-06-22 19:40 - 2014-06-22 19:40 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2014-06-22 19:40 - 2014-06-22 19:40 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe 2014-06-22 19:40 - 2014-06-22 19:40 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2014-06-22 19:40 - 2014-06-22 19:40 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2014-06-22 19:37 - 2014-06-22 19:37 - 00001571 _____ () C:\Users\Christina\Downloads\URLLink(54).acsm 2014-06-22 19:37 - 2014-06-22 19:37 - 00001549 _____ () C:\Users\Christina\Downloads\URLLink(52).acsm 2014-06-22 19:37 - 2014-06-22 19:37 - 00001501 _____ () C:\Users\Christina\Downloads\URLLink(53).acsm 2014-06-22 19:37 - 2014-06-22 19:37 - 00001493 _____ () C:\Users\Christina\Downloads\URLLink(51).acsm 2014-06-22 19:37 - 2014-06-22 19:37 - 00001473 _____ () C:\Users\Christina\Downloads\URLLink(55).acsm ==================== One Month Modified Files and Folders ======= 2014-07-17 08:29 - 2014-07-17 08:29 - 00000000 ____D () C:\FRST 2014-07-17 08:27 - 2014-07-17 08:27 - 01077248 _____ (Farbar) C:\Users\Christina\Downloads\FRST (2).exe 2014-07-17 08:25 - 2014-07-17 08:25 - 01077248 _____ (Farbar) C:\Users\Christina\Downloads\FRST.exe 2014-07-17 08:25 - 2014-07-17 08:25 - 01077248 _____ (Farbar) C:\Users\Christina\Downloads\FRST (1).exe 2014-07-17 08:21 - 2014-07-16 15:46 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-17 08:21 - 2014-04-15 19:09 - 01102368 _____ () C:\windows\WindowsUpdate.log 2014-07-17 08:20 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\system32\sru 2014-07-16 21:01 - 2014-05-08 08:32 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job 2014-07-16 20:30 - 2014-04-15 19:15 - 00003600 _____ () C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3508085089-3033536294-3423735549-1001 2014-07-16 20:00 - 2014-07-16 20:00 - 00602112 _____ (OldTimer Tools) C:\Users\Christina\Downloads\OTL.exe 2014-07-16 19:45 - 2013-08-22 16:45 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2014-07-16 19:43 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\MediaViewer 2014-07-16 19:43 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\FileManager 2014-07-16 19:43 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\Camera 2014-07-16 19:42 - 2013-08-22 16:46 - 00036995 _____ () C:\windows\setupact.log 2014-07-16 19:40 - 2014-02-11 07:12 - 00000000 ____D () C:\windows\SysWOW64\RTCOM 2014-07-16 19:29 - 2013-08-22 17:20 - 00000000 ____D () C:\windows\CbsTemp 2014-07-16 19:12 - 2014-07-16 19:12 - 00000000 ____D () C:\Program Files\AMD 2014-07-16 19:09 - 2014-04-18 10:04 - 00233912 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll 2014-07-16 19:07 - 2014-06-22 19:43 - 00428888 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS 2014-07-16 18:51 - 2014-07-16 18:51 - 00001359 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Browser 7 der Telekom.lnk 2014-07-16 18:51 - 2014-07-16 18:51 - 00001347 _____ () C:\Users\Public\Desktop\Browser 7 der Telekom.lnk 2014-07-16 18:51 - 2014-07-16 18:51 - 00000000 ____D () C:\Program Files (x86)\Browser 7 Maintenance Service 2014-07-16 18:50 - 2014-04-15 20:02 - 00000000 ____D () C:\Program Files (x86)\Deutsche Telekom AG 2014-07-16 18:48 - 2014-07-16 18:48 - 00362592 _____ (Deutsche Telekom AG) C:\Users\Christina\Downloads\browser7_setup (1).exe.hy7enp8.partial 2014-07-16 18:45 - 2014-05-24 14:47 - 00000000 ____D () C:\Users\Christina\AppData\Local\NPE 2014-07-16 18:44 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\system32\FxsTmp 2014-07-16 18:43 - 2014-07-16 16:34 - 00000000 ____D () C:\NPE 2014-07-16 18:39 - 2013-08-24 23:32 - 00093894 _____ () C:\windows\PFRO.log 2014-07-16 18:27 - 2014-07-16 18:22 - 00000000 ____D () C:\Users\Christina\AppData\Roaming\GlarySoft 2014-07-16 18:22 - 2014-07-16 18:22 - 00001129 _____ () C:\Users\Christina\Desktop\Absolute Uninstaller.lnk 2014-07-16 18:21 - 2014-07-16 18:21 - 02194784 _____ (Glarysoft.com ) C:\Users\Christina\Downloads\au29setup.exe 2014-07-16 18:21 - 2014-07-16 18:21 - 02194784 _____ (Glarysoft.com ) C:\Users\Christina\Downloads\au29setup (1).exe 2014-07-16 17:29 - 2014-07-16 17:29 - 02347384 _____ (ESET) C:\Users\Christina\Downloads\esetsmartinstaller_enu.exe 2014-07-16 17:28 - 2014-07-16 17:28 - 00441592 _____ (Bleeping Computer, LLC) C:\Users\Christina\Downloads\sc-cleaner.exe 2014-07-16 17:28 - 2014-07-16 17:28 - 00001770 _____ () C:\sc-cleaner.txt 2014-07-16 17:09 - 2014-07-16 17:09 - 00000911 _____ () C:\Users\Christina\Desktop\JRT.txt 2014-07-16 16:59 - 2014-07-16 16:59 - 00000000 ____D () C:\windows\ERUNT 2014-07-16 16:58 - 2014-07-16 16:58 - 01016261 _____ (Thisisu) C:\Users\Christina\Downloads\JRT.exe 2014-07-16 16:47 - 2014-07-16 16:44 - 00000000 ____D () C:\AdwCleaner 2014-07-16 16:43 - 2014-07-16 16:43 - 01348263 _____ () C:\Users\Christina\Downloads\adwcleaner_3.215.exe 2014-07-16 16:33 - 2014-04-15 20:30 - 00000000 ____D () C:\ProgramData\Norton 2014-07-16 16:28 - 2014-07-16 16:28 - 00010226 _____ () C:\Users\Christina\Downloads\hijackthis.log 2014-07-16 16:27 - 2014-07-16 16:27 - 00388608 _____ (Trend Micro Inc.) C:\Users\Christina\Downloads\HijackThis.exe 2014-07-16 16:27 - 2014-04-15 19:09 - 00000000 ____D () C:\Users\Christina\AppData\Local\VirtualStore 2014-07-16 16:21 - 2014-07-16 16:21 - 00304857 _____ () C:\Users\Christina\Downloads\HijackThis_205.zip 2014-07-16 16:09 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\L2Schemas 2014-07-16 15:54 - 2014-02-11 08:07 - 00757756 _____ () C:\windows\system32\perfh007.dat 2014-07-16 15:54 - 2014-02-11 08:07 - 00173028 _____ () C:\windows\system32\perfc007.dat 2014-07-16 15:54 - 2013-08-24 23:38 - 01783968 _____ () C:\windows\system32\PerfStringBackup.INI 2014-07-16 15:47 - 2014-04-15 19:09 - 00001461 _____ () C:\Users\Christina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-07-16 15:46 - 2014-04-26 12:31 - 00000000 ____D () C:\Users\Christina\AppData\Local\CrashDumps 2014-07-16 15:45 - 2014-07-16 15:45 - 00003190 _____ () C:\windows\System32\Tasks\{AD428E5A-001B-408D-97F0-5BBCB5C4A4C4} 2014-07-16 15:44 - 2014-07-16 15:44 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Christina\Downloads\mbam-setup-2.0.2.1012.exe 2014-07-16 15:44 - 2014-07-16 15:44 - 00001125 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-07-16 15:44 - 2014-07-16 15:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-16 15:44 - 2014-07-16 15:44 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-16 15:44 - 2014-07-16 15:44 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-07-16 15:22 - 2014-07-16 15:22 - 00362592 _____ (Deutsche Telekom AG) C:\Users\Christina\Downloads\browser7_setup.exe 2014-07-16 15:17 - 2013-08-22 17:36 - 00000000 ___HD () C:\windows\ELAMBKUP 2014-07-16 15:17 - 2013-08-22 15:25 - 00524288 ___SH () C:\windows\system32\config\BBI 2014-07-16 15:11 - 2014-07-16 15:11 - 01286520 _____ (Netviewer AG) C:\Users\Christina\Downloads\diagnose.exe 2014-07-16 14:03 - 2014-07-16 14:03 - 00000000 ____H () C:\windows\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf 2014-07-16 13:11 - 2014-07-16 13:11 - 00000000 ____D () C:\windows\System32\Tasks\Norton 360 2014-07-16 13:06 - 2014-04-15 20:31 - 00003206 _____ () C:\windows\System32\Tasks\Norton WSC Integration 2014-07-16 13:06 - 2014-04-15 20:31 - 00002346 _____ () C:\Users\Public\Desktop\Norton 360.lnk 2014-07-16 13:06 - 2014-04-15 20:30 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360 2014-07-16 13:06 - 2014-04-15 20:30 - 00000000 ____D () C:\windows\system32\Drivers\N360x64 2014-07-16 13:05 - 2013-08-22 16:44 - 00503128 _____ () C:\windows\system32\FNTCACHE.DAT 2014-07-16 12:48 - 2014-07-16 12:48 - 00000000 ____D () C:\Users\Christina\Documents\Neuer Ordner 2014-07-16 12:44 - 2013-08-22 15:25 - 00262144 ___SH () C:\windows\system32\config\ELAM 2014-07-16 11:53 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\system32\NDF 2014-07-16 11:24 - 2014-02-11 07:12 - 00065536 _____ () C:\windows\system32\spu_storage.bin 2014-07-14 16:28 - 2014-07-14 16:28 - 00001550 _____ () C:\Users\Christina\Downloads\URLLink(73).acsm 2014-07-14 16:27 - 2014-07-14 16:27 - 00001501 _____ () C:\Users\Christina\Downloads\URLLink(70).acsm 2014-07-14 16:27 - 2014-07-14 16:27 - 00001475 _____ () C:\Users\Christina\Downloads\URLLink(71).acsm 2014-07-14 16:27 - 2014-07-14 16:27 - 00001458 _____ () C:\Users\Christina\Downloads\URLLink(72).acsm 2014-07-14 09:50 - 2014-05-12 13:11 - 00022973 _____ () C:\Users\Christina\Documents\2014.ods 2014-07-10 09:23 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\rescache 2014-07-09 19:37 - 2014-04-15 19:09 - 00000000 ____D () C:\Users\Christina\AppData\Local\Packages 2014-07-09 08:52 - 2013-08-22 17:36 - 00000000 ___RD () C:\windows\ToastData 2014-07-09 08:52 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-09 08:52 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-09 08:52 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\WinStore 2014-07-09 07:34 - 2014-04-18 20:42 - 00000000 ____D () C:\windows\system32\MRT 2014-07-09 07:32 - 2014-04-18 20:42 - 96441528 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2014-07-09 07:30 - 2014-04-15 20:55 - 00000000 ____D () C:\Program Files\Microsoft Office 15 2014-07-09 07:29 - 2013-08-22 21:12 - 00000000 ____D () C:\Program Files\Windows Journal 2014-07-09 07:13 - 2014-07-09 07:13 - 00079872 _____ (Microsoft Corporation) C:\windows\system32\WSReset.exe 2014-07-08 18:00 - 2014-02-11 07:43 - 00000000 ____D () C:\ProgramData\McAfee 2014-07-08 17:59 - 2014-05-08 08:32 - 00003772 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater 2014-07-08 14:23 - 2014-07-08 14:22 - 00001563 _____ () C:\Users\Christina\Downloads\URLLink(69).acsm 2014-07-08 09:03 - 2014-07-08 09:03 - 00001516 _____ () C:\Users\Christina\Downloads\URLLink(68).acsm 2014-07-04 13:16 - 2014-05-12 13:12 - 00018438 _____ () C:\Users\Christina\Documents\2015.ods 2014-07-02 09:56 - 2014-07-02 09:56 - 01058200 _____ (Adobe) C:\Users\Christina\Downloads\install_flashplayer14x32au_mssa_aaa_aih(1).exe 2014-06-29 19:11 - 2014-06-29 19:11 - 00001549 _____ () C:\Users\Christina\Downloads\URLLink(67).acsm 2014-06-29 19:10 - 2014-06-29 19:10 - 00001580 _____ () C:\Users\Christina\Downloads\URLLink(66).acsm 2014-06-29 19:10 - 2014-06-29 19:10 - 00001546 _____ () C:\Users\Christina\Downloads\URLLink(65).acsm 2014-06-29 19:10 - 2014-06-29 19:10 - 00001472 _____ () C:\Users\Christina\Downloads\URLLink(64).acsm 2014-06-29 19:10 - 2014-06-29 19:10 - 00001470 _____ () C:\Users\Christina\Downloads\URLLink(63).acsm 2014-06-29 19:10 - 2014-06-29 19:10 - 00001469 _____ () C:\Users\Christina\Downloads\URLLink(62).acsm 2014-06-27 14:25 - 2014-06-27 14:25 - 00001486 _____ () C:\Users\Christina\Downloads\URLLink(59).acsm 2014-06-27 14:25 - 2014-06-27 14:25 - 00001457 _____ () C:\Users\Christina\Downloads\URLLink(61).acsm 2014-06-27 14:25 - 2014-06-27 14:25 - 00001457 _____ () C:\Users\Christina\Downloads\URLLink(60).acsm 2014-06-26 22:55 - 2014-04-22 20:30 - 00703968 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe 2014-06-26 22:55 - 2014-04-22 20:30 - 00105440 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-06-26 20:01 - 2014-06-26 20:01 - 00025664 _____ () C:\Users\Christina\Documents\Elisa 12. Geburtstag.odt 2014-06-25 21:09 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\AppReadiness 2014-06-25 20:13 - 2014-06-25 20:13 - 05408139 _____ () C:\Users\Christina\Downloads\AmazonApps-release.apk 2014-06-25 10:30 - 2014-06-23 20:46 - 00014094 _____ () C:\Users\Christina\Documents\ADAC.odt 2014-06-23 20:49 - 2013-08-22 17:36 - 00000000 ___RD () C:\windows\ImmersiveControlPanel 2014-06-23 20:49 - 2013-08-22 15:36 - 00000000 ____D () C:\windows\system32\oobe 2014-06-23 17:07 - 2014-06-23 17:07 - 01058200 _____ (Adobe) C:\Users\Christina\Downloads\install_flashplayer14x32au_mssa_aaa_aih.exe 2014-06-22 19:53 - 2014-06-22 19:53 - 00001518 _____ () C:\Users\Christina\Downloads\URLLink(58).acsm 2014-06-22 19:52 - 2014-06-22 19:52 - 00001549 _____ () C:\Users\Christina\Downloads\URLLink(57).acsm 2014-06-22 19:41 - 2014-06-22 19:41 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsgqec.dll 2014-06-22 19:41 - 2014-06-22 19:41 - 00001549 _____ () C:\Users\Christina\Downloads\URLLink(56).acsm 2014-06-22 19:40 - 2014-06-22 19:40 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2014-06-22 19:40 - 2014-06-22 19:40 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe 2014-06-22 19:40 - 2014-06-22 19:40 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2014-06-22 19:40 - 2014-06-22 19:40 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2014-06-22 19:37 - 2014-06-22 19:37 - 00001571 _____ () C:\Users\Christina\Downloads\URLLink(54).acsm 2014-06-22 19:37 - 2014-06-22 19:37 - 00001549 _____ () C:\Users\Christina\Downloads\URLLink(52).acsm 2014-06-22 19:37 - 2014-06-22 19:37 - 00001501 _____ () C:\Users\Christina\Downloads\URLLink(53).acsm 2014-06-22 19:37 - 2014-06-22 19:37 - 00001493 _____ () C:\Users\Christina\Downloads\URLLink(51).acsm 2014-06-22 19:37 - 2014-06-22 19:37 - 00001473 _____ () C:\Users\Christina\Downloads\URLLink(55).acsm 2014-06-19 03:39 - 2014-07-09 07:17 - 23464448 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-06-19 02:48 - 2014-07-09 07:17 - 02768384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2014-06-19 02:16 - 2014-07-09 07:17 - 17276416 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2014-06-19 02:09 - 2014-07-09 07:17 - 00452608 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2014-06-19 01:51 - 2014-07-09 07:17 - 05721088 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2014-06-19 01:50 - 2014-07-09 07:17 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2014-06-19 01:48 - 2014-07-09 07:17 - 00292864 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2014-06-19 01:46 - 2014-07-09 07:17 - 00250880 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll 2014-06-19 01:39 - 2014-07-09 07:17 - 00608768 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2014-06-19 01:33 - 2014-07-09 07:17 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2014-06-19 01:32 - 2014-07-09 07:17 - 02179072 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll 2014-06-19 01:27 - 2014-07-09 07:17 - 02040832 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2014-06-19 01:12 - 2014-07-09 07:17 - 00367616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll 2014-06-19 00:59 - 2014-07-09 07:17 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll 2014-06-19 00:58 - 2014-07-09 07:17 - 02266112 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2014-06-19 00:58 - 2014-07-09 07:17 - 00239616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll 2014-06-19 00:57 - 2014-07-09 07:17 - 00225280 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll 2014-06-19 00:52 - 2014-07-09 07:17 - 04254720 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll 2014-06-19 00:51 - 2014-07-09 07:17 - 13527040 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2014-06-19 00:49 - 2014-07-09 07:17 - 00526336 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll 2014-06-19 00:45 - 2014-07-09 07:17 - 01964544 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl 2014-06-19 00:35 - 2014-07-09 07:17 - 11742208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll 2014-06-19 00:34 - 2014-07-09 07:17 - 01393664 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2014-06-19 00:15 - 2014-07-09 07:17 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2014-06-19 00:13 - 2014-07-09 07:17 - 01791488 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll 2014-06-19 00:09 - 2014-07-09 07:17 - 01139200 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll 2014-06-19 00:07 - 2014-07-09 07:17 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll 2014-06-17 00:26 - 2014-07-09 07:18 - 00779264 _____ (Microsoft Corporation) C:\windows\SysWOW64\osk.exe 2014-06-17 00:24 - 2014-07-09 07:18 - 00834048 _____ (Microsoft Corporation) C:\windows\system32\osk.exe Some content of TEMP: ==================== C:\Users\Christina\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-12 03:41 ==================== End Of Log ============================ --- --- --- --- --- --- DE] Richtig so ? Die Reihenfolge war falsch, sorry. LG |
17.07.2014, 13:28 | #4 | |
/// TB-Ausbilder | Lösung: Nach Omiga startet Telekom Browser nicht mehrZitat:
Zudem lassen sich dann am Ende der Bereinigung alle verwendeten Tools sehr einfach entfernen. |
17.07.2014, 13:49 | #5 |
| Wie Nach Omiga startet Telekom Browser nicht mehr Ok, hab das Programm jetzt auf dem Desktop. Soll ich nochmal scannen ? |
17.07.2014, 14:00 | #6 |
/// TB-Ausbilder | Wo Nach Omiga startet Telekom Browser nicht mehr Lösung! ja, und zwar so:
|
17.07.2014, 14:06 | #7 |
| Nach Omiga startet Telekom Browser nicht mehr FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-07-2014 01 Ran by Christina (administrator) on GEBBISFIRST on 17-07-2014 15:03:07 Running from C:\Users\Christina\Downloads Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= () C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe (Softex Inc.) C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe (AMD) C:\Windows\System32\atiesrxx.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\n360.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (AMD) C:\Windows\System32\atieclxx.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe () C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\n360.exe (Deutsche Telekom AG) C:\Program Files (x86)\Deutsche Telekom AG\Browser 7\Browser7.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\HPSmplPass.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATIJCE.EXE () C:\Users\Christina\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe () C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Sony Corporation) C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BDExtHost.exe (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BDAppHost.exe (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BDRuntimeHost.exe (Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\symerr.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SimplePass] => C:\Program Files\Hewlett-Packard\SimplePass\HPSmplPass.exe [2793016 2013-09-05] (Hewlett-Packard) HKLM\...\Run: [OPBHOBroker] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe [154680 2013-09-05] (Hewlett-Packard) HKLM\...\Run: [OPBHOBrokerDesktop] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe [154680 2013-09-05] (Hewlett-Packard) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13663448 2014-01-13] (Realtek Semiconductor) HKLM-x32\...\Run: [StartCCC] => c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-09-11] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Reader Application Helper] => C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe [899400 2013-11-27] (Sony Corporation) HKLM-x32\...\Run: [BingDesktop] => C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe [2368728 2014-05-23] (Microsoft Corp.) HKU\S-1-5-21-3508085089-3033536294-3423735549-1001\...\Run: [EPLTarget\P0000000000000000] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATIJCE.EXE [283232 2012-10-01] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-3508085089-3033536294-3423735549-1001\...\Run: [Amazon Cloud Player] => C:\Users\Christina\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe [3145536 2014-05-08] () HKU\S-1-5-21-3508085089-3033536294-3423735549-1001\...\MountPoints2: {35ffaafd-c4bf-11e3-8254-806e6f6e6963} - "E:\SETUP.EXE" Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ImageBrowser EX Agent.lnk ShortcutTarget: ImageBrowser EX Agent.lnk -> C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe () ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ShellIconOverlayIdentifiers: SkyDrivePro1 (ErrorConflict) -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: SkyDrivePro2 (SyncInProgress) -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: SkyDrivePro3 (InSync) -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: OverlayExcluded -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton 360\Engine64\21.4.0.13\buShell.dll (Symantec Corporation) ShellIconOverlayIdentifiers: OverlayPending -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton 360\Engine64\21.4.0.13\buShell.dll (Symantec Corporation) ShellIconOverlayIdentifiers: OverlayProtected -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton 360\Engine64\21.4.0.13\buShell.dll (Symantec Corporation) ShellIconOverlayIdentifiers-x32: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers-x32: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers-x32: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.t-online.de/ HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://isearch.glarysoft.com/?src=iehome HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://isearch.glarysoft.com/?src=iehome SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPDTDFJS SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPDTDFJS SearchScopes: HKLM - {A7ECAA6F-6CCA-49A8-B2A9-42C16E330BAF} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {c1d89ae7-449d-4929-b24b-fded04adbe06} URL = hxxp://isearch.glarysoft.com/?q={searchTerms}&src=iesearch SearchScopes: HKLM-x32 - {c1d89ae7-449d-4929-b24b-fded04adbe06} URL = hxxp://isearch.glarysoft.com/?q={searchTerms}&src=iesearch SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPDTDFJS SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPDTDFJS SearchScopes: HKCU - {c1d89ae7-449d-4929-b24b-fded04adbe06} URL = hxxp://isearch.glarysoft.com/?q={searchTerms}&src=iesearch SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine64\21.4.0.13\coIEPlg.dll (Symantec Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard) BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\coIEPlg.dll (Symantec Corporation) BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\IPS\IPSBHO.DLL (Symantec Corporation) BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard) Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine64\21.4.0.13\coIEPlg.dll (Symantec Corporation) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\coIEPlg.dll (Symantec Corporation) Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @sony.com/ReaderDesktop - C:\Program Files (x86)\Sony\ReaderDesktop\npreaderdetectmoz.dll (Sony Corporation) FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.0.1.3\coFFPlgn FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.0.1.3\coFFPlgn [2014-07-16] FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.0.1.3\IPSFF FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.0.1.3\IPSFF [2014-04-16] ==================== Services (Whitelisted) ================= R2 BingDesktopUpdate; C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [173784 2014-05-23] (Microsoft Corp.) S3 Browser7Maintenance; C:\Program Files (x86)\Browser 7 Maintenance Service\maintenanceservice.exe [117560 2014-06-10] (Deutsche Telekom AG) R2 Cachedrv server; C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe [109568 2013-09-05] () [File not signed] R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2356408 2014-06-19] (Microsoft Corporation) R2 CyberLink PowerDVD 12 Media Server Monitor Service; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [77576 2013-08-12] (CyberLink) R2 CyberLink PowerDVD 12 Media Server Service; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [298760 2013-08-12] (CyberLink) R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-08-27] (Hewlett-Packard Company) [File not signed] R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R2 N360; C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\N360.exe [265040 2014-06-27] (Symantec Corporation) R2 omniserv; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [87552 2013-09-05] (Softex Inc.) [File not signed] R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [290520 2014-01-13] (Realtek Semiconductor) S3 Sony SCSI Helper Service; C:\Program Files (x86)\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe [73728 2013-11-26] (Sony Corporation) [File not signed] S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2013-08-24] (Microsoft Corporation) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation) S2 0201921397581903mcinstcleanup; C:\windows\TEMP\020192~1.EXE -cleanup -nolog [X] S2 mcbootdelaystartsvc; "C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe" /McCoreSvc [X] ==================== Drivers (Whitelisted) ==================== R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36096 2013-05-22] (Advanced Micro Devices, Inc.) R1 BHDrvx64; C:\Program Files (x86)\Norton 360\NortonData\21.0.1.3\Definitions\BASHDefs\20140703.001\BHDrvx64.sys [1530160 2014-05-10] (Symantec Corporation) R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1504000.00D\ccSetx64.sys [162392 2014-02-25] (Symantec Corporation) R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-05] (CyberLink) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [486192 2014-06-21] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [142128 2014-06-21] (Symantec Corporation) R1 IDSVia64; C:\Program Files (x86)\Norton 360\NortonData\21.0.1.3\Definitions\IPSDefs\20140716.001\IDSvia64.sys [525016 2014-06-20] (Symantec Corporation) R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-07-17] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation) R3 NAVENG; C:\Program Files (x86)\Norton 360\NortonData\21.0.1.3\Definitions\VirusDefs\20140716.024\ENG64.SYS [126040 2014-06-21] (Symantec Corporation) R3 NAVEX15; C:\Program Files (x86)\Norton 360\NortonData\21.0.1.3\Definitions\VirusDefs\20140716.024\EX64.SYS [2099288 2014-06-21] (Symantec Corporation) R3 SRTSP; C:\Windows\System32\Drivers\N360x64\1504000.00D\SRTSP64.SYS [875736 2014-02-13] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1504000.00D\SRTSPX64.SYS [36952 2013-07-31] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\N360x64\1504000.00D\SYMDS64.SYS [493656 2013-08-01] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\N360x64\1504000.00D\SYMEFA64.SYS [1148120 2014-03-04] (Symantec Corporation) S0 SymELAM; C:\Windows\System32\drivers\N360x64\1504000.00D\SymELAM.sys [23568 2013-08-01] (Symantec Corporation) R3 SymEvent; C:\windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2014-04-15] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\N360x64\1504000.00D\Ironx64.SYS [264280 2013-07-31] (Symantec Corporation) R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1504000.00D\SYMNETS.SYS [593112 2014-02-18] (Symantec Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation) U3 McMPFSvc; U3 McNaiAnn; U3 mcpltsvc; U3 McProxy; U3 mfecore; U3 MSK80Service; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-17 15:03 - 2014-07-17 15:03 - 00018265 _____ () C:\Users\Christina\Downloads\FRST.txt 2014-07-17 14:48 - 2014-07-17 14:48 - 00001149 _____ () C:\Users\Christina\Desktop\FRST64 - Verknüpfung.lnk 2014-07-17 14:48 - 2014-07-17 14:48 - 00000926 _____ () C:\Users\Christina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FRST64.lnk 2014-07-17 14:45 - 2014-07-17 14:45 - 02086912 _____ (Farbar) C:\Users\Christina\Downloads\FRST64.exe 2014-07-17 08:29 - 2014-07-17 15:03 - 00000000 ____D () C:\FRST 2014-07-17 08:27 - 2014-07-17 08:27 - 01077248 _____ (Farbar) C:\Users\Christina\Downloads\FRST (2).exe 2014-07-17 08:25 - 2014-07-17 08:25 - 01077248 _____ (Farbar) C:\Users\Christina\Downloads\FRST.exe 2014-07-17 08:25 - 2014-07-17 08:25 - 01077248 _____ (Farbar) C:\Users\Christina\Downloads\FRST (1).exe 2014-07-16 20:00 - 2014-07-16 20:00 - 00602112 _____ (OldTimer Tools) C:\Users\Christina\Downloads\OTL.exe 2014-07-16 19:12 - 2014-07-16 19:12 - 00000000 ____D () C:\Program Files\AMD 2014-07-16 19:10 - 2014-06-05 16:13 - 00216368 _____ (Microsoft Corporation) C:\windows\system32\rsaenh.dll 2014-07-16 19:10 - 2014-06-05 15:14 - 00189016 _____ (Microsoft Corporation) C:\windows\SysWOW64\rsaenh.dll 2014-07-16 19:10 - 2014-06-02 04:10 - 00423768 _____ (Microsoft Corporation) C:\windows\system32\hal.dll 2014-07-16 19:10 - 2014-05-31 12:07 - 00467800 ____C (Microsoft Corporation) C:\windows\system32\Drivers\USBHUB3.SYS 2014-07-16 19:10 - 2014-05-31 12:07 - 00440664 ____C (Microsoft Corporation) C:\windows\system32\Drivers\usbport.sys 2014-07-16 19:10 - 2014-05-31 12:07 - 00419672 ____C (Microsoft Corporation) C:\windows\system32\Drivers\usbhub.sys 2014-07-16 19:10 - 2014-05-31 12:07 - 00089944 ____C (Microsoft Corporation) C:\windows\system32\Drivers\usbehci.sys 2014-07-16 19:10 - 2014-05-31 12:07 - 00027480 ____C (Microsoft Corporation) C:\windows\system32\Drivers\usbd.sys 2014-07-16 19:10 - 2014-05-31 08:30 - 00037376 ____C (Microsoft Corporation) C:\windows\system32\Drivers\usbuhci.sys 2014-07-16 19:10 - 2014-05-31 08:27 - 00206848 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys 2014-07-16 19:10 - 2014-05-31 08:27 - 00110592 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WUDFPf.sys 2014-07-16 19:10 - 2014-05-31 08:26 - 00227840 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WUDFRd.sys 2014-07-16 19:10 - 2014-05-31 06:01 - 00284672 _____ (Microsoft Corporation) C:\windows\system32\WUDFHost.exe 2014-07-16 19:10 - 2014-05-31 06:01 - 00209408 _____ (Microsoft Corporation) C:\windows\system32\WUDFPlatform.dll 2014-07-16 19:10 - 2014-05-31 06:01 - 00099840 _____ (Microsoft Corporation) C:\windows\system32\WUDFSvc.dll 2014-07-16 19:10 - 2014-05-27 17:53 - 02518360 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys 2014-07-16 19:10 - 2014-05-27 11:56 - 00323584 _____ (Microsoft Corporation) C:\windows\system32\DaOtpCredentialProvider.dll 2014-07-16 19:10 - 2014-05-27 11:53 - 00270848 _____ (Microsoft Corporation) C:\windows\SysWOW64\DaOtpCredentialProvider.dll 2014-07-16 19:10 - 2014-05-17 06:59 - 16871936 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Xaml.dll 2014-07-16 19:10 - 2014-05-17 06:13 - 12711424 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Xaml.dll 2014-07-16 19:10 - 2014-05-15 00:47 - 04720640 _____ (Microsoft Corporation) C:\windows\system32\SyncEngine.dll 2014-07-16 19:10 - 2014-05-13 09:01 - 00076800 _____ (Microsoft Corporation) C:\windows\system32\BulkOperationHost.exe 2014-07-16 19:10 - 2014-05-13 07:07 - 02844160 _____ (Microsoft Corporation) C:\windows\system32\actxprxy.dll 2014-07-16 19:10 - 2014-05-13 06:41 - 00118272 _____ (Microsoft Corporation) C:\windows\system32\winbici.dll 2014-07-16 19:10 - 2014-05-13 06:27 - 00716800 _____ (Microsoft Corporation) C:\windows\system32\SkyDriveTelemetry.dll 2014-07-16 19:10 - 2014-05-13 06:26 - 00285696 _____ (Microsoft Corporation) C:\windows\system32\SkyDriveShell.dll 2014-07-16 19:10 - 2014-05-13 05:59 - 01035264 _____ (Microsoft Corporation) C:\windows\SysWOW64\actxprxy.dll 2014-07-16 19:10 - 2014-05-13 05:41 - 01118720 _____ (Microsoft Corporation) C:\windows\system32\SkyDrive.exe 2014-07-16 19:10 - 2014-05-13 05:31 - 00265216 _____ (Microsoft Corporation) C:\windows\SysWOW64\SkyDriveShell.dll 2014-07-16 19:10 - 2014-05-03 13:29 - 01726224 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll 2014-07-16 19:10 - 2014-05-03 11:20 - 01473080 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll 2014-07-16 19:10 - 2014-05-03 07:36 - 00997888 _____ (Microsoft Corporation) C:\windows\system32\reseteng.dll 2014-07-16 19:10 - 2014-05-03 07:19 - 00071168 _____ (Microsoft Corporation) C:\windows\system32\ncobjapi.dll 2014-07-16 19:10 - 2014-05-03 07:08 - 00301056 _____ (Microsoft Corporation) C:\windows\system32\framedynos.dll 2014-07-16 19:10 - 2014-05-03 07:07 - 00262656 _____ (Microsoft Corporation) C:\windows\system32\framedyn.dll 2014-07-16 19:10 - 2014-05-03 06:46 - 00052736 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncobjapi.dll 2014-07-16 19:10 - 2014-05-03 06:37 - 00235008 _____ (Microsoft Corporation) C:\windows\SysWOW64\framedynos.dll 2014-07-16 19:10 - 2014-05-03 06:37 - 00207360 _____ (Microsoft Corporation) C:\windows\SysWOW64\framedyn.dll 2014-07-16 19:10 - 2014-05-03 05:30 - 02641920 _____ (Microsoft Corporation) C:\windows\system32\authui.dll 2014-07-16 19:10 - 2014-05-03 05:27 - 02317824 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll 2014-07-16 19:10 - 2014-05-03 01:26 - 00050745 _____ () C:\windows\system32\srms.dat 2014-07-16 19:10 - 2014-05-01 07:44 - 01025536 _____ (Microsoft Corporation) C:\windows\system32\localspl.dll 2014-07-16 19:10 - 2014-04-30 08:43 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\vwififlt.sys 2014-07-16 19:10 - 2014-04-30 08:41 - 00402432 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys 2014-07-16 19:10 - 2014-04-30 08:41 - 00096768 _____ (Microsoft Corporation) C:\windows\system32\Drivers\agilevpn.sys 2014-07-16 19:10 - 2014-04-30 08:41 - 00038912 _____ (Microsoft Corporation) C:\windows\system32\Drivers\vwifimp.sys 2014-07-16 19:10 - 2014-04-30 07:45 - 00123392 _____ (Microsoft Corporation) C:\windows\system32\Robocopy.exe 2014-07-16 19:10 - 2014-04-30 06:48 - 00106496 _____ (Microsoft Corporation) C:\windows\SysWOW64\Robocopy.exe 2014-07-16 19:10 - 2014-04-30 06:24 - 00065024 _____ (Microsoft Corporation) C:\windows\system32\dhcpcsvc6.dll 2014-07-16 19:10 - 2014-04-30 06:23 - 00353280 _____ (Microsoft Corporation) C:\windows\system32\dhcpcore.dll 2014-07-16 19:10 - 2014-04-30 06:23 - 00271872 _____ (Microsoft Corporation) C:\windows\system32\dhcpcore6.dll 2014-07-16 19:10 - 2014-04-30 06:23 - 00087552 _____ (Microsoft Corporation) C:\windows\system32\dhcpcsvc.dll 2014-07-16 19:10 - 2014-04-30 06:14 - 00827392 _____ (Microsoft Corporation) C:\windows\system32\BFE.DLL 2014-07-16 19:10 - 2014-04-30 05:59 - 01063424 _____ (Microsoft Corporation) C:\windows\system32\IKEEXT.DLL 2014-07-16 19:10 - 2014-04-30 05:46 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dhcpcore.dll 2014-07-16 19:10 - 2014-04-30 05:46 - 00229888 _____ (Microsoft Corporation) C:\windows\SysWOW64\dhcpcore6.dll 2014-07-16 19:10 - 2014-04-30 05:46 - 00056320 _____ (Microsoft Corporation) C:\windows\SysWOW64\dhcpcsvc6.dll 2014-07-16 19:10 - 2014-04-30 05:45 - 00062976 _____ (Microsoft Corporation) C:\windows\SysWOW64\dhcpcsvc.dll 2014-07-16 19:10 - 2014-04-30 05:42 - 00403968 _____ (Microsoft Corporation) C:\windows\system32\vpnike.dll 2014-07-16 19:10 - 2014-04-29 00:40 - 00721408 _____ (Microsoft Corporation) C:\windows\system32\fveapi.dll 2014-07-16 19:10 - 2014-04-27 00:03 - 02140888 _____ (Microsoft Corporation) C:\windows\system32\mfcore.dll 2014-07-16 19:10 - 2014-04-26 22:14 - 02144984 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfcore.dll 2014-07-16 19:10 - 2014-04-26 18:39 - 00339456 _____ (Microsoft Corporation) C:\windows\system32\bdesvc.dll 2014-07-16 19:10 - 2014-04-14 11:37 - 02125344 _____ (Microsoft Corporation) C:\windows\system32\d3d9.dll 2014-07-16 19:10 - 2014-04-14 10:08 - 01797896 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d9.dll 2014-07-16 19:10 - 2014-04-14 07:18 - 00011776 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d8thk.dll 2014-07-16 19:10 - 2014-04-09 08:11 - 00226816 _____ (Microsoft Corporation) C:\windows\system32\WebClnt.dll 2014-07-16 19:10 - 2014-04-09 07:20 - 00198656 _____ (Microsoft Corporation) C:\windows\SysWOW64\WebClnt.dll 2014-07-16 18:51 - 2014-07-16 18:51 - 00001359 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Browser 7 der Telekom.lnk 2014-07-16 18:51 - 2014-07-16 18:51 - 00001347 _____ () C:\Users\Public\Desktop\Browser 7 der Telekom.lnk 2014-07-16 18:51 - 2014-07-16 18:51 - 00000000 ____D () C:\Program Files (x86)\Browser 7 Maintenance Service 2014-07-16 18:48 - 2014-07-16 18:48 - 00362592 _____ (Deutsche Telekom AG) C:\Users\Christina\Downloads\browser7_setup (1).exe.hy7enp8.partial 2014-07-16 18:22 - 2014-07-16 18:27 - 00000000 ____D () C:\Users\Christina\AppData\Roaming\GlarySoft 2014-07-16 18:22 - 2014-07-16 18:22 - 00001129 _____ () C:\Users\Christina\Desktop\Absolute Uninstaller.lnk 2014-07-16 18:21 - 2014-07-16 18:21 - 02194784 _____ (Glarysoft.com ) C:\Users\Christina\Downloads\au29setup.exe 2014-07-16 18:21 - 2014-07-16 18:21 - 02194784 _____ (Glarysoft.com ) C:\Users\Christina\Downloads\au29setup (1).exe 2014-07-16 17:29 - 2014-07-16 17:29 - 02347384 _____ (ESET) C:\Users\Christina\Downloads\esetsmartinstaller_enu.exe 2014-07-16 17:28 - 2014-07-16 17:28 - 00441592 _____ (Bleeping Computer, LLC) C:\Users\Christina\Downloads\sc-cleaner.exe 2014-07-16 17:28 - 2014-07-16 17:28 - 00001770 _____ () C:\sc-cleaner.txt 2014-07-16 17:09 - 2014-07-16 17:09 - 00000911 _____ () C:\Users\Christina\Desktop\JRT.txt 2014-07-16 16:59 - 2014-07-16 16:59 - 00000000 ____D () C:\windows\ERUNT 2014-07-16 16:58 - 2014-07-16 16:58 - 01016261 _____ (Thisisu) C:\Users\Christina\Downloads\JRT.exe 2014-07-16 16:44 - 2014-07-16 16:47 - 00000000 ____D () C:\AdwCleaner 2014-07-16 16:43 - 2014-07-16 16:43 - 01348263 _____ () C:\Users\Christina\Downloads\adwcleaner_3.215.exe 2014-07-16 16:34 - 2014-07-16 18:43 - 00000000 ____D () C:\NPE 2014-07-16 16:28 - 2014-07-16 16:28 - 00010226 _____ () C:\Users\Christina\Downloads\hijackthis.log 2014-07-16 16:27 - 2014-07-16 16:27 - 00388608 _____ (Trend Micro Inc.) C:\Users\Christina\Downloads\HijackThis.exe 2014-07-16 16:21 - 2014-07-16 16:21 - 00304857 _____ () C:\Users\Christina\Downloads\HijackThis_205.zip 2014-07-16 15:46 - 2014-07-17 12:49 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-16 15:45 - 2014-07-16 15:45 - 00003190 _____ () C:\windows\System32\Tasks\{AD428E5A-001B-408D-97F0-5BBCB5C4A4C4} 2014-07-16 15:44 - 2014-07-16 15:44 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Christina\Downloads\mbam-setup-2.0.2.1012.exe 2014-07-16 15:44 - 2014-07-16 15:44 - 00001125 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-07-16 15:44 - 2014-07-16 15:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-16 15:44 - 2014-07-16 15:44 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-16 15:44 - 2014-07-16 15:44 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-07-16 15:44 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys 2014-07-16 15:44 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys 2014-07-16 15:44 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2014-07-16 15:22 - 2014-07-16 15:22 - 00362592 _____ (Deutsche Telekom AG) C:\Users\Christina\Downloads\browser7_setup.exe 2014-07-16 15:11 - 2014-07-16 15:11 - 01286520 _____ (Netviewer AG) C:\Users\Christina\Downloads\diagnose.exe 2014-07-16 14:03 - 2014-07-16 14:03 - 00000000 ____H () C:\windows\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf 2014-07-16 13:11 - 2014-07-16 13:11 - 00000000 ____D () C:\windows\System32\Tasks\Norton 360 2014-07-16 12:48 - 2014-07-16 12:48 - 00000000 ____D () C:\Users\Christina\Documents\Neuer Ordner 2014-07-14 16:28 - 2014-07-14 16:28 - 00001550 _____ () C:\Users\Christina\Downloads\URLLink(73).acsm 2014-07-14 16:27 - 2014-07-14 16:27 - 00001501 _____ () C:\Users\Christina\Downloads\URLLink(70).acsm 2014-07-14 16:27 - 2014-07-14 16:27 - 00001475 _____ () C:\Users\Christina\Downloads\URLLink(71).acsm 2014-07-14 16:27 - 2014-07-14 16:27 - 00001458 _____ () C:\Users\Christina\Downloads\URLLink(72).acsm 2014-07-09 07:30 - 2014-04-14 05:29 - 01018880 _____ (Microsoft Corporation) C:\windows\system32\termsrv.dll 2014-07-09 07:18 - 2014-06-17 00:26 - 00779264 _____ (Microsoft Corporation) C:\windows\SysWOW64\osk.exe 2014-07-09 07:18 - 2014-06-17 00:24 - 00834048 _____ (Microsoft Corporation) C:\windows\system32\osk.exe 2014-07-09 07:18 - 2014-06-06 16:20 - 04190720 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys 2014-07-09 07:18 - 2014-05-30 05:03 - 00563200 _____ (Microsoft Corporation) C:\windows\system32\Drivers\afd.sys 2014-07-09 07:18 - 2014-05-29 14:02 - 00565576 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys 2014-07-09 07:18 - 2014-05-29 09:55 - 00735232 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll 2014-07-09 07:18 - 2014-05-29 08:40 - 00735232 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll 2014-07-09 07:18 - 2014-05-29 08:37 - 00436224 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll 2014-07-09 07:18 - 2014-05-29 07:34 - 00318976 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll 2014-07-09 07:18 - 2014-05-29 07:27 - 01417216 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll 2014-07-09 07:17 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-07-09 07:17 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2014-07-09 07:17 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2014-07-09 07:17 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2014-07-09 07:17 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2014-07-09 07:17 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2014-07-09 07:17 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2014-07-09 07:17 - 2014-06-19 01:46 - 00250880 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll 2014-07-09 07:17 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2014-07-09 07:17 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2014-07-09 07:17 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll 2014-07-09 07:17 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2014-07-09 07:17 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll 2014-07-09 07:17 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll 2014-07-09 07:17 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2014-07-09 07:17 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll 2014-07-09 07:17 - 2014-06-19 00:57 - 00225280 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll 2014-07-09 07:17 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll 2014-07-09 07:17 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2014-07-09 07:17 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll 2014-07-09 07:17 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl 2014-07-09 07:17 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll 2014-07-09 07:17 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2014-07-09 07:17 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2014-07-09 07:17 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll 2014-07-09 07:17 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll 2014-07-09 07:17 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll 2014-07-09 07:17 - 2014-06-06 15:04 - 00586240 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll 2014-07-09 07:17 - 2014-06-06 14:18 - 00488960 _____ (Microsoft Corporation) C:\windows\SysWOW64\qedit.dll 2014-07-09 07:17 - 2014-05-31 05:40 - 13287936 _____ (Microsoft Corporation) C:\windows\system32\twinui.dll 2014-07-09 07:17 - 2014-05-31 04:36 - 00923136 _____ (Microsoft Corporation) C:\windows\system32\WSShared.dll 2014-07-09 07:17 - 2014-05-31 04:32 - 00756224 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSShared.dll 2014-07-09 07:16 - 2014-05-31 12:07 - 00054776 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe 2014-07-09 07:16 - 2014-05-31 12:06 - 00555736 _____ (Microsoft Corporation) C:\windows\system32\twinapi.appcore.dll 2014-07-09 07:16 - 2014-05-31 05:30 - 11792384 _____ (Microsoft Corporation) C:\windows\SysWOW64\twinui.dll 2014-07-09 07:16 - 2014-05-31 05:12 - 00249344 _____ (Microsoft Corporation) C:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2014-07-09 07:16 - 2014-05-31 05:06 - 00093696 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll 2014-07-09 07:16 - 2014-05-31 05:03 - 00827392 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll 2014-07-09 07:16 - 2014-05-31 05:01 - 00189952 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2014-07-09 07:16 - 2014-05-31 04:56 - 00080896 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll 2014-07-09 07:16 - 2014-05-31 04:54 - 00666624 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll 2014-07-09 07:16 - 2014-05-31 04:48 - 03463680 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll 2014-07-09 07:16 - 2014-05-31 04:37 - 01054208 _____ (Microsoft Corporation) C:\windows\system32\twinui.appcore.dll 2014-07-09 07:16 - 2014-05-31 04:35 - 00828928 _____ (Microsoft Corporation) C:\windows\SysWOW64\twinui.appcore.dll 2014-07-09 07:13 - 2014-07-09 07:13 - 00079872 _____ (Microsoft Corporation) C:\windows\system32\WSReset.exe 2014-07-08 14:22 - 2014-07-08 14:23 - 00001563 _____ () C:\Users\Christina\Downloads\URLLink(69).acsm 2014-07-08 09:03 - 2014-07-08 09:03 - 00001516 _____ () C:\Users\Christina\Downloads\URLLink(68).acsm 2014-07-02 09:56 - 2014-07-02 09:56 - 01058200 _____ (Adobe) C:\Users\Christina\Downloads\install_flashplayer14x32au_mssa_aaa_aih(1).exe 2014-06-29 19:11 - 2014-06-29 19:11 - 00001549 _____ () C:\Users\Christina\Downloads\URLLink(67).acsm 2014-06-29 19:10 - 2014-06-29 19:10 - 00001580 _____ () C:\Users\Christina\Downloads\URLLink(66).acsm 2014-06-29 19:10 - 2014-06-29 19:10 - 00001546 _____ () C:\Users\Christina\Downloads\URLLink(65).acsm 2014-06-29 19:10 - 2014-06-29 19:10 - 00001472 _____ () C:\Users\Christina\Downloads\URLLink(64).acsm 2014-06-29 19:10 - 2014-06-29 19:10 - 00001470 _____ () C:\Users\Christina\Downloads\URLLink(63).acsm 2014-06-29 19:10 - 2014-06-29 19:10 - 00001469 _____ () C:\Users\Christina\Downloads\URLLink(62).acsm 2014-06-27 14:25 - 2014-06-27 14:25 - 00001486 _____ () C:\Users\Christina\Downloads\URLLink(59).acsm 2014-06-27 14:25 - 2014-06-27 14:25 - 00001457 _____ () C:\Users\Christina\Downloads\URLLink(61).acsm 2014-06-27 14:25 - 2014-06-27 14:25 - 00001457 _____ () C:\Users\Christina\Downloads\URLLink(60).acsm 2014-06-26 20:01 - 2014-06-26 20:01 - 00025664 _____ () C:\Users\Christina\Documents\Elisa 12. Geburtstag.odt 2014-06-25 20:13 - 2014-06-25 20:13 - 05408139 _____ () C:\Users\Christina\Downloads\AmazonApps-release.apk 2014-06-23 20:46 - 2014-06-25 10:30 - 00014094 _____ () C:\Users\Christina\Documents\ADAC.odt 2014-06-23 17:07 - 2014-06-23 17:07 - 01058200 _____ (Adobe) C:\Users\Christina\Downloads\install_flashplayer14x32au_mssa_aaa_aih.exe 2014-06-22 19:53 - 2014-06-22 19:53 - 00001518 _____ () C:\Users\Christina\Downloads\URLLink(58).acsm 2014-06-22 19:52 - 2014-06-22 19:52 - 00001549 _____ () C:\Users\Christina\Downloads\URLLink(57).acsm 2014-06-22 19:44 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2014-06-22 19:44 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll 2014-06-22 19:44 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll 2014-06-22 19:44 - 2014-05-10 05:46 - 02151424 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll 2014-06-22 19:44 - 2014-05-10 05:22 - 01312256 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll 2014-06-22 19:44 - 2014-05-05 06:02 - 03360256 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll 2014-06-22 19:44 - 2014-04-30 13:16 - 01336648 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll 2014-06-22 19:44 - 2014-04-30 05:51 - 01064448 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll 2014-06-22 19:43 - 2014-07-16 19:07 - 00428888 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS 2014-06-22 19:43 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll 2014-06-22 19:43 - 2014-05-09 01:06 - 00295424 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ks.sys 2014-06-22 19:43 - 2014-04-18 16:57 - 00032600 _____ (Microsoft Corporation) C:\windows\system32\ploptin.dll 2014-06-22 19:43 - 2014-04-18 16:44 - 01466856 _____ (Microsoft Corporation) C:\windows\system32\propsys.dll 2014-06-22 19:43 - 2014-04-18 15:29 - 01200288 _____ (Microsoft Corporation) C:\windows\SysWOW64\propsys.dll 2014-06-22 19:43 - 2014-04-18 11:44 - 00055296 _____ (Microsoft Corporation) C:\windows\system32\energyprov.dll 2014-06-22 19:43 - 2014-04-18 10:32 - 00805376 _____ (Microsoft Corporation) C:\windows\system32\win32spl.dll 2014-06-22 19:43 - 2014-04-18 10:21 - 01126912 _____ (Microsoft Corporation) C:\windows\system32\SearchFolder.dll 2014-06-22 19:43 - 2014-04-18 10:09 - 08652800 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Search.dll 2014-06-22 19:43 - 2014-04-18 09:51 - 00836608 _____ (Microsoft Corporation) C:\windows\SysWOW64\SearchFolder.dll 2014-06-22 19:43 - 2014-04-18 09:49 - 05833216 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Search.dll 2014-06-22 19:43 - 2014-04-14 11:20 - 00324888 _____ (Microsoft Corporation) C:\windows\system32\MFCaptureEngine.dll 2014-06-22 19:43 - 2014-04-14 10:01 - 00285144 _____ (Microsoft Corporation) C:\windows\SysWOW64\MFCaptureEngine.dll 2014-06-22 19:43 - 2014-04-11 06:51 - 00250368 _____ (Microsoft Corporation) C:\windows\system32\rdpencom.dll 2014-06-22 19:43 - 2014-04-11 06:23 - 00209920 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdpencom.dll 2014-06-22 19:43 - 2014-04-11 05:30 - 00449536 _____ (Microsoft Corporation) C:\windows\system32\defragsvc.dll 2014-06-22 19:43 - 2014-04-09 13:53 - 00337240 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Classpnp.sys 2014-06-22 19:43 - 2014-04-09 08:39 - 00191488 _____ (Microsoft Corporation) C:\windows\system32\rpchttp.dll 2014-06-22 19:43 - 2014-04-09 07:44 - 00144384 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpchttp.dll 2014-06-22 19:43 - 2014-04-09 05:33 - 00135168 _____ (Microsoft Corporation) C:\windows\system32\wscsvc.dll 2014-06-22 19:43 - 2014-04-08 04:01 - 00589656 _____ (Microsoft Corporation) C:\windows\system32\Drivers\fvevol.sys 2014-06-22 19:43 - 2014-04-06 18:34 - 00372568 _____ (Microsoft Corporation) C:\windows\system32\Drivers\storport.sys 2014-06-22 19:43 - 2014-04-06 18:34 - 00275800 ____C (Microsoft Corporation) C:\windows\system32\Drivers\msiscsi.sys 2014-06-22 19:43 - 2014-04-06 18:32 - 00125496 _____ (Microsoft Corporation) C:\windows\system32\dwmapi.dll 2014-06-22 19:43 - 2014-04-06 18:31 - 21268952 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll 2014-06-22 19:43 - 2014-04-06 18:30 - 00201920 _____ (Microsoft Corporation) C:\windows\system32\MSVideoDSP.dll 2014-06-22 19:43 - 2014-04-06 18:24 - 00360792 _____ (Microsoft Corporation) C:\windows\system32\Drivers\fltMgr.sys 2014-06-22 19:43 - 2014-04-06 18:20 - 01403856 _____ (Microsoft Corporation) C:\windows\system32\winmde.dll 2014-06-22 19:43 - 2014-04-06 18:20 - 01379064 _____ (Microsoft Corporation) C:\windows\system32\wmpmde.dll 2014-06-22 19:43 - 2014-04-06 18:20 - 00881616 _____ (Microsoft Corporation) C:\windows\system32\mfplat.dll 2014-06-22 19:43 - 2014-04-06 18:20 - 00765408 _____ (Microsoft Corporation) C:\windows\system32\mfmpeg2srcsnk.dll 2014-06-22 19:43 - 2014-04-06 18:20 - 00609448 _____ (Microsoft Corporation) C:\windows\system32\mf.dll 2014-06-22 19:43 - 2014-04-06 18:20 - 00491744 _____ (Microsoft Corporation) C:\windows\system32\mfsvr.dll 2014-06-22 19:43 - 2014-04-06 18:20 - 00467496 _____ (Microsoft Corporation) C:\windows\system32\AudioSes.dll 2014-06-22 19:43 - 2014-04-06 18:20 - 00463256 _____ (Microsoft Corporation) C:\windows\system32\AudioEng.dll 2014-06-22 19:43 - 2014-04-06 18:20 - 00364640 _____ (Microsoft Corporation) C:\windows\system32\AUDIOKSE.dll 2014-06-22 19:43 - 2014-04-06 18:20 - 00244880 _____ (Microsoft Corporation) C:\windows\system32\audiodg.exe 2014-06-22 19:43 - 2014-04-06 18:20 - 00028408 _____ (Microsoft Corporation) C:\windows\system32\mfpmp.exe 2014-06-22 19:43 - 2014-04-06 17:23 - 00098584 _____ (Microsoft Corporation) C:\windows\SysWOW64\dwmapi.dll 2014-06-22 19:43 - 2014-04-06 17:22 - 18755672 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll 2014-06-22 19:43 - 2014-04-06 17:22 - 00178184 _____ (Microsoft Corporation) C:\windows\SysWOW64\MSVideoDSP.dll 2014-06-22 19:43 - 2014-04-06 17:16 - 01209616 _____ (Microsoft Corporation) C:\windows\SysWOW64\winmde.dll 2014-06-22 19:43 - 2014-04-06 17:16 - 00707048 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfplat.dll 2014-06-22 19:43 - 2014-04-06 17:16 - 00669856 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfmpeg2srcsnk.dll 2014-06-22 19:43 - 2014-04-06 17:16 - 00518544 _____ (Microsoft Corporation) C:\windows\SysWOW64\mf.dll 2014-06-22 19:43 - 2014-04-06 17:16 - 00406504 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioEng.dll 2014-06-22 19:43 - 2014-04-06 17:16 - 00387896 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfsvr.dll 2014-06-22 19:43 - 2014-04-06 17:16 - 00326024 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioSes.dll 2014-06-22 19:43 - 2014-04-06 17:16 - 00305768 _____ (Microsoft Corporation) C:\windows\SysWOW64\AUDIOKSE.dll 2014-06-22 19:43 - 2014-04-06 14:58 - 00070656 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll 2014-06-22 19:43 - 2014-04-06 14:51 - 00467968 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll 2014-06-22 19:43 - 2014-04-06 14:33 - 00335872 _____ (Microsoft Corporation) C:\windows\system32\MDEServer.exe 2014-06-22 19:43 - 2014-04-06 14:24 - 00271872 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe 2014-06-22 19:43 - 2014-04-06 14:06 - 00061440 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll 2014-06-22 19:43 - 2014-04-06 13:26 - 00143872 _____ (Microsoft Corporation) C:\windows\system32\BootMenuUX.dll 2014-06-22 19:43 - 2014-04-06 13:20 - 00201216 _____ (Microsoft Corporation) C:\windows\system32\AudioEndpointBuilder.dll 2014-06-22 19:43 - 2014-04-06 13:01 - 00834048 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll 2014-06-22 19:43 - 2014-04-06 12:52 - 00955904 _____ (Microsoft Corporation) C:\windows\system32\MFMediaEngine.dll 2014-06-22 19:43 - 2014-04-06 12:51 - 01230336 _____ (Microsoft Corporation) C:\windows\system32\Windows.Media.dll 2014-06-22 19:43 - 2014-04-06 12:37 - 00800768 _____ (Microsoft Corporation) C:\windows\SysWOW64\MFMediaEngine.dll 2014-06-22 19:43 - 2014-04-06 12:36 - 00888320 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Media.dll 2014-06-22 19:43 - 2014-04-06 12:05 - 01222656 _____ (Microsoft Corporation) C:\windows\system32\Windows.Media.Streaming.dll 2014-06-22 19:43 - 2014-04-06 11:59 - 00982016 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Media.Streaming.dll 2014-06-22 19:43 - 2014-04-03 10:12 - 00307304 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll 2014-06-22 19:43 - 2014-04-03 10:12 - 00130144 _____ (Microsoft Corporation) C:\windows\system32\gpapi.dll 2014-06-22 19:43 - 2014-04-03 06:03 - 00230808 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll 2014-06-22 19:43 - 2014-04-03 06:03 - 00111528 _____ (Microsoft Corporation) C:\windows\SysWOW64\gpapi.dll 2014-06-22 19:43 - 2014-04-03 04:53 - 00677376 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv2.sys 2014-06-22 19:43 - 2014-04-03 04:51 - 01584128 _____ (Microsoft Corporation) C:\windows\system32\workfolderssvc.dll 2014-06-22 19:43 - 2014-04-03 04:23 - 00046592 _____ (Microsoft Corporation) C:\windows\SysWOW64\tlscsp.dll 2014-06-22 19:43 - 2014-04-03 04:22 - 00047616 _____ (Microsoft Corporation) C:\windows\system32\tlscsp.dll 2014-06-22 19:43 - 2014-04-01 08:23 - 00384856 ____C (Microsoft Corporation) C:\windows\system32\Drivers\spaceport.sys 2014-06-22 19:43 - 2014-03-31 07:42 - 07425368 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe 2014-06-22 19:43 - 2014-03-31 02:01 - 00186880 _____ (Microsoft Corporation) C:\windows\system32\WorkFoldersShell.dll 2014-06-22 19:43 - 2014-03-31 01:43 - 00761856 _____ (Microsoft Corporation) C:\windows\system32\WorkfoldersControl.dll 2014-06-22 19:43 - 2014-03-31 00:54 - 01308160 _____ (Microsoft Corporation) C:\windows\system32\gpsvc.dll 2014-06-22 19:43 - 2014-03-31 00:49 - 01287168 _____ (Microsoft Corporation) C:\windows\system32\mispace.dll 2014-06-22 19:43 - 2014-03-31 00:35 - 01029120 _____ (Microsoft Corporation) C:\windows\SysWOW64\mispace.dll 2014-06-22 19:43 - 2014-03-28 17:58 - 00407016 _____ (Microsoft Corporation) C:\windows\system32\services.exe 2014-06-22 19:43 - 2014-03-27 08:16 - 00246272 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srvnet.sys 2014-06-22 19:43 - 2014-03-27 07:36 - 00281600 _____ (Microsoft Corporation) C:\windows\system32\resutils.dll 2014-06-22 19:43 - 2014-03-27 06:59 - 00426496 _____ (Microsoft Corporation) C:\windows\system32\clusapi.dll 2014-06-22 19:43 - 2014-03-27 06:48 - 00219136 _____ (Microsoft Corporation) C:\windows\SysWOW64\resutils.dll 2014-06-22 19:43 - 2014-03-27 06:19 - 00313344 _____ (Microsoft Corporation) C:\windows\SysWOW64\clusapi.dll 2014-06-22 19:43 - 2014-03-27 05:46 - 00323072 _____ (Microsoft Corporation) C:\windows\system32\srvsvc.dll 2014-06-22 19:43 - 2014-03-27 05:15 - 00718336 _____ (Microsoft Corporation) C:\windows\system32\swprv.dll 2014-06-22 19:43 - 2014-03-27 05:10 - 01436160 _____ (Microsoft Corporation) C:\windows\system32\VSSVC.exe 2014-06-22 19:43 - 2014-03-20 05:48 - 00263424 _____ (Microsoft Corporation) C:\windows\system32\SystemSettingsAdminFlows.exe 2014-06-22 19:43 - 2014-03-20 02:44 - 06645248 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll 2014-06-22 19:43 - 2014-03-20 01:33 - 05774848 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll 2014-06-22 19:43 - 2014-03-19 10:15 - 00011264 _____ (Microsoft Corporation) C:\windows\system32\wlanhlp.dll 2014-06-22 19:43 - 2014-03-19 10:07 - 00443904 _____ (Microsoft Corporation) C:\windows\system32\Drivers\nwifi.sys 2014-06-22 19:43 - 2014-03-19 09:24 - 00064512 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll 2014-06-22 19:43 - 2014-03-19 09:17 - 00011264 _____ (Microsoft Corporation) C:\windows\SysWOW64\wlanhlp.dll 2014-06-22 19:43 - 2014-03-19 08:36 - 01057280 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll 2014-06-22 19:43 - 2014-03-19 07:56 - 00855552 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdvidcrl.dll 2014-06-22 19:43 - 2014-03-19 07:45 - 00443904 _____ (Microsoft Corporation) C:\windows\system32\wlansec.dll 2014-06-22 19:43 - 2014-03-19 07:19 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\wlanapi.dll 2014-06-22 19:43 - 2014-03-19 07:07 - 00370176 _____ (Microsoft Corporation) C:\windows\system32\wlanmsm.dll 2014-06-22 19:43 - 2014-03-19 07:02 - 01527296 _____ (Microsoft Corporation) C:\windows\system32\wlansvc.dll 2014-06-22 19:43 - 2014-03-19 07:00 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\wlanapi.dll 2014-06-22 19:43 - 2014-03-19 06:51 - 00300544 _____ (Microsoft Corporation) C:\windows\SysWOW64\wlanmsm.dll 2014-06-22 19:43 - 2014-03-19 06:31 - 02100736 _____ (Microsoft Corporation) C:\windows\system32\SystemSettingsAdminFlowUI.dll 2014-06-22 19:43 - 2014-03-19 06:18 - 02688000 _____ (Microsoft Corporation) C:\windows\system32\SettingsHandlers.dll 2014-06-22 19:43 - 2014-03-18 10:19 - 00077312 ____C (Microsoft Corporation) C:\windows\system32\Drivers\hdaudbus.sys 2014-06-22 19:43 - 2014-03-18 07:00 - 07173120 _____ (Microsoft Corporation) C:\windows\system32\Windows.Data.Pdf.dll 2014-06-22 19:43 - 2014-03-18 06:52 - 05104640 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Data.Pdf.dll 2014-06-22 19:43 - 2014-03-17 07:09 - 00462336 _____ (Microsoft Corporation) C:\windows\system32\XpsGdiConverter.dll 2014-06-22 19:43 - 2014-03-17 06:11 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\XpsGdiConverter.dll 2014-06-22 19:43 - 2014-03-17 05:01 - 00486912 _____ (Microsoft Corporation) C:\windows\system32\winspool.drv 2014-06-22 19:43 - 2014-03-17 04:45 - 00370176 _____ (Microsoft Corporation) C:\windows\SysWOW64\winspool.drv 2014-06-22 19:43 - 2014-03-14 08:26 - 00491520 _____ (Microsoft Corporation) C:\windows\system32\GeofenceMonitorService.dll 2014-06-22 19:43 - 2014-03-14 08:10 - 00357376 _____ (Microsoft Corporation) C:\windows\SysWOW64\GeofenceMonitorService.dll 2014-06-22 19:43 - 2014-03-06 14:42 - 00310616 ____C (Microsoft Corporation) C:\windows\system32\Drivers\volsnap.sys 2014-06-22 19:42 - 2014-05-19 08:31 - 00057856 _____ (Microsoft Corporation) C:\windows\system32\drvcfg.exe 2014-06-22 19:42 - 2014-05-19 08:21 - 00110592 _____ (Microsoft Corporation) C:\windows\system32\drvinst.exe 2014-06-22 19:42 - 2014-05-19 07:23 - 00098816 _____ (Microsoft Corporation) C:\windows\SysWOW64\drvinst.exe 2014-06-22 19:42 - 2014-05-01 15:31 - 03048904 _____ (Microsoft Corporation) C:\windows\system32\WpcMon.exe 2014-06-22 19:42 - 2014-05-01 15:31 - 00055328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\wpcfltr.sys 2014-06-22 19:42 - 2014-05-01 09:14 - 03118080 _____ (Microsoft Corporation) C:\windows\system32\Wpc.dll 2014-06-22 19:42 - 2014-05-01 09:05 - 02861056 _____ (Microsoft Corporation) C:\windows\system32\WpcWebSync.dll 2014-06-22 19:42 - 2014-05-01 08:51 - 02344448 _____ (Microsoft Corporation) C:\windows\SysWOW64\Wpc.dll 2014-06-22 19:42 - 2014-05-01 07:24 - 02834944 _____ (Microsoft Corporation) C:\windows\system32\wpccpl.dll 2014-06-22 19:42 - 2014-04-30 06:43 - 01975296 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll 2014-06-22 19:42 - 2014-04-30 06:26 - 01345536 _____ (Microsoft Corporation) C:\windows\system32\FntCache.dll 2014-06-22 19:42 - 2014-04-30 05:47 - 01509888 _____ (Microsoft Corporation) C:\windows\SysWOW64\DWrite.dll 2014-06-22 19:41 - 2014-06-22 19:41 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsgqec.dll 2014-06-22 19:41 - 2014-06-22 19:41 - 00001549 _____ () C:\Users\Christina\Downloads\URLLink(56).acsm 2014-06-22 19:40 - 2014-06-22 19:40 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2014-06-22 19:40 - 2014-06-22 19:40 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe 2014-06-22 19:40 - 2014-06-22 19:40 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2014-06-22 19:40 - 2014-06-22 19:40 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2014-06-22 19:37 - 2014-06-22 19:37 - 00001571 _____ () C:\Users\Christina\Downloads\URLLink(54).acsm 2014-06-22 19:37 - 2014-06-22 19:37 - 00001549 _____ () C:\Users\Christina\Downloads\URLLink(52).acsm 2014-06-22 19:37 - 2014-06-22 19:37 - 00001501 _____ () C:\Users\Christina\Downloads\URLLink(53).acsm 2014-06-22 19:37 - 2014-06-22 19:37 - 00001493 _____ () C:\Users\Christina\Downloads\URLLink(51).acsm 2014-06-22 19:37 - 2014-06-22 19:37 - 00001473 _____ () C:\Users\Christina\Downloads\URLLink(55).acsm ==================== One Month Modified Files and Folders ======= 2014-07-17 15:03 - 2014-07-17 15:03 - 00018265 _____ () C:\Users\Christina\Downloads\FRST.txt 2014-07-17 15:03 - 2014-07-17 08:29 - 00000000 ____D () C:\FRST 2014-07-17 15:01 - 2014-05-08 08:32 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job 2014-07-17 15:00 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\system32\sru 2014-07-17 14:53 - 2014-04-15 19:15 - 00003598 _____ () C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3508085089-3033536294-3423735549-1001 2014-07-17 14:48 - 2014-07-17 14:48 - 00001149 _____ () C:\Users\Christina\Desktop\FRST64 - Verknüpfung.lnk 2014-07-17 14:48 - 2014-07-17 14:48 - 00000926 _____ () C:\Users\Christina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FRST64.lnk 2014-07-17 14:45 - 2014-07-17 14:45 - 02086912 _____ (Farbar) C:\Users\Christina\Downloads\FRST64.exe 2014-07-17 12:49 - 2014-07-16 15:46 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-17 12:15 - 2014-04-26 12:31 - 00000000 ____D () C:\Users\Christina\AppData\Local\CrashDumps 2014-07-17 12:08 - 2014-04-15 19:09 - 00000000 ____D () C:\Users\Christina\AppData\Local\Packages 2014-07-17 11:54 - 2014-05-12 13:11 - 00022956 _____ () C:\Users\Christina\Documents\2014.ods 2014-07-17 09:44 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\rescache 2014-07-17 08:43 - 2014-04-15 19:09 - 01104026 _____ () C:\windows\WindowsUpdate.log 2014-07-17 08:27 - 2014-07-17 08:27 - 01077248 _____ (Farbar) C:\Users\Christina\Downloads\FRST (2).exe 2014-07-17 08:25 - 2014-07-17 08:25 - 01077248 _____ (Farbar) C:\Users\Christina\Downloads\FRST.exe 2014-07-17 08:25 - 2014-07-17 08:25 - 01077248 _____ (Farbar) C:\Users\Christina\Downloads\FRST (1).exe 2014-07-16 20:00 - 2014-07-16 20:00 - 00602112 _____ (OldTimer Tools) C:\Users\Christina\Downloads\OTL.exe 2014-07-16 19:45 - 2013-08-22 16:45 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2014-07-16 19:43 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\MediaViewer 2014-07-16 19:43 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\FileManager 2014-07-16 19:43 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\Camera 2014-07-16 19:42 - 2013-08-22 16:46 - 00036995 _____ () C:\windows\setupact.log 2014-07-16 19:40 - 2014-02-11 07:12 - 00000000 ____D () C:\windows\SysWOW64\RTCOM 2014-07-16 19:29 - 2013-08-22 17:20 - 00000000 ____D () C:\windows\CbsTemp 2014-07-16 19:12 - 2014-07-16 19:12 - 00000000 ____D () C:\Program Files\AMD 2014-07-16 19:09 - 2014-04-18 10:04 - 00233912 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll 2014-07-16 19:07 - 2014-06-22 19:43 - 00428888 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS 2014-07-16 18:51 - 2014-07-16 18:51 - 00001359 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Browser 7 der Telekom.lnk 2014-07-16 18:51 - 2014-07-16 18:51 - 00001347 _____ () C:\Users\Public\Desktop\Browser 7 der Telekom.lnk 2014-07-16 18:51 - 2014-07-16 18:51 - 00000000 ____D () C:\Program Files (x86)\Browser 7 Maintenance Service 2014-07-16 18:50 - 2014-04-15 20:02 - 00000000 ____D () C:\Program Files (x86)\Deutsche Telekom AG 2014-07-16 18:48 - 2014-07-16 18:48 - 00362592 _____ (Deutsche Telekom AG) C:\Users\Christina\Downloads\browser7_setup (1).exe.hy7enp8.partial 2014-07-16 18:45 - 2014-05-24 14:47 - 00000000 ____D () C:\Users\Christina\AppData\Local\NPE 2014-07-16 18:44 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\system32\FxsTmp 2014-07-16 18:43 - 2014-07-16 16:34 - 00000000 ____D () C:\NPE 2014-07-16 18:39 - 2013-08-24 23:32 - 00093894 _____ () C:\windows\PFRO.log 2014-07-16 18:27 - 2014-07-16 18:22 - 00000000 ____D () C:\Users\Christina\AppData\Roaming\GlarySoft 2014-07-16 18:22 - 2014-07-16 18:22 - 00001129 _____ () C:\Users\Christina\Desktop\Absolute Uninstaller.lnk 2014-07-16 18:21 - 2014-07-16 18:21 - 02194784 _____ (Glarysoft.com ) C:\Users\Christina\Downloads\au29setup.exe 2014-07-16 18:21 - 2014-07-16 18:21 - 02194784 _____ (Glarysoft.com ) C:\Users\Christina\Downloads\au29setup (1).exe 2014-07-16 17:29 - 2014-07-16 17:29 - 02347384 _____ (ESET) C:\Users\Christina\Downloads\esetsmartinstaller_enu.exe 2014-07-16 17:28 - 2014-07-16 17:28 - 00441592 _____ (Bleeping Computer, LLC) C:\Users\Christina\Downloads\sc-cleaner.exe 2014-07-16 17:28 - 2014-07-16 17:28 - 00001770 _____ () C:\sc-cleaner.txt 2014-07-16 17:09 - 2014-07-16 17:09 - 00000911 _____ () C:\Users\Christina\Desktop\JRT.txt 2014-07-16 16:59 - 2014-07-16 16:59 - 00000000 ____D () C:\windows\ERUNT 2014-07-16 16:58 - 2014-07-16 16:58 - 01016261 _____ (Thisisu) C:\Users\Christina\Downloads\JRT.exe 2014-07-16 16:47 - 2014-07-16 16:44 - 00000000 ____D () C:\AdwCleaner 2014-07-16 16:43 - 2014-07-16 16:43 - 01348263 _____ () C:\Users\Christina\Downloads\adwcleaner_3.215.exe 2014-07-16 16:33 - 2014-04-15 20:30 - 00000000 ____D () C:\ProgramData\Norton 2014-07-16 16:28 - 2014-07-16 16:28 - 00010226 _____ () C:\Users\Christina\Downloads\hijackthis.log 2014-07-16 16:27 - 2014-07-16 16:27 - 00388608 _____ (Trend Micro Inc.) C:\Users\Christina\Downloads\HijackThis.exe 2014-07-16 16:27 - 2014-04-15 19:09 - 00000000 ____D () C:\Users\Christina\AppData\Local\VirtualStore 2014-07-16 16:21 - 2014-07-16 16:21 - 00304857 _____ () C:\Users\Christina\Downloads\HijackThis_205.zip 2014-07-16 16:09 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\L2Schemas 2014-07-16 15:54 - 2014-02-11 08:07 - 00757756 _____ () C:\windows\system32\perfh007.dat 2014-07-16 15:54 - 2014-02-11 08:07 - 00173028 _____ () C:\windows\system32\perfc007.dat 2014-07-16 15:54 - 2013-08-24 23:38 - 01783968 _____ () C:\windows\system32\PerfStringBackup.INI 2014-07-16 15:47 - 2014-04-15 19:09 - 00001461 _____ () C:\Users\Christina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-07-16 15:45 - 2014-07-16 15:45 - 00003190 _____ () C:\windows\System32\Tasks\{AD428E5A-001B-408D-97F0-5BBCB5C4A4C4} 2014-07-16 15:44 - 2014-07-16 15:44 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Christina\Downloads\mbam-setup-2.0.2.1012.exe 2014-07-16 15:44 - 2014-07-16 15:44 - 00001125 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-07-16 15:44 - 2014-07-16 15:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-16 15:44 - 2014-07-16 15:44 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-16 15:44 - 2014-07-16 15:44 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-07-16 15:22 - 2014-07-16 15:22 - 00362592 _____ (Deutsche Telekom AG) C:\Users\Christina\Downloads\browser7_setup.exe 2014-07-16 15:17 - 2013-08-22 17:36 - 00000000 ___HD () C:\windows\ELAMBKUP 2014-07-16 15:17 - 2013-08-22 15:25 - 00524288 ___SH () C:\windows\system32\config\BBI 2014-07-16 15:11 - 2014-07-16 15:11 - 01286520 _____ (Netviewer AG) C:\Users\Christina\Downloads\diagnose.exe 2014-07-16 14:03 - 2014-07-16 14:03 - 00000000 ____H () C:\windows\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf 2014-07-16 13:11 - 2014-07-16 13:11 - 00000000 ____D () C:\windows\System32\Tasks\Norton 360 2014-07-16 13:06 - 2014-04-15 20:31 - 00003206 _____ () C:\windows\System32\Tasks\Norton WSC Integration 2014-07-16 13:06 - 2014-04-15 20:31 - 00002346 _____ () C:\Users\Public\Desktop\Norton 360.lnk 2014-07-16 13:06 - 2014-04-15 20:30 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360 2014-07-16 13:06 - 2014-04-15 20:30 - 00000000 ____D () C:\windows\system32\Drivers\N360x64 2014-07-16 13:05 - 2013-08-22 16:44 - 00503128 _____ () C:\windows\system32\FNTCACHE.DAT 2014-07-16 12:48 - 2014-07-16 12:48 - 00000000 ____D () C:\Users\Christina\Documents\Neuer Ordner 2014-07-16 12:44 - 2013-08-22 15:25 - 00262144 ___SH () C:\windows\system32\config\ELAM 2014-07-16 11:53 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\system32\NDF 2014-07-16 11:24 - 2014-02-11 07:12 - 00065536 _____ () C:\windows\system32\spu_storage.bin 2014-07-14 16:28 - 2014-07-14 16:28 - 00001550 _____ () C:\Users\Christina\Downloads\URLLink(73).acsm 2014-07-14 16:27 - 2014-07-14 16:27 - 00001501 _____ () C:\Users\Christina\Downloads\URLLink(70).acsm 2014-07-14 16:27 - 2014-07-14 16:27 - 00001475 _____ () C:\Users\Christina\Downloads\URLLink(71).acsm 2014-07-14 16:27 - 2014-07-14 16:27 - 00001458 _____ () C:\Users\Christina\Downloads\URLLink(72).acsm 2014-07-09 08:52 - 2013-08-22 17:36 - 00000000 ___RD () C:\windows\ToastData 2014-07-09 08:52 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-09 08:52 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-09 08:52 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\WinStore 2014-07-09 07:34 - 2014-04-18 20:42 - 00000000 ____D () C:\windows\system32\MRT 2014-07-09 07:32 - 2014-04-18 20:42 - 96441528 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2014-07-09 07:30 - 2014-04-15 20:55 - 00000000 ____D () C:\Program Files\Microsoft Office 15 2014-07-09 07:29 - 2013-08-22 21:12 - 00000000 ____D () C:\Program Files\Windows Journal 2014-07-09 07:13 - 2014-07-09 07:13 - 00079872 _____ (Microsoft Corporation) C:\windows\system32\WSReset.exe 2014-07-08 18:00 - 2014-02-11 07:43 - 00000000 ____D () C:\ProgramData\McAfee 2014-07-08 17:59 - 2014-05-08 08:32 - 00003772 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater 2014-07-08 14:23 - 2014-07-08 14:22 - 00001563 _____ () C:\Users\Christina\Downloads\URLLink(69).acsm 2014-07-08 09:03 - 2014-07-08 09:03 - 00001516 _____ () C:\Users\Christina\Downloads\URLLink(68).acsm 2014-07-04 13:16 - 2014-05-12 13:12 - 00018438 _____ () C:\Users\Christina\Documents\2015.ods 2014-07-02 09:56 - 2014-07-02 09:56 - 01058200 _____ (Adobe) C:\Users\Christina\Downloads\install_flashplayer14x32au_mssa_aaa_aih(1).exe 2014-06-29 19:11 - 2014-06-29 19:11 - 00001549 _____ () C:\Users\Christina\Downloads\URLLink(67).acsm 2014-06-29 19:10 - 2014-06-29 19:10 - 00001580 _____ () C:\Users\Christina\Downloads\URLLink(66).acsm 2014-06-29 19:10 - 2014-06-29 19:10 - 00001546 _____ () C:\Users\Christina\Downloads\URLLink(65).acsm 2014-06-29 19:10 - 2014-06-29 19:10 - 00001472 _____ () C:\Users\Christina\Downloads\URLLink(64).acsm 2014-06-29 19:10 - 2014-06-29 19:10 - 00001470 _____ () C:\Users\Christina\Downloads\URLLink(63).acsm 2014-06-29 19:10 - 2014-06-29 19:10 - 00001469 _____ () C:\Users\Christina\Downloads\URLLink(62).acsm 2014-06-27 14:25 - 2014-06-27 14:25 - 00001486 _____ () C:\Users\Christina\Downloads\URLLink(59).acsm 2014-06-27 14:25 - 2014-06-27 14:25 - 00001457 _____ () C:\Users\Christina\Downloads\URLLink(61).acsm 2014-06-27 14:25 - 2014-06-27 14:25 - 00001457 _____ () C:\Users\Christina\Downloads\URLLink(60).acsm 2014-06-26 22:55 - 2014-04-22 20:30 - 00703968 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe 2014-06-26 22:55 - 2014-04-22 20:30 - 00105440 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-06-26 20:01 - 2014-06-26 20:01 - 00025664 _____ () C:\Users\Christina\Documents\Elisa 12. Geburtstag.odt 2014-06-25 21:09 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\AppReadiness 2014-06-25 20:13 - 2014-06-25 20:13 - 05408139 _____ () C:\Users\Christina\Downloads\AmazonApps-release.apk 2014-06-25 10:30 - 2014-06-23 20:46 - 00014094 _____ () C:\Users\Christina\Documents\ADAC.odt 2014-06-23 20:49 - 2013-08-22 17:36 - 00000000 ___RD () C:\windows\ImmersiveControlPanel 2014-06-23 20:49 - 2013-08-22 15:36 - 00000000 ____D () C:\windows\system32\oobe 2014-06-23 17:07 - 2014-06-23 17:07 - 01058200 _____ (Adobe) C:\Users\Christina\Downloads\install_flashplayer14x32au_mssa_aaa_aih.exe 2014-06-22 19:53 - 2014-06-22 19:53 - 00001518 _____ () C:\Users\Christina\Downloads\URLLink(58).acsm 2014-06-22 19:52 - 2014-06-22 19:52 - 00001549 _____ () C:\Users\Christina\Downloads\URLLink(57).acsm 2014-06-22 19:41 - 2014-06-22 19:41 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsgqec.dll 2014-06-22 19:41 - 2014-06-22 19:41 - 00001549 _____ () C:\Users\Christina\Downloads\URLLink(56).acsm 2014-06-22 19:40 - 2014-06-22 19:40 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2014-06-22 19:40 - 2014-06-22 19:40 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe 2014-06-22 19:40 - 2014-06-22 19:40 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2014-06-22 19:40 - 2014-06-22 19:40 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2014-06-22 19:37 - 2014-06-22 19:37 - 00001571 _____ () C:\Users\Christina\Downloads\URLLink(54).acsm 2014-06-22 19:37 - 2014-06-22 19:37 - 00001549 _____ () C:\Users\Christina\Downloads\URLLink(52).acsm 2014-06-22 19:37 - 2014-06-22 19:37 - 00001501 _____ () C:\Users\Christina\Downloads\URLLink(53).acsm 2014-06-22 19:37 - 2014-06-22 19:37 - 00001493 _____ () C:\Users\Christina\Downloads\URLLink(51).acsm 2014-06-22 19:37 - 2014-06-22 19:37 - 00001473 _____ () C:\Users\Christina\Downloads\URLLink(55).acsm 2014-06-19 03:39 - 2014-07-09 07:17 - 23464448 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-06-19 02:48 - 2014-07-09 07:17 - 02768384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2014-06-19 02:16 - 2014-07-09 07:17 - 17276416 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2014-06-19 02:09 - 2014-07-09 07:17 - 00452608 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2014-06-19 01:51 - 2014-07-09 07:17 - 05721088 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2014-06-19 01:50 - 2014-07-09 07:17 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2014-06-19 01:48 - 2014-07-09 07:17 - 00292864 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2014-06-19 01:46 - 2014-07-09 07:17 - 00250880 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll 2014-06-19 01:39 - 2014-07-09 07:17 - 00608768 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2014-06-19 01:33 - 2014-07-09 07:17 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2014-06-19 01:32 - 2014-07-09 07:17 - 02179072 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll 2014-06-19 01:27 - 2014-07-09 07:17 - 02040832 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2014-06-19 01:12 - 2014-07-09 07:17 - 00367616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll 2014-06-19 00:59 - 2014-07-09 07:17 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll 2014-06-19 00:58 - 2014-07-09 07:17 - 02266112 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2014-06-19 00:58 - 2014-07-09 07:17 - 00239616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll 2014-06-19 00:57 - 2014-07-09 07:17 - 00225280 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll 2014-06-19 00:52 - 2014-07-09 07:17 - 04254720 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll 2014-06-19 00:51 - 2014-07-09 07:17 - 13527040 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2014-06-19 00:49 - 2014-07-09 07:17 - 00526336 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll 2014-06-19 00:45 - 2014-07-09 07:17 - 01964544 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl 2014-06-19 00:35 - 2014-07-09 07:17 - 11742208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll 2014-06-19 00:34 - 2014-07-09 07:17 - 01393664 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2014-06-19 00:15 - 2014-07-09 07:17 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2014-06-19 00:13 - 2014-07-09 07:17 - 01791488 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll 2014-06-19 00:09 - 2014-07-09 07:17 - 01139200 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll 2014-06-19 00:07 - 2014-07-09 07:17 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll 2014-06-17 00:26 - 2014-07-09 07:18 - 00779264 _____ (Microsoft Corporation) C:\windows\SysWOW64\osk.exe 2014-06-17 00:24 - 2014-07-09 07:18 - 00834048 _____ (Microsoft Corporation) C:\windows\system32\osk.exe Some content of TEMP: ==================== C:\Users\Christina\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-12 03:41 ==================== End Of Log ============================ --- --- --- [CODEAdditional scan result of Farbar Recovery Scan Tool (x64) Version: 15-07-2014 01 Ran by Christina at 2014-07-17 15:04:27 Running from C:\Users\Christina\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Norton 360 Online (Enabled - Up to date) {D87FA2C0-F526-77B1-D6EC-0EDF3936CEDB} AS: Norton 360 Online (Enabled - Up to date) {631E4324-D31C-783F-EC5C-35AD42B18466} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Norton 360 Online (Enabled) {E04423E5-BF49-76E9-FDB3-A7EAC7E589A0} ==================== Installed Programs ====================== 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Absolute Uninstaller 2.9.0.722 (HKLM-x32\...\Absolute Uninstaller_is1) (Version: - Glarysoft.com) Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated) Alcor Micro USB Card Reader Driver (HKLM-x32\...\AmUStor) (Version: 20.21.3317.03861 - Alcor Micro Corp.) Alcor Micro USB Card Reader Driver (x32 Version: 20.21.3317.03861 - Alcor Micro Corp.) Hidden Amazon Cloud Player (HKCU\...\Amazon Amazon Cloud Player) (Version: 2.4.0.33 - Amazon Services LLC) AMD Catalyst Control Center (x32 Version: 2013.0910.2222.38361 - Advanced Micro Devices, Inc.) Hidden AMD Catalyst Install Manager (HKLM\...\{B38CC495-7657-3D5A-80C2-8D6E0ED8E638}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.) Bing-Desktop (HKLM-x32\...\{7D095455-D971-4D4C-9EFD-9AF6A6584F3A}) (Version: 1.3.466.0 - Microsoft Corporation) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Browser 7 der Telekom (HKLM-x32\...\Browser 7 der Telekom 29.0.40 (x86 de)) (Version: 29.0.40 - Deutsche Telekom AG) Browser 7 Maintenance Service (HKLM-x32\...\Browser7MaintenanceService) (Version: 29.0.40 - Deutsche Telekom AG) Canon Utilities Digital Photo Professional (HKLM-x32\...\Digital Photo Professional) (Version: 3.13.10.0 - Canon Inc.) Canon Utilities EOS Sample Music (HKLM-x32\...\EOS Sample Music) (Version: 1.0.1.1 - Canon Inc.) Canon Utilities EOS Utility (HKLM-x32\...\EOS Utility) (Version: 2.13.10.0 - Canon Inc.) Canon Utilities ImageBrowser EX (HKLM-x32\...\ImageBrowser EX) (Version: 1.4.0.5 - Canon Inc.) Canon Utilities PhotoStitch (HKLM-x32\...\PhotoStitch) (Version: 3.1.23.47 - Canon Inc.) Canon Utilities Picture Style Editor (HKLM-x32\...\Picture Style Editor) (Version: 1.13.10.0 - Canon Inc.) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2013.0910.2222.38361 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2013.0910.2222.38361 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2013.0910.2222.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2013.0910.2222.38361 - Advanced Micro Devices, Inc.) Hidden Content Transfer (HKLM-x32\...\{CFADE4AF-C0CF-4A04-A776-741318F1658F}) (Version: 1.3.0.23190 - Sony Corporation) CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.5.6805 - CyberLink Corp.) CyberLink LabelPrint (x32 Version: 2.5.5.6805 - CyberLink Corp.) Hidden CyberLink Media Suite 10 (HKLM-x32\...\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.5.3103 - CyberLink Corp.) CyberLink Media Suite 10 (x32 Version: 10.0.5.3103 - CyberLink Corp.) Hidden CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.5.3215 - CyberLink Corp.) CyberLink Power2Go 8 (x32 Version: 8.0.5.3215 - CyberLink Corp.) Hidden CyberLink PowerDVD 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.2.3212 - CyberLink Corp.) CyberLink PowerDVD 12 (x32 Version: 12.0.2.3212 - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Energy Star (HKLM-x32\...\{FC0ADA4D-8FA5-4452-8AFF-F0A0BAC97EF7}) (Version: 1.0.9 - Hewlett-Packard Company) EPSON XP-600 Series Printer Uninstall (HKLM\...\EPSON XP-600 Series) (Version: - SEIKO EPSON Corporation) Fotogalerie (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden HP Connected Music (Meridian - installer) (HKLM-x32\...\StartHPConnectedMusic) (Version: 1.0 - Meridian Audio Ltd) HP Customer Experience Enhancements (x32 Version: 6.0.1.7 - Hewlett-Packard) Hidden HP Documentation (HKLM-x32\...\{06600E94-1C34-40E2-AB09-D30AECF78172}) (Version: 1.1.0.0 - Hewlett-Packard) HP Postscript Converter (Version: 4.5.12202 - Hewlett-Packard) Hidden HP Registration Service (HKLM\...\{D1E8F2D7-7794-4245-B286-87ED86C1893C}) (Version: 1.2.7045.4591 - Hewlett-Packard) HP SimplePass (HKLM-x32\...\InstallShield_{314FAD12-F785-4471-BCE8-AB506642B9A1}) (Version: 8.00.51 - Hewlett-Packard) HP SimplePass (Version: 8.00.51 - Hewlett-Packard) Hidden HP Support Assistant (HKLM-x32\...\{390AD982-A331-4D4F-AFD1-64005BC7C99D}) (Version: 7.3.35.12 - Hewlett-Packard Company) HP Support Information (HKLM-x32\...\{B2B7B1C8-7C8B-476C-BE2C-049731C55992}) (Version: 13.00.0000 - Hewlett-Packard) Inst5675 (Version: 8.00.51 - Softex Inc.) Hidden Inst5676 (Version: 8.00.51 - Softex Inc.) Hidden Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office 365 - de-de (HKLM\...\O365HomePremRetail - de-de) (Version: 15.0.4631.1002 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SkyDrive (HKCU\...\SkyDriveSetup.exe) (Version: 16.4.6013.0910 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 (HKLM-x32\...\{6e8f74e0-43bd-4dce-8477-6ff6828acc07}) (Version: 11.0.51106.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (HKLM-x32\...\{8e70e4e1-06d7-470b-9f74-a51bef21088e}) (Version: 11.0.51106.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.51106 (Version: 11.0.51106 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.51106 (Version: 11.0.51106 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 (x32 Version: 11.0.51106 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 (x32 Version: 11.0.51106 - Microsoft Corporation) Hidden Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden Norton 360 (HKLM-x32\...\N360) (Version: 21.4.0.13 - Symantec Corporation) Office 15 Click-to-Run Licensing Component (Version: 15.0.4631.1002 - Microsoft Corporation) Hidden OpenOffice 4.1.0 (HKLM-x32\...\{E19483E2-6C18-494D-A307-D4498BCFD2C7}) (Version: 4.10.9764 - Apache Software Foundation) Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Photo Gallery (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Reader for PC (HKLM-x32\...\{71FB3127-E6B2-4058-ACEE-99813554FAB6}) (Version: 2.2.00.11270 - Sony Corporation) Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.30164 - Realtek Semiconductor Corp.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7135 - Realtek Semiconductor Corp.) Recovery Manager (x32 Version: 5.5.0.7001 - CyberLink Corp.) Hidden Windows Live Communications Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation) Windows Live Essentials (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden ==================== Restore Points ========================= 02-07-2014 08:41:41 Windows Update 09-07-2014 05:24:36 Windows Update 16-07-2014 10:44:48 Norton 360 Registry Clean ==================== Hosts content: ========================== 2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____N C:\windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask Task: {084FB597-4DEE-4D9B-87F2-A694BC650D95} - System32\Tasks\CLVDLauncher => c:\Program Files (x86)\CyberLink\Power2Go8\CLVDLauncher.exe [2013-03-12] (CyberLink Corp.) Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList Task: {122A80BA-CC77-4E16-B7EF-253C86B8F029} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate Task: {2CCFB192-D944-4BD0-A76B-27817D9041A0} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-08] (Adobe Systems Incorporated) Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation) Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation) Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance Task: {574A4641-B59D-4ADE-9E72-D8803CF61DFF} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\windows\system32\MRT.exe [2014-07-09] (Microsoft Corporation) Task: {654019A3-5547-45A9-B5C5-A4AD5731A436} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\WSCStub.exe [2014-06-27] (Symantec Corporation) Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task Task: {8C3F336C-E9A2-4CD6-A2A2-D20FCBF0A889} - System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup => C:\Windows\system32\cleanmgr.exe [2014-02-22] (Microsoft Corporation) Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask Task: {9D96B0A8-A606-4AE4-AADE-553BEDF1C423} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\SymErr.exe [2014-01-30] (Symantec Corporation) Task: {9E38C571-697B-4487-AE06-71CD50A305D0} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2012-11-29] (Hewlett-Packard Company) Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work Task: {A3210FCD-5162-45A3-9439-20672D90AE27} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Validation Task: {AAF95213-F4C9-4ADE-BF54-7A7A46A7C60F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2013-08-10] (Hewlett-Packard) Task: {C046D88A-C291-4F0D-81B2-DBA7C9C0A44F} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Management Task: {C3C7A1AA-FFD0-41F8-B42E-E1ADD3DB5063} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2013-08-10] (Hewlett-Packard) Task: {C7DCD301-3FE2-43DE-8AD0-9F875C802AC0} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-08-27] (Hewlett-Packard Company) Task: {CCF33DC8-C907-4573-83E3-A6F01015EB18} - System32\Tasks\CLMLSvc_P2G8 => c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2013-08-05] (CyberLink) Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing Task: {D8DAF26F-28D7-44F8-91BC-35FEF55A9B8D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-08-27] (Hewlett-Packard Company) Task: {D945C0F9-4076-4246-BA3D-791CAEBBF359} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network => Sc.exe start wuauserv Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization Task: {DDC99CD5-465B-4FD7-9A92-97E3528F4019} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics Task: {E56515ED-8129-4A90-994A-603694336AAD} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2014-06-10] (Microsoft Corporation) Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE Task: {F1130D9E-79EE-4CB4-BD6B-9A3EB903C278} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2014-06-19] (Microsoft Corporation) Task: {FF09418F-CBE7-4F76-8EDF-4C9C4029863D} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\SymErr.exe [2014-01-30] (Symantec Corporation) Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2013-09-05 13:22 - 2013-09-05 13:22 - 00109568 _____ () C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe 2013-09-05 13:24 - 2013-09-05 13:24 - 00627200 _____ () C:\Program Files\Hewlett-Packard\SimplePass\cachedrv.dll 2013-09-05 13:24 - 2013-09-05 13:24 - 02540544 _____ () C:\Program Files\Hewlett-Packard\SimplePass\autheng.dll 2013-09-05 13:21 - 2013-09-05 13:21 - 00035328 _____ () C:\Program Files\Hewlett-Packard\SimplePass\ssplogon.dll 2013-09-05 13:21 - 2013-09-05 13:21 - 00055296 _____ () C:\Program Files\Hewlett-Packard\SimplePass\RandomPass.dll 2013-09-05 13:21 - 2013-09-05 13:21 - 00021504 _____ () C:\Program Files\Hewlett-Packard\SimplePass\cryptodll.dll 2013-09-05 13:36 - 2013-09-05 13:36 - 00306064 _____ () C:\Program Files\Hewlett-Packard\SimplePass\mstrpwd.dll 2013-09-05 13:36 - 2013-09-05 13:36 - 01298832 _____ () C:\Program Files\Hewlett-Packard\SimplePass\GraphicalPwd.dll 2014-04-16 13:58 - 2014-05-20 09:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll 2013-09-05 13:31 - 2013-09-05 13:31 - 00064000 _____ () C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe 2014-05-30 17:58 - 2014-05-08 19:26 - 03145536 _____ () C:\Users\Christina\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe 2012-08-30 13:46 - 2013-10-03 10:42 - 00069120 _____ () C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe 2013-06-06 01:51 - 2013-06-06 01:51 - 00098304 _____ () c:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\BrandingNet4.dll 2014-07-16 18:51 - 2014-06-10 14:46 - 03654456 _____ () C:\Program Files (x86)\Deutsche Telekom AG\Browser 7\mozjs.dll 2012-08-30 13:39 - 2013-10-03 10:42 - 00112128 _____ () C:\Program Files (x86)\Canon\ImageBrowser EX\MFMFileSystemWatcher.dll 2013-11-27 20:48 - 2013-11-27 20:48 - 00880640 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\fsk.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00040264 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskMediaPlayers.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00239944 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\Fskin.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00026952 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskinLocalize.dll 2013-11-26 11:34 - 2013-11-26 11:34 - 00798720 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskSecurity.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00125256 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskDocumentViewer.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00016200 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskPower.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00024904 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskNetInterface.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00017224 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskMobileMediaDevice.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00015176 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskTimeHardware.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00034632 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ticket.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00018760 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ebookDeviceNotifier.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00092488 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ebookUsb.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00149832 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\readerAppHelper.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00178504 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\USBDetector.dll 2014-02-11 07:35 - 2013-08-05 09:49 - 00627672 _____ () c:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll 2013-08-06 01:48 - 2013-08-06 01:48 - 00016856 _____ () c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\Christina\Desktop\Cashback.jpeg:3or4kl4x13tuuug3Byamue2s4b AlternateDataStreams: C:\Users\Christina\Desktop\Cashback.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" ==================== EXE Association (whitelisted) ============= ==================== MSCONFIG/TASK MANAGER disabled items ========= ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (07/17/2014 02:47:40 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest. Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest. Error: (07/17/2014 00:15:07 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: OPBHOBrokerDsktop.exe, Version: 8.0.0.51, Zeitstempel: 0x5228424c Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x0000000000000000 ID des fehlerhaften Prozesses: 0x11b0 Startzeit der fehlerhaften Anwendung: 0xOPBHOBrokerDsktop.exe0 Pfad der fehlerhaften Anwendung: OPBHOBrokerDsktop.exe1 Pfad des fehlerhaften Moduls: OPBHOBrokerDsktop.exe2 Berichtskennung: OPBHOBrokerDsktop.exe3 Vollständiger Name des fehlerhaften Pakets: OPBHOBrokerDsktop.exe4 Anwendungs-ID, die relativ zum fehlerhaften Paket ist: OPBHOBrokerDsktop.exe5 Error: (07/16/2014 07:48:18 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: ) Description: Subscription licensing service failed: -1073415161 Error: (07/16/2014 07:46:22 PM) (Source: Windows Search Service) (EventID: 10021) (User: ) Description: Die Registrierungsinformationen der Leistungsindikatoren für WSearchIdxPi für die Instanz konnten wegen des folgenden Fehlers nicht abgerufen werden: Der Vorgang wurde erfolgreich beendet. 0x0. Error: (07/16/2014 07:46:22 PM) (Source: Windows Search Service) (EventID: 3007) (User: ) Description: Die Leistungsüberwachung für den Gatherer-Dienst kann nicht initialisiert werden, da die Datenquellen nicht geladen sind oder das freigegebene Speicherobjekt nicht geöffnet werden konnte. Dies beeinträchtigt lediglich die Verfügbarkeit der Leistungsindikatoren. Starten Sie den Computer erneut. Kontext: Anwendung, SystemIndex Katalog Error: (07/16/2014 07:46:22 PM) (Source: Windows Search Service) (EventID: 3006) (User: ) Description: Die Leistungsüberwachung kann für den Gatherer-Dienst nicht initialisiert werden, da die Datenquellen nicht geladen sind oder das freigegebene Speicherobjekt nicht geöffnet werden konnte. Dies beeinträchtigt lediglich die Verfügbarkeit der Leistungsindikatoren. Starten Sie den Computer erneut. Error: (07/16/2014 06:42:24 PM) (Source: Windows Search Service) (EventID: 10021) (User: ) Description: Die Registrierungsinformationen der Leistungsindikatoren für WSearchIdxPi für die Instanz konnten wegen des folgenden Fehlers nicht abgerufen werden: Der Vorgang wurde erfolgreich beendet. 0x0. Error: (07/16/2014 06:42:23 PM) (Source: Windows Search Service) (EventID: 3007) (User: ) Description: Die Leistungsüberwachung für den Gatherer-Dienst kann nicht initialisiert werden, da die Datenquellen nicht geladen sind oder das freigegebene Speicherobjekt nicht geöffnet werden konnte. Dies beeinträchtigt lediglich die Verfügbarkeit der Leistungsindikatoren. Starten Sie den Computer erneut. Kontext: Anwendung, SystemIndex Katalog Error: (07/16/2014 06:42:21 PM) (Source: Windows Search Service) (EventID: 3006) (User: ) Description: Die Leistungsüberwachung kann für den Gatherer-Dienst nicht initialisiert werden, da die Datenquellen nicht geladen sind oder das freigegebene Speicherobjekt nicht geöffnet werden konnte. Dies beeinträchtigt lediglich die Verfügbarkeit der Leistungsindikatoren. Starten Sie den Computer erneut. Error: (07/16/2014 06:19:42 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest. Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest. System errors: ============= Error: (07/17/2014 09:36:08 AM) (Source: DCOM) (EventID: 10010) (User: gebbisfirst) Description: {1B1F472E-3221-4826-97DB-2C2324D389AE} Error: (07/17/2014 09:35:37 AM) (Source: DCOM) (EventID: 10010) (User: gebbisfirst) Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} Error: (07/17/2014 09:23:44 AM) (Source: DCOM) (EventID: 10010) (User: gebbisfirst) Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} Error: (07/17/2014 09:23:14 AM) (Source: DCOM) (EventID: 10010) (User: gebbisfirst) Description: {1B1F472E-3221-4826-97DB-2C2324D389AE} Error: (07/17/2014 09:18:40 AM) (Source: DCOM) (EventID: 10010) (User: gebbisfirst) Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} Error: (07/17/2014 09:18:10 AM) (Source: DCOM) (EventID: 10010) (User: gebbisfirst) Description: {1B1F472E-3221-4826-97DB-2C2324D389AE} Error: (07/17/2014 09:14:32 AM) (Source: DCOM) (EventID: 10010) (User: gebbisfirst) Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} Error: (07/17/2014 09:14:02 AM) (Source: DCOM) (EventID: 10010) (User: gebbisfirst) Description: {1B1F472E-3221-4826-97DB-2C2324D389AE} Error: (07/17/2014 08:40:19 AM) (Source: DCOM) (EventID: 10010) (User: gebbisfirst) Description: {1B1F472E-3221-4826-97DB-2C2324D389AE} Error: (07/17/2014 08:39:49 AM) (Source: DCOM) (EventID: 10010) (User: gebbisfirst) Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} Microsoft Office Sessions: ========================= Error: (07/17/2014 02:47:40 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Users\Christina\Downloads\esetsmartinstaller_enu.exe Error: (07/17/2014 00:15:07 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: OPBHOBrokerDsktop.exe8.0.0.515228424cunknown0.0.0.000000000c0000005000000000000000011b001cfa1874f2371dcC:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exeunknown399528b5-0d9b-11e4-826e-2c44fd2ff525 Error: (07/16/2014 07:48:18 PM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: ) Description: Subscription licensing service failed: -1073415161 Error: (07/16/2014 07:46:22 PM) (Source: Windows Search Service) (EventID: 10021) (User: ) Description: WSearchIdxPiDer Vorgang wurde erfolgreich beendet. 0x0 Error: (07/16/2014 07:46:22 PM) (Source: Windows Search Service) (EventID: 3007) (User: ) Description: Kontext: Anwendung, SystemIndex Katalog Error: (07/16/2014 07:46:22 PM) (Source: Windows Search Service) (EventID: 3006) (User: ) Description: Error: (07/16/2014 06:42:24 PM) (Source: Windows Search Service) (EventID: 10021) (User: ) Description: WSearchIdxPiDer Vorgang wurde erfolgreich beendet. 0x0 Error: (07/16/2014 06:42:23 PM) (Source: Windows Search Service) (EventID: 3007) (User: ) Description: Kontext: Anwendung, SystemIndex Katalog Error: (07/16/2014 06:42:21 PM) (Source: Windows Search Service) (EventID: 3006) (User: ) Description: Error: (07/16/2014 06:19:42 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Users\Christina\Downloads\esetsmartinstaller_enu.exe ==================== Memory info =========================== Percentage of memory in use: 61% Total physical RAM: 3531.63 MB Available physical RAM: 1347.28 MB Total Pagefile: 4235.63 MB Available Pagefile: 1667.22 MB Total Virtual: 131072 MB Available Virtual: 131071.84 MB ==================== Drives ================================ Drive c: (Windows) (Fixed) (Total:920.54 GB) (Free:808.69 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (Recovery Image) (Fixed) (Total:9.5 GB) (Free:1.11 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 932 GB) (Disk ID: 11D6C89C) Partition: GPT Partition Type. ==================== End Of Log ============================][/CODE] |
17.07.2014, 14:11 | #8 | |
/// TB-Ausbilder | Nach Omiga startet Telekom Browser nicht mehr Servus, Zitat:
Schritt 1 Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt 2 Downloade Dir bitte Malwarebytes Anti-Malware
Schritt 3 Bitte deaktiviere dein Anti-Viren-Programm, da es das Ergebnis beeinflussen oder ggf. die Bereinigung stören kann. Bitte lade dir zoek.exe von hier: http://hijackthis.nl/smeenk/ und speichere die Datei auf deinem Desktop.
Schritt 4
Bitte poste mit deiner nächsten Antwort
|
17.07.2014, 17:14 | #9 |
| Nach Omiga startet Telekom Browser nicht mehrCode:
ATTFilter # AdwCleaner v3.215 - Bericht erstellt am 17/07/2014 um 17:06:18 # Aktualisiert 09/07/2014 von Xplode # Betriebssystem : Windows 8.1 (64 bits) # Benutzername : Christina - GEBBISFIRST # Gestartet von : C:\Users\Christina\Desktop\adwcleaner_3.215.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17126 Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] ************************* AdwCleaner[R0].txt - [1352 octets] - [16/07/2014 16:44:37] AdwCleaner[R1].txt - [1042 octets] - [17/07/2014 16:41:13] AdwCleaner[S0].txt - [1359 octets] - [16/07/2014 16:47:30] AdwCleaner[S1].txt - [897 octets] - [17/07/2014 17:06:18] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [956 octets] ########## www.malwarebytes.org Suchlauf Datum: 17.07.2014 Suchlauf-Zeit: 17:16:47 Logdatei: mbam.txt Administrator: Ja Version: 2.00.2.1012 Malware Datenbank: v2014.07.17.07 Rootkit Datenbank: v2014.07.14.01 Lizenz: Testversion Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Self-protection: Deaktiviert Betriebssystem: Windows 8.1 CPU: x64 Dateisystem: NTFS Benutzer: Christina Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 314598 Verstrichene Zeit: 14 Min, 10 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristics: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 0 (No malicious items detected) Physische Sektoren: 0 (No malicious items detected) (end)E][/CODE] Code:
ATTFilter Zoek.exe v5.0.0.0 Updated 16-07-2014 Tool run by Christina on 17.07.2014 at 17:36:40,15. Microsoft Windows 8.1 6.3.9600 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Christina\Desktop\zoek.exe [Scan all users] [Script inserted] ==== System Restore Info ====================== 17.07.2014 17:38:42 Zoek.exe System Restore Point Created Succesfully. ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-3508085089-3033536294-3423735549-1001\Software\Microsoft\Internet Explorer\SearchScopes\{c1d89ae7-449d-4929-b24b-fded04adbe06} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== FireFox Fix ====================== Deleted from C:\Users\CHRIST~1\AppData\Roaming\Deutsche Telekom AG\Browser7\Profiles\n23n79k0.default\prefs.js: Added to C:\Users\CHRIST~1\AppData\Roaming\Deutsche Telekom AG\Browser7\Profiles\n23n79k0.default\prefs.js: user_pref("browser.startup.homepage", "hxxp://www.google.com"); user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q="); user_pref("browser.newtab.url", "hxxp://www.google.com/"); user_pref("browser.search.defaultengine", "Google"); user_pref("browser.search.defaultenginename", "Google"); user_pref("browser.search.selectedEngine", "Google"); user_pref("browser.search.order.1", "Google"); user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q="); user_pref("browser.search.suggest.enabled", true); user_pref("browser.search.useDBForOrder", true); ProfilePath: C:\Users\CHRIST~1\AppData\Roaming\Deutsche Telekom AG\Browser7\Profiles\n23n79k0.default user.js not found ---- FireFox user.js and prefs.js backups ---- prefs__1756_.backup ==== Deleting Files \ Folders ====================== C:\PROGRA~3\Package Cache deleted C:\Users\Christina\Searches deleted C:\Users\CHRIST~1\AppData\Roaming\Deutsche Telekom AG\Browser7\Profiles\n23n79k0.default\extensions\12ffxtbr@MyScrapNook_12.com deleted ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "{BBDA0591-3099-440a-AA10-41764D9DB4DB}"="C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.0.1.3\IPSFF" [16.04.2014 11:07] ==== Firefox Extensions ====================== ProfilePath: C:\Users\CHRIST~1\AppData\Roaming\Deutsche Telekom AG\Browser7\Profiles\n23n79k0.default - Undetermined - C:\Users\Christina\AppData\Roaming\Deutsche Telekom AG\Browser7\Profiles\n23n79k0.default\extensions\12ffxtbr@MyScrapNook_12.com ==== Firefox Plugins ====================== ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions mkfokfffehpeedafpekjeddnmnjhmcmk - C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\Exts\Chrome.crx[26.06.2014 12:22] ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="hxxp://www.t-online.de/" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Page_URL"="hxxp://www.google.com" "Start Page"="hxxp://www.google.com" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Page_URL"="hxxp://www.google.com" "Start Page"="hxxp://www.google.com" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="hxxp://www.t-online.de/" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="hxxp://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPDTDFJS" {D944BB61-2E34-4DBF-A683-47E505C587DC} eBay Url="hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4" ==== Reset Google Chrome ====================== Nothing found to reset ==== Reset IE Proxy ====================== Value(s) before fix: "ProxyEnable"=dword:00000000 Value(s) after fix: "ProxyEnable"=dword:00000000 ==== Empty IE Cache ====================== C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Christina\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Christina\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully C:\windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== No Chrome User Data found ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== No Java Cache Found ==== C:\zoek_backup content ====================== C:\zoek_backup (files=48 folders=38 30016459 bytes) ==== Empty Temp Folders ====================== C:\Users\Christina\AppData\Local\Temp will be emptied at reboot C:\Users\Christina_2\AppData\Local\Temp emptied successfully C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\windows\Temp successfully emptied C:\Users\CHRIST~1\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on 17.07.2014 at 18:01:24,32 ====================== Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-07-2014 01 Ran by Christina at 2014-07-17 18:06:03 Running from C:\Users\Christina\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Norton 360 Online (Enabled - Up to date) {D87FA2C0-F526-77B1-D6EC-0EDF3936CEDB} AS: Norton 360 Online (Enabled - Up to date) {631E4324-D31C-783F-EC5C-35AD42B18466} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Norton 360 Online (Enabled) {E04423E5-BF49-76E9-FDB3-A7EAC7E589A0} ==================== Installed Programs ====================== 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Absolute Uninstaller 2.9.0.722 (HKLM-x32\...\Absolute Uninstaller_is1) (Version: - Glarysoft.com) Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated) Alcor Micro USB Card Reader Driver (HKLM-x32\...\AmUStor) (Version: 20.21.3317.03861 - Alcor Micro Corp.) Alcor Micro USB Card Reader Driver (x32 Version: 20.21.3317.03861 - Alcor Micro Corp.) Hidden Amazon Cloud Player (HKCU\...\Amazon Amazon Cloud Player) (Version: 2.4.0.33 - Amazon Services LLC) AMD Catalyst Control Center (x32 Version: 2013.0910.2222.38361 - Advanced Micro Devices, Inc.) Hidden AMD Catalyst Install Manager (HKLM\...\{B38CC495-7657-3D5A-80C2-8D6E0ED8E638}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.) Bing-Desktop (HKLM-x32\...\{7D095455-D971-4D4C-9EFD-9AF6A6584F3A}) (Version: 1.3.466.0 - Microsoft Corporation) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Browser 7 der Telekom (HKLM-x32\...\Browser 7 der Telekom 29.0.40 (x86 de)) (Version: 29.0.40 - Deutsche Telekom AG) Browser 7 Maintenance Service (HKLM-x32\...\Browser7MaintenanceService) (Version: 29.0.40 - Deutsche Telekom AG) Canon Utilities Digital Photo Professional (HKLM-x32\...\Digital Photo Professional) (Version: 3.13.10.0 - Canon Inc.) Canon Utilities EOS Sample Music (HKLM-x32\...\EOS Sample Music) (Version: 1.0.1.1 - Canon Inc.) Canon Utilities EOS Utility (HKLM-x32\...\EOS Utility) (Version: 2.13.10.0 - Canon Inc.) Canon Utilities ImageBrowser EX (HKLM-x32\...\ImageBrowser EX) (Version: 1.4.0.5 - Canon Inc.) Canon Utilities PhotoStitch (HKLM-x32\...\PhotoStitch) (Version: 3.1.23.47 - Canon Inc.) Canon Utilities Picture Style Editor (HKLM-x32\...\Picture Style Editor) (Version: 1.13.10.0 - Canon Inc.) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2013.0910.2222.38361 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2013.0910.2222.38361 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2013.0910.2222.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2013.0910.2221.38361 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2013.0910.2222.38361 - Advanced Micro Devices, Inc.) Hidden Content Transfer (HKLM-x32\...\{CFADE4AF-C0CF-4A04-A776-741318F1658F}) (Version: 1.3.0.23190 - Sony Corporation) CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.5.6805 - CyberLink Corp.) CyberLink LabelPrint (x32 Version: 2.5.5.6805 - CyberLink Corp.) Hidden CyberLink Media Suite 10 (HKLM-x32\...\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.5.3103 - CyberLink Corp.) CyberLink Media Suite 10 (x32 Version: 10.0.5.3103 - CyberLink Corp.) Hidden CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.5.3215 - CyberLink Corp.) CyberLink Power2Go 8 (x32 Version: 8.0.5.3215 - CyberLink Corp.) Hidden CyberLink PowerDVD 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.2.3212 - CyberLink Corp.) CyberLink PowerDVD 12 (x32 Version: 12.0.2.3212 - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Energy Star (HKLM-x32\...\{FC0ADA4D-8FA5-4452-8AFF-F0A0BAC97EF7}) (Version: 1.0.9 - Hewlett-Packard Company) EPSON XP-600 Series Printer Uninstall (HKLM\...\EPSON XP-600 Series) (Version: - SEIKO EPSON Corporation) Fotogalerie (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden HP Connected Music (Meridian - installer) (HKLM-x32\...\StartHPConnectedMusic) (Version: 1.0 - Meridian Audio Ltd) HP Customer Experience Enhancements (x32 Version: 6.0.1.7 - Hewlett-Packard) Hidden HP Documentation (HKLM-x32\...\{06600E94-1C34-40E2-AB09-D30AECF78172}) (Version: 1.1.0.0 - Hewlett-Packard) HP Postscript Converter (Version: 4.5.12202 - Hewlett-Packard) Hidden HP Registration Service (HKLM\...\{D1E8F2D7-7794-4245-B286-87ED86C1893C}) (Version: 1.2.7045.4591 - Hewlett-Packard) HP SimplePass (HKLM-x32\...\InstallShield_{314FAD12-F785-4471-BCE8-AB506642B9A1}) (Version: 8.00.51 - Hewlett-Packard) HP SimplePass (Version: 8.00.51 - Hewlett-Packard) Hidden HP Support Assistant (HKLM-x32\...\{390AD982-A331-4D4F-AFD1-64005BC7C99D}) (Version: 7.3.35.12 - Hewlett-Packard Company) HP Support Information (HKLM-x32\...\{B2B7B1C8-7C8B-476C-BE2C-049731C55992}) (Version: 13.00.0000 - Hewlett-Packard) Inst5675 (Version: 8.00.51 - Softex Inc.) Hidden Inst5676 (Version: 8.00.51 - Softex Inc.) Hidden Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office 365 - de-de (HKLM\...\O365HomePremRetail - de-de) (Version: 15.0.4631.1002 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SkyDrive (HKCU\...\SkyDriveSetup.exe) (Version: 16.4.6013.0910 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 (HKLM-x32\...\{6e8f74e0-43bd-4dce-8477-6ff6828acc07}) (Version: 11.0.51106.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (HKLM-x32\...\{8e70e4e1-06d7-470b-9f74-a51bef21088e}) (Version: 11.0.51106.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.51106 (Version: 11.0.51106 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.51106 (Version: 11.0.51106 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 (x32 Version: 11.0.51106 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 (x32 Version: 11.0.51106 - Microsoft Corporation) Hidden Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden Norton 360 (HKLM-x32\...\N360) (Version: 21.4.0.13 - Symantec Corporation) Office 15 Click-to-Run Licensing Component (Version: 15.0.4631.1002 - Microsoft Corporation) Hidden OpenOffice 4.1.0 (HKLM-x32\...\{E19483E2-6C18-494D-A307-D4498BCFD2C7}) (Version: 4.10.9764 - Apache Software Foundation) Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Photo Gallery (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Reader for PC (HKLM-x32\...\{71FB3127-E6B2-4058-ACEE-99813554FAB6}) (Version: 2.2.00.11270 - Sony Corporation) Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.30164 - Realtek Semiconductor Corp.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7135 - Realtek Semiconductor Corp.) Recovery Manager (x32 Version: 5.5.0.7001 - CyberLink Corp.) Hidden Windows Live Communications Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation) Windows Live Essentials (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden ==================== Restore Points ========================= 02-07-2014 08:41:41 Windows Update 09-07-2014 05:24:36 Windows Update 16-07-2014 10:44:48 Norton 360 Registry Clean 17-07-2014 15:38:11 zoek.exe restore point ==================== Hosts content: ========================== 2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____N C:\windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask Task: {084FB597-4DEE-4D9B-87F2-A694BC650D95} - System32\Tasks\CLVDLauncher => c:\Program Files (x86)\CyberLink\Power2Go8\CLVDLauncher.exe [2013-03-12] (CyberLink Corp.) Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList Task: {122A80BA-CC77-4E16-B7EF-253C86B8F029} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate Task: {2CCFB192-D944-4BD0-A76B-27817D9041A0} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-08] (Adobe Systems Incorporated) Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation) Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation) Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance Task: {574A4641-B59D-4ADE-9E72-D8803CF61DFF} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\windows\system32\MRT.exe [2014-07-09] (Microsoft Corporation) Task: {654019A3-5547-45A9-B5C5-A4AD5731A436} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\WSCStub.exe [2014-06-27] (Symantec Corporation) Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task Task: {8C3F336C-E9A2-4CD6-A2A2-D20FCBF0A889} - System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup => C:\Windows\system32\cleanmgr.exe [2014-02-22] (Microsoft Corporation) Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask Task: {9D96B0A8-A606-4AE4-AADE-553BEDF1C423} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\SymErr.exe [2014-01-30] (Symantec Corporation) Task: {9E38C571-697B-4487-AE06-71CD50A305D0} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2012-11-29] (Hewlett-Packard Company) Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work Task: {A3210FCD-5162-45A3-9439-20672D90AE27} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Validation Task: {AAF95213-F4C9-4ADE-BF54-7A7A46A7C60F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2013-08-10] (Hewlett-Packard) Task: {C046D88A-C291-4F0D-81B2-DBA7C9C0A44F} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Management Task: {C3C7A1AA-FFD0-41F8-B42E-E1ADD3DB5063} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2013-08-10] (Hewlett-Packard) Task: {C7DCD301-3FE2-43DE-8AD0-9F875C802AC0} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-08-27] (Hewlett-Packard Company) Task: {CCF33DC8-C907-4573-83E3-A6F01015EB18} - System32\Tasks\CLMLSvc_P2G8 => c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2013-08-05] (CyberLink) Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing Task: {D8DAF26F-28D7-44F8-91BC-35FEF55A9B8D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-08-27] (Hewlett-Packard Company) Task: {D945C0F9-4076-4246-BA3D-791CAEBBF359} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network => Sc.exe start wuauserv Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization Task: {DDC99CD5-465B-4FD7-9A92-97E3528F4019} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics Task: {E56515ED-8129-4A90-994A-603694336AAD} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2014-06-10] (Microsoft Corporation) Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE Task: {F1130D9E-79EE-4CB4-BD6B-9A3EB903C278} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2014-06-19] (Microsoft Corporation) Task: {FF09418F-CBE7-4F76-8EDF-4C9C4029863D} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\SymErr.exe [2014-01-30] (Symantec Corporation) Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2013-09-05 13:22 - 2013-09-05 13:22 - 00109568 _____ () C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe 2013-09-05 13:24 - 2013-09-05 13:24 - 00627200 _____ () C:\Program Files\Hewlett-Packard\SimplePass\cachedrv.dll 2013-09-05 13:24 - 2013-09-05 13:24 - 02540544 _____ () C:\Program Files\Hewlett-Packard\SimplePass\autheng.dll 2013-09-05 13:21 - 2013-09-05 13:21 - 00035328 _____ () C:\Program Files\Hewlett-Packard\SimplePass\ssplogon.dll 2013-09-05 13:21 - 2013-09-05 13:21 - 00055296 _____ () C:\Program Files\Hewlett-Packard\SimplePass\RandomPass.dll 2013-09-05 13:21 - 2013-09-05 13:21 - 00021504 _____ () C:\Program Files\Hewlett-Packard\SimplePass\cryptodll.dll 2013-09-05 13:36 - 2013-09-05 13:36 - 00306064 _____ () C:\Program Files\Hewlett-Packard\SimplePass\mstrpwd.dll 2013-09-05 13:36 - 2013-09-05 13:36 - 01298832 _____ () C:\Program Files\Hewlett-Packard\SimplePass\GraphicalPwd.dll 2014-04-16 13:58 - 2014-05-20 09:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll 2013-09-05 13:31 - 2013-09-05 13:31 - 00064000 _____ () C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe 2014-05-30 17:58 - 2014-05-08 19:26 - 03145536 _____ () C:\Users\Christina\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe 2012-08-30 13:46 - 2013-10-03 10:42 - 00069120 _____ () C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe 2013-06-06 01:51 - 2013-06-06 01:51 - 00098304 _____ () c:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\BrandingNet4.dll 2012-08-30 13:39 - 2013-10-03 10:42 - 00112128 _____ () C:\Program Files (x86)\Canon\ImageBrowser EX\MFMFileSystemWatcher.dll 2013-11-27 20:48 - 2013-11-27 20:48 - 00880640 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\fsk.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00040264 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskMediaPlayers.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00239944 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\Fskin.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00026952 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskinLocalize.dll 2013-11-26 11:34 - 2013-11-26 11:34 - 00798720 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskSecurity.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00125256 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskDocumentViewer.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00016200 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskPower.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00024904 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskNetInterface.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00017224 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskMobileMediaDevice.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00015176 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\FskTimeHardware.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00034632 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ticket.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00018760 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ebookDeviceNotifier.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00092488 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ebookUsb.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00149832 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\readerAppHelper.dll 2013-11-27 20:49 - 2013-11-27 20:49 - 00178504 _____ () C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\USBDetector.dll 2014-02-11 07:35 - 2013-08-05 09:49 - 00627672 _____ () c:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll 2013-08-06 01:48 - 2013-08-06 01:48 - 00016856 _____ () c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\Christina\Desktop\Cashback.jpeg:3or4kl4x13tuuug3Byamue2s4b AlternateDataStreams: C:\Users\Christina\Desktop\Cashback.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" ==================== EXE Association (whitelisted) ============= ==================== MSCONFIG/TASK MANAGER disabled items ========= ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (07/17/2014 06:01:21 PM) (Source: Windows Search Service) (EventID: 10021) (User: ) Description: Die Registrierungsinformationen der Leistungsindikatoren für WSearchIdxPi für die Instanz konnten wegen des folgenden Fehlers nicht abgerufen werden: Der Vorgang wurde erfolgreich beendet. 0x0. Error: (07/17/2014 06:01:21 PM) (Source: Windows Search Service) (EventID: 3007) (User: ) Description: Die Leistungsüberwachung für den Gatherer-Dienst kann nicht initialisiert werden, da die Datenquellen nicht geladen sind oder das freigegebene Speicherobjekt nicht geöffnet werden konnte. Dies beeinträchtigt lediglich die Verfügbarkeit der Leistungsindikatoren. Starten Sie den Computer erneut. Kontext: Anwendung, SystemIndex Katalog Error: (07/17/2014 06:01:21 PM) (Source: Windows Search Service) (EventID: 3006) (User: ) Description: Die Leistungsüberwachung kann für den Gatherer-Dienst nicht initialisiert werden, da die Datenquellen nicht geladen sind oder das freigegebene Speicherobjekt nicht geöffnet werden konnte. Dies beeinträchtigt lediglich die Verfügbarkeit der Leistungsindikatoren. Starten Sie den Computer erneut. Error: (07/17/2014 05:16:32 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm mbam.exe, Version 1.0.0.532 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 179c Startzeit: 01cfa1d20515d96f Endzeit: 0 Anwendungspfad: C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe Berichts-ID: 5209a626-0dc5-11e4-826f-2c44fd2ff525 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (07/17/2014 05:15:52 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm mbam.exe, Version 1.0.0.532 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: a1c Startzeit: 01cfa1d0e3823323 Endzeit: 15 Anwendungspfad: C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe Berichts-ID: 3a609f0b-0dc5-11e4-826f-2c44fd2ff525 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (07/17/2014 05:08:01 PM) (Source: Windows Search Service) (EventID: 10021) (User: ) Description: Die Registrierungsinformationen der Leistungsindikatoren für WSearchIdxPi für die Instanz konnten wegen des folgenden Fehlers nicht abgerufen werden: Der Vorgang wurde erfolgreich beendet. 0x0. Error: (07/17/2014 05:08:01 PM) (Source: Windows Search Service) (EventID: 3007) (User: ) Description: Die Leistungsüberwachung für den Gatherer-Dienst kann nicht initialisiert werden, da die Datenquellen nicht geladen sind oder das freigegebene Speicherobjekt nicht geöffnet werden konnte. Dies beeinträchtigt lediglich die Verfügbarkeit der Leistungsindikatoren. Starten Sie den Computer erneut. Kontext: Anwendung, SystemIndex Katalog Error: (07/17/2014 05:08:01 PM) (Source: Windows Search Service) (EventID: 3006) (User: ) Description: Die Leistungsüberwachung kann für den Gatherer-Dienst nicht initialisiert werden, da die Datenquellen nicht geladen sind oder das freigegebene Speicherobjekt nicht geöffnet werden konnte. Dies beeinträchtigt lediglich die Verfügbarkeit der Leistungsindikatoren. Starten Sie den Computer erneut. Error: (07/17/2014 04:39:58 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest. Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest. Error: (07/17/2014 02:47:40 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest. Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest. System errors: ============= Error: (07/17/2014 06:01:08 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "McAfee Boot Delay Start Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (07/17/2014 05:56:41 PM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (07/17/2014 05:56:40 PM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (07/17/2014 05:56:40 PM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (07/17/2014 05:56:39 PM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (07/17/2014 05:56:38 PM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (07/17/2014 05:07:45 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "McAfee Boot Delay Start Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (07/17/2014 05:06:58 PM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Superfetch" wurde mit folgendem Fehler beendet: %%1062 Error: (07/17/2014 09:36:08 AM) (Source: DCOM) (EventID: 10010) (User: gebbisfirst) Description: {1B1F472E-3221-4826-97DB-2C2324D389AE} Error: (07/17/2014 09:35:37 AM) (Source: DCOM) (EventID: 10010) (User: gebbisfirst) Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001} Microsoft Office Sessions: ========================= Error: (07/17/2014 06:01:21 PM) (Source: Windows Search Service) (EventID: 10021) (User: ) Description: WSearchIdxPiDer Vorgang wurde erfolgreich beendet. 0x0 Error: (07/17/2014 06:01:21 PM) (Source: Windows Search Service) (EventID: 3007) (User: ) Description: Kontext: Anwendung, SystemIndex Katalog Error: (07/17/2014 06:01:21 PM) (Source: Windows Search Service) (EventID: 3006) (User: ) Description: Error: (07/17/2014 05:16:32 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: mbam.exe1.0.0.532179c01cfa1d20515d96f0C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe5209a626-0dc5-11e4-826f-2c44fd2ff525 Error: (07/17/2014 05:15:52 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: mbam.exe1.0.0.532a1c01cfa1d0e382332315C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe3a609f0b-0dc5-11e4-826f-2c44fd2ff525 Error: (07/17/2014 05:08:01 PM) (Source: Windows Search Service) (EventID: 10021) (User: ) Description: WSearchIdxPiDer Vorgang wurde erfolgreich beendet. 0x0 Error: (07/17/2014 05:08:01 PM) (Source: Windows Search Service) (EventID: 3007) (User: ) Description: Kontext: Anwendung, SystemIndex Katalog Error: (07/17/2014 05:08:01 PM) (Source: Windows Search Service) (EventID: 3006) (User: ) Description: Error: (07/17/2014 04:39:58 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Users\Christina\Downloads\esetsmartinstaller_enu.exe Error: (07/17/2014 02:47:40 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Users\Christina\Downloads\esetsmartinstaller_enu.exe ==================== Memory info =========================== Percentage of memory in use: 42% Total physical RAM: 3531.63 MB Available physical RAM: 2046.93 MB Total Pagefile: 4235.63 MB Available Pagefile: 2380.68 MB Total Virtual: 131072 MB Available Virtual: 131071.85 MB ==================== Drives ================================ Drive c: (Windows) (Fixed) (Total:920.54 GB) (Free:808.66 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (Recovery Image) (Fixed) (Total:9.5 GB) (Free:1.11 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 932 GB) (Disk ID: 11D6C89C) Partition: GPT Partition Type. ==================== End Of Log ============================ |
17.07.2014, 17:15 | #10 |
| Nach Omiga startet Telekom Browser nicht mehr [gelöst] FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-07-2014 01 Ran by Christina (administrator) on GEBBISFIRST on 17-07-2014 18:04:37 Running from C:\Users\Christina\Downloads Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= () C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe (Softex Inc.) C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\n360.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe (Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\n360.exe () C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\HPSmplPass.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATIJCE.EXE () C:\Users\Christina\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe () C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Sony Corporation) C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BDExtHost.exe (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BDAppHost.exe (Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BDRuntimeHost.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SimplePass] => C:\Program Files\Hewlett-Packard\SimplePass\HPSmplPass.exe [2793016 2013-09-05] (Hewlett-Packard) HKLM\...\Run: [OPBHOBroker] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe [154680 2013-09-05] (Hewlett-Packard) HKLM\...\Run: [OPBHOBrokerDesktop] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe [154680 2013-09-05] (Hewlett-Packard) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13663448 2014-01-13] (Realtek Semiconductor) HKLM-x32\...\Run: [StartCCC] => c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-09-11] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Reader Application Helper] => C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe [899400 2013-11-27] (Sony Corporation) HKLM-x32\...\Run: [BingDesktop] => C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe [2368728 2014-05-23] (Microsoft Corp.) HKU\S-1-5-21-3508085089-3033536294-3423735549-1001\...\Run: [EPLTarget\P0000000000000000] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATIJCE.EXE [283232 2012-10-01] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-3508085089-3033536294-3423735549-1001\...\Run: [Amazon Cloud Player] => C:\Users\Christina\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe [3145536 2014-05-08] () HKU\S-1-5-21-3508085089-3033536294-3423735549-1001\...\MountPoints2: {35ffaafd-c4bf-11e3-8254-806e6f6e6963} - "E:\SETUP.EXE" Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ImageBrowser EX Agent.lnk ShortcutTarget: ImageBrowser EX Agent.lnk -> C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe () ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ShellIconOverlayIdentifiers: SkyDrivePro1 (ErrorConflict) -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: SkyDrivePro2 (SyncInProgress) -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: SkyDrivePro3 (InSync) -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) ShellIconOverlayIdentifiers: OverlayExcluded -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton 360\Engine64\21.4.0.13\buShell.dll (Symantec Corporation) ShellIconOverlayIdentifiers: OverlayPending -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton 360\Engine64\21.4.0.13\buShell.dll (Symantec Corporation) ShellIconOverlayIdentifiers: OverlayProtected -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton 360\Engine64\21.4.0.13\buShell.dll (Symantec Corporation) ShellIconOverlayIdentifiers-x32: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers-x32: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers-x32: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.t-online.de/ HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPDTDFJS SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPDTDFJS SearchScopes: HKLM - {A7ECAA6F-6CCA-49A8-B2A9-42C16E330BAF} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de1-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} SearchScopes: HKLM-x32 - DefaultScope value is missing. SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPDTDFJS SearchScopes: HKCU - {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPDTDFJS SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation) BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine64\21.4.0.13\coIEPlg.dll (Symantec Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation) BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard) BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\coIEPlg.dll (Symantec Corporation) BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\IPS\IPSBHO.DLL (Symantec Corporation) BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard) Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine64\21.4.0.13\coIEPlg.dll (Symantec Corporation) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\coIEPlg.dll (Symantec Corporation) Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @sony.com/ReaderDesktop - C:\Program Files (x86)\Sony\ReaderDesktop\npreaderdetectmoz.dll (Sony Corporation) FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.0.1.3\coFFPlgn FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.0.1.3\coFFPlgn [2014-07-17] FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.0.1.3\IPSFF FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.0.1.3\IPSFF [2014-04-16] ==================== Services (Whitelisted) ================= R2 BingDesktopUpdate; C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [173784 2014-05-23] (Microsoft Corp.) S3 Browser7Maintenance; C:\Program Files (x86)\Browser 7 Maintenance Service\maintenanceservice.exe [117560 2014-06-10] (Deutsche Telekom AG) R2 Cachedrv server; C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe [109568 2013-09-05] () [File not signed] R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2356408 2014-06-19] (Microsoft Corporation) R2 CyberLink PowerDVD 12 Media Server Monitor Service; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [77576 2013-08-12] (CyberLink) R2 CyberLink PowerDVD 12 Media Server Service; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [298760 2013-08-12] (CyberLink) R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-08-27] (Hewlett-Packard Company) [File not signed] R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R2 N360; C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\N360.exe [265040 2014-06-27] (Symantec Corporation) R2 omniserv; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [87552 2013-09-05] (Softex Inc.) [File not signed] R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [290520 2014-01-13] (Realtek Semiconductor) S3 Sony SCSI Helper Service; C:\Program Files (x86)\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe [73728 2013-11-26] (Sony Corporation) [File not signed] S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2013-08-24] (Microsoft Corporation) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation) S2 0201921397581903mcinstcleanup; C:\windows\TEMP\020192~1.EXE -cleanup -nolog [X] S2 mcbootdelaystartsvc; "C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe" /McCoreSvc [X] ==================== Drivers (Whitelisted) ==================== R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36096 2013-05-22] (Advanced Micro Devices, Inc.) R1 BHDrvx64; C:\Program Files (x86)\Norton 360\NortonData\21.0.1.3\Definitions\BASHDefs\20140703.001\BHDrvx64.sys [1530160 2014-05-10] (Symantec Corporation) R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1504000.00D\ccSetx64.sys [162392 2014-02-25] (Symantec Corporation) R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-05] (CyberLink) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [486192 2014-06-21] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [142128 2014-06-21] (Symantec Corporation) R1 IDSVia64; C:\Program Files (x86)\Norton 360\NortonData\21.0.1.3\Definitions\IPSDefs\20140716.001\IDSvia64.sys [525016 2014-06-20] (Symantec Corporation) R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-07-17] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation) R3 NAVENG; C:\Program Files (x86)\Norton 360\NortonData\21.0.1.3\Definitions\VirusDefs\20140717.001\ENG64.SYS [126040 2014-06-21] (Symantec Corporation) R3 NAVEX15; C:\Program Files (x86)\Norton 360\NortonData\21.0.1.3\Definitions\VirusDefs\20140717.001\EX64.SYS [2099288 2014-06-21] (Symantec Corporation) R3 SRTSP; C:\Windows\System32\Drivers\N360x64\1504000.00D\SRTSP64.SYS [875736 2014-02-13] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1504000.00D\SRTSPX64.SYS [36952 2013-07-31] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\N360x64\1504000.00D\SYMDS64.SYS [493656 2013-08-01] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\N360x64\1504000.00D\SYMEFA64.SYS [1148120 2014-03-04] (Symantec Corporation) S0 SymELAM; C:\Windows\System32\drivers\N360x64\1504000.00D\SymELAM.sys [23568 2013-08-01] (Symantec Corporation) R3 SymEvent; C:\windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2014-04-15] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\N360x64\1504000.00D\Ironx64.SYS [264280 2013-07-31] (Symantec Corporation) R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1504000.00D\SYMNETS.SYS [593112 2014-02-18] (Symantec Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation) U3 McMPFSvc; U3 McNaiAnn; U3 mcpltsvc; U3 McProxy; U3 mfecore; U3 MSK80Service; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-17 18:04 - 2014-07-17 18:04 - 00006671 _____ () C:\Users\Christina\Downloads\zoek-results.txt 2014-07-17 17:59 - 2014-07-17 17:36 - 00024064 _____ () C:\windows\zoek-delete.exe 2014-07-17 17:55 - 2014-07-17 18:01 - 00000000 ____D () C:\zoek 2014-07-17 17:38 - 2014-07-17 18:01 - 00006671 _____ () C:\zoek-results.log 2014-07-17 17:36 - 2014-07-17 17:56 - 00000000 ____D () C:\zoek_backup 2014-07-17 17:36 - 2014-07-17 17:36 - 01287168 _____ () C:\Users\Christina\Desktop\zoek.exe 2014-07-17 17:34 - 2014-07-17 17:34 - 00001148 _____ () C:\Users\Christina\Desktop\mbam.txt 2014-07-17 16:40 - 2014-07-17 16:40 - 01348263 _____ () C:\Users\Christina\Desktop\adwcleaner_3.215.exe 2014-07-17 15:04 - 2014-07-17 15:05 - 00035294 _____ () C:\Users\Christina\Downloads\Addition.txt 2014-07-17 15:03 - 2014-07-17 18:05 - 00017683 _____ () C:\Users\Christina\Downloads\FRST.txt 2014-07-17 14:48 - 2014-07-17 14:48 - 00001149 _____ () C:\Users\Christina\Desktop\FRST64 - Verknüpfung.lnk 2014-07-17 14:48 - 2014-07-17 14:48 - 00000926 _____ () C:\Users\Christina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FRST64.lnk 2014-07-17 14:45 - 2014-07-17 14:45 - 02086912 _____ (Farbar) C:\Users\Christina\Downloads\FRST64.exe 2014-07-17 08:29 - 2014-07-17 18:04 - 00000000 ____D () C:\FRST 2014-07-17 08:27 - 2014-07-17 08:27 - 01077248 _____ (Farbar) C:\Users\Christina\Downloads\FRST (2).exe 2014-07-17 08:25 - 2014-07-17 08:25 - 01077248 _____ (Farbar) C:\Users\Christina\Downloads\FRST.exe 2014-07-17 08:25 - 2014-07-17 08:25 - 01077248 _____ (Farbar) C:\Users\Christina\Downloads\FRST (1).exe 2014-07-16 19:12 - 2014-07-16 19:12 - 00000000 ____D () C:\Program Files\AMD 2014-07-16 19:10 - 2014-06-05 16:13 - 00216368 _____ (Microsoft Corporation) C:\windows\system32\rsaenh.dll 2014-07-16 19:10 - 2014-06-05 15:14 - 00189016 _____ (Microsoft Corporation) C:\windows\SysWOW64\rsaenh.dll 2014-07-16 19:10 - 2014-06-02 04:10 - 00423768 _____ (Microsoft Corporation) C:\windows\system32\hal.dll 2014-07-16 19:10 - 2014-05-31 12:07 - 00467800 ____C (Microsoft Corporation) C:\windows\system32\Drivers\USBHUB3.SYS 2014-07-16 19:10 - 2014-05-31 12:07 - 00440664 ____C (Microsoft Corporation) C:\windows\system32\Drivers\usbport.sys 2014-07-16 19:10 - 2014-05-31 12:07 - 00419672 ____C (Microsoft Corporation) C:\windows\system32\Drivers\usbhub.sys 2014-07-16 19:10 - 2014-05-31 12:07 - 00089944 ____C (Microsoft Corporation) C:\windows\system32\Drivers\usbehci.sys 2014-07-16 19:10 - 2014-05-31 12:07 - 00027480 ____C (Microsoft Corporation) C:\windows\system32\Drivers\usbd.sys 2014-07-16 19:10 - 2014-05-31 08:30 - 00037376 ____C (Microsoft Corporation) C:\windows\system32\Drivers\usbuhci.sys 2014-07-16 19:10 - 2014-05-31 08:27 - 00206848 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys 2014-07-16 19:10 - 2014-05-31 08:27 - 00110592 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WUDFPf.sys 2014-07-16 19:10 - 2014-05-31 08:26 - 00227840 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WUDFRd.sys 2014-07-16 19:10 - 2014-05-31 06:01 - 00284672 _____ (Microsoft Corporation) C:\windows\system32\WUDFHost.exe 2014-07-16 19:10 - 2014-05-31 06:01 - 00209408 _____ (Microsoft Corporation) C:\windows\system32\WUDFPlatform.dll 2014-07-16 19:10 - 2014-05-31 06:01 - 00099840 _____ (Microsoft Corporation) C:\windows\system32\WUDFSvc.dll 2014-07-16 19:10 - 2014-05-27 17:53 - 02518360 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys 2014-07-16 19:10 - 2014-05-27 11:56 - 00323584 _____ (Microsoft Corporation) C:\windows\system32\DaOtpCredentialProvider.dll 2014-07-16 19:10 - 2014-05-27 11:53 - 00270848 _____ (Microsoft Corporation) C:\windows\SysWOW64\DaOtpCredentialProvider.dll 2014-07-16 19:10 - 2014-05-17 06:59 - 16871936 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Xaml.dll 2014-07-16 19:10 - 2014-05-17 06:13 - 12711424 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Xaml.dll 2014-07-16 19:10 - 2014-05-15 00:47 - 04720640 _____ (Microsoft Corporation) C:\windows\system32\SyncEngine.dll 2014-07-16 19:10 - 2014-05-13 09:01 - 00076800 _____ (Microsoft Corporation) C:\windows\system32\BulkOperationHost.exe 2014-07-16 19:10 - 2014-05-13 07:07 - 02844160 _____ (Microsoft Corporation) C:\windows\system32\actxprxy.dll 2014-07-16 19:10 - 2014-05-13 06:41 - 00118272 _____ (Microsoft Corporation) C:\windows\system32\winbici.dll 2014-07-16 19:10 - 2014-05-13 06:27 - 00716800 _____ (Microsoft Corporation) C:\windows\system32\SkyDriveTelemetry.dll 2014-07-16 19:10 - 2014-05-13 06:26 - 00285696 _____ (Microsoft Corporation) C:\windows\system32\SkyDriveShell.dll 2014-07-16 19:10 - 2014-05-13 05:59 - 01035264 _____ (Microsoft Corporation) C:\windows\SysWOW64\actxprxy.dll 2014-07-16 19:10 - 2014-05-13 05:41 - 01118720 _____ (Microsoft Corporation) C:\windows\system32\SkyDrive.exe 2014-07-16 19:10 - 2014-05-13 05:31 - 00265216 _____ (Microsoft Corporation) C:\windows\SysWOW64\SkyDriveShell.dll 2014-07-16 19:10 - 2014-05-03 13:29 - 01726224 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll 2014-07-16 19:10 - 2014-05-03 11:20 - 01473080 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll 2014-07-16 19:10 - 2014-05-03 07:36 - 00997888 _____ (Microsoft Corporation) C:\windows\system32\reseteng.dll 2014-07-16 19:10 - 2014-05-03 07:19 - 00071168 _____ (Microsoft Corporation) C:\windows\system32\ncobjapi.dll 2014-07-16 19:10 - 2014-05-03 07:08 - 00301056 _____ (Microsoft Corporation) C:\windows\system32\framedynos.dll 2014-07-16 19:10 - 2014-05-03 07:07 - 00262656 _____ (Microsoft Corporation) C:\windows\system32\framedyn.dll 2014-07-16 19:10 - 2014-05-03 06:46 - 00052736 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncobjapi.dll 2014-07-16 19:10 - 2014-05-03 06:37 - 00235008 _____ (Microsoft Corporation) C:\windows\SysWOW64\framedynos.dll 2014-07-16 19:10 - 2014-05-03 06:37 - 00207360 _____ (Microsoft Corporation) C:\windows\SysWOW64\framedyn.dll 2014-07-16 19:10 - 2014-05-03 05:30 - 02641920 _____ (Microsoft Corporation) C:\windows\system32\authui.dll 2014-07-16 19:10 - 2014-05-03 05:27 - 02317824 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll 2014-07-16 19:10 - 2014-05-03 01:26 - 00050745 _____ () C:\windows\system32\srms.dat 2014-07-16 19:10 - 2014-05-01 07:44 - 01025536 _____ (Microsoft Corporation) C:\windows\system32\localspl.dll 2014-07-16 19:10 - 2014-04-30 08:43 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\vwififlt.sys 2014-07-16 19:10 - 2014-04-30 08:41 - 00402432 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys 2014-07-16 19:10 - 2014-04-30 08:41 - 00096768 _____ (Microsoft Corporation) C:\windows\system32\Drivers\agilevpn.sys 2014-07-16 19:10 - 2014-04-30 08:41 - 00038912 _____ (Microsoft Corporation) C:\windows\system32\Drivers\vwifimp.sys 2014-07-16 19:10 - 2014-04-30 07:45 - 00123392 _____ (Microsoft Corporation) C:\windows\system32\Robocopy.exe 2014-07-16 19:10 - 2014-04-30 06:48 - 00106496 _____ (Microsoft Corporation) C:\windows\SysWOW64\Robocopy.exe 2014-07-16 19:10 - 2014-04-30 06:24 - 00065024 _____ (Microsoft Corporation) C:\windows\system32\dhcpcsvc6.dll 2014-07-16 19:10 - 2014-04-30 06:23 - 00353280 _____ (Microsoft Corporation) C:\windows\system32\dhcpcore.dll 2014-07-16 19:10 - 2014-04-30 06:23 - 00271872 _____ (Microsoft Corporation) C:\windows\system32\dhcpcore6.dll 2014-07-16 19:10 - 2014-04-30 06:23 - 00087552 _____ (Microsoft Corporation) C:\windows\system32\dhcpcsvc.dll 2014-07-16 19:10 - 2014-04-30 06:14 - 00827392 _____ (Microsoft Corporation) C:\windows\system32\BFE.DLL 2014-07-16 19:10 - 2014-04-30 05:59 - 01063424 _____ (Microsoft Corporation) C:\windows\system32\IKEEXT.DLL 2014-07-16 19:10 - 2014-04-30 05:46 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dhcpcore.dll 2014-07-16 19:10 - 2014-04-30 05:46 - 00229888 _____ (Microsoft Corporation) C:\windows\SysWOW64\dhcpcore6.dll 2014-07-16 19:10 - 2014-04-30 05:46 - 00056320 _____ (Microsoft Corporation) C:\windows\SysWOW64\dhcpcsvc6.dll 2014-07-16 19:10 - 2014-04-30 05:45 - 00062976 _____ (Microsoft Corporation) C:\windows\SysWOW64\dhcpcsvc.dll 2014-07-16 19:10 - 2014-04-30 05:42 - 00403968 _____ (Microsoft Corporation) C:\windows\system32\vpnike.dll 2014-07-16 19:10 - 2014-04-29 00:40 - 00721408 _____ (Microsoft Corporation) C:\windows\system32\fveapi.dll 2014-07-16 19:10 - 2014-04-27 00:03 - 02140888 _____ (Microsoft Corporation) C:\windows\system32\mfcore.dll 2014-07-16 19:10 - 2014-04-26 22:14 - 02144984 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfcore.dll 2014-07-16 19:10 - 2014-04-26 18:39 - 00339456 _____ (Microsoft Corporation) C:\windows\system32\bdesvc.dll 2014-07-16 19:10 - 2014-04-14 11:37 - 02125344 _____ (Microsoft Corporation) C:\windows\system32\d3d9.dll 2014-07-16 19:10 - 2014-04-14 10:08 - 01797896 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d9.dll 2014-07-16 19:10 - 2014-04-14 07:18 - 00011776 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d8thk.dll 2014-07-16 19:10 - 2014-04-09 08:11 - 00226816 _____ (Microsoft Corporation) C:\windows\system32\WebClnt.dll 2014-07-16 19:10 - 2014-04-09 07:20 - 00198656 _____ (Microsoft Corporation) C:\windows\SysWOW64\WebClnt.dll 2014-07-16 18:51 - 2014-07-16 18:51 - 00001359 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Browser 7 der Telekom.lnk 2014-07-16 18:51 - 2014-07-16 18:51 - 00001347 _____ () C:\Users\Public\Desktop\Browser 7 der Telekom.lnk 2014-07-16 18:51 - 2014-07-16 18:51 - 00000000 ____D () C:\Program Files (x86)\Browser 7 Maintenance Service 2014-07-16 18:48 - 2014-07-16 18:48 - 00362592 _____ (Deutsche Telekom AG) C:\Users\Christina\Downloads\browser7_setup (1).exe.hy7enp8.partial 2014-07-16 18:22 - 2014-07-16 18:27 - 00000000 ____D () C:\Users\Christina\AppData\Roaming\GlarySoft 2014-07-16 18:22 - 2014-07-16 18:22 - 00001129 _____ () C:\Users\Christina\Desktop\Absolute Uninstaller.lnk 2014-07-16 18:21 - 2014-07-16 18:21 - 02194784 _____ (Glarysoft.com ) C:\Users\Christina\Downloads\au29setup.exe 2014-07-16 18:21 - 2014-07-16 18:21 - 02194784 _____ (Glarysoft.com ) C:\Users\Christina\Downloads\au29setup (1).exe 2014-07-16 17:29 - 2014-07-16 17:29 - 02347384 _____ (ESET) C:\Users\Christina\Downloads\esetsmartinstaller_enu.exe 2014-07-16 17:28 - 2014-07-16 17:28 - 00441592 _____ (Bleeping Computer, LLC) C:\Users\Christina\Downloads\sc-cleaner.exe 2014-07-16 17:28 - 2014-07-16 17:28 - 00001770 _____ () C:\sc-cleaner.txt 2014-07-16 17:09 - 2014-07-16 17:09 - 00000911 _____ () C:\Users\Christina\Desktop\JRT.txt 2014-07-16 16:59 - 2014-07-16 16:59 - 00000000 ____D () C:\windows\ERUNT 2014-07-16 16:58 - 2014-07-16 16:58 - 01016261 _____ (Thisisu) C:\Users\Christina\Downloads\JRT.exe 2014-07-16 16:44 - 2014-07-17 17:06 - 00000000 ____D () C:\AdwCleaner 2014-07-16 16:43 - 2014-07-16 16:43 - 01348263 _____ () C:\Users\Christina\Downloads\adwcleaner_3.215.exe 2014-07-16 16:34 - 2014-07-16 18:43 - 00000000 ____D () C:\NPE 2014-07-16 16:28 - 2014-07-16 16:28 - 00010226 _____ () C:\Users\Christina\Downloads\hijackthis.log 2014-07-16 16:27 - 2014-07-16 16:27 - 00388608 _____ (Trend Micro Inc.) C:\Users\Christina\Downloads\HijackThis.exe 2014-07-16 16:21 - 2014-07-16 16:21 - 00304857 _____ () C:\Users\Christina\Downloads\HijackThis_205.zip 2014-07-16 15:46 - 2014-07-17 18:01 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-16 15:45 - 2014-07-16 15:45 - 00003190 _____ () C:\windows\System32\Tasks\{AD428E5A-001B-408D-97F0-5BBCB5C4A4C4} 2014-07-16 15:44 - 2014-07-16 15:44 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Christina\Downloads\mbam-setup-2.0.2.1012.exe 2014-07-16 15:44 - 2014-07-16 15:44 - 00001125 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-07-16 15:44 - 2014-07-16 15:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-16 15:44 - 2014-07-16 15:44 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-16 15:44 - 2014-07-16 15:44 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-07-16 15:44 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys 2014-07-16 15:44 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys 2014-07-16 15:44 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2014-07-16 15:22 - 2014-07-16 15:22 - 00362592 _____ (Deutsche Telekom AG) C:\Users\Christina\Downloads\browser7_setup.exe 2014-07-16 15:11 - 2014-07-16 15:11 - 01286520 _____ (Netviewer AG) C:\Users\Christina\Downloads\diagnose.exe 2014-07-16 14:03 - 2014-07-16 14:03 - 00000000 ____H () C:\windows\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf 2014-07-16 13:11 - 2014-07-16 13:11 - 00000000 ____D () C:\windows\System32\Tasks\Norton 360 2014-07-16 12:48 - 2014-07-16 12:48 - 00000000 ____D () C:\Users\Christina\Documents\Neuer Ordner 2014-07-14 16:28 - 2014-07-14 16:28 - 00001550 _____ () C:\Users\Christina\Downloads\URLLink(73).acsm 2014-07-14 16:27 - 2014-07-14 16:27 - 00001501 _____ () C:\Users\Christina\Downloads\URLLink(70).acsm 2014-07-14 16:27 - 2014-07-14 16:27 - 00001475 _____ () C:\Users\Christina\Downloads\URLLink(71).acsm 2014-07-14 16:27 - 2014-07-14 16:27 - 00001458 _____ () C:\Users\Christina\Downloads\URLLink(72).acsm 2014-07-09 07:30 - 2014-04-14 05:29 - 01018880 _____ (Microsoft Corporation) C:\windows\system32\termsrv.dll 2014-07-09 07:18 - 2014-06-17 00:26 - 00779264 _____ (Microsoft Corporation) C:\windows\SysWOW64\osk.exe 2014-07-09 07:18 - 2014-06-17 00:24 - 00834048 _____ (Microsoft Corporation) C:\windows\system32\osk.exe 2014-07-09 07:18 - 2014-06-06 16:20 - 04190720 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys 2014-07-09 07:18 - 2014-05-30 05:03 - 00563200 _____ (Microsoft Corporation) C:\windows\system32\Drivers\afd.sys 2014-07-09 07:18 - 2014-05-29 14:02 - 00565576 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys 2014-07-09 07:18 - 2014-05-29 09:55 - 00735232 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll 2014-07-09 07:18 - 2014-05-29 08:40 - 00735232 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll 2014-07-09 07:18 - 2014-05-29 08:37 - 00436224 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll 2014-07-09 07:18 - 2014-05-29 07:34 - 00318976 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll 2014-07-09 07:18 - 2014-05-29 07:27 - 01417216 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll 2014-07-09 07:17 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-07-09 07:17 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2014-07-09 07:17 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2014-07-09 07:17 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2014-07-09 07:17 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2014-07-09 07:17 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2014-07-09 07:17 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2014-07-09 07:17 - 2014-06-19 01:46 - 00250880 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll 2014-07-09 07:17 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2014-07-09 07:17 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2014-07-09 07:17 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll 2014-07-09 07:17 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2014-07-09 07:17 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll 2014-07-09 07:17 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll 2014-07-09 07:17 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2014-07-09 07:17 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll 2014-07-09 07:17 - 2014-06-19 00:57 - 00225280 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll 2014-07-09 07:17 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll 2014-07-09 07:17 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2014-07-09 07:17 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll 2014-07-09 07:17 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl 2014-07-09 07:17 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll 2014-07-09 07:17 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2014-07-09 07:17 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2014-07-09 07:17 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll 2014-07-09 07:17 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll 2014-07-09 07:17 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll 2014-07-09 07:17 - 2014-06-06 15:04 - 00586240 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll 2014-07-09 07:17 - 2014-06-06 14:18 - 00488960 _____ (Microsoft Corporation) C:\windows\SysWOW64\qedit.dll 2014-07-09 07:17 - 2014-05-31 05:40 - 13287936 _____ (Microsoft Corporation) C:\windows\system32\twinui.dll 2014-07-09 07:17 - 2014-05-31 04:36 - 00923136 _____ (Microsoft Corporation) C:\windows\system32\WSShared.dll 2014-07-09 07:17 - 2014-05-31 04:32 - 00756224 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSShared.dll 2014-07-09 07:16 - 2014-05-31 12:07 - 00054776 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe 2014-07-09 07:16 - 2014-05-31 12:06 - 00555736 _____ (Microsoft Corporation) C:\windows\system32\twinapi.appcore.dll 2014-07-09 07:16 - 2014-05-31 05:30 - 11792384 _____ (Microsoft Corporation) C:\windows\SysWOW64\twinui.dll 2014-07-09 07:16 - 2014-05-31 05:12 - 00249344 _____ (Microsoft Corporation) C:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2014-07-09 07:16 - 2014-05-31 05:06 - 00093696 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll 2014-07-09 07:16 - 2014-05-31 05:03 - 00827392 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll 2014-07-09 07:16 - 2014-05-31 05:01 - 00189952 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2014-07-09 07:16 - 2014-05-31 04:56 - 00080896 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll 2014-07-09 07:16 - 2014-05-31 04:54 - 00666624 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll 2014-07-09 07:16 - 2014-05-31 04:48 - 03463680 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll 2014-07-09 07:16 - 2014-05-31 04:37 - 01054208 _____ (Microsoft Corporation) C:\windows\system32\twinui.appcore.dll 2014-07-09 07:16 - 2014-05-31 04:35 - 00828928 _____ (Microsoft Corporation) C:\windows\SysWOW64\twinui.appcore.dll 2014-07-09 07:13 - 2014-07-09 07:13 - 00079872 _____ (Microsoft Corporation) C:\windows\system32\WSReset.exe 2014-07-08 14:22 - 2014-07-08 14:23 - 00001563 _____ () C:\Users\Christina\Downloads\URLLink(69).acsm 2014-07-08 09:03 - 2014-07-08 09:03 - 00001516 _____ () C:\Users\Christina\Downloads\URLLink(68).acsm 2014-07-02 09:56 - 2014-07-02 09:56 - 01058200 _____ (Adobe) C:\Users\Christina\Downloads\install_flashplayer14x32au_mssa_aaa_aih(1).exe 2014-06-29 19:11 - 2014-06-29 19:11 - 00001549 _____ () C:\Users\Christina\Downloads\URLLink(67).acsm 2014-06-29 19:10 - 2014-06-29 19:10 - 00001580 _____ () C:\Users\Christina\Downloads\URLLink(66).acsm 2014-06-29 19:10 - 2014-06-29 19:10 - 00001546 _____ () C:\Users\Christina\Downloads\URLLink(65).acsm 2014-06-29 19:10 - 2014-06-29 19:10 - 00001472 _____ () C:\Users\Christina\Downloads\URLLink(64).acsm 2014-06-29 19:10 - 2014-06-29 19:10 - 00001470 _____ () C:\Users\Christina\Downloads\URLLink(63).acsm 2014-06-29 19:10 - 2014-06-29 19:10 - 00001469 _____ () C:\Users\Christina\Downloads\URLLink(62).acsm 2014-06-27 14:25 - 2014-06-27 14:25 - 00001486 _____ () C:\Users\Christina\Downloads\URLLink(59).acsm 2014-06-27 14:25 - 2014-06-27 14:25 - 00001457 _____ () C:\Users\Christina\Downloads\URLLink(61).acsm 2014-06-27 14:25 - 2014-06-27 14:25 - 00001457 _____ () C:\Users\Christina\Downloads\URLLink(60).acsm 2014-06-26 20:01 - 2014-06-26 20:01 - 00025664 _____ () C:\Users\Christina\Documents\Elisa 12. Geburtstag.odt 2014-06-25 20:13 - 2014-06-25 20:13 - 05408139 _____ () C:\Users\Christina\Downloads\AmazonApps-release.apk 2014-06-23 20:46 - 2014-06-25 10:30 - 00014094 _____ () C:\Users\Christina\Documents\ADAC.odt 2014-06-23 17:07 - 2014-06-23 17:07 - 01058200 _____ (Adobe) C:\Users\Christina\Downloads\install_flashplayer14x32au_mssa_aaa_aih.exe 2014-06-22 19:53 - 2014-06-22 19:53 - 00001518 _____ () C:\Users\Christina\Downloads\URLLink(58).acsm 2014-06-22 19:52 - 2014-06-22 19:52 - 00001549 _____ () C:\Users\Christina\Downloads\URLLink(57).acsm 2014-06-22 19:44 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2014-06-22 19:44 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll 2014-06-22 19:44 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll 2014-06-22 19:44 - 2014-05-10 05:46 - 02151424 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll 2014-06-22 19:44 - 2014-05-10 05:22 - 01312256 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll 2014-06-22 19:44 - 2014-05-05 06:02 - 03360256 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll 2014-06-22 19:44 - 2014-04-30 13:16 - 01336648 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll 2014-06-22 19:44 - 2014-04-30 05:51 - 01064448 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll 2014-06-22 19:43 - 2014-07-16 19:07 - 00428888 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS 2014-06-22 19:43 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll 2014-06-22 19:43 - 2014-05-09 01:06 - 00295424 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ks.sys 2014-06-22 19:43 - 2014-04-18 16:57 - 00032600 _____ (Microsoft Corporation) C:\windows\system32\ploptin.dll 2014-06-22 19:43 - 2014-04-18 16:44 - 01466856 _____ (Microsoft Corporation) C:\windows\system32\propsys.dll 2014-06-22 19:43 - 2014-04-18 15:29 - 01200288 _____ (Microsoft Corporation) C:\windows\SysWOW64\propsys.dll 2014-06-22 19:43 - 2014-04-18 11:44 - 00055296 _____ (Microsoft Corporation) C:\windows\system32\energyprov.dll 2014-06-22 19:43 - 2014-04-18 10:32 - 00805376 _____ (Microsoft Corporation) C:\windows\system32\win32spl.dll 2014-06-22 19:43 - 2014-04-18 10:21 - 01126912 _____ (Microsoft Corporation) C:\windows\system32\SearchFolder.dll 2014-06-22 19:43 - 2014-04-18 10:09 - 08652800 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Search.dll 2014-06-22 19:43 - 2014-04-18 09:51 - 00836608 _____ (Microsoft Corporation) C:\windows\SysWOW64\SearchFolder.dll 2014-06-22 19:43 - 2014-04-18 09:49 - 05833216 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Search.dll 2014-06-22 19:43 - 2014-04-14 11:20 - 00324888 _____ (Microsoft Corporation) C:\windows\system32\MFCaptureEngine.dll 2014-06-22 19:43 - 2014-04-14 10:01 - 00285144 _____ (Microsoft Corporation) C:\windows\SysWOW64\MFCaptureEngine.dll 2014-06-22 19:43 - 2014-04-11 06:51 - 00250368 _____ (Microsoft Corporation) C:\windows\system32\rdpencom.dll 2014-06-22 19:43 - 2014-04-11 06:23 - 00209920 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdpencom.dll 2014-06-22 19:43 - 2014-04-11 05:30 - 00449536 _____ (Microsoft Corporation) C:\windows\system32\defragsvc.dll 2014-06-22 19:43 - 2014-04-09 13:53 - 00337240 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Classpnp.sys 2014-06-22 19:43 - 2014-04-09 08:39 - 00191488 _____ (Microsoft Corporation) C:\windows\system32\rpchttp.dll 2014-06-22 19:43 - 2014-04-09 07:44 - 00144384 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpchttp.dll 2014-06-22 19:43 - 2014-04-09 05:33 - 00135168 _____ (Microsoft Corporation) C:\windows\system32\wscsvc.dll 2014-06-22 19:43 - 2014-04-08 04:01 - 00589656 _____ (Microsoft Corporation) C:\windows\system32\Drivers\fvevol.sys 2014-06-22 19:43 - 2014-04-06 18:34 - 00372568 _____ (Microsoft Corporation) C:\windows\system32\Drivers\storport.sys 2014-06-22 19:43 - 2014-04-06 18:34 - 00275800 ____C (Microsoft Corporation) C:\windows\system32\Drivers\msiscsi.sys 2014-06-22 19:43 - 2014-04-06 18:32 - 00125496 _____ (Microsoft Corporation) C:\windows\system32\dwmapi.dll 2014-06-22 19:43 - 2014-04-06 18:31 - 21268952 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll 2014-06-22 19:43 - 2014-04-06 18:30 - 00201920 _____ (Microsoft Corporation) C:\windows\system32\MSVideoDSP.dll 2014-06-22 19:43 - 2014-04-06 18:24 - 00360792 _____ (Microsoft Corporation) C:\windows\system32\Drivers\fltMgr.sys 2014-06-22 19:43 - 2014-04-06 18:20 - 01403856 _____ (Microsoft Corporation) C:\windows\system32\winmde.dll 2014-06-22 19:43 - 2014-04-06 18:20 - 01379064 _____ (Microsoft Corporation) C:\windows\system32\wmpmde.dll 2014-06-22 19:43 - 2014-04-06 18:20 - 00881616 _____ (Microsoft Corporation) C:\windows\system32\mfplat.dll 2014-06-22 19:43 - 2014-04-06 18:20 - 00765408 _____ (Microsoft Corporation) C:\windows\system32\mfmpeg2srcsnk.dll 2014-06-22 19:43 - 2014-04-06 18:20 - 00609448 _____ (Microsoft Corporation) C:\windows\system32\mf.dll 2014-06-22 19:43 - 2014-04-06 18:20 - 00491744 _____ (Microsoft Corporation) C:\windows\system32\mfsvr.dll 2014-06-22 19:43 - 2014-04-06 18:20 - 00467496 _____ (Microsoft Corporation) C:\windows\system32\AudioSes.dll 2014-06-22 19:43 - 2014-04-06 18:20 - 00463256 _____ (Microsoft Corporation) C:\windows\system32\AudioEng.dll 2014-06-22 19:43 - 2014-04-06 18:20 - 00364640 _____ (Microsoft Corporation) C:\windows\system32\AUDIOKSE.dll 2014-06-22 19:43 - 2014-04-06 18:20 - 00244880 _____ (Microsoft Corporation) C:\windows\system32\audiodg.exe 2014-06-22 19:43 - 2014-04-06 18:20 - 00028408 _____ (Microsoft Corporation) C:\windows\system32\mfpmp.exe 2014-06-22 19:43 - 2014-04-06 17:23 - 00098584 _____ (Microsoft Corporation) C:\windows\SysWOW64\dwmapi.dll 2014-06-22 19:43 - 2014-04-06 17:22 - 18755672 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll 2014-06-22 19:43 - 2014-04-06 17:22 - 00178184 _____ (Microsoft Corporation) C:\windows\SysWOW64\MSVideoDSP.dll 2014-06-22 19:43 - 2014-04-06 17:16 - 01209616 _____ (Microsoft Corporation) C:\windows\SysWOW64\winmde.dll 2014-06-22 19:43 - 2014-04-06 17:16 - 00707048 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfplat.dll 2014-06-22 19:43 - 2014-04-06 17:16 - 00669856 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfmpeg2srcsnk.dll 2014-06-22 19:43 - 2014-04-06 17:16 - 00518544 _____ (Microsoft Corporation) C:\windows\SysWOW64\mf.dll 2014-06-22 19:43 - 2014-04-06 17:16 - 00406504 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioEng.dll 2014-06-22 19:43 - 2014-04-06 17:16 - 00387896 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfsvr.dll 2014-06-22 19:43 - 2014-04-06 17:16 - 00326024 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioSes.dll 2014-06-22 19:43 - 2014-04-06 17:16 - 00305768 _____ (Microsoft Corporation) C:\windows\SysWOW64\AUDIOKSE.dll 2014-06-22 19:43 - 2014-04-06 14:58 - 00070656 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll 2014-06-22 19:43 - 2014-04-06 14:51 - 00467968 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll 2014-06-22 19:43 - 2014-04-06 14:33 - 00335872 _____ (Microsoft Corporation) C:\windows\system32\MDEServer.exe 2014-06-22 19:43 - 2014-04-06 14:24 - 00271872 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe 2014-06-22 19:43 - 2014-04-06 14:06 - 00061440 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll 2014-06-22 19:43 - 2014-04-06 13:26 - 00143872 _____ (Microsoft Corporation) C:\windows\system32\BootMenuUX.dll 2014-06-22 19:43 - 2014-04-06 13:20 - 00201216 _____ (Microsoft Corporation) C:\windows\system32\AudioEndpointBuilder.dll 2014-06-22 19:43 - 2014-04-06 13:01 - 00834048 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll 2014-06-22 19:43 - 2014-04-06 12:52 - 00955904 _____ (Microsoft Corporation) C:\windows\system32\MFMediaEngine.dll 2014-06-22 19:43 - 2014-04-06 12:51 - 01230336 _____ (Microsoft Corporation) C:\windows\system32\Windows.Media.dll 2014-06-22 19:43 - 2014-04-06 12:37 - 00800768 _____ (Microsoft Corporation) C:\windows\SysWOW64\MFMediaEngine.dll 2014-06-22 19:43 - 2014-04-06 12:36 - 00888320 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Media.dll 2014-06-22 19:43 - 2014-04-06 12:05 - 01222656 _____ (Microsoft Corporation) C:\windows\system32\Windows.Media.Streaming.dll 2014-06-22 19:43 - 2014-04-06 11:59 - 00982016 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Media.Streaming.dll 2014-06-22 19:43 - 2014-04-03 10:12 - 00307304 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll 2014-06-22 19:43 - 2014-04-03 10:12 - 00130144 _____ (Microsoft Corporation) C:\windows\system32\gpapi.dll 2014-06-22 19:43 - 2014-04-03 06:03 - 00230808 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll 2014-06-22 19:43 - 2014-04-03 06:03 - 00111528 _____ (Microsoft Corporation) C:\windows\SysWOW64\gpapi.dll 2014-06-22 19:43 - 2014-04-03 04:53 - 00677376 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv2.sys 2014-06-22 19:43 - 2014-04-03 04:51 - 01584128 _____ (Microsoft Corporation) C:\windows\system32\workfolderssvc.dll 2014-06-22 19:43 - 2014-04-03 04:23 - 00046592 _____ (Microsoft Corporation) C:\windows\SysWOW64\tlscsp.dll 2014-06-22 19:43 - 2014-04-03 04:22 - 00047616 _____ (Microsoft Corporation) C:\windows\system32\tlscsp.dll 2014-06-22 19:43 - 2014-04-01 08:23 - 00384856 ____C (Microsoft Corporation) C:\windows\system32\Drivers\spaceport.sys 2014-06-22 19:43 - 2014-03-31 07:42 - 07425368 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe 2014-06-22 19:43 - 2014-03-31 02:01 - 00186880 _____ (Microsoft Corporation) C:\windows\system32\WorkFoldersShell.dll 2014-06-22 19:43 - 2014-03-31 01:43 - 00761856 _____ (Microsoft Corporation) C:\windows\system32\WorkfoldersControl.dll 2014-06-22 19:43 - 2014-03-31 00:54 - 01308160 _____ (Microsoft Corporation) C:\windows\system32\gpsvc.dll 2014-06-22 19:43 - 2014-03-31 00:49 - 01287168 _____ (Microsoft Corporation) C:\windows\system32\mispace.dll 2014-06-22 19:43 - 2014-03-31 00:35 - 01029120 _____ (Microsoft Corporation) C:\windows\SysWOW64\mispace.dll 2014-06-22 19:43 - 2014-03-28 17:58 - 00407016 _____ (Microsoft Corporation) C:\windows\system32\services.exe 2014-06-22 19:43 - 2014-03-27 08:16 - 00246272 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srvnet.sys 2014-06-22 19:43 - 2014-03-27 07:36 - 00281600 _____ (Microsoft Corporation) C:\windows\system32\resutils.dll 2014-06-22 19:43 - 2014-03-27 06:59 - 00426496 _____ (Microsoft Corporation) C:\windows\system32\clusapi.dll 2014-06-22 19:43 - 2014-03-27 06:48 - 00219136 _____ (Microsoft Corporation) C:\windows\SysWOW64\resutils.dll 2014-06-22 19:43 - 2014-03-27 06:19 - 00313344 _____ (Microsoft Corporation) C:\windows\SysWOW64\clusapi.dll 2014-06-22 19:43 - 2014-03-27 05:46 - 00323072 _____ (Microsoft Corporation) C:\windows\system32\srvsvc.dll 2014-06-22 19:43 - 2014-03-27 05:15 - 00718336 _____ (Microsoft Corporation) C:\windows\system32\swprv.dll 2014-06-22 19:43 - 2014-03-27 05:10 - 01436160 _____ (Microsoft Corporation) C:\windows\system32\VSSVC.exe 2014-06-22 19:43 - 2014-03-20 05:48 - 00263424 _____ (Microsoft Corporation) C:\windows\system32\SystemSettingsAdminFlows.exe 2014-06-22 19:43 - 2014-03-20 02:44 - 06645248 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll 2014-06-22 19:43 - 2014-03-20 01:33 - 05774848 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll 2014-06-22 19:43 - 2014-03-19 10:15 - 00011264 _____ (Microsoft Corporation) C:\windows\system32\wlanhlp.dll 2014-06-22 19:43 - 2014-03-19 10:07 - 00443904 _____ (Microsoft Corporation) C:\windows\system32\Drivers\nwifi.sys 2014-06-22 19:43 - 2014-03-19 09:24 - 00064512 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll 2014-06-22 19:43 - 2014-03-19 09:17 - 00011264 _____ (Microsoft Corporation) C:\windows\SysWOW64\wlanhlp.dll 2014-06-22 19:43 - 2014-03-19 08:36 - 01057280 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll 2014-06-22 19:43 - 2014-03-19 07:56 - 00855552 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdvidcrl.dll 2014-06-22 19:43 - 2014-03-19 07:45 - 00443904 _____ (Microsoft Corporation) C:\windows\system32\wlansec.dll 2014-06-22 19:43 - 2014-03-19 07:19 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\wlanapi.dll 2014-06-22 19:43 - 2014-03-19 07:07 - 00370176 _____ (Microsoft Corporation) C:\windows\system32\wlanmsm.dll 2014-06-22 19:43 - 2014-03-19 07:02 - 01527296 _____ (Microsoft Corporation) C:\windows\system32\wlansvc.dll 2014-06-22 19:43 - 2014-03-19 07:00 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\wlanapi.dll 2014-06-22 19:43 - 2014-03-19 06:51 - 00300544 _____ (Microsoft Corporation) C:\windows\SysWOW64\wlanmsm.dll 2014-06-22 19:43 - 2014-03-19 06:31 - 02100736 _____ (Microsoft Corporation) C:\windows\system32\SystemSettingsAdminFlowUI.dll 2014-06-22 19:43 - 2014-03-19 06:18 - 02688000 _____ (Microsoft Corporation) C:\windows\system32\SettingsHandlers.dll 2014-06-22 19:43 - 2014-03-18 10:19 - 00077312 ____C (Microsoft Corporation) C:\windows\system32\Drivers\hdaudbus.sys 2014-06-22 19:43 - 2014-03-18 07:00 - 07173120 _____ (Microsoft Corporation) C:\windows\system32\Windows.Data.Pdf.dll 2014-06-22 19:43 - 2014-03-18 06:52 - 05104640 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Data.Pdf.dll 2014-06-22 19:43 - 2014-03-17 07:09 - 00462336 _____ (Microsoft Corporation) C:\windows\system32\XpsGdiConverter.dll 2014-06-22 19:43 - 2014-03-17 06:11 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\XpsGdiConverter.dll 2014-06-22 19:43 - 2014-03-17 05:01 - 00486912 _____ (Microsoft Corporation) C:\windows\system32\winspool.drv 2014-06-22 19:43 - 2014-03-17 04:45 - 00370176 _____ (Microsoft Corporation) C:\windows\SysWOW64\winspool.drv 2014-06-22 19:43 - 2014-03-14 08:26 - 00491520 _____ (Microsoft Corporation) C:\windows\system32\GeofenceMonitorService.dll 2014-06-22 19:43 - 2014-03-14 08:10 - 00357376 _____ (Microsoft Corporation) C:\windows\SysWOW64\GeofenceMonitorService.dll 2014-06-22 19:43 - 2014-03-06 14:42 - 00310616 ____C (Microsoft Corporation) C:\windows\system32\Drivers\volsnap.sys 2014-06-22 19:42 - 2014-05-19 08:31 - 00057856 _____ (Microsoft Corporation) C:\windows\system32\drvcfg.exe 2014-06-22 19:42 - 2014-05-19 08:21 - 00110592 _____ (Microsoft Corporation) C:\windows\system32\drvinst.exe 2014-06-22 19:42 - 2014-05-19 07:23 - 00098816 _____ (Microsoft Corporation) C:\windows\SysWOW64\drvinst.exe 2014-06-22 19:42 - 2014-05-01 15:31 - 03048904 _____ (Microsoft Corporation) C:\windows\system32\WpcMon.exe 2014-06-22 19:42 - 2014-05-01 15:31 - 00055328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\wpcfltr.sys 2014-06-22 19:42 - 2014-05-01 09:14 - 03118080 _____ (Microsoft Corporation) C:\windows\system32\Wpc.dll 2014-06-22 19:42 - 2014-05-01 09:05 - 02861056 _____ (Microsoft Corporation) C:\windows\system32\WpcWebSync.dll 2014-06-22 19:42 - 2014-05-01 08:51 - 02344448 _____ (Microsoft Corporation) C:\windows\SysWOW64\Wpc.dll 2014-06-22 19:42 - 2014-05-01 07:24 - 02834944 _____ (Microsoft Corporation) C:\windows\system32\wpccpl.dll 2014-06-22 19:42 - 2014-04-30 06:43 - 01975296 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll 2014-06-22 19:42 - 2014-04-30 06:26 - 01345536 _____ (Microsoft Corporation) C:\windows\system32\FntCache.dll 2014-06-22 19:42 - 2014-04-30 05:47 - 01509888 _____ (Microsoft Corporation) C:\windows\SysWOW64\DWrite.dll 2014-06-22 19:41 - 2014-06-22 19:41 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsgqec.dll 2014-06-22 19:41 - 2014-06-22 19:41 - 00001549 _____ () C:\Users\Christina\Downloads\URLLink(56).acsm 2014-06-22 19:40 - 2014-06-22 19:40 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2014-06-22 19:40 - 2014-06-22 19:40 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe 2014-06-22 19:40 - 2014-06-22 19:40 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2014-06-22 19:40 - 2014-06-22 19:40 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2014-06-22 19:37 - 2014-06-22 19:37 - 00001571 _____ () C:\Users\Christina\Downloads\URLLink(54).acsm 2014-06-22 19:37 - 2014-06-22 19:37 - 00001549 _____ () C:\Users\Christina\Downloads\URLLink(52).acsm 2014-06-22 19:37 - 2014-06-22 19:37 - 00001501 _____ () C:\Users\Christina\Downloads\URLLink(53).acsm 2014-06-22 19:37 - 2014-06-22 19:37 - 00001493 _____ () C:\Users\Christina\Downloads\URLLink(51).acsm 2014-06-22 19:37 - 2014-06-22 19:37 - 00001473 _____ () C:\Users\Christina\Downloads\URLLink(55).acsm ==================== One Month Modified Files and Folders ======= 2014-07-17 18:05 - 2014-07-17 15:03 - 00017683 _____ () C:\Users\Christina\Downloads\FRST.txt 2014-07-17 18:04 - 2014-07-17 18:04 - 00006671 _____ () C:\Users\Christina\Downloads\zoek-results.txt 2014-07-17 18:04 - 2014-07-17 08:29 - 00000000 ____D () C:\FRST 2014-07-17 18:01 - 2014-07-17 17:55 - 00000000 ____D () C:\zoek 2014-07-17 18:01 - 2014-07-17 17:38 - 00006671 _____ () C:\zoek-results.log 2014-07-17 18:01 - 2014-07-16 15:46 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-17 18:01 - 2014-04-15 19:09 - 00000000 ____D () C:\Users\Christina 2014-07-17 18:01 - 2013-08-22 16:45 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2014-07-17 18:00 - 2013-08-24 23:32 - 00095410 _____ () C:\windows\PFRO.log 2014-07-17 18:00 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\system32\sru 2014-07-17 17:56 - 2014-07-17 17:36 - 00000000 ____D () C:\zoek_backup 2014-07-17 17:36 - 2014-07-17 17:59 - 00024064 _____ () C:\windows\zoek-delete.exe 2014-07-17 17:36 - 2014-07-17 17:36 - 01287168 _____ () C:\Users\Christina\Desktop\zoek.exe 2014-07-17 17:34 - 2014-07-17 17:34 - 00001148 _____ () C:\Users\Christina\Desktop\mbam.txt 2014-07-17 17:06 - 2014-07-16 16:44 - 00000000 ____D () C:\AdwCleaner 2014-07-17 17:01 - 2014-05-08 08:32 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job 2014-07-17 16:43 - 2014-04-15 19:15 - 00003600 _____ () C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3508085089-3033536294-3423735549-1001 2014-07-17 16:40 - 2014-07-17 16:40 - 01348263 _____ () C:\Users\Christina\Desktop\adwcleaner_3.215.exe 2014-07-17 15:56 - 2014-04-15 19:09 - 01135183 _____ () C:\windows\WindowsUpdate.log 2014-07-17 15:05 - 2014-07-17 15:04 - 00035294 _____ () C:\Users\Christina\Downloads\Addition.txt 2014-07-17 14:48 - 2014-07-17 14:48 - 00001149 _____ () C:\Users\Christina\Desktop\FRST64 - Verknüpfung.lnk 2014-07-17 14:48 - 2014-07-17 14:48 - 00000926 _____ () C:\Users\Christina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FRST64.lnk 2014-07-17 14:45 - 2014-07-17 14:45 - 02086912 _____ (Farbar) C:\Users\Christina\Downloads\FRST64.exe 2014-07-17 12:15 - 2014-04-26 12:31 - 00000000 ____D () C:\Users\Christina\AppData\Local\CrashDumps 2014-07-17 12:08 - 2014-04-15 19:09 - 00000000 ____D () C:\Users\Christina\AppData\Local\Packages 2014-07-17 11:54 - 2014-05-12 13:11 - 00022956 _____ () C:\Users\Christina\Documents\2014.ods 2014-07-17 09:44 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\rescache 2014-07-17 08:27 - 2014-07-17 08:27 - 01077248 _____ (Farbar) C:\Users\Christina\Downloads\FRST (2).exe 2014-07-17 08:25 - 2014-07-17 08:25 - 01077248 _____ (Farbar) C:\Users\Christina\Downloads\FRST.exe 2014-07-17 08:25 - 2014-07-17 08:25 - 01077248 _____ (Farbar) C:\Users\Christina\Downloads\FRST (1).exe 2014-07-16 19:43 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\MediaViewer 2014-07-16 19:43 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\FileManager 2014-07-16 19:43 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\Camera 2014-07-16 19:42 - 2013-08-22 16:46 - 00036995 _____ () C:\windows\setupact.log 2014-07-16 19:40 - 2014-02-11 07:12 - 00000000 ____D () C:\windows\SysWOW64\RTCOM 2014-07-16 19:29 - 2013-08-22 17:20 - 00000000 ____D () C:\windows\CbsTemp 2014-07-16 19:12 - 2014-07-16 19:12 - 00000000 ____D () C:\Program Files\AMD 2014-07-16 19:09 - 2014-04-18 10:04 - 00233912 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll 2014-07-16 19:07 - 2014-06-22 19:43 - 00428888 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS 2014-07-16 18:51 - 2014-07-16 18:51 - 00001359 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Browser 7 der Telekom.lnk 2014-07-16 18:51 - 2014-07-16 18:51 - 00001347 _____ () C:\Users\Public\Desktop\Browser 7 der Telekom.lnk 2014-07-16 18:51 - 2014-07-16 18:51 - 00000000 ____D () C:\Program Files (x86)\Browser 7 Maintenance Service 2014-07-16 18:50 - 2014-04-15 20:02 - 00000000 ____D () C:\Program Files (x86)\Deutsche Telekom AG 2014-07-16 18:48 - 2014-07-16 18:48 - 00362592 _____ (Deutsche Telekom AG) C:\Users\Christina\Downloads\browser7_setup (1).exe.hy7enp8.partial 2014-07-16 18:45 - 2014-05-24 14:47 - 00000000 ____D () C:\Users\Christina\AppData\Local\NPE 2014-07-16 18:44 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\system32\FxsTmp 2014-07-16 18:43 - 2014-07-16 16:34 - 00000000 ____D () C:\NPE 2014-07-16 18:27 - 2014-07-16 18:22 - 00000000 ____D () C:\Users\Christina\AppData\Roaming\GlarySoft 2014-07-16 18:22 - 2014-07-16 18:22 - 00001129 _____ () C:\Users\Christina\Desktop\Absolute Uninstaller.lnk 2014-07-16 18:21 - 2014-07-16 18:21 - 02194784 _____ (Glarysoft.com ) C:\Users\Christina\Downloads\au29setup.exe 2014-07-16 18:21 - 2014-07-16 18:21 - 02194784 _____ (Glarysoft.com ) C:\Users\Christina\Downloads\au29setup (1).exe 2014-07-16 17:29 - 2014-07-16 17:29 - 02347384 _____ (ESET) C:\Users\Christina\Downloads\esetsmartinstaller_enu.exe 2014-07-16 17:28 - 2014-07-16 17:28 - 00441592 _____ (Bleeping Computer, LLC) C:\Users\Christina\Downloads\sc-cleaner.exe 2014-07-16 17:28 - 2014-07-16 17:28 - 00001770 _____ () C:\sc-cleaner.txt 2014-07-16 17:09 - 2014-07-16 17:09 - 00000911 _____ () C:\Users\Christina\Desktop\JRT.txt 2014-07-16 16:59 - 2014-07-16 16:59 - 00000000 ____D () C:\windows\ERUNT 2014-07-16 16:58 - 2014-07-16 16:58 - 01016261 _____ (Thisisu) C:\Users\Christina\Downloads\JRT.exe 2014-07-16 16:43 - 2014-07-16 16:43 - 01348263 _____ () C:\Users\Christina\Downloads\adwcleaner_3.215.exe 2014-07-16 16:33 - 2014-04-15 20:30 - 00000000 ____D () C:\ProgramData\Norton 2014-07-16 16:28 - 2014-07-16 16:28 - 00010226 _____ () C:\Users\Christina\Downloads\hijackthis.log 2014-07-16 16:27 - 2014-07-16 16:27 - 00388608 _____ (Trend Micro Inc.) C:\Users\Christina\Downloads\HijackThis.exe 2014-07-16 16:27 - 2014-04-15 19:09 - 00000000 ____D () C:\Users\Christina\AppData\Local\VirtualStore 2014-07-16 16:21 - 2014-07-16 16:21 - 00304857 _____ () C:\Users\Christina\Downloads\HijackThis_205.zip 2014-07-16 16:09 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\L2Schemas 2014-07-16 15:54 - 2014-02-11 08:07 - 00757756 _____ () C:\windows\system32\perfh007.dat 2014-07-16 15:54 - 2014-02-11 08:07 - 00173028 _____ () C:\windows\system32\perfc007.dat 2014-07-16 15:54 - 2013-08-24 23:38 - 01783968 _____ () C:\windows\system32\PerfStringBackup.INI 2014-07-16 15:47 - 2014-04-15 19:09 - 00001461 _____ () C:\Users\Christina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-07-16 15:45 - 2014-07-16 15:45 - 00003190 _____ () C:\windows\System32\Tasks\{AD428E5A-001B-408D-97F0-5BBCB5C4A4C4} 2014-07-16 15:44 - 2014-07-16 15:44 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Christina\Downloads\mbam-setup-2.0.2.1012.exe 2014-07-16 15:44 - 2014-07-16 15:44 - 00001125 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-07-16 15:44 - 2014-07-16 15:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-16 15:44 - 2014-07-16 15:44 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-16 15:44 - 2014-07-16 15:44 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-07-16 15:22 - 2014-07-16 15:22 - 00362592 _____ (Deutsche Telekom AG) C:\Users\Christina\Downloads\browser7_setup.exe 2014-07-16 15:17 - 2013-08-22 17:36 - 00000000 ___HD () C:\windows\ELAMBKUP 2014-07-16 15:17 - 2013-08-22 15:25 - 00524288 ___SH () C:\windows\system32\config\BBI 2014-07-16 15:11 - 2014-07-16 15:11 - 01286520 _____ (Netviewer AG) C:\Users\Christina\Downloads\diagnose.exe 2014-07-16 14:03 - 2014-07-16 14:03 - 00000000 ____H () C:\windows\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf 2014-07-16 13:11 - 2014-07-16 13:11 - 00000000 ____D () C:\windows\System32\Tasks\Norton 360 2014-07-16 13:06 - 2014-04-15 20:31 - 00003206 _____ () C:\windows\System32\Tasks\Norton WSC Integration 2014-07-16 13:06 - 2014-04-15 20:31 - 00002346 _____ () C:\Users\Public\Desktop\Norton 360.lnk 2014-07-16 13:06 - 2014-04-15 20:30 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360 2014-07-16 13:06 - 2014-04-15 20:30 - 00000000 ____D () C:\windows\system32\Drivers\N360x64 2014-07-16 13:05 - 2013-08-22 16:44 - 00503128 _____ () C:\windows\system32\FNTCACHE.DAT 2014-07-16 12:48 - 2014-07-16 12:48 - 00000000 ____D () C:\Users\Christina\Documents\Neuer Ordner 2014-07-16 12:44 - 2013-08-22 15:25 - 00262144 ___SH () C:\windows\system32\config\ELAM 2014-07-16 11:53 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\system32\NDF 2014-07-16 11:24 - 2014-02-11 07:12 - 00065536 _____ () C:\windows\system32\spu_storage.bin 2014-07-14 16:28 - 2014-07-14 16:28 - 00001550 _____ () C:\Users\Christina\Downloads\URLLink(73).acsm 2014-07-14 16:27 - 2014-07-14 16:27 - 00001501 _____ () C:\Users\Christina\Downloads\URLLink(70).acsm 2014-07-14 16:27 - 2014-07-14 16:27 - 00001475 _____ () C:\Users\Christina\Downloads\URLLink(71).acsm 2014-07-14 16:27 - 2014-07-14 16:27 - 00001458 _____ () C:\Users\Christina\Downloads\URLLink(72).acsm 2014-07-09 08:52 - 2013-08-22 17:36 - 00000000 ___RD () C:\windows\ToastData 2014-07-09 08:52 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-09 08:52 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-09 08:52 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\WinStore 2014-07-09 07:34 - 2014-04-18 20:42 - 00000000 ____D () C:\windows\system32\MRT 2014-07-09 07:32 - 2014-04-18 20:42 - 96441528 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2014-07-09 07:30 - 2014-04-15 20:55 - 00000000 ____D () C:\Program Files\Microsoft Office 15 2014-07-09 07:29 - 2013-08-22 21:12 - 00000000 ____D () C:\Program Files\Windows Journal 2014-07-09 07:13 - 2014-07-09 07:13 - 00079872 _____ (Microsoft Corporation) C:\windows\system32\WSReset.exe 2014-07-08 18:00 - 2014-02-11 07:43 - 00000000 ____D () C:\ProgramData\McAfee 2014-07-08 17:59 - 2014-05-08 08:32 - 00003772 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater 2014-07-08 14:23 - 2014-07-08 14:22 - 00001563 _____ () C:\Users\Christina\Downloads\URLLink(69).acsm 2014-07-08 09:03 - 2014-07-08 09:03 - 00001516 _____ () C:\Users\Christina\Downloads\URLLink(68).acsm 2014-07-04 13:16 - 2014-05-12 13:12 - 00018438 _____ () C:\Users\Christina\Documents\2015.ods 2014-07-02 09:56 - 2014-07-02 09:56 - 01058200 _____ (Adobe) C:\Users\Christina\Downloads\install_flashplayer14x32au_mssa_aaa_aih(1).exe 2014-06-29 19:11 - 2014-06-29 19:11 - 00001549 _____ () C:\Users\Christina\Downloads\URLLink(67).acsm 2014-06-29 19:10 - 2014-06-29 19:10 - 00001580 _____ () C:\Users\Christina\Downloads\URLLink(66).acsm 2014-06-29 19:10 - 2014-06-29 19:10 - 00001546 _____ () C:\Users\Christina\Downloads\URLLink(65).acsm 2014-06-29 19:10 - 2014-06-29 19:10 - 00001472 _____ () C:\Users\Christina\Downloads\URLLink(64).acsm 2014-06-29 19:10 - 2014-06-29 19:10 - 00001470 _____ () C:\Users\Christina\Downloads\URLLink(63).acsm 2014-06-29 19:10 - 2014-06-29 19:10 - 00001469 _____ () C:\Users\Christina\Downloads\URLLink(62).acsm 2014-06-27 14:25 - 2014-06-27 14:25 - 00001486 _____ () C:\Users\Christina\Downloads\URLLink(59).acsm 2014-06-27 14:25 - 2014-06-27 14:25 - 00001457 _____ () C:\Users\Christina\Downloads\URLLink(61).acsm 2014-06-27 14:25 - 2014-06-27 14:25 - 00001457 _____ () C:\Users\Christina\Downloads\URLLink(60).acsm 2014-06-26 22:55 - 2014-04-22 20:30 - 00703968 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe 2014-06-26 22:55 - 2014-04-22 20:30 - 00105440 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-06-26 20:01 - 2014-06-26 20:01 - 00025664 _____ () C:\Users\Christina\Documents\Elisa 12. Geburtstag.odt 2014-06-25 21:09 - 2013-08-22 17:36 - 00000000 ____D () C:\windows\AppReadiness 2014-06-25 20:13 - 2014-06-25 20:13 - 05408139 _____ () C:\Users\Christina\Downloads\AmazonApps-release.apk 2014-06-25 10:30 - 2014-06-23 20:46 - 00014094 _____ () C:\Users\Christina\Documents\ADAC.odt 2014-06-23 20:49 - 2013-08-22 17:36 - 00000000 ___RD () C:\windows\ImmersiveControlPanel 2014-06-23 20:49 - 2013-08-22 15:36 - 00000000 ____D () C:\windows\system32\oobe 2014-06-23 17:07 - 2014-06-23 17:07 - 01058200 _____ (Adobe) C:\Users\Christina\Downloads\install_flashplayer14x32au_mssa_aaa_aih.exe 2014-06-22 19:53 - 2014-06-22 19:53 - 00001518 _____ () C:\Users\Christina\Downloads\URLLink(58).acsm 2014-06-22 19:52 - 2014-06-22 19:52 - 00001549 _____ () C:\Users\Christina\Downloads\URLLink(57).acsm 2014-06-22 19:41 - 2014-06-22 19:41 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsgqec.dll 2014-06-22 19:41 - 2014-06-22 19:41 - 00001549 _____ () C:\Users\Christina\Downloads\URLLink(56).acsm 2014-06-22 19:40 - 2014-06-22 19:40 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2014-06-22 19:40 - 2014-06-22 19:40 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe 2014-06-22 19:40 - 2014-06-22 19:40 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2014-06-22 19:40 - 2014-06-22 19:40 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll 2014-06-22 19:40 - 2014-06-22 19:40 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2014-06-22 19:37 - 2014-06-22 19:37 - 00001571 _____ () C:\Users\Christina\Downloads\URLLink(54).acsm 2014-06-22 19:37 - 2014-06-22 19:37 - 00001549 _____ () C:\Users\Christina\Downloads\URLLink(52).acsm 2014-06-22 19:37 - 2014-06-22 19:37 - 00001501 _____ () C:\Users\Christina\Downloads\URLLink(53).acsm 2014-06-22 19:37 - 2014-06-22 19:37 - 00001493 _____ () C:\Users\Christina\Downloads\URLLink(51).acsm 2014-06-22 19:37 - 2014-06-22 19:37 - 00001473 _____ () C:\Users\Christina\Downloads\URLLink(55).acsm 2014-06-19 03:39 - 2014-07-09 07:17 - 23464448 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-06-19 02:48 - 2014-07-09 07:17 - 02768384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2014-06-19 02:16 - 2014-07-09 07:17 - 17276416 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2014-06-19 02:09 - 2014-07-09 07:17 - 00452608 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2014-06-19 01:51 - 2014-07-09 07:17 - 05721088 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2014-06-19 01:50 - 2014-07-09 07:17 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2014-06-19 01:48 - 2014-07-09 07:17 - 00292864 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2014-06-19 01:46 - 2014-07-09 07:17 - 00250880 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll 2014-06-19 01:39 - 2014-07-09 07:17 - 00608768 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2014-06-19 01:33 - 2014-07-09 07:17 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2014-06-19 01:32 - 2014-07-09 07:17 - 02179072 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll 2014-06-19 01:27 - 2014-07-09 07:17 - 02040832 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2014-06-19 01:12 - 2014-07-09 07:17 - 00367616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll 2014-06-19 00:59 - 2014-07-09 07:17 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll 2014-06-19 00:58 - 2014-07-09 07:17 - 02266112 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2014-06-19 00:58 - 2014-07-09 07:17 - 00239616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll 2014-06-19 00:57 - 2014-07-09 07:17 - 00225280 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll 2014-06-19 00:52 - 2014-07-09 07:17 - 04254720 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll 2014-06-19 00:51 - 2014-07-09 07:17 - 13527040 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2014-06-19 00:49 - 2014-07-09 07:17 - 00526336 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll 2014-06-19 00:45 - 2014-07-09 07:17 - 01964544 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl 2014-06-19 00:35 - 2014-07-09 07:17 - 11742208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll 2014-06-19 00:34 - 2014-07-09 07:17 - 01393664 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2014-06-19 00:15 - 2014-07-09 07:17 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2014-06-19 00:13 - 2014-07-09 07:17 - 01791488 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll 2014-06-19 00:09 - 2014-07-09 07:17 - 01139200 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll 2014-06-19 00:07 - 2014-07-09 07:17 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll 2014-06-17 00:26 - 2014-07-09 07:18 - 00779264 _____ (Microsoft Corporation) C:\windows\SysWOW64\osk.exe 2014-06-17 00:24 - 2014-07-09 07:18 - 00834048 _____ (Microsoft Corporation) C:\windows\system32\osk.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-12 03:41 ==================== End Of Log ============================ --- --- --- Fertig, oder ? |
17.07.2014, 19:37 | #11 |
/// TB-Ausbilder | Nach Omiga startet Telekom Browser nicht mehr [gelöst] Servus, wie sieht es mit dem Browser aus? Funktioniert der wieder? Schritt 1 ESET Online Scanner
Schritt 2 Downloade Dir bitte SecurityCheck und:
Bitte poste mit deiner nächsten Antwort
|
18.07.2014, 07:06 | #12 |
| Nach Omiga startet Telekom Browser nicht mehr [gelöst] Der Browser geht wieder, danke, danke, danke !! Sogar die Favoriten sind noch da ! Trotzdem noch weitermachen ? LG |
18.07.2014, 13:29 | #13 |
/// TB-Ausbilder | Nach Omiga startet Telekom Browser nicht mehr [gelöst] Ja bitte, sei so nett. Wir haben es dann auch gleich geschafft. |
18.07.2014, 20:42 | #14 |
| Nach Omiga startet Telekom Browser nicht mehr [gelöst]Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=be3b48a7ad8ce24f81048ad60b34b0b4 # engine=19241 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2014-07-18 06:47:30 # local_time=2014-07-18 08:47:30 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.2.9200 NT # compatibility_mode_1='Norton 360' # compatibility_mode=3598 16777213 100 100 99585 156371746 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 5627947 30590543 0 0 # scanned=200567 # found=1 # cleaned=0 # scan_time=4666 sh=E97CBDBD7CFED2C58464C1ABF186520022DE5666 ft=1 fh=7a2ea5ecc33ad0e3 vn="Variante von Win64/Thinknice.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SpAPPSv64.dll.vir" Code:
ATTFilter Results of screen317's Security Check version 0.99.85 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Windows Defender Norton 360 Online WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Adobe Flash Player 14.0.0.145 ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbam.exe Malwarebytes Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` |
18.07.2014, 20:43 | #15 |
/// TB-Ausbilder | Nach Omiga startet Telekom Browser nicht mehr [gelöst] Wenn du keine Probleme mehr hast, dann sind wir hier fertig. Deine Logdateien sind sauber. Zum Schluss müssen wir noch ein paar abschließende Schritte unternehmen, um deinen Pc aufzuräumen und abzusichern. Schritt 1 Die Reihenfolge ist hier entscheidend.
Schritt 2 Abschließend habe ich noch ein paar Tipps zur Absicherung deines Systems. Ich kann gar nicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti-Viren-Programm und zusätzlicher Schutz
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden. Mozilla Firefox
Performance
Was du vermeiden solltest:
Nun bleibt mir nur noch dir viel Spaß beim sicheren Surfen zu wünschen... ... und vielleicht möchtest du ja das Trojaner-Board unterstützen? Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so dass ich dieses Thema aus meinen Abos löschen kann. |
Themen zu Nach Omiga startet Telekom Browser nicht mehr |
autorun, bho, bonjour, browser, cdrom, check, excel, explorer, explorer.exe, helper, internet, internet explorer, logfile, microsoft, neustart, programme, realtek, seite, software, symantec, system, system32, virus, windows, winlogon |