Hallo Schrauber,
leider bin ich mit meinen Papieren noch nicht ganz fertig :crazy:, Kannst Du mir ALternativen zu Avira nennen, die Ihr empfehlt (freeware und Kostenpflichtig) ?
Aber ich fange jetzt mal mit dem Computer meiner Tochter an.
Malwarebytes brachte folgende Logfiles:
am 28.08.13 Code:
Malwarebytes Anti-Malware (Test) 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.08.28.02
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 10.0.9200.16660
Admin :: LUISA-PC [Administrator]
Schutz: Aktiviert
28.08.2013 12:20:39
mbam-log-2013-08-28 (12-20-39).txt
Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 375474
Laufzeit: 1 Stunde(n), 46 Minute(n), 48 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 1
C:\Users\Luisa\Downloads\VideoPerformerSetup.exe (PUP.Optional.InstallBrain) -> Erfolgreich gelöscht und in Quarantäne gestellt.
(Ende) und gestern Code:
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.09.16.02
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 10.0.9200.16686
Admin :: LUISA-PC [Administrator]
16.09.2013 12:47:56
mbam-log-2013-09-16 (12-47-56).txt
Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 377646
Laufzeit: 1 Stunde(n), 47 Minute(n), 44 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 1
C:\Program Files\AskPartnerNetwork\Toolbar\APNSetup.exe (PUP.Optional.ASKToolbar.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
(Ende) FRST:
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 16-09-2013 03
Ran by Admin (administrator) on LUISA-PC on 17-09-2013 12:59:37
Running from C:\Users\Admin\Downloads
Microsoft Windows 7 Starter Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Microsoft Corporation) C:\windows\system32\WLANExt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(Secunia) C:\Program Files\Secunia\PSI\PSIA.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(SAMSUNG Electronics) C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\SFB\SmartRestarter.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
(SEC) C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(DoctorSoft) C:\Program Files\AnyPC Client\APLangApp.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\windows\system32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Secunia) C:\Program Files\Secunia\PSI\psi_tray.exe
(Intel Corporation) C:\windows\system32\igfxext.exe
(Intel Corporation) C:\windows\system32\igfxsrvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [8555040 2010-04-07] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1713448 2010-02-26] (Synaptics Incorporated)
HKLM\...\Run: [APLangApp] - C:\Program Files\AnyPC Client\APLangApp.exe [13312 2009-11-20] (DoctorSoft)
HKLM\...\Run: [UCam_Menu] - C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM\...\Run: [HotKeysCmds] - C:\windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-02] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
MountPoints2: {de7e4d9b-e153-11e1-85b2-806e6f6e6963} - E:\Setup.exe
HKU\MGC temp (200113)\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [ 2012-08-12] (Google Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com/ig/redirectdomain?brand=smsn&bmod=smsn
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=smsn&bmod=smsn
SearchScopes: HKCU - DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL =
SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL =
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Toolbar: HKCU - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\cka0y1me.default
FF DefaultSearchEngine: Google
FF SearchEngineOrder.1: Ask.com
FF Homepage: hxxp://www.mozilla.com/de/firefox/central/
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\3.0.40624.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\IPSFFPlgn\
FF HKLM\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\coFFPlgn\
========================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [84024 2013-09-02] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-02] (Avira Operations GmbH & Co. KG)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia)
S2 Secunia Update Agent; C:\Program Files\Secunia\PSI\sua.exe [660184 2013-07-03] (Secunia)
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [88840 2013-09-02] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136672 2013-09-02] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-08-22] (Avira Operations GmbH & Co. KG)
R3 btwampfl; C:\Windows\System32\drivers\btwampfl.sys [286248 2010-03-06] (Broadcom Corporation.)
R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_x86.sys [16024 2013-07-03] (Secunia)
R1 SABI; C:\windows\system32\Drivers\SABI.sys [10752 2009-05-28] (SAMSUNG ELECTRONICS)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-08-22] (Avira GmbH)
R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] ()
U3 ugloapoc; \??\C:\Users\Admin\AppData\Local\Temp\ugloapoc.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-17 12:48 - 2013-09-17 12:48 - 00377856 _____ C:\Users\Admin\Downloads\gmer_2.1.19163.exe
2013-09-17 12:42 - 2013-09-17 12:45 - 00020549 _____ C:\Users\Admin\Downloads\Addition.txt
2013-09-17 12:37 - 2013-09-17 12:37 - 00000000 ____D C:\FRST
2013-09-17 12:35 - 2013-09-17 12:37 - 01083437 _____ (Farbar) C:\Users\Admin\Downloads\FRST.exe
2013-09-17 12:30 - 2013-09-17 12:32 - 00000472 _____ C:\Users\Admin\Downloads\defogger_disable.log
2013-09-17 12:30 - 2013-09-17 12:30 - 00000000 _____ C:\Users\Admin\defogger_reenable
2013-09-17 12:29 - 2013-09-17 12:30 - 00050477 _____ C:\Users\Admin\Downloads\Defogger.exe
2013-09-16 14:48 - 2013-09-16 14:48 - 00000000 ____D C:\Users\Luisa\AppData\Roaming\OpenOffice
2013-09-16 12:03 - 2013-09-16 12:03 - 00001074 _____ C:\Users\Public\Desktop\OpenOffice 4.0.0.lnk
2013-09-16 12:01 - 2013-09-16 12:01 - 00000000 ____D C:\Program Files\OpenOffice 4
2013-09-16 11:54 - 2013-09-16 11:54 - 00001989 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk
2013-09-16 11:52 - 2013-09-16 11:53 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-09-16 11:51 - 2013-09-16 11:51 - 00000000 ____D C:\Users\Default\AppData\Local\Adobe
2013-09-16 11:51 - 2013-09-16 11:51 - 00000000 ____D C:\Users\Default User\AppData\Local\Adobe
2013-09-16 11:46 - 2013-09-16 11:46 - 00002505 _____ C:\Users\Public\Desktop\Skype.lnk
2013-09-16 11:46 - 2013-09-16 11:46 - 00000000 ____D C:\Program Files\Common Files\Skype
2013-09-16 11:32 - 2013-09-16 11:32 - 00000000 ____D C:\Users\Admin\AppData\Local\Secunia PSI
2013-09-16 11:32 - 2013-09-16 11:32 - 00000000 ____D C:\Program Files\Secunia
2013-09-16 11:31 - 2013-09-16 11:31 - 03272136 _____ (Secunia) C:\Users\Admin\Downloads\PSISetup711.exe
2013-09-16 11:19 - 2013-09-16 11:19 - 97745148 _____ C:\windows\system32\�ፈ᭔_
2013-09-14 12:35 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-09-14 12:35 - 2013-08-10 05:59 - 00042496 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2013-09-14 12:35 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-09-14 12:35 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-09-14 12:35 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2013-09-14 12:35 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2013-09-14 12:35 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2013-09-14 12:35 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2013-09-14 12:35 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2013-09-14 12:35 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-09-14 12:35 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2013-09-14 12:35 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-09-14 12:35 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2013-09-14 12:34 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-09-14 12:34 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-09-14 12:34 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-09-11 20:39 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2013-09-11 20:39 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\windows\system32\shdocvw.dll
2013-09-11 20:38 - 2013-08-08 03:03 - 02348544 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2013-09-11 20:38 - 2013-08-05 03:56 - 00133056 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ataport.sys
2013-09-11 20:38 - 2013-08-02 03:50 - 00169984 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2013-09-11 20:38 - 2013-08-02 03:49 - 00868352 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2013-09-11 20:38 - 2013-08-02 03:49 - 00293376 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2013-09-11 20:38 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-09-11 20:38 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-11 20:38 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-11 20:38 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-09-11 20:38 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-09-11 20:38 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-11 20:38 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-09-11 20:38 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-11 20:38 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-11 20:38 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-09-11 20:38 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-11 20:38 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-11 20:38 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-09-11 20:38 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-09-11 20:38 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-11 20:38 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-09-11 20:38 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-09-11 20:38 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-09-11 20:38 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-09-11 20:38 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-11 20:38 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-09-11 20:38 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-09-11 20:38 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-09-11 20:38 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-09-11 20:38 - 2013-08-02 02:52 - 00271360 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2013-09-11 20:38 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-09-11 20:38 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-11 20:38 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-09-11 20:38 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-09-11 17:35 - 2013-09-11 17:35 - 00000000 ____D C:\Users\Luisa\AppData\Roaming\Malwarebytes
2013-09-09 18:45 - 2013-09-09 18:45 - 96732368 _____ C:\windows\system32\ູ瓳᭔[
2013-09-07 17:18 - 2013-09-07 17:18 - 96511910 _____ C:\windows\system32\鴌᭔e
2013-08-28 12:17 - 2013-08-28 12:17 - 00000000 ____D C:\Program Files\Common Files\Java
2013-08-28 12:17 - 2013-08-28 12:16 - 00263592 _____ (Oracle Corporation) C:\windows\system32\javaws.exe
2013-08-28 12:17 - 2013-08-28 12:16 - 00175016 _____ (Oracle Corporation) C:\windows\system32\javaw.exe
2013-08-28 12:17 - 2013-08-28 12:16 - 00175016 _____ (Oracle Corporation) C:\windows\system32\java.exe
2013-08-28 12:17 - 2013-08-28 12:16 - 00094632 _____ (Oracle Corporation) C:\windows\system32\WindowsAccessBridge.dll
2013-08-28 12:16 - 2013-08-28 12:16 - 00000000 ____D C:\Program Files\Java
2013-08-28 12:07 - 2013-08-28 12:07 - 00001067 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-28 12:07 - 2013-08-28 12:07 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Malwarebytes
2013-08-28 12:07 - 2013-08-28 12:07 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-28 12:07 - 2013-08-28 12:07 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-08-28 12:07 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2013-08-28 11:58 - 2013-08-28 11:58 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Admin\Downloads\mbam-setup-1.75.0.1300.exe
2013-08-28 11:57 - 2013-08-28 11:57 - 00000000 ____D C:\Users\Admin\AppData\Local\Macromedia
2013-08-28 11:56 - 2013-08-28 11:56 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Avira
2013-08-23 19:33 - 2013-08-23 19:33 - 00000000 ____D C:\Users\Luisa\AppData\Roaming\Avira
2013-08-23 18:32 - 2013-09-02 14:43 - 00066144 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avnetflt.sys
2013-08-23 18:30 - 2013-08-23 18:30 - 00000000 ____D C:\ProgramData\APN
2013-08-23 18:27 - 2013-08-23 18:27 - 00001940 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
2013-08-23 18:26 - 2013-09-02 14:43 - 00136672 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avipbb.sys
2013-08-23 18:26 - 2013-09-02 14:43 - 00088840 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avgntflt.sys
2013-08-23 18:26 - 2013-08-23 18:26 - 00000000 ____D C:\Program Files\Avira
2013-08-23 18:26 - 2013-08-22 21:46 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avkmgr.sys
2013-08-23 18:26 - 2013-08-22 21:46 - 00028520 _____ (Avira GmbH) C:\windows\system32\Drivers\ssmdrv.sys
2013-08-18 16:07 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\windows\system32\WMVDECOD.DLL
2013-08-18 16:07 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\windows\system32\ntkrnlpa.exe
2013-08-18 16:07 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2013-08-18 16:07 - 2013-07-09 06:53 - 01289096 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2013-08-18 16:07 - 2013-07-09 06:50 - 00652800 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
==================== One Month Modified Files and Folders =======
2013-09-17 12:48 - 2013-09-17 12:48 - 00377856 _____ C:\Users\Admin\Downloads\gmer_2.1.19163.exe
2013-09-17 12:45 - 2013-09-17 12:42 - 00020549 _____ C:\Users\Admin\Downloads\Addition.txt
2013-09-17 12:45 - 2012-11-20 15:49 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2013-09-17 12:40 - 2009-07-14 06:34 - 00010272 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-17 12:40 - 2009-07-14 06:34 - 00010272 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-17 12:37 - 2013-09-17 12:37 - 00000000 ____D C:\FRST
2013-09-17 12:37 - 2013-09-17 12:35 - 01083437 _____ (Farbar) C:\Users\Admin\Downloads\FRST.exe
2013-09-17 12:35 - 2012-08-12 16:04 - 00001092 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-09-17 12:33 - 2012-08-12 16:04 - 00001096 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-09-17 12:33 - 2010-05-11 03:56 - 01824615 _____ C:\windows\WindowsUpdate.log
2013-09-17 12:32 - 2013-09-17 12:30 - 00000472 _____ C:\Users\Admin\Downloads\defogger_disable.log
2013-09-17 12:30 - 2013-09-17 12:30 - 00000000 _____ C:\Users\Admin\defogger_reenable
2013-09-17 12:30 - 2013-09-17 12:29 - 00050477 _____ C:\Users\Admin\Downloads\Defogger.exe
2013-09-17 12:30 - 2012-08-08 16:35 - 00000000 ____D C:\Users\Admin
2013-09-17 11:42 - 2012-11-22 11:48 - 00031107 _____ C:\windows\setupact.log
2013-09-17 11:42 - 2009-07-14 06:53 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-09-17 11:39 - 2012-11-22 12:07 - 00064024 _____ C:\Users\Admin\AppData\Local\GDIPFONTCACHEV1.DAT
2013-09-16 14:48 - 2013-09-16 14:48 - 00000000 ____D C:\Users\Luisa\AppData\Roaming\OpenOffice
2013-09-16 14:44 - 2009-07-14 06:33 - 00289512 _____ C:\windows\system32\FNTCACHE.DAT
2013-09-16 14:43 - 2013-01-12 11:56 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-09-16 14:43 - 2012-12-29 13:52 - 00020602 _____ C:\windows\PFRO.log
2013-09-16 12:03 - 2013-09-16 12:03 - 00001074 _____ C:\Users\Public\Desktop\OpenOffice 4.0.0.lnk
2013-09-16 12:03 - 2013-01-12 11:56 - 00001033 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-09-16 12:03 - 2013-01-12 11:56 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-09-16 12:01 - 2013-09-16 12:01 - 00000000 ____D C:\Program Files\OpenOffice 4
2013-09-16 11:54 - 2013-09-16 11:54 - 00001989 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk
2013-09-16 11:53 - 2013-09-16 11:52 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-09-16 11:53 - 2012-08-07 15:59 - 00000000 ____D C:\ProgramData\Adobe
2013-09-16 11:52 - 2012-11-20 15:10 - 00000000 ____D C:\Program Files\Adobe
2013-09-16 11:51 - 2013-09-16 11:51 - 00000000 ____D C:\Users\Default\AppData\Local\Adobe
2013-09-16 11:51 - 2013-09-16 11:51 - 00000000 ____D C:\Users\Default User\AppData\Local\Adobe
2013-09-16 11:47 - 2010-05-11 04:06 - 00000000 ____D C:\ProgramData\Skype
2013-09-16 11:46 - 2013-09-16 11:46 - 00002505 _____ C:\Users\Public\Desktop\Skype.lnk
2013-09-16 11:46 - 2013-09-16 11:46 - 00000000 ____D C:\Program Files\Common Files\Skype
2013-09-16 11:46 - 2010-05-11 04:07 - 00000000 ___RD C:\Program Files\Skype
2013-09-16 11:32 - 2013-09-16 11:32 - 00000000 ____D C:\Users\Admin\AppData\Local\Secunia PSI
2013-09-16 11:32 - 2013-09-16 11:32 - 00000000 ____D C:\Program Files\Secunia
2013-09-16 11:31 - 2013-09-16 11:31 - 03272136 _____ (Secunia) C:\Users\Admin\Downloads\PSISetup711.exe
2013-09-16 11:19 - 2013-09-16 11:19 - 97745148 _____ C:\windows\system32\�ፈ᭔_
2013-09-15 21:06 - 2009-07-14 04:37 - 00000000 ____D C:\windows\rescache
2013-09-15 19:57 - 2009-07-14 04:37 - 00000000 ____D C:\windows\Microsoft.NET
2013-09-15 11:18 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\de-DE
2013-09-14 12:25 - 2013-07-24 20:32 - 00000000 ____D C:\windows\system32\MRT
2013-09-14 12:04 - 2012-11-22 11:23 - 76725432 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2013-09-13 22:45 - 2012-08-12 16:03 - 00692616 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerApp.exe
2013-09-13 22:45 - 2012-08-12 16:03 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerCPLApp.cpl
2013-09-11 17:51 - 2012-08-08 15:16 - 00000000 ____D C:\Users\Luisa\Documents\Schule
2013-09-11 17:35 - 2013-09-11 17:35 - 00000000 ____D C:\Users\Luisa\AppData\Roaming\Malwarebytes
2013-09-09 18:45 - 2013-09-09 18:45 - 96732368 _____ C:\windows\system32\ູ瓳᭔[
2013-09-07 17:18 - 2013-09-07 17:18 - 96511910 _____ C:\windows\system32\鴌᭔e
2013-09-02 14:43 - 2013-08-23 18:32 - 00066144 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avnetflt.sys
2013-09-02 14:43 - 2013-08-23 18:26 - 00136672 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avipbb.sys
2013-09-02 14:43 - 2013-08-23 18:26 - 00088840 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avgntflt.sys
2013-08-28 12:17 - 2013-08-28 12:17 - 00000000 ____D C:\Program Files\Common Files\Java
2013-08-28 12:16 - 2013-08-28 12:17 - 00263592 _____ (Oracle Corporation) C:\windows\system32\javaws.exe
2013-08-28 12:16 - 2013-08-28 12:17 - 00175016 _____ (Oracle Corporation) C:\windows\system32\javaw.exe
2013-08-28 12:16 - 2013-08-28 12:17 - 00175016 _____ (Oracle Corporation) C:\windows\system32\java.exe
2013-08-28 12:16 - 2013-08-28 12:17 - 00094632 _____ (Oracle Corporation) C:\windows\system32\WindowsAccessBridge.dll
2013-08-28 12:16 - 2013-08-28 12:16 - 00000000 ____D C:\Program Files\Java
2013-08-28 12:16 - 2013-01-23 17:33 - 00867240 _____ (Oracle Corporation) C:\windows\system32\npDeployJava1.dll
2013-08-28 12:16 - 2013-01-23 17:33 - 00789416 _____ (Oracle Corporation) C:\windows\system32\deployJava1.dll
2013-08-28 12:07 - 2013-08-28 12:07 - 00001067 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-28 12:07 - 2013-08-28 12:07 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Malwarebytes
2013-08-28 12:07 - 2013-08-28 12:07 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-28 12:07 - 2013-08-28 12:07 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-08-28 11:58 - 2013-08-28 11:58 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Admin\Downloads\mbam-setup-1.75.0.1300.exe
2013-08-28 11:57 - 2013-08-28 11:57 - 00000000 ____D C:\Users\Admin\AppData\Local\Macromedia
2013-08-28 11:56 - 2013-08-28 11:56 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Avira
2013-08-23 19:33 - 2013-08-23 19:33 - 00000000 ____D C:\Users\Luisa\AppData\Roaming\Avira
2013-08-23 18:30 - 2013-08-23 18:30 - 00000000 ____D C:\ProgramData\APN
2013-08-23 18:27 - 2013-08-23 18:27 - 00001940 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
2013-08-23 18:26 - 2013-08-23 18:26 - 00000000 ____D C:\Program Files\Avira
2013-08-23 18:26 - 2012-08-07 17:56 - 00000000 ____D C:\ProgramData\Avira
2013-08-22 21:46 - 2013-08-23 18:26 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avkmgr.sys
2013-08-22 21:46 - 2013-08-23 18:26 - 00028520 _____ (Avira GmbH) C:\windows\system32\Drivers\ssmdrv.sys
2013-08-19 10:27 - 2009-07-26 22:06 - 01519874 _____ C:\windows\system32\PerfStringBackup.INI
Some content of TEMP:
====================
C:\Users\Admin\AppData\Local\Temp\AskSLib.dll
C:\Users\Admin\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe
C:\Users\Luisa\AppData\Local\Temp\AskSLib.dll
C:\Users\Luisa\AppData\Local\Temp\fp_pl_pfs_installer-1.exe
C:\Users\Luisa\AppData\Local\Temp\fp_pl_pfs_installer.exe
C:\Users\MGC temp (200113)\AppData\Local\Temp\AskSLib.dll
C:\Users\MGC temp (200113)\AppData\Local\Temp\MouseKeyboardCenterx86_1031.exe
C:\Users\MGC temp (200113)\AppData\Local\Temp\SkypeSetup.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-09-12 21:51
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
und Addition: Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 16-09-2013 03
Ran by Admin at 2013-09-17 12:42:31
Running from C:\Users\Admin\Downloads
Boot Mode: Normal
==========================================================
==================== Installed Programs =======================
Adobe Flash Player 11 ActiveX (Version: 11.8.800.174)
Adobe Flash Player 11 Plugin (Version: 11.8.800.168)
Adobe Reader XI (11.0.04) - Deutsch (Version: 11.0.04)
Alice Greenfingers
AnyPC Client (Version: 1.0.0.25)
Atheros Client Installation Program (Version: 1.0.2.1119)
Avira Free Antivirus (Version: 13.0.0.4052)
BatteryLifeExtender (Version: 1.0.1)
Bonbon Quest
Broadcom 802.11 Network Adapter (Version: 5.60.48.44)
Cake Mania
CCleaner (Version: 3.24)
ChargeableUSB (Version: 1.0.0.0)
CyberLink YouCam (Version: 2.0.3911)
Daycare Nightmare
Easy Content Share (Version: 1.0.0.13)
Easy Display Manager (Version: 3.1)
Easy Network Manager (Version: 4.3.1)
Easy Resolution Manager (Version: 1.0.0)
Easy SpeedUp Manager (Version: 2.1.0.10)
EasyBatteryManager (Version: 4.0.0.4)
EasyFileShare (Version: 1.0.2)
English G 21 e-Workbook B2 (Version: 1.00.000)
English G 21 e-Workbook B3 (Version: 1.00.000)
Fast Booting SW (Version: 1.6.0.0)
Flip Words
Galapago
Game Pack (Version: 6.3.1.1)
Gem Shop
Google Toolbar for Internet Explorer (Version: 1.0.0)
Google Toolbar for Internet Explorer (Version: 7.5.4413.1752)
Google Update Helper (Version: 1.3.21.153)
Insaniquarium Deluxe
Intel(R) Graphics Media Accelerator Driver (Version: 8.14.10.2230)
Intel® Matrix Storage Manager
Java 7 Update 25 (Version: 7.0.250)
Java Auto Updater (Version: 2.1.9.5)
Junk Mail filter update (Version: 14.0.8089.726)
Mahjong Escape Ancient China
Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300)
Marvell Miniport Driver (Version: 11.22.3.3)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6012.5000)
Microsoft Choice Guard (Version: 2.0.48.0)
Microsoft Silverlight (Version: 3.0.40624.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (Version: 9.0.30411)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Mozilla Firefox 23.0 (x86 de) (Version: 23.0)
Mozilla Maintenance Service (Version: 23.0)
MSVCRT (Version: 14.0.1468.721)
OpenOffice 4.0.0 (Version: 4.00.9702)
Realtek High Definition Audio Driver (Version: 6.0.1.6083)
REALTEK PCIE Wireless LAN Software (Version: 0136.10.0325)
Samsung Recovery Solution 4 (Version: 4.0.0.6)
Samsung Support Center (Version: 1.1.3)
Samsung Update Plus (Version: 2.0)
Secunia PSI (3.0.0.7011) (Version: 3.0.0.7011)
Skype Toolbars (Version: 1.0.4051)
Skype™ 6.3 (Version: 6.3.105)
Slingo
Spelling Dictionaries Support For Adobe Reader 9 (Version: 9.0.0)
Synaptics Pointing Device Driver (Version: 15.0.10.0)
tulox
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1)
User Guide (Version: 1.0)
WIDCOMM Bluetooth Software (Version: 6.3.0.4500)
Windows Live Anmelde-Assistent (Version: 5.000.818.5)
Windows Live Call (Version: 14.0.8064.0206)
Windows Live Communications Platform (Version: 14.0.8064.206)
Windows Live Essentials (Version: 14.0.8089.0726)
Windows Live Essentials (Version: 14.0.8089.726)
Windows Live Family Safety (Version: 14.0.8093.805)
Windows Live Fotogalerie (Version: 14.0.8081.709)
Windows Live Mail (Version: 14.0.8089.0726)
Windows Live Messenger (Version: 14.0.8089.0726)
Windows Live Movie Maker (Version: 14.0.8091.0730)
Windows Live Sync (Version: 14.0.8089.726)
Windows Live Writer (Version: 14.0.8089.0726)
Windows Live-Uploadtool (Version: 14.0.8014.1029)
==================== Restore Points =========================
23-08-2013 09:12:04 Windows Update
28-08-2013 10:14:34 Installed Java 7 Update 25
07-09-2013 18:07:07 Geplanter Prüfpunkt
14-09-2013 10:02:13 Windows Update
==================== Hosts content: ==========================
2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {003F54B3-7AB6-42B7-BEC8-0B17C1D39DBB} - System32\Tasks\SamsungSupportCenter => C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe [2009-12-14] (SAMSUNG Electronics)
Task: {0C2367AD-FD7A-41B9-BE3D-B44CBB026E0B} - System32\Tasks\SmartRestarter => C:\Program Files\Samsung\SFB\SmartRestarter.exe [2010-05-01] (Samsung Electronics Co., Ltd.)
Task: {0D9B5D92-3A22-486D-A887-3AA21597CF27} - System32\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime => Sc.exe start w32time task_started
Task: {1B097FD8-9484-4C16-8A5C-0BFA2215AA0E} - System32\Tasks\EasyDisplayMgr => C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe [2010-04-07] (Samsung Electronics Co., Ltd.)
Task: {2E7F5712-B9D2-4224-B0EE-63F5E53871C2} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => C:\Windows\System32\sdengin2.dll [2010-11-20] (Microsoft Corporation)
Task: {2FE46663-2E6A-483B-9E78-43FD9A4C7D62} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2012-10-24] (Piriform Ltd)
Task: {4B9219C8-66E8-45F0-AA24-DDA3621A45D0} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\windows\System32\lpksetup.exe [2010-11-20] (Microsoft Corporation)
Task: {54CC7029-4876-4EF0-A187-52BD3C71AA8F} - System32\Tasks\BatteryLifeExtender => C:\Program Files\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe [2009-11-19] (Samsung Electronics. Co. Ltd.)
Task: {620C1925-1F03-4E6B-9052-81973F0D2829} - System32\Tasks\APSchedulerC => C:\Program Files\AnyPC Client\APLanMgrC.exe [2009-11-20] (DoctorSoft)
Task: {86B2B0C1-D204-4A36-816E-26DE522307EF} - System32\Tasks\EasyBatteryManager => C:\Program Files\Samsung\EasyBatteryManager\EasyBatteryMgr4.exe [2010-03-29] (SAMSUNG Electronics co., LTD.)
Task: {949E81CF-D188-43B2-ADE1-40C8725EEA23} - System32\Tasks\WPD\SqmUpload_S-1-5-21-1208384110-4107883307-101704457-500 => C:\Windows\System32\portabledeviceapi.dll [2010-11-20] (Microsoft Corporation)
Task: {9525C70A-34F7-465B-8ABA-C6DE532D0DED} - System32\Tasks\SUPBackground => C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe [2010-04-20] ()
Task: {98FF545A-E906-4723-9D56-9FFBAD8B3BFF} - System32\Tasks\EasySpeedUpManager => C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe [2010-02-10] (Samsung Electronics Co., Ltd.)
Task: {996C4A8A-BAAF-4FEF-8F31-64836A2472E6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-08-12] (Google Inc.)
Task: {AFA52ED2-F3A8-406E-BB69-7A93FF34BE2B} - System32\Tasks\advSRS4 => C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe [2010-01-19] (SEC)
Task: {C85D694F-E0C8-4F49-8869-F798B668E3C1} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation)
Task: {D6B8E824-AAE2-4E88-A594-26FCADF220A6} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-11] (Microsoft Corporation)
Task: {DBE5A903-F2E0-477D-A1B2-955CE9CAC5ED} - System32\Tasks\WPD\SqmUpload_S-1-5-21-1208384110-4107883307-101704457-1002 => C:\Windows\System32\portabledeviceapi.dll [2010-11-20] (Microsoft Corporation)
Task: {DEB2D505-7368-47D5-8A31-A939140207AE} - System32\Tasks\Adobe Flash Player Updater => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-13] (Adobe Systems Incorporated)
Task: {E177326C-53BA-4B8C-937F-321E8396A39B} - System32\Tasks\Microsoft\Windows\WindowsBackup\Windows Backup Monitor => C:\Windows\system32\sdclt.exe [2010-11-20] (Microsoft Corporation)
Task: {E27D200E-9AD7-4996-9EED-B20949317676} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-08-12] (Google Inc.)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2010-05-11 04:11 - 2006-08-12 05:48 - 00049152 _____ () C:\Program Files\Samsung\Easy Display Manager\HookDllPS2.dll
2010-05-11 19:59 - 2010-02-26 20:31 - 00173352 _____ (Synaptics Incorporated) C:\windows\system32\SynCOM.dll
2010-05-11 19:59 - 2010-02-26 20:31 - 00165160 _____ (Synaptics Incorporated) C:\windows\system32\SynTPAPI.dll
2010-10-25 04:56 - 2010-10-25 04:56 - 00303616 _____ (Intel Corporation) C:\windows\system32\igfxrDEU.lrc
2013-01-12 11:56 - 2013-07-31 00:47 - 03534232 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll
==================== Alternate Data Streams (whitelisted) ==========
AlternateDataStreams: C:\ProgramData\Temp:9E22BBE8
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (09/16/2013 11:36:36 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: iexplore.exe, Version: 10.0.9200.16686, Zeitstempel: 0x52058cf0
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00240000
ID des fehlerhaften Prozesses: 0xab8
Startzeit der fehlerhaften Anwendung: 0xiexplore.exe0
Pfad der fehlerhaften Anwendung: iexplore.exe1
Pfad des fehlerhaften Moduls: iexplore.exe2
Berichtskennung: iexplore.exe3
Error: (09/15/2013 08:49:37 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (09/15/2013 08:49:35 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (09/15/2013 08:48:20 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (09/15/2013 08:46:17 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (09/15/2013 08:45:07 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (09/15/2013 08:45:04 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (09/15/2013 07:00:07 PM) (Source: Windows Backup) (User: )
Description: Die Sicherung wurde aufgrund eines Fehlers beim Schreiben am Sicherungsspeicherort "E:\" nicht abgeschlossen. Fehler: "Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und den Sicherungsort. (0x81000006)"
Error: (09/14/2013 04:20:21 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (09/14/2013 04:20:18 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1".
Die abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
System errors:
=============
Error: (09/17/2013 11:43:34 AM) (Source: Service Control Manager) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
cdrom
Error: (09/17/2013 11:40:49 AM) (Source: DCOM) (User: )
Description: {51FA2736-5DEE-11D4-98E8-006008BF430C}
Error: (09/17/2013 11:19:40 AM) (Source: DCOM) (User: )
Description: {51FA2736-5DEE-11D4-98E8-006008BF430C}
Error: (09/16/2013 09:54:48 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst AntiVirSchedulerService erreicht.
Error: (09/16/2013 05:45:14 PM) (Source: DCOM) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}
Error: (09/16/2013 02:49:21 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Microsoft .NET Framework NGEN v4.0.30319_X86 erreicht.
Error: (09/16/2013 02:46:53 PM) (Source: Service Control Manager) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
cdrom
Error: (09/16/2013 02:42:58 PM) (Source: DCOM) (User: )
Description: {C2BFE331-6739-4270-86C9-493D9A04CD38}
Error: (09/16/2013 02:42:49 PM) (Source: DCOM) (User: )
Description: {51FA2736-5DEE-11D4-98E8-006008BF430C}
Error: (09/16/2013 00:35:37 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst ShellHWDetection erreicht.
Microsoft Office Sessions:
=========================
Error: (09/16/2013 11:36:36 AM) (Source: Application Error)(User: )
Description: iexplore.exe10.0.9200.1668652058cf0unknown0.0.0.000000000c000000500240000ab801ceb2c02c9501e2C:\Program Files\Internet Explorer\iexplore.exeunknown7a9a3fe4-1eb3-11e3-9d91-001bb111cb0f
Error: (09/15/2013 08:49:37 PM) (Source: SideBySide)(User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"c:\program files\Samsung\chargeableusb\vista_xp_driver\x64\KStartMem.exe.Manifest
Error: (09/15/2013 08:49:35 PM) (Source: SideBySide)(User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"c:\program files\Samsung\chargeableusb\ChargeableUSB_64.exe
Error: (09/15/2013 08:48:20 PM) (Source: SideBySide)(User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"c:\program files\Samsung\easy display manager\RunGfxUI64.exe
Error: (09/15/2013 08:46:17 PM) (Source: SideBySide)(User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\Samsung\BatteryLifeExtender\Drv\SABI2x64\KStartMem.exe.Manifest
Error: (09/15/2013 08:45:07 PM) (Source: SideBySide)(User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\Samsung\EasyFileShare\Drv\SABI2x64\KStartMem.exe.Manifest
Error: (09/15/2013 08:45:04 PM) (Source: SideBySide)(User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Program Files\Samsung\Samsung Support Center\Drv\drv2x64\KStartMem.exe.Manifest
Error: (09/15/2013 07:00:07 PM) (Source: Windows Backup)(User: )
Description: E:\Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und den Sicherungsort. (0x81000006)
Error: (09/14/2013 04:20:21 PM) (Source: SideBySide)(User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"c:\program files\Samsung\chargeableusb\vista_xp_driver\x64\KStartMem.exe.Manifest
Error: (09/14/2013 04:20:18 PM) (Source: SideBySide)(User: )
Description: Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"c:\program files\Samsung\chargeableusb\ChargeableUSB_64.exe
==================== Memory info ===========================
Percentage of memory in use: 70%
Total physical RAM: 1013.3 MB
Available physical RAM: 297.23 MB
Total Pagefile: 2037.3 MB
Available Pagefile: 858.55 MB
Total Virtual: 2047.88 MB
Available Virtual: 1908.4 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:85 GB) (Free:58.12 GB) NTFS
Drive d: () (Fixed) (Total:192.99 GB) (Free:106.35 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 298 GB) (Disk ID: 4B51E00D)
Partition 1: (Not Active) - (Size=20 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=85 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=193 GB) - (Type=OF Extended)
==================== End Of Log ============================ Nicht wundern, dass die Addition.txt zeitlich vor der FRST.txt ist. Nach FRST bekam ich eine Fehlermeldung 'Auto IT Error, Line 11193, Cannot redeclare a constant.' Danach war die erste FRST.txt-Datei weg, also habe ich es nochmal laufen lassen und dann kam die txt-Datei wie oben.
Auch bei GMER bekam ich eine Fehlermeldung. Soll ich das noch mal laufen lassen ?
Erstmal wieder vielen Dank im Voraus
Mummb |