Code:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 16:51 on 06/10/2013 (André)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=-
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2013
Ran by André (administrator) on ANDRÉ-PC on 06-10-2013 19:15:42
Running from C:\Users\André\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
() C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe
(pdfforge GbR) C:\Program Files (x86)\PDF Architect\HelperService.exe
(pdfforge GbR) C:\Program Files (x86)\PDF Architect\ConversionService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe
() C:\Program Files (x86)\Hardcopy\hcdll2_ex_x64.exe
() C:\Program Files (x86)\Hardcopy\hcdll2_ex_Win32.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE
(Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Panasonic Corporation) C:\Program Files (x86)\Common Files\Panasonic\PHOTOfunSTUDIO AutoStart\AutoStartupService.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
(sw4you, Siegfried Weckmann) C:\Program Files (x86)\Hardcopy\hardcopy.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\Bluetooth Headset Helper.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor)
HKCU\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2013-03-10] (Google Inc.)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19875944 2013-06-21] (Skype Technologies S.A.)
HKCU\...\Run: [OfficeSyncProcess] - C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [720064 2013-04-22] (Microsoft Corporation)
HKCU\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1564016 2013-07-26] (Samsung)
HKCU\...\Run: [KiesAirMessage] - C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup
HKCU\...\Run: [] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844656 2013-07-26] (Samsung)
HKCU\...\Run: [GoogleDriveSync] - C:\Program Files (x86)\Google\Drive\googledrivesync.exe [20097696 2013-06-27] (Google)
HKCU\...\Policies\system: [LogonHoursAction] 2
HKCU\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-06] (Intel Corporation)
HKLM-x32\...\Run: [NUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-12-20] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [CLMLServer] - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [103720 2009-11-03] (CyberLink)
HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311152 2013-07-26] (Samsung Electronics Co., Ltd.)
HKU\Anouk\...\Policies\system: [LogonHoursAction] 2
HKU\Anouk\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\Bennet\...\Policies\system: [LogonHoursAction] 2
HKU\Bennet\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
AppInit_DLLs: C:\PROGRA~1\BULLGU~1\BULLGU~1\BdInstHk.dll [97280 2009-07-14] ()
Lsa: [Notification Packages] scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
Startup: C:\Users\André\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Hardcopy.LNK
ShortcutTarget: Hardcopy.LNK -> C:\Program Files (x86)\Hardcopy\hardcopy.exe (sw4you, Siegfried Weckmann)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=bff9a462-2fa0-47ee-97fb-a6f2a0dd32cc&searchtype=ds&q={searchTerms}&installDate=13/04/2013
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.searchgol.com/?babsrc=HP_ss&mntrId=76F7000A3A76D068&affID=125035&tsp=5027
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=ST31000528AS_9VPAWTFXXXXX9VPAWTFX&ts=1381070669
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=bff9a462-2fa0-47ee-97fb-a6f2a0dd32cc&searchtype=ds&q={searchTerms}&installDate=13/04/2013
HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://www.searchgol.com/?babsrc=HP_ss&mntrId=76F7000A3A76D068&affID=125035&tsp=5027
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=ST31000528AS_9VPAWTFXXXXX9VPAWTFX&ts=1381070669
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=ST31000528AS_9VPAWTFXXXXX9VPAWTFX&ts=1381070669
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=ST31000528AS_9VPAWTFXXXXX9VPAWTFX&ts=1381070669
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=ST31000528AS_9VPAWTFXXXXX9VPAWTFX&ts=1381070669
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=sc&from=cor&uid=ST31000528AS_9VPAWTFXXXXX9VPAWTFX&ts=1381070669
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=ST31000528AS_9VPAWTFXXXXX9VPAWTFX&ts=1381070669&type=default&q={searchTerms}
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=559&systemid=406&apn_dtid=BND406&apn_ptnrs=AG6&o=APN10645&apn_uid=9572212153014614&q={searchTerms}
SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=bff9a462-2fa0-47ee-97fb-a6f2a0dd32cc&searchtype=ds&q={searchTerms}&installDate=13/04/2013
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=ST31000528AS_9VPAWTFXXXXX9VPAWTFX&ts=1381070669&type=default&q={searchTerms}
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snap.do/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=bff9a462-2fa0-47ee-97fb-a6f2a0dd32cc&searchtype=ds&q={searchTerms}&installDate=13/04/2013
SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=ds&from=cor&uid=ST31000528AS_9VPAWTFXXXXX9VPAWTFX&ts=1381070669&type=default&q={searchTerms}
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GbR)
BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: searchgol Helper Object - {8F547BDD-FCD4-48F8-A06F-573D6F404A3C} - C:\Program Files (x86)\searchgol\searchgol\1.8.16.19\bh\searchgol.dll (Montera Technologeis LTD)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - PDF Architect Toolbar - {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files (x86)\PDF Architect\PDFIEPlugin.dll (pdfforge GbR)
Toolbar: HKLM-x32 - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM-x32 - searchgol Toolbar - {00078E95-3A4A-4137-8DE7-2824908D1C17} - C:\Program Files (x86)\searchgol\searchgol\1.8.16.19\searchgolTlbr.dll (Montera Technologeis LTD)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\André\AppData\Roaming\Mozilla\Firefox\Profiles\ufemhtb5.default
FF user.js: detected! => C:\Users\André\AppData\Roaming\Mozilla\Firefox\Profiles\ufemhtb5.default\user.js
FF NewTab: hxxp://www.searchgol.com/?babsrc=NT_ss&mntrId=76F7000A3A76D068&affID=125035&tsp=5027
FF DefaultSearchEngine: qvo6
FF SearchEngineOrder.1: Search Results
FF SelectedSearchEngine: qvo6
FF Homepage: hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=hp&from=cor&uid=ST31000528AS_9VPAWTFXXXXX9VPAWTFX&ts=1381070669
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll ()
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.bdupdater.com/BonanzaDealsLive Update;version=3 - C:\Program Files (x86)\BonanzaDealsLive\Update\1.3.23.0\npGoogleUpdate3.dll (BonanzaDeals)
FF Plugin-x32: @tools.bdupdater.com/BonanzaDealsLive Update;version=9 - C:\Program Files (x86)\BonanzaDealsLive\Update\1.3.23.0\npGoogleUpdate3.dll (BonanzaDeals)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\André\AppData\Roaming\Mozilla\Firefox\Profiles\ufemhtb5.default\searchplugins\11-suche.xml
FF SearchPlugin: C:\Users\André\AppData\Roaming\Mozilla\Firefox\Profiles\ufemhtb5.default\searchplugins\englische-ergebnisse.xml
FF SearchPlugin: C:\Users\André\AppData\Roaming\Mozilla\Firefox\Profiles\ufemhtb5.default\searchplugins\gmx-suche.xml
FF SearchPlugin: C:\Users\André\AppData\Roaming\Mozilla\Firefox\Profiles\ufemhtb5.default\searchplugins\lastminute.xml
FF SearchPlugin: C:\Users\André\AppData\Roaming\Mozilla\Firefox\Profiles\ufemhtb5.default\searchplugins\searchgol.xml
FF SearchPlugin: C:\Users\André\AppData\Roaming\Mozilla\Firefox\Profiles\ufemhtb5.default\searchplugins\Web Search.xml
FF SearchPlugin: C:\Users\André\AppData\Roaming\Mozilla\Firefox\Profiles\ufemhtb5.default\searchplugins\webde-suche.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\qvo6.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: SearchGol - C:\Users\André\AppData\Roaming\Mozilla\Firefox\Profiles\ufemhtb5.default\Extensions\ffxtlbr@searchgol.com
FF Extension: toolbar - C:\Users\André\AppData\Roaming\Mozilla\Firefox\Profiles\ufemhtb5.default\Extensions\toolbar@gmx.net.xpi
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433}
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\coFFPlgn\
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\coFFPlgn\
FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\IPSFFPlgn\
FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\IPSFFPlgn\
FF StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://www.qvo6.com/?utm_source=b&utm_medium=cor&utm_campaign=eXQ&utm_content=sc&from=cor&uid=ST31000528AS_9VPAWTFXXXXX9VPAWTFX&ts=1381070669
Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\Exts\Chrome.crx
==================== Services (Whitelisted) =================
R2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] ()
S2 bonanzadealslive; C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [148976 2013-10-06] (BonanzaDeals)
S3 bonanzadealslivem; C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [148976 2013-10-06] (BonanzaDeals)
R2 N360; C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe [144368 2013-05-21] (Symantec Corporation)
R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1324104 2013-01-09] (pdfforge GbR)
R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [795208 2013-01-09] (pdfforge GbR)
==================== Drivers (Whitelisted) ====================
R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\BASHDefs\20130924.001\BHDrvx64.sys [1525848 2013-09-24] (Symantec Corporation)
R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\BASHDefs\20130924.001\BHDrvx64.sys [1525848 2013-09-24] (Symantec Corporation)
R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1404000.028\ccSetx64.sys [169048 2013-04-16] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-08-27] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-08-27] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [140376 2013-08-27] (Symantec Corporation)
S3 GigasetGenericUSB_x64; C:\Windows\System32\DRIVERS\GigasetGenericUSB_x64.sys [54272 2013-03-05] (Siemens Home and Office Communication Devices GmbH & Co. KG)
R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\IPSDefs\20131004.001\IDSvia64.sys [520280 2013-08-22] (Symantec Corporation)
R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\IPSDefs\20131004.001\IDSvia64.sys [520280 2013-08-22] (Symantec Corporation)
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20131005.007\ENG64.SYS [126040 2013-08-29] (Symantec Corporation)
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20131005.007\ENG64.SYS [126040 2013-08-29] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20131005.007\EX64.SYS [2099288 2013-08-29] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20131005.007\EX64.SYS [2099288 2013-08-29] (Symantec Corporation)
R3 SRTSP; C:\Windows\System32\Drivers\N360x64\1404000.028\SRTSP64.SYS [796760 2013-05-16] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1404000.028\SRTSPX64.SYS [36952 2013-03-05] (Symantec Corporation)
S3 ssudserd; C:\Windows\System32\DRIVERS\ssudserd.sys [203672 2013-06-21] (DEVGURU Co., LTD.(www.devguru.co.kr))
R0 SymDS; C:\Windows\System32\drivers\N360x64\1404000.028\SYMDS64.SYS [493656 2013-05-21] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360x64\1404000.028\SYMEFA64.SYS [1139800 2013-05-23] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177312 2013-06-21] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360x64\1404000.028\Ironx64.SYS [224416 2013-03-05] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1404000.028\SYMNETS.SYS [433752 2013-04-25] (Symantec Corporation)
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-10-06 19:15 - 2013-10-06 19:15 - 00000000 ____D C:\FRST
2013-10-06 19:13 - 2013-10-06 19:13 - 01954124 _____ (Farbar) C:\Users\André\Downloads\FRST64.exe
2013-10-06 16:51 - 2013-10-06 16:51 - 00000472 _____ C:\Users\André\Desktop\defogger_disable.log
2013-10-06 16:51 - 2013-10-06 16:51 - 00000000 _____ C:\Users\André\defogger_reenable
2013-10-06 16:49 - 2013-10-06 16:49 - 00050477 _____ C:\Users\André\Downloads\Defogger.exe
2013-10-06 16:45 - 2013-10-06 16:45 - 00000000 ____D C:\Program Files (x86)\searchgol
2013-10-06 16:44 - 2013-10-06 19:06 - 00000920 _____ C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job
2013-10-06 16:44 - 2013-10-06 18:49 - 00000924 _____ C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job
2013-10-06 16:44 - 2013-10-06 18:44 - 00000294 _____ C:\Windows\Tasks\DigitalSite.job
2013-10-06 16:44 - 2013-10-06 16:54 - 00000000 ____D C:\Program Files (x86)\BonanzaDeals
2013-10-06 16:44 - 2013-10-06 16:45 - 00003390 _____ C:\Windows\System32\Tasks\EPUpdater
2013-10-06 16:44 - 2013-10-06 16:44 - 00003920 _____ C:\Windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineUA
2013-10-06 16:44 - 2013-10-06 16:44 - 00003668 _____ C:\Windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineCore
2013-10-06 16:44 - 2013-10-06 16:44 - 00003234 _____ C:\Windows\System32\Tasks\DigitalSite
2013-10-06 16:44 - 2013-10-06 16:44 - 00000000 ____D C:\Users\André\AppData\Roaming\DigitalSite
2013-10-06 16:44 - 2013-10-06 16:44 - 00000000 ____D C:\Users\André\AppData\Roaming\BabSolution
2013-10-06 16:44 - 2013-10-06 16:44 - 00000000 ____D C:\Users\André\AppData\Local\BonanzaDealsLive
2013-10-06 16:44 - 2013-10-06 16:44 - 00000000 ____D C:\ProgramData\BonanzaDealsLive
2013-10-06 16:44 - 2013-10-06 16:44 - 00000000 ____D C:\ProgramData\BitGuard
2013-10-06 16:44 - 2013-10-06 16:44 - 00000000 ____D C:\Program Files (x86)\BonanzaDealsLive
2013-10-06 16:43 - 2013-10-06 16:43 - 00749248 _____ C:\Users\André\Downloads\ZipExtractorSetup.exe
2013-10-06 13:56 - 2013-10-06 13:56 - 00000000 _____ C:\autoexec.bat
2013-10-06 13:55 - 2013-10-06 13:55 - 00000000 ____D C:\Program Files\Enigma Software Group
2013-10-06 13:53 - 2013-10-06 19:01 - 00000000 ____D C:\Windows\037F8C0EE8E1408FABB4FC4ABF947E1B.TMP
2013-10-06 13:52 - 2013-10-06 13:52 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Bennet\Downloads\SpyHunter-Installer.exe
2013-10-02 23:28 - 2013-10-02 23:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-24 15:29 - 2013-09-24 15:29 - 00000000 ____D C:\Users\Bennet\AppData\Local\Google
2013-09-21 20:18 - 2013-09-21 20:18 - 00001291 _____ C:\Users\Public\Desktop\FullHD Videobearbeitung LoiLoScope Herunterladen.lnk
2013-09-21 20:18 - 2013-09-21 20:18 - 00000000 ____D C:\Program Files (x86)\LoiLo
2013-09-21 20:17 - 2013-09-21 20:17 - 00000000 ____D C:\Users\André\AppData\Local\Panasonic
2013-09-21 20:14 - 2013-09-21 20:14 - 00000000 ____D C:\Users\André\AppData\Roaming\InstallShield
2013-09-21 20:14 - 2007-06-22 00:10 - 00501912 _____ (SEIKO EPSON CORPORATION) C:\Windows\SysWOW64\PICSDK2.dll
2013-09-21 20:14 - 2007-06-22 00:10 - 00000097 _____ C:\Windows\SysWOW64\PICSDK.ini
2013-09-21 20:14 - 2006-10-31 00:10 - 00120992 _____ (SEIKO EPSON CORPORATION) C:\Windows\SysWOW64\EpPicPrt.dll
2013-09-21 20:14 - 2006-10-31 00:10 - 00071840 _____ (SEIKO EPSON CORPORATION) C:\Windows\SysWOW64\EPPicMgr.dll
2013-09-21 20:14 - 2006-10-20 00:10 - 00108704 _____ (SEIKO EPSON CORPORATION) C:\Windows\SysWOW64\PICEntry.dll
2013-09-21 20:14 - 2006-10-20 00:10 - 00080024 _____ (SEIKO EPSON CORPORATION) C:\Windows\SysWOW64\PICSDK.dll
2013-09-21 20:14 - 2005-06-01 00:20 - 00111932 _____ C:\Windows\SysWOW64\EPPICPrinterDB.dat
2013-09-21 20:14 - 2004-03-03 06:10 - 00031053 _____ C:\Windows\SysWOW64\EPPICPattern131.dat
2013-09-21 20:14 - 2004-03-03 06:10 - 00027417 _____ C:\Windows\SysWOW64\EPPICPattern121.dat
2013-09-21 20:14 - 2004-03-03 06:10 - 00026154 _____ C:\Windows\SysWOW64\EPPICPattern1.dat
2013-09-21 20:14 - 2004-03-03 06:10 - 00024903 _____ C:\Windows\SysWOW64\EPPICPattern3.dat
2013-09-21 20:14 - 2004-03-03 06:10 - 00021390 _____ C:\Windows\SysWOW64\EPPICPattern5.dat
2013-09-21 20:14 - 2004-03-03 06:10 - 00020148 _____ C:\Windows\SysWOW64\EPPICPattern2.dat
2013-09-21 20:14 - 2004-03-03 06:10 - 00013732 _____ C:\Windows\SysWOW64\EPPICLocal_EN.cfg
2013-09-21 20:14 - 2004-03-03 06:10 - 00011811 _____ C:\Windows\SysWOW64\EPPICPattern4.dat
2013-09-21 20:14 - 2004-03-03 06:10 - 00006442 _____ C:\Windows\SysWOW64\EPPICLocal_IT.cfg
2013-09-21 20:14 - 2004-03-03 06:10 - 00006347 _____ C:\Windows\SysWOW64\EPPICLocal_PT.cfg
2013-09-21 20:14 - 2004-03-03 06:10 - 00006347 _____ C:\Windows\SysWOW64\EPPICLocal_BP.cfg
2013-09-21 20:14 - 2004-03-03 06:10 - 00006335 _____ C:\Windows\SysWOW64\EPPICLocal_GE.cfg
2013-09-21 20:14 - 2004-03-03 06:10 - 00006195 _____ C:\Windows\SysWOW64\EPPICLocal_FR.cfg
2013-09-21 20:14 - 2004-03-03 06:10 - 00006195 _____ C:\Windows\SysWOW64\EPPICLocal_CF.cfg
2013-09-21 20:14 - 2004-03-03 06:10 - 00006122 _____ C:\Windows\SysWOW64\EPPICLocal_DU.cfg
2013-09-21 20:14 - 2004-03-03 06:10 - 00006103 _____ C:\Windows\SysWOW64\EPPICLocal_ES.cfg
2013-09-21 20:14 - 2004-03-03 06:10 - 00005817 _____ C:\Windows\SysWOW64\EPPICLocal_KO.cfg
2013-09-21 20:14 - 2004-03-03 06:10 - 00005436 _____ C:\Windows\SysWOW64\EPPICLocal_SC.cfg
2013-09-21 20:14 - 2004-03-03 06:10 - 00004943 _____ C:\Windows\SysWOW64\EPPICPattern6.dat
2013-09-21 20:14 - 2004-03-03 06:10 - 00002889 _____ C:\Windows\SysWOW64\EPPICLocal_RU.cfg
2013-09-21 20:14 - 2004-03-03 06:10 - 00002426 _____ C:\Windows\SysWOW64\EPPICLocal_TC.cfg
2013-09-21 20:14 - 2004-03-03 06:10 - 00001146 _____ C:\Windows\SysWOW64\EPPICPresetData_DU.dat
2013-09-21 20:14 - 2004-03-03 06:10 - 00001139 _____ C:\Windows\SysWOW64\EPPICPresetData_PT.dat
2013-09-21 20:14 - 2004-03-03 06:10 - 00001139 _____ C:\Windows\SysWOW64\EPPICPresetData_BP.dat
2013-09-21 20:14 - 2004-03-03 06:10 - 00001136 _____ C:\Windows\SysWOW64\EPPICPresetData_ES.dat
2013-09-21 20:14 - 2004-03-03 06:10 - 00001129 _____ C:\Windows\SysWOW64\EPPICPresetData_FR.dat
2013-09-21 20:14 - 2004-03-03 06:10 - 00001129 _____ C:\Windows\SysWOW64\EPPICPresetData_CF.dat
2013-09-21 20:14 - 2004-03-03 06:10 - 00001120 _____ C:\Windows\SysWOW64\EPPICPresetData_IT.dat
2013-09-21 20:14 - 2004-03-03 06:10 - 00001107 _____ C:\Windows\SysWOW64\EPPICPresetData_GE.dat
2013-09-21 20:14 - 2004-03-03 06:10 - 00001104 _____ C:\Windows\SysWOW64\EPPICPresetData_EN.dat
2013-09-21 20:13 - 2013-09-21 20:13 - 00002210 _____ C:\Users\Public\Desktop\PHOTOfunSTUDIO 9.0 AE.lnk
2013-09-21 20:12 - 2013-09-21 20:12 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services
2013-09-21 20:12 - 2013-09-21 20:12 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition
2013-09-21 20:11 - 2013-09-21 20:11 - 00000000 ____D C:\Program Files (x86)\Panasonic
2013-09-11 22:47 - 2013-08-10 07:22 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-11 22:47 - 2013-08-10 07:22 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-11 22:47 - 2013-08-10 07:22 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-09-11 22:47 - 2013-08-10 07:21 - 19246592 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-11 22:47 - 2013-08-10 07:21 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-11 22:47 - 2013-08-10 07:21 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-11 22:47 - 2013-08-10 07:20 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-11 22:47 - 2013-08-10 07:20 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-11 22:47 - 2013-08-10 07:20 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-11 22:47 - 2013-08-10 07:20 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-11 22:47 - 2013-08-10 07:20 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-09-11 22:47 - 2013-08-10 07:20 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-09-11 22:47 - 2013-08-10 07:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-09-11 22:47 - 2013-08-10 07:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-09-11 22:47 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-09-11 22:47 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-09-11 22:47 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-09-11 22:47 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-09-11 22:47 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-09-11 22:47 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-09-11 22:47 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-09-11 22:47 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-09-11 22:47 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-09-11 22:47 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-09-11 22:47 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-09-11 22:47 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-09-11 22:47 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-09-11 22:47 - 2013-08-10 05:17 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-11 22:47 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-09-11 22:47 - 2013-08-10 04:27 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-09-11 22:47 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-09-11 18:41 - 2013-09-11 18:41 - 00000000 ____D C:\Users\Anouk\AppData\Local\Google
2013-09-11 13:47 - 2013-08-08 03:20 - 03155456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-09-11 13:47 - 2013-08-05 04:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2013-09-11 13:47 - 2013-08-02 04:23 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-09-11 13:47 - 2013-08-02 04:15 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-09-11 13:47 - 2013-08-02 04:15 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2013-09-11 13:47 - 2013-08-02 04:15 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-09-11 13:47 - 2013-08-02 04:15 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2013-09-11 13:47 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2013-09-11 13:47 - 2013-08-02 04:14 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2013-09-11 13:47 - 2013-08-02 04:13 - 01161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2013-09-11 13:47 - 2013-08-02 04:13 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2013-09-11 13:47 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2013-09-11 13:47 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2013-09-11 13:47 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 03:59 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-09-11 13:47 - 2013-08-02 03:59 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-09-11 13:47 - 2013-08-02 03:51 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-09-11 13:47 - 2013-08-02 03:50 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2013-09-11 13:47 - 2013-08-02 03:50 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2013-09-11 13:47 - 2013-08-02 03:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-09-11 13:47 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2013-09-11 13:47 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2013-09-11 13:47 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2013-09-11 13:47 - 2013-08-02 02:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-09-11 13:47 - 2013-08-02 02:45 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-09-11 13:47 - 2013-08-02 02:45 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-09-11 13:47 - 2013-08-02 02:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-09-11 13:47 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-09-11 13:47 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2013-09-11 13:47 - 2013-07-26 04:24 - 14172672 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2013-09-11 13:47 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2013-09-11 13:47 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2013-09-11 13:47 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
==================== One Month Modified Files and Folders =======
2013-10-06 19:15 - 2013-10-06 19:15 - 00000000 ____D C:\FRST
2013-10-06 19:13 - 2013-10-06 19:13 - 01954124 _____ (Farbar) C:\Users\André\Downloads\FRST64.exe
2013-10-06 19:12 - 2009-07-14 06:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-06 19:12 - 2009-07-14 06:45 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-06 19:09 - 2013-03-10 22:00 - 01760591 _____ C:\Windows\WindowsUpdate.log
2013-10-06 19:06 - 2013-10-06 16:44 - 00000920 _____ C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job
2013-10-06 19:06 - 2013-09-03 19:30 - 00000000 ___RD C:\Users\André\Google Drive
2013-10-06 19:06 - 2013-03-12 21:34 - 00000000 ____D C:\Users\André\AppData\Roaming\Skype
2013-10-06 19:06 - 2013-03-10 05:40 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-10-06 19:05 - 2013-03-10 05:41 - 00000000 ____D C:\ProgramData\Partner
2013-10-06 19:05 - 2010-12-09 21:14 - 00095920 _____ C:\Windows\PFRO.log
2013-10-06 19:05 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-06 19:05 - 2009-07-14 06:51 - 00079834 _____ C:\Windows\setupact.log
2013-10-06 19:01 - 2013-10-06 13:53 - 00000000 ____D C:\Windows\037F8C0EE8E1408FABB4FC4ABF947E1B.TMP
2013-10-06 19:01 - 2013-03-12 20:06 - 00003930 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{CD0A17BD-6F8D-4D0B-BC54-E292B83A37F1}
2013-10-06 19:01 - 2013-03-10 14:18 - 00000000 ____D C:\Users\André\AppData\Local\Google
2013-10-06 18:49 - 2013-10-06 16:44 - 00000924 _____ C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job
2013-10-06 18:44 - 2013-10-06 16:44 - 00000294 _____ C:\Windows\Tasks\DigitalSite.job
2013-10-06 18:30 - 2013-03-12 22:50 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-06 18:18 - 2013-03-10 05:40 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-06 16:54 - 2013-10-06 16:44 - 00000000 ____D C:\Program Files (x86)\BonanzaDeals
2013-10-06 16:51 - 2013-10-06 16:51 - 00000472 _____ C:\Users\André\Desktop\defogger_disable.log
2013-10-06 16:51 - 2013-10-06 16:51 - 00000000 _____ C:\Users\André\defogger_reenable
2013-10-06 16:51 - 2013-03-10 13:44 - 00000000 ____D C:\Users\André
2013-10-06 16:49 - 2013-10-06 16:49 - 00050477 _____ C:\Users\André\Downloads\Defogger.exe
2013-10-06 16:45 - 2013-10-06 16:45 - 00000000 ____D C:\Program Files (x86)\searchgol
2013-10-06 16:45 - 2013-10-06 16:44 - 00003390 _____ C:\Windows\System32\Tasks\EPUpdater
2013-10-06 16:45 - 2013-04-13 18:00 - 00001448 _____ C:\Users\André\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2013-10-06 16:45 - 2013-03-10 23:11 - 00001435 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-10-06 16:45 - 2013-03-10 13:44 - 00001721 _____ C:\Users\André\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-10-06 16:44 - 2013-10-06 16:44 - 00003920 _____ C:\Windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineUA
2013-10-06 16:44 - 2013-10-06 16:44 - 00003668 _____ C:\Windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineCore
2013-10-06 16:44 - 2013-10-06 16:44 - 00003234 _____ C:\Windows\System32\Tasks\DigitalSite
2013-10-06 16:44 - 2013-10-06 16:44 - 00000000 ____D C:\Users\André\AppData\Roaming\DigitalSite
2013-10-06 16:44 - 2013-10-06 16:44 - 00000000 ____D C:\Users\André\AppData\Roaming\BabSolution
2013-10-06 16:44 - 2013-10-06 16:44 - 00000000 ____D C:\Users\André\AppData\Local\BonanzaDealsLive
2013-10-06 16:44 - 2013-10-06 16:44 - 00000000 ____D C:\ProgramData\BonanzaDealsLive
2013-10-06 16:44 - 2013-10-06 16:44 - 00000000 ____D C:\ProgramData\BitGuard
2013-10-06 16:44 - 2013-10-06 16:44 - 00000000 ____D C:\Program Files (x86)\BonanzaDealsLive
2013-10-06 16:43 - 2013-10-06 16:43 - 00749248 _____ C:\Users\André\Downloads\ZipExtractorSetup.exe
2013-10-06 13:56 - 2013-10-06 13:56 - 00000000 _____ C:\autoexec.bat
2013-10-06 13:55 - 2013-10-06 13:55 - 00000000 ____D C:\Program Files\Enigma Software Group
2013-10-06 13:52 - 2013-10-06 13:52 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Bennet\Downloads\SpyHunter-Installer.exe
2013-10-06 12:44 - 2013-03-16 13:20 - 00000000 ____D C:\Users\Anouk\AppData\Local\Mozilla
2013-10-03 21:02 - 2013-03-10 23:11 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-10-03 00:21 - 2013-03-10 23:11 - 00000000 ____D C:\Users\André\AppData\Local\Mozilla
2013-10-02 23:28 - 2013-10-02 23:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-24 15:29 - 2013-09-24 15:29 - 00000000 ____D C:\Users\Bennet\AppData\Local\Google
2013-09-24 15:29 - 2013-03-17 00:33 - 00110088 _____ C:\Users\Bennet\AppData\Local\GDIPFONTCACHEV1.DAT
2013-09-24 15:29 - 2013-03-15 22:49 - 00000000 ___RD C:\Users\Bennet\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-09-24 15:29 - 2013-03-15 22:49 - 00000000 ___RD C:\Users\Bennet\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-09-24 14:49 - 2013-03-16 14:00 - 00110088 _____ C:\Users\Anouk\AppData\Local\GDIPFONTCACHEV1.DAT
2013-09-22 23:12 - 2013-04-10 11:26 - 00000000 ____D C:\ProgramData\BtCrashDumps
2013-09-22 07:11 - 2009-07-14 06:45 - 00418448 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-22 00:14 - 2013-03-10 13:44 - 00000000 ____D C:\Users\André\AppData\Local\VirtualStore
2013-09-21 20:18 - 2013-09-21 20:18 - 00001291 _____ C:\Users\Public\Desktop\FullHD Videobearbeitung LoiLoScope Herunterladen.lnk
2013-09-21 20:18 - 2013-09-21 20:18 - 00000000 ____D C:\Program Files (x86)\LoiLo
2013-09-21 20:17 - 2013-09-21 20:17 - 00000000 ____D C:\Users\André\AppData\Local\Panasonic
2013-09-21 20:17 - 2013-03-10 13:45 - 00110088 _____ C:\Users\André\AppData\Local\GDIPFONTCACHEV1.DAT
2013-09-21 20:14 - 2013-09-21 20:14 - 00000000 ____D C:\Users\André\AppData\Roaming\InstallShield
2013-09-21 20:13 - 2013-09-21 20:13 - 00002210 _____ C:\Users\Public\Desktop\PHOTOfunSTUDIO 9.0 AE.lnk
2013-09-21 20:12 - 2013-09-21 20:12 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services
2013-09-21 20:12 - 2013-09-21 20:12 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition
2013-09-21 20:12 - 2011-02-02 21:53 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-09-21 20:11 - 2013-09-21 20:11 - 00000000 ____D C:\Program Files (x86)\Panasonic
2013-09-15 18:05 - 2013-03-13 00:52 - 00000000 ____D C:\Users\André\AppData\Local\CrashDumps
2013-09-15 11:16 - 2013-03-16 13:18 - 00000000 ___RD C:\Users\Anouk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-09-15 11:16 - 2013-03-16 13:18 - 00000000 ___RD C:\Users\Anouk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-09-13 17:47 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-09-13 15:03 - 2013-05-17 20:22 - 00002023 _____ C:\Users\Public\Desktop\Adobe Reader X.lnk
2013-09-12 21:05 - 2013-03-10 13:44 - 00000000 ___RD C:\Users\André\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-09-12 21:05 - 2013-03-10 13:44 - 00000000 ___RD C:\Users\André\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-09-11 22:47 - 2013-08-14 23:43 - 00000000 ____D C:\Windows\system32\MRT
2013-09-11 22:45 - 2013-03-14 23:49 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-09-11 22:45 - 2010-12-04 00:00 - 79143768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-09-11 18:41 - 2013-09-11 18:41 - 00000000 ____D C:\Users\Anouk\AppData\Local\Google
2013-09-10 22:38 - 2013-03-12 22:50 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-09-10 22:38 - 2013-03-12 22:50 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-09-10 22:38 - 2013-03-12 22:50 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
Some content of TEMP:
====================
C:\Users\André\AppData\Local\Temp\ose00000.exe
C:\Users\André\AppData\Local\Temp\uninst1.exe
C:\Users\André\AppData\Local\Temp\_isF9B5.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-10-02 19:25
==================== End Of Log ============================ --- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-10-2013
Ran by André at 2013-10-06 19:16:09
Running from C:\Users\André\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Norton 360 Online (Enabled - Up to date) {63DF5164-9100-186D-2187-8DC619EFD8BF}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Norton 360 Online (Enabled - Up to date) {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton 360 Online (Enabled) {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
==================== Installed Programs ======================
AAVUpdateManager (x32 Version: 18.00.0000)
Adobe AIR (x32 Version: 2.5.1.17730)
Adobe Flash Player 10 ActiveX (x32 Version: 10.0.45.2)
Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.168)
Adobe Reader X (10.1.8) MUI (x32 Version: 10.1.8)
Control ActiveX de Windows Live Mesh para conexiones remotas (x32 Version: 15.4.5722.2)
Contrôle ActiveX Windows Live Mesh pour connexions à distance (x32 Version: 15.4.5722.2)
Controlo ActiveX do Windows Live Mesh para Ligações Remotas (x32 Version: 15.4.5722.2)
CyberLink LabelPrint (x32 Version: 2.5.3418)
CyberLink Power2Go (x32 Version: 6.1.3802)
CyberLink PowerDVD Copy (x32 Version: 1.5.1306)
D3DX10 (x32 Version: 15.4.2368.0902)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (x32)
DHTML Editing Component (x32 Version: 6.02.0001)
ElsterFormular (x32 Version: 14.1.20130301)
EPSON Copy Utility 3 (x32 Version: 3.1.5.0)
EPSON Scan (x32)
Fara und Fu 1 (x32)
Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych (x32 Version: 15.4.5722.2)
Fotogalerija Windows Live (x32 Version: 15.4.3502.0922)
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922)
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922)
Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922)
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922)
Geldtipps Homebanking 2013 AAV (x32 Version: 5.10)
Gigaset QuickSync (Version: 8.2.0865.2)
Google Drive (x32 Version: 1.11.4865.2530)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0)
Google Toolbar for Internet Explorer (x32 Version: 7.5.4413.1752)
Google Update Helper (x32 Version: 1.3.21.153)
Hardcopy (x32 Version: 2013.03.11)
Intel(R) Rapid Storage Technology (x32 Version: 10.1.0.1008)
Java Auto Updater (x32 Version: 2.0.2.4)
Java(TM) 6 Update 23 (64-bit) (Version: 6.0.230)
Java(TM) 6 Update 23 (x32 Version: 6.0.230)
Junk Mail filter update (x32 Version: 15.4.3502.0922)
Kontrolnik Windows Live Mesh ActiveX za oddaljene povezave (x32 Version: 15.4.5722.2)
LoiLoScope Herunterladen (x32 Version: 2.0)
Medion Home Cinema (x32 Version: 8.0.2227)
Mesh Runtime (x32 Version: 15.4.5722.2)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320)
Microsoft .NET Framework 4 Extended (Version: 4.0.30320)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Office 2010 Service Pack 1 (SP1) (x32)
Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Groove MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office InfoPath MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.6029.1000)
Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Professional Plus 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.6029.1000)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft SQL Server Compact 3.5 SP2 ENU (x32 Version: 3.5.8080.0)
Microsoft SQL Server Compact 3.5 SP2 x64 ENU (Version: 3.5.8080.0)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (x32 Version: 10.0.30319)
Mozilla Firefox 24.0 (x86 de) (x32 Version: 24.0)
Mozilla Maintenance Service (x32 Version: 24.0)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT_amd64 (x32 Version: 15.4.2862.0708)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
MyFreeCodec (HKCU)
Norton 360 (x32 Version: 20.4.0.40)
NVIDIA Display Control Panel (Version: 6.14.12.6313)
NVIDIA Graphics Driver 263.13 (Version: 263.13)
NVIDIA HD-Audiotreiber 1.3.18.0 (Version: 1.3.18.0)
NVIDIA Install Application (Version: 2.1002.109.718)
NVIDIA PhysX (x32 Version: 9.10.0514)
NVIDIA PhysX System Software 9.10.0514 (Version: 9.10.0514)
PDF Architect (x32 Version: 1.0.52.8917)
PDFCreator (x32 Version: 1.6.2)
PHOTOfunSTUDIO 9.0 AE (x32 Version: 9.00.517)
PlayReady PC Runtime amd64 (Version: 1.3.0)
Poczta usługi Windows Live (x32 Version: 15.4.3502.0922)
Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922)
Pošta Windows Live (x32 Version: 15.4.3502.0922)
Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6662)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.32.0)
Samsung Kies (x32 Version: 2.5.3.13043_14)
Samsung Story Album Viewer (x32 Version: 1.0.0.13054_1)
SAMSUNG USB Driver for Mobile Phones (Version: 1.5.27.0)
Skype™ 6.6 (x32 Version: 6.6.106)
Spelling Dictionaries Support For Adobe Reader X (x32 Version: 10.0.0)
T-Online Banking Software (x32 Version: 7.02.0004)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (x32)
Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2553065) (x32)
Update for Microsoft Office 2010 (KB2553157) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2566458) (x32)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2589370) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2760758) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (x32)
Update for Microsoft Office 2010 (KB2825640) 32-Bit Edition (x32)
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition (x32)
Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition (x32)
Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition (x32)
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition (x32)
Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (x32)
Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition (x32)
Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (x32)
Uzak Bağlantılar İçin Windows Live Mesh ActiveX Denetimi (x32 Version: 15.4.5722.2)
Versandhelfer (x32 Version: 0.9.511)
WIDCOMM Bluetooth Software (Version: 6.5.1.4100)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3508.1109)
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922)
Windows Live Fotoğraf Galerisi (x32 Version: 15.4.3502.0922)
Windows Live Fotótár (x32 Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4225.0)
Windows Live Installer (x32 Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3508.1109)
Windows Live Mail (x32 Version: 15.4.3502.0922)
Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (x32 Version: 15.4.5722.2)
Windows Live Mesh (x32 Version: 15.4.3502.0922)
Windows Live Mesh ActiveX Control for Remote Connections (x32 Version: 15.4.5722.2)
Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2)
Windows Live Mesh ActiveX-objekt til fjernforbindelser (x32 Version: 15.4.5722.2)
Windows Live Mesh ActiveX-vezérlő távoli kapcsolatokhoz (x32 Version: 15.4.5722.2)
Windows Live Messenger (x32 Version: 15.4.3502.0922)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (x32 Version: 15.4.3502.0922)
Windows Live Photo Common (x32 Version: 15.4.3502.0922)
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922)
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (x32 Version: 15.4.3502.0922)
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922)
Windows Live Temel Parçalar (x32 Version: 15.4.3502.0922)
Windows Live UX Platform (x32 Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109)
Windows Live Writer (x32 Version: 15.4.3502.0922)
Windows Live Writer Resources (x32 Version: 15.4.3502.0922)
Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις (x32 Version: 15.4.5722.2)
Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922)
==================== Restore Points =========================
20-09-2013 17:03:23 Geplanter Prüfpunkt
21-09-2013 18:11:20 Installiert PHOTOfunSTUDIO 9.0 AE
29-09-2013 19:09:43 Geplanter Prüfpunkt
06-10-2013 11:54:11 Installed SpyHunter
06-10-2013 14:53:24 Removed SpyHunter
06-10-2013 15:02:11 Removed SpyHunter
==================== Hosts content: ==========================
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {0105480A-1688-44A3-9346-64F01100D3CD} - System32\Tasks\hcdll2_ex_x64 => C:\Program Files (x86)\Hardcopy\hcdll2_ex_x64.exe [2012-11-08] ()
Task: {06F61A4D-E69C-4350-BCAB-D7F2E00D6777} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {219587FC-36BD-4A29-921B-98E6AD6CC505} - System32\Tasks\hcdll2_ex_Win32 => C:\Program Files (x86)\Hardcopy\hcdll2_ex_Win32.exe [2012-11-08] ()
Task: {233DBEC2-C4C9-4F73-9A5A-B6C8E8862108} - System32\Tasks\BonanzaDealsLiveUpdateTaskMachineUA => C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [2013-10-06] (BonanzaDeals)
Task: {30ADCE99-BF6B-4851-BEA8-905FBD610DBB} - System32\Tasks\{4B00CDBF-54FF-42D2-84CD-56E17DDDBA57} => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorUI.exe [2010-11-06] (Intel Corporation)
Task: {35191A90-7F96-4303-8000-62455F6BABAF} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\WSCStub.exe [2013-06-04] (Symantec Corporation)
Task: {3AA5EE1E-99AC-454B-B0B2-A285535D55CB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-10] (Google Inc.)
Task: {3EAAF079-F781-4C59-AB2F-6C1584617CAF} - System32\Tasks\{1B4046F7-B8EC-4D94-8AD0-BAFAD8A215D9} => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorUI.exe [2010-11-06] (Intel Corporation)
Task: {6094581B-9CC6-4529-A1EA-453185BA5F45} - System32\Tasks\DigitalSite => C:\Users\ANDR~1\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE
Task: {7BAA5EFD-941A-4FE5-B075-4FE093B44432} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation)
Task: {8D849280-2676-4644-B1A6-0C0A98015C71} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\SymErr.exe [2013-06-04] (Symantec Corporation)
Task: {8D8A8C89-6E1C-45D4-AB26-F035072425C3} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\SymErr.exe [2013-06-04] (Symantec Corporation)
Task: {94413454-2107-4F2B-8104-E14F5C55F7CA} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-10] (Adobe Systems Incorporated)
Task: {C39D63C6-743D-4D2F-BB7B-2D5377577777} - System32\Tasks\EPUpdater => C:\Users\André\AppData\Roaming\BabSolution\Shared\BabMaint.exe [2013-09-01] ()
Task: {D927F504-814F-46F7-B788-2ED922476268} - System32\Tasks\{14E12F3D-F791-4561-95DA-D8D192096B2F} => D:\Programme\download\setup_Gigaset_QuickSync_8_2_64bit.exe [2013-03-24] (Gigaset Communications GmbH)
Task: {D9D66EB8-D9AA-483E-A840-B6CD8DEB15B5} - System32\Tasks\BonanzaDealsLiveUpdateTaskMachineCore => C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe [2013-10-06] (BonanzaDeals)
Task: {ED5DE8CA-91B6-43BD-92F1-F3F48B3E7182} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2010-11-20] (Microsoft Corporation)
Task: {F5D82CCF-FD33-466E-81FF-83961B207CE5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-10] (Google Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job => C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe
Task: C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job => C:\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe
Task: C:\Windows\Tasks\DigitalSite.job => C:\Users\ANDR~1\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2013-03-16 13:02 - 2012-07-30 10:28 - 00125504 _____ () C:\Program Files (x86)\Hardcopy\HcDLL2_38_x64.dll
2011-03-17 01:07 - 2011-03-17 01:07 - 04297568 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2013-03-16 13:02 - 2012-07-30 10:27 - 00116800 _____ () C:\Program Files (x86)\Hardcopy\HcDLL2_38_Win32.dll
2013-06-13 20:55 - 2012-05-30 08:51 - 00699280 ____R () C:\PROGRAM FILES (X86)\NORTON 360\ENGINE\20.4.0.40\wincfi39.dll
2013-03-16 13:02 - 2012-07-05 15:56 - 00052800 _____ () C:\Program Files (x86)\Hardcopy\hardcopy_05.dll
2011-03-17 01:11 - 2011-03-17 01:11 - 04297568 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2011-03-17 01:11 - 2011-03-17 01:11 - 04297568 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\office14\Cultures\office.odf
2010-12-21 02:15 - 2010-12-21 02:15 - 01041248 _____ () C:\Program Files (x86)\Microsoft Office\Office14\ADDINS\UmOutlookAddin.dll
2011-09-01 22:10 - 2011-09-01 22:10 - 00122720 _____ () C:\Program Files (x86)\Microsoft Office\Office14\OUTLCTL.DLL
2009-11-03 00:20 - 2009-11-03 00:20 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
2009-11-03 00:23 - 2009-11-03 00:23 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
2013-03-16 13:02 - 2013-03-08 08:17 - 02920952 _____ () C:\Program Files (x86)\Hardcopy\HcDllS.dll
2013-10-06 19:06 - 2013-10-06 19:06 - 00098816 _____ () C:\Users\ANDR~1\AppData\Local\Temp\_MEI33362\win32api.pyd
2013-10-06 19:06 - 2013-10-06 19:06 - 00110080 _____ () C:\Users\ANDR~1\AppData\Local\Temp\_MEI33362\pywintypes27.dll
2013-10-06 19:06 - 2013-10-06 19:06 - 00364544 _____ () C:\Users\ANDR~1\AppData\Local\Temp\_MEI33362\pythoncom27.dll
2013-10-06 19:06 - 2013-10-06 19:06 - 00044032 _____ () C:\Users\ANDR~1\AppData\Local\Temp\_MEI33362\_socket.pyd
2013-10-06 19:06 - 2013-10-06 19:06 - 01153024 _____ () C:\Users\ANDR~1\AppData\Local\Temp\_MEI33362\_ssl.pyd
2013-10-06 19:06 - 2013-10-06 19:06 - 00320512 _____ () C:\Users\ANDR~1\AppData\Local\Temp\_MEI33362\win32com.shell.shell.pyd
2013-10-06 19:06 - 2013-10-06 19:06 - 00711680 _____ () C:\Users\ANDR~1\AppData\Local\Temp\_MEI33362\_hashlib.pyd
2013-10-06 19:06 - 2013-10-06 19:06 - 01175040 _____ () C:\Users\ANDR~1\AppData\Local\Temp\_MEI33362\wx._core_.pyd
2013-10-06 19:06 - 2013-10-06 19:06 - 00805888 _____ () C:\Users\ANDR~1\AppData\Local\Temp\_MEI33362\wx._gdi_.pyd
2013-10-06 19:06 - 2013-10-06 19:06 - 00811008 _____ () C:\Users\ANDR~1\AppData\Local\Temp\_MEI33362\wx._windows_.pyd
2013-10-06 19:06 - 2013-10-06 19:06 - 01062400 _____ () C:\Users\ANDR~1\AppData\Local\Temp\_MEI33362\wx._controls_.pyd
2013-10-06 19:06 - 2013-10-06 19:06 - 00735232 _____ () C:\Users\ANDR~1\AppData\Local\Temp\_MEI33362\wx._misc_.pyd
2013-10-06 19:06 - 2013-10-06 19:06 - 00128512 _____ () C:\Users\ANDR~1\AppData\Local\Temp\_MEI33362\_elementtree.pyd
2013-10-06 19:06 - 2013-10-06 19:06 - 00127488 _____ () C:\Users\ANDR~1\AppData\Local\Temp\_MEI33362\pyexpat.pyd
2013-10-06 19:06 - 2013-10-06 19:06 - 00557056 _____ () C:\Users\ANDR~1\AppData\Local\Temp\_MEI33362\pysqlite2._sqlite.pyd
2013-10-06 19:06 - 2013-10-06 19:06 - 00087040 _____ () C:\Users\ANDR~1\AppData\Local\Temp\_MEI33362\_ctypes.pyd
2013-10-06 19:06 - 2013-10-06 19:06 - 00119808 _____ () C:\Users\ANDR~1\AppData\Local\Temp\_MEI33362\win32file.pyd
2013-10-06 19:06 - 2013-10-06 19:06 - 00108544 _____ () C:\Users\ANDR~1\AppData\Local\Temp\_MEI33362\win32security.pyd
2013-10-06 19:06 - 2013-10-06 19:06 - 00018432 _____ () C:\Users\ANDR~1\AppData\Local\Temp\_MEI33362\win32event.pyd
2013-10-06 19:06 - 2013-10-06 19:06 - 00038912 _____ () C:\Users\ANDR~1\AppData\Local\Temp\_MEI33362\win32inet.pyd
2013-10-06 19:06 - 2013-10-06 19:06 - 00122368 _____ () C:\Users\ANDR~1\AppData\Local\Temp\_MEI33362\wx._wizard.pyd
2013-10-06 19:06 - 2013-10-06 19:06 - 00686080 _____ () C:\Users\ANDR~1\AppData\Local\Temp\_MEI33362\unicodedata.pyd
2013-10-06 19:06 - 2013-10-06 19:06 - 00026624 _____ () C:\Users\ANDR~1\AppData\Local\Temp\_MEI33362\_multiprocessing.pyd
2013-10-06 19:06 - 2013-10-06 19:06 - 00070656 _____ () C:\Users\ANDR~1\AppData\Local\Temp\_MEI33362\wx._html2.pyd
2013-10-06 19:06 - 2013-10-06 19:06 - 00010240 _____ () C:\Users\ANDR~1\AppData\Local\Temp\_MEI33362\select.pyd
2013-10-06 19:06 - 2013-10-06 19:06 - 00025600 _____ () C:\Users\ANDR~1\AppData\Local\Temp\_MEI33362\win32pdh.pyd
2013-10-06 19:06 - 2013-10-06 19:06 - 00504832 _____ () C:\Users\ANDR~1\AppData\Local\Temp\_MEI33362\windows._cacheinvalidation.pyd
2013-10-06 19:06 - 2013-10-06 19:06 - 00011264 _____ () C:\Users\ANDR~1\AppData\Local\Temp\_MEI33362\win32crypt.pyd
2013-10-06 19:06 - 2013-10-06 19:06 - 00035840 _____ () C:\Users\ANDR~1\AppData\Local\Temp\_MEI33362\win32process.pyd
2013-10-06 19:06 - 2013-10-06 19:06 - 00017408 _____ () C:\Users\ANDR~1\AppData\Local\Temp\_MEI33362\win32profile.pyd
2013-10-06 19:06 - 2013-10-06 19:06 - 00022528 _____ () C:\Users\ANDR~1\AppData\Local\Temp\_MEI33362\win32ts.pyd
2013-08-17 09:43 - 2013-08-17 09:43 - 00169472 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\eb4812681f6ab4406053f3a1803e6da0\IsdiInterop.ni.dll
2011-02-02 21:53 - 2010-11-06 09:50 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2013-10-02 23:28 - 2013-10-02 23:28 - 03279768 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2013-06-13 20:55 - 2012-05-30 08:51 - 00699280 ____R () C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\wincfi39.dll
2013-09-10 22:38 - 2013-09-10 22:38 - 16177544 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BsScanner => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BsScanner => ""="Service"
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (10/06/2013 04:45:19 PM) (Source: MsiInstaller) (User: André-PC)
Description: Product: Google Update Helper -- Error 1316. A network error occurred while attempting to read from the file: C:\Program Files (x86)\BonanzaDealsLive\Update\1.3.23.0\GoogleUpdateHelper.msi
Error: (10/06/2013 03:21:25 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: NvXDSync.exe, Version: 7.17.12.6313, Zeitstempel: 0x4cf9ceb3
Name des fehlerhaften Moduls: NVXDApiX.dll, Version: 7.17.12.6313, Zeitstempel: 0x4cf9d218
Ausnahmecode: 0xc0000417
Fehleroffset: 0x0000000000266978
ID des fehlerhaften Prozesses: 0x538
Startzeit der fehlerhaften Anwendung: 0xNvXDSync.exe0
Pfad der fehlerhaften Anwendung: NvXDSync.exe1
Pfad des fehlerhaften Moduls: NvXDSync.exe2
Berichtskennung: NvXDSync.exe3
Error: (09/29/2013 06:37:43 PM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert
.
Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess.
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {deaac182-10c9-4f3e-87d1-cf44e7157d5e}
Error: (09/26/2013 07:52:03 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: NvXDSync.exe, Version: 7.17.12.6313, Zeitstempel: 0x4cf9ceb3
Name des fehlerhaften Moduls: NVXDApiX.dll, Version: 7.17.12.6313, Zeitstempel: 0x4cf9d218
Ausnahmecode: 0xc0000417
Fehleroffset: 0x0000000000266978
ID des fehlerhaften Prozesses: 0x650
Startzeit der fehlerhaften Anwendung: 0xNvXDSync.exe0
Pfad der fehlerhaften Anwendung: NvXDSync.exe1
Pfad des fehlerhaften Moduls: NvXDSync.exe2
Berichtskennung: NvXDSync.exe3
Error: (09/24/2013 10:11:41 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: NvXDSync.exe, Version: 7.17.12.6313, Zeitstempel: 0x4cf9ceb3
Name des fehlerhaften Moduls: NVXDApiX.dll, Version: 7.17.12.6313, Zeitstempel: 0x4cf9d218
Ausnahmecode: 0xc0000417
Fehleroffset: 0x0000000000266978
ID des fehlerhaften Prozesses: 0x14f0
Startzeit der fehlerhaften Anwendung: 0xNvXDSync.exe0
Pfad der fehlerhaften Anwendung: NvXDSync.exe1
Pfad des fehlerhaften Moduls: NvXDSync.exe2
Berichtskennung: NvXDSync.exe3
Error: (09/22/2013 11:12:31 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: BtStackServer.exe, Version: 6.5.1.4100, Zeitstempel: 0x512e5750
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000000000
ID des fehlerhaften Prozesses: 0x10d8
Startzeit der fehlerhaften Anwendung: 0xBtStackServer.exe0
Pfad der fehlerhaften Anwendung: BtStackServer.exe1
Pfad des fehlerhaften Moduls: BtStackServer.exe2
Berichtskennung: BtStackServer.exe3
Error: (09/15/2013 06:05:06 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: Kies.exe, Version: 1.0.0.1346, Zeitstempel: 0x51f26ead
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb1116
Ausnahmecode: 0xe0434352
Fehleroffset: 0x0000c41f
ID des fehlerhaften Prozesses: 0x1a50
Startzeit der fehlerhaften Anwendung: 0xKies.exe0
Pfad der fehlerhaften Anwendung: Kies.exe1
Pfad des fehlerhaften Moduls: Kies.exe2
Berichtskennung: Kies.exe3
Error: (09/15/2013 06:04:59 PM) (Source: .NET Runtime) (User: )
Description: Application: Kies.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.ComponentModel.Win32Exception
Stack:
at System.Diagnostics.ProcessManager.OpenProcess(Int32, Int32, Boolean)
at System.Diagnostics.Process.GetProcessHandle(Int32, Boolean)
at System.Diagnostics.Process.OpenProcessHandle(Int32)
at System.Diagnostics.Process.get_Handle()
at Kies.App.CheckExistenceTrayAgent()
at Kies.App..ctor()
at Kies.App.Main()
Error: (09/13/2013 03:52:27 PM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert
.
Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess.
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {45dce203-0b14-4573-994c-7a97a8aefadf}
Error: (09/11/2013 10:40:08 PM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - Failed to execute command from the offline queue: uninstall "System.Web.RegularExpressions, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil" /NoDependencies . The error returned was Error: The specified assembly is not installed.
.
System errors:
=============
Error: (09/30/2013 10:27:11 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst lmhosts erreicht.
Error: (09/25/2013 03:38:57 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Server" wurde mit folgendem Fehler beendet:
%%14
Error: (09/21/2013 00:01:31 AM) (Source: WMPNetworkSvc) (User: )
Description: 0x80004004-1
Error: (09/12/2013 09:03:12 PM) (Source: Microsoft-Windows-LanguagePackSetup) (User: NT-AUTORITÄT)
Description: Fehler bei der CBS-Clientinitialisierung. Letzter Fehler: 0x8007045b
Error: (08/28/2013 09:12:10 PM) (Source: WMPNetworkSvc) (User: )
Description: 0x80004004-1
Error: (08/28/2013 09:12:10 PM) (Source: WMPNetworkSvc) (User: )
Description: 0x80004004-1
Error: (08/22/2013 02:08:26 PM) (Source: DCOM) (User: )
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}
Error: (08/20/2013 09:49:44 PM) (Source: WMPNetworkSvc) (User: )
Description: 0x80004004-1
Error: (08/20/2013 09:47:29 PM) (Source: WMPNetworkSvc) (User: )
Description: 0x80004004-1
Error: (08/20/2013 09:47:29 PM) (Source: WMPNetworkSvc) (User: )
Description: 0x80004004-1
Microsoft Office Sessions:
=========================
Error: (10/06/2013 04:45:19 PM) (Source: MsiInstaller)(User: André-PC)
Description: Product: Google Update Helper -- Error 1316. A network error occurred while attempting to read from the file: C:\Program Files (x86)\BonanzaDealsLive\Update\1.3.23.0\GoogleUpdateHelper.msi(NULL)(NULL)(NULL)(NULL)(NULL)
Error: (10/06/2013 03:21:25 PM) (Source: Application Error)(User: )
Description: NvXDSync.exe7.17.12.63134cf9ceb3NVXDApiX.dll7.17.12.63134cf9d218c0000417000000000026697853801cec2779d62e6ebC:\Program Files\NVIDIA Corporation\Display\NvXDSync.exeC:\Program Files\NVIDIA Corporation\Display\NVXDApiX.dll32edd75f-2e8a-11e3-9905-000a3a76d068
Error: (09/29/2013 06:37:43 PM) (Source: VSS)(User: )
Description: 0x80070005, Zugriff verweigert
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {deaac182-10c9-4f3e-87d1-cf44e7157d5e}
Error: (09/26/2013 07:52:03 PM) (Source: Application Error)(User: )
Description: NvXDSync.exe7.17.12.63134cf9ceb3NVXDApiX.dll7.17.12.63134cf9d218c0000417000000000026697865001ceba7dd35741a1C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exeC:\Program Files\NVIDIA Corporation\Display\NVXDApiX.dll590c2b0c-26d4-11e3-8985-000a3a76d068
Error: (09/24/2013 10:11:41 PM) (Source: Application Error)(User: )
Description: NvXDSync.exe7.17.12.63134cf9ceb3NVXDApiX.dll7.17.12.63134cf9d218c0000417000000000026697814f001ceb92478a3fca6C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exeC:\Program Files\NVIDIA Corporation\Display\NVXDApiX.dll86265bb1-2555-11e3-987b-000a3a76d068
Error: (09/22/2013 11:12:31 PM) (Source: Application Error)(User: )
Description: BtStackServer.exe6.5.1.4100512e5750unknown0.0.0.000000000c0000005000000000000000010d801ceb752493a6949C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exeunknownb0fc5bd0-23cb-11e3-a575-000a3a76d068
Error: (09/15/2013 06:05:06 PM) (Source: Application Error)(User: )
Description: Kies.exe1.0.0.134651f26eadKERNELBASE.dll6.1.7601.1822951fb1116e04343520000c41f1a5001ceb22d45fe1449C:\Program Files (x86)\Samsung\Kies\Kies.exeC:\Windows\syswow64\KERNELBASE.dll961dc8f6-1e20-11e3-a337-000a3a76d068
Error: (09/15/2013 06:04:59 PM) (Source: .NET Runtime)(User: )
Description: Application: Kies.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.ComponentModel.Win32Exception
Stack:
at System.Diagnostics.ProcessManager.OpenProcess(Int32, Int32, Boolean)
at System.Diagnostics.Process.GetProcessHandle(Int32, Boolean)
at System.Diagnostics.Process.OpenProcessHandle(Int32)
at System.Diagnostics.Process.get_Handle()
at Kies.App.CheckExistenceTrayAgent()
at Kies.App..ctor()
at Kies.App.Main()
Error: (09/13/2013 03:52:27 PM) (Source: VSS)(User: )
Description: 0x80070005, Zugriff verweigert
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {45dce203-0b14-4573-994c-7a97a8aefadf}
Error: (09/11/2013 10:40:08 PM) (Source: .NET Runtime Optimization Service)(User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - Failed to execute command from the offline queue: uninstall "System.Web.RegularExpressions, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil" /NoDependencies . The error returned was Error: The specified assembly is not installed.
.
==================== Memory info ===========================
Percentage of memory in use: 37%
Total physical RAM: 6135.11 MB
Available physical RAM: 3834.43 MB
Total Pagefile: 12268.41 MB
Available Pagefile: 9771.46 MB
Total Virtual: 8192 MB
Available Virtual: 8191.8 MB
==================== Drives ================================
Drive c: (Boot) (Fixed) (Total:900.41 GB) (Free:727.55 GB) NTFS
Drive d: (PRIVAT) (Fixed) (Total:298.09 GB) (Free:196.5 GB) NTFS
Drive e: (Recover) (Fixed) (Total:30 GB) (Free:10.97 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 932 GB) (Disk ID: 2BD2C32A)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=900 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=30 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=1 GB) - (Type=12)
========================================================
Disk: 1 (Size: 298 GB) (Disk ID: CAB10BEE)
Partition 1: (Active) - (Size=298 GB) - (Type=07 NTFS)
==================== End Of Log ============================ Code:
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-10-06 19:35:35
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST310005 rev.CC46 931,51GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\ANDR~1\AppData\Local\Temp\pwdorpob.sys
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[3172] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000766d1465 2 bytes [6D, 76]
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[3172] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000766d14bb 2 bytes [6D, 76]
.text ... * 2
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[3172] C:\Windows\SysWOW64\ksuser.dll!KsCreatePin + 35 0000000073cf11a8 2 bytes [CF, 73]
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[3172] C:\Windows\SysWOW64\ksuser.dll!KsCreateAllocator + 21 0000000073cf13a8 2 bytes [CF, 73]
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[3172] C:\Windows\SysWOW64\ksuser.dll!KsCreateClock + 21 0000000073cf1422 2 bytes [CF, 73]
.text C:\Program Files (x86)\Skype\Phone\Skype.exe[3172] C:\Windows\SysWOW64\ksuser.dll!KsCreateTopologyNode + 19 0000000073cf1498 2 bytes [CF, 73]
.text C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE[3276] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000766d1465 2 bytes [6D, 76]
.text C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE[3276] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000766d14bb 2 bytes [6D, 76]
.text ... * 2
.text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3292] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000766d1465 2 bytes [6D, 76]
.text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3292] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000766d14bb 2 bytes [6D, 76]
.text ... * 2
.text C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe[3304] C:\Windows\SysWOW64\ntdll.dll!DbgBreakPoint 000000007766000c 1 byte [C3]
.text C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe[3304] C:\Windows\SysWOW64\ntdll.dll!DbgUiRemoteBreakin 00000000776ef8ea 5 bytes JMP 000000017769d5c1
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3776] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000766d1465 2 bytes [6D, 76]
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3776] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000766d14bb 2 bytes [6D, 76]
.text ... * 2
.text C:\Windows\SysWOW64\RunDll32.exe[4616] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000766d1465 2 bytes [6D, 76]
.text C:\Windows\SysWOW64\RunDll32.exe[4616] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000766d14bb 2 bytes [6D, 76]
.text ... * 2
---- Threads - GMER 2.1 ----
Thread [2196:2096] 00000000776a2e65
Thread [2196:2376] 000000007320c59c
Thread [2196:2424] 000000007320c59c
Thread [2196:2504] 00000000776a3e85
Thread [2196:2816] 000000007320c59c
Thread [2196:3012] 000000007320c59c
Thread [2196:3016] 000000007320c59c
Thread [2196:3020] 000000007320c59c
Thread [2196:6136] 000000007320c59c
Thread [2196:2552] 000000007320c59c
Thread [2196:2548] 000000007320c59c
Thread [2196:2544] 000000007320c59c
Thread [2196:5548] 00000000776a3e85
Thread [2196:5556] 000000007320c59c
Thread [2196:5588] 000000007320c59c
Thread [2196:5608] 000000007320c59c
Thread [2196:5640] 000000007320c59c
Thread [2196:5652] 000000007320c59c
Thread [2196:5656] 000000007320c59c
Thread [2196:5668] 000000007320c59c
Thread [2196:5680] 000000007320c59c
Thread [2196:6364] 00000000776a3e85
Thread [2196:1756] 00000000776a3e85
Thread [2196:2616] 000000007320c59c
Thread [2196:7108] 00000000776a3e85
Thread [2196:4720] 00000000776a3e85
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4572:4728] 000007fefb642a7c
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4572:5020] 000007fee68ed618
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4572:5100] 000007fee68ed618
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4572:5104] 000007fee68ed618
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4572:5440] 000007fef9a55124
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ---- |