ESET Online Scanner: Code:
ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=44d922e759814b4f94d55d7fa9de526b
# engine=16769
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-01-23 06:59:41
# local_time=2014-01-23 07:59:41 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1799 16775165 100 95 13324 161174886 11450 0
# compatibility_mode=5893 16776573 100 94 5369 142134772 0 0
# scanned=16837
# found=0
# cleaned=0
# scan_time=1033
ESETSmartInstaller@High as downloader log:
Can not open internetESETSmartInstaller@High as downloader log:
Can not open internetCan not open internetESETSmartInstaller@High as downloader log:
Can not open internetCan not open internetESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=44d922e759814b4f94d55d7fa9de526b
# engine=16769
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-01-23 08:55:03
# local_time=2014-01-23 09:55:03 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1799 16775165 100 95 16646 161181808 18372 0
# compatibility_mode=5893 16776573 100 94 7905 142141694 0 0
# scanned=154112
# found=0
# cleaned=0
# scan_time=6745 SecurityCheck: Code:
Results of screen317's Security Check version 0.99.79
Windows 7 Service Pack 1 x86 (UAC is enabled)
Internet Explorer 11 ``````````````Antivirus/Firewall Check:``````````````
Avira Desktop
Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:`````````
WinPatrol
Malwarebytes Anti-Malware Version 1.75.0.1300
Java 7 Update 51
Adobe Flash Player 11.9.900.170
Adobe Reader 10.1.9 Adobe Reader out of Date!
Mozilla Firefox (26.0) ````````Process Check: objlist.exe by Laurent````````
WinPatrol winpatrol.exe is disabled!
Malwarebytes Anti-Malware mbamservice.exe
Avira Antivir avgnt.exe
Avira Antivir avguard.exe
Malwarebytes' Anti-Malware mbamscheduler.exe `````````````````System Health check`````````````````
Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 22-01-2014 02
Ran by Nina (administrator) on NINA-PC on 23-01-2014 22:03:30
Running from C:\Users\Nina\Desktop
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(AMD) C:\Windows\System32\atieclxx.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\AsLdrSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\HControl.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(ASUS) C:\Program Files\ASUS\ATK Hotkey\ATKOSD.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\WDC.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-18] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM\...\Run: [CanonSolutionMenuEx] - C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE [1637528 2012-10-09] (CANON INC.)
HKLM\...\Run: [ATKMEDIA] - C:\Program Files\ASUS\ATK Media\DMedia.exe [159744 2009-04-20] (ASUS)
HKLM\...\Run: [ATKOSD2] - C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe [6859392 2009-08-17] (ASUS)
HKLM\...\Run: [HControlUser] - C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [3672384 2012-04-11] (DT Soft Ltd)
HKCU\...\Run: [WinPatrol] - C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe [455744 2013-12-10] (BillP Studios)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.asus.com
SearchScopes: HKLM - DefaultScope value is missing.
BHO: No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Winsock: Catalog5 05 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Nina\AppData\Roaming\Mozilla\Firefox\Profiles\q1jf9dpe.default
FF Homepage: www.google.de
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Users\Nina\AppData\Roaming\Mozilla\Firefox\Profiles\q1jf9dpe.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi [2012-11-26]
========================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-12-18] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-27] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1011768 2013-12-18] (Avira Operations GmbH & Co. KG)
S4 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-12-20] ()
R2 ASLDRService; C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe [84536 2009-06-15] (ASUS)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-27] (Avira Operations GmbH & Co. KG)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2012-10-28] (DT Soft Ltd)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2007-07-31] (ATK0100)
R3 pfc; C:\Windows\System32\drivers\pfc.sys [10368 2012-10-07] (Padus, Inc.)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-08-05] (Avira GmbH)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-23 22:01 - 2014-01-23 22:01 - 00001042 _____ C:\Users\Nina\Desktop\checkup.txt
2014-01-23 21:58 - 2014-01-22 21:25 - 01222144 _____ (Farbar) C:\Users\Nina\Desktop\FRST.exe
2014-01-23 20:02 - 2014-01-23 20:02 - 02347384 _____ (ESET) C:\Users\Nina\Downloads\esetsmartinstaller_enu(1).exe
2014-01-23 19:48 - 2014-01-23 19:48 - 00987425 _____ C:\Users\Nina\Downloads\SecurityCheck.exe
2014-01-23 19:48 - 2014-01-23 19:48 - 00987425 _____ C:\Users\Nina\Desktop\SecurityCheck.exe
2014-01-23 19:36 - 2014-01-23 19:29 - 00912440 _____ (BillP Studios) C:\Users\Nina\Desktop\wpsetup.exe
2014-01-23 19:35 - 2014-01-23 19:33 - 00448512 _____ (OldTimer Tools) C:\Users\Nina\Desktop\TFC.exe
2014-01-23 19:33 - 2014-01-23 19:33 - 00448512 _____ (OldTimer Tools) C:\Users\Nina\Downloads\TFC.exe
2014-01-23 19:30 - 2013-12-18 06:13 - 00231584 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-01-23 19:29 - 2014-01-23 19:29 - 00912440 _____ (BillP Studios) C:\Users\Nina\Downloads\wpsetup.exe
2014-01-23 19:29 - 2014-01-23 19:29 - 00000000 ____D C:\Users\Nina\AppData\Roaming\WinPatrol
2014-01-23 19:29 - 2014-01-23 19:29 - 00000000 ____D C:\ProgramData\InstallMate
2014-01-23 19:29 - 2014-01-23 19:29 - 00000000 ____D C:\Program Files\BillP Studios
2014-01-23 19:26 - 2014-01-23 19:26 - 02347384 _____ (ESET) C:\Users\Nina\Downloads\esetsmartinstaller_enu.exe
2014-01-22 23:01 - 2014-01-22 23:01 - 00020995 _____ C:\Users\Nina\Desktop\FRST1.txt
2014-01-22 22:59 - 2014-01-22 23:00 - 00000901 _____ C:\Users\Nina\Desktop\JRT.txt
2014-01-22 22:54 - 2014-01-22 22:54 - 00003381 _____ C:\Users\Nina\Desktop\AdwCleaner[S0].txt
2014-01-22 22:44 - 2014-01-22 22:44 - 00000000 ____D C:\Windows\ERUNT
2014-01-22 22:43 - 2014-01-22 22:43 - 01037068 _____ (Thisisu) C:\Users\Nina\Downloads\JRT(1).exe
2014-01-22 22:38 - 2014-01-22 22:38 - 01037068 _____ (Thisisu) C:\Users\Nina\Downloads\JRT.exe
2014-01-22 22:36 - 2014-01-22 22:37 - 00000153 _____ C:\Users\Nina\AppData\Roaming\WB.CFG
2014-01-22 22:36 - 2014-01-22 22:36 - 00000288 _____ C:\Windows\Tasks\Digital Sites.job
2014-01-22 22:36 - 2014-01-22 22:36 - 00000005 _____ C:\Users\Nina\AppData\Roaming\WBPU-TTL.DAT
2014-01-22 22:36 - 2014-01-22 22:36 - 00000000 ____D C:\Users\Nina\AppData\Roaming\DigitalSites
2014-01-22 22:27 - 2014-01-22 22:48 - 00000000 ____D C:\AdwCleaner
2014-01-22 22:09 - 2014-01-22 22:09 - 00017352 _____ C:\Users\Nina\Desktop\Addition.txt
2014-01-22 22:08 - 2014-01-23 22:03 - 00009357 _____ C:\Users\Nina\Desktop\FRST.txt
2014-01-22 21:38 - 2014-01-22 21:38 - 01236282 _____ C:\Users\Nina\Downloads\adwcleaner_3.017.exe
2014-01-22 21:27 - 2014-01-22 21:28 - 00017352 _____ C:\Users\Nina\Downloads\Addition.txt
2014-01-22 21:26 - 2014-01-22 23:01 - 00020995 _____ C:\Users\Nina\Downloads\FRST.txt
2014-01-22 21:26 - 2014-01-22 21:26 - 00000000 ____D C:\FRST
2014-01-22 21:25 - 2014-01-22 21:25 - 01222144 _____ (Farbar) C:\Users\Nina\Downloads\FRST.exe
2014-01-22 20:33 - 2014-01-22 20:33 - 00016486 _____ C:\Users\Nina\Desktop\AVSCAN-20140122-191224-8829FB0F.LOG
2014-01-22 19:09 - 2014-01-22 19:09 - 00000000 ____D C:\Users\Nina\AppData\Roaming\Malwarebytes
2014-01-22 19:08 - 2014-01-22 19:08 - 00001067 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-22 19:08 - 2014-01-22 19:08 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-22 19:08 - 2014-01-22 19:08 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2014-01-22 19:08 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-01-22 19:07 - 2014-01-22 19:07 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Nina\Downloads\mbam-setup-1.75.0.1300.exe
2014-01-20 20:18 - 2013-12-18 21:10 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-01-20 20:18 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-01-20 20:18 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-01-20 20:18 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-01-20 20:17 - 2014-01-20 20:18 - 00005315 _____ C:\Windows\system32\jupdate-1.7.0_51-b13.log
2014-01-17 14:05 - 2014-01-17 14:05 - 05065889 _____ C:\Users\Nina\Downloads\Dafont-Top50-FontPack.zip
2014-01-17 14:01 - 2014-01-17 14:01 - 00902443 _____ C:\Users\Nina\Downloads\Leipzigfraktur_font.zip
2014-01-16 12:44 - 2014-01-16 12:44 - 00000673 _____ C:\Users\Nina\Desktop\Hochzeit.lnk
2014-01-15 19:28 - 2013-11-27 02:14 - 00258560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-01-15 19:28 - 2013-11-27 02:13 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-01-15 19:28 - 2013-11-27 02:13 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-01-15 19:28 - 2013-11-27 02:13 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-01-15 19:28 - 2013-11-27 02:13 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-01-15 19:28 - 2013-11-27 02:13 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-01-15 19:28 - 2013-11-27 02:13 - 00006016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-01-15 19:28 - 2013-11-26 12:11 - 00240576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-01-15 19:28 - 2013-11-26 11:10 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-01-15 13:09 - 2014-01-15 13:09 - 00921000 _____ (Oracle Corporation) C:\Users\Nina\Downloads\jxpiinstall.exe
2014-01-15 12:56 - 2014-01-15 12:56 - 00001187 _____ C:\Users\Public\Desktop\ElsterFormular.lnk
2014-01-15 12:56 - 2014-01-15 12:56 - 00000000 ____D C:\Program Files\ElsterFormular
2014-01-15 12:53 - 2014-01-15 12:53 - 78302976 _____ (Landesfinanzdirektion Thüringen) C:\Users\Nina\Downloads\ElsterFormular-15.0.20140114p.exe
2013-12-28 17:37 - 2013-12-28 17:37 - 00000642 _____ C:\Users\Nina\Desktop\Fotos - Verknüpfung.lnk
==================== One Month Modified Files and Folders =======
2014-01-23 22:03 - 2014-01-22 22:08 - 00009357 _____ C:\Users\Nina\Desktop\FRST.txt
2014-01-23 22:01 - 2014-01-23 22:01 - 00001042 _____ C:\Users\Nina\Desktop\checkup.txt
2014-01-23 21:55 - 2012-09-29 08:37 - 01878749 _____ C:\Windows\WindowsUpdate.log
2014-01-23 21:52 - 2012-09-16 17:17 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-23 20:02 - 2014-01-23 20:02 - 02347384 _____ (ESET) C:\Users\Nina\Downloads\esetsmartinstaller_enu(1).exe
2014-01-23 19:48 - 2014-01-23 19:48 - 00987425 _____ C:\Users\Nina\Downloads\SecurityCheck.exe
2014-01-23 19:48 - 2014-01-23 19:48 - 00987425 _____ C:\Users\Nina\Desktop\SecurityCheck.exe
2014-01-23 19:33 - 2014-01-23 19:35 - 00448512 _____ (OldTimer Tools) C:\Users\Nina\Desktop\TFC.exe
2014-01-23 19:33 - 2014-01-23 19:33 - 00448512 _____ (OldTimer Tools) C:\Users\Nina\Downloads\TFC.exe
2014-01-23 19:29 - 2014-01-23 19:36 - 00912440 _____ (BillP Studios) C:\Users\Nina\Desktop\wpsetup.exe
2014-01-23 19:29 - 2014-01-23 19:29 - 00912440 _____ (BillP Studios) C:\Users\Nina\Downloads\wpsetup.exe
2014-01-23 19:29 - 2014-01-23 19:29 - 00000000 ____D C:\Users\Nina\AppData\Roaming\WinPatrol
2014-01-23 19:29 - 2014-01-23 19:29 - 00000000 ____D C:\ProgramData\InstallMate
2014-01-23 19:29 - 2014-01-23 19:29 - 00000000 ____D C:\Program Files\BillP Studios
2014-01-23 19:26 - 2014-01-23 19:26 - 02347384 _____ (ESET) C:\Users\Nina\Downloads\esetsmartinstaller_enu.exe
2014-01-23 18:49 - 2009-07-14 05:34 - 00014928 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-23 18:49 - 2009-07-14 05:34 - 00014928 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-23 18:40 - 2012-09-22 11:35 - 00000312 _____ C:\Windows\Tasks\GlaryInitialize.job
2014-01-23 18:40 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-23 16:42 - 2009-08-20 04:40 - 00006248 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-22 23:01 - 2014-01-22 23:01 - 00020995 _____ C:\Users\Nina\Desktop\FRST1.txt
2014-01-22 23:01 - 2014-01-22 21:26 - 00020995 _____ C:\Users\Nina\Downloads\FRST.txt
2014-01-22 23:00 - 2014-01-22 22:59 - 00000901 _____ C:\Users\Nina\Desktop\JRT.txt
2014-01-22 22:54 - 2014-01-22 22:54 - 00003381 _____ C:\Users\Nina\Desktop\AdwCleaner[S0].txt
2014-01-22 22:48 - 2014-01-22 22:27 - 00000000 ____D C:\AdwCleaner
2014-01-22 22:48 - 2009-07-14 05:56 - 00000000 ____D C:\Windows\DigitalLocker
2014-01-22 22:44 - 2014-01-22 22:44 - 00000000 ____D C:\Windows\ERUNT
2014-01-22 22:43 - 2014-01-22 22:43 - 01037068 _____ (Thisisu) C:\Users\Nina\Downloads\JRT(1).exe
2014-01-22 22:38 - 2014-01-22 22:38 - 01037068 _____ (Thisisu) C:\Users\Nina\Downloads\JRT.exe
2014-01-22 22:37 - 2014-01-22 22:36 - 00000153 _____ C:\Users\Nina\AppData\Roaming\WB.CFG
2014-01-22 22:36 - 2014-01-22 22:36 - 00000288 _____ C:\Windows\Tasks\Digital Sites.job
2014-01-22 22:36 - 2014-01-22 22:36 - 00000005 _____ C:\Users\Nina\AppData\Roaming\WBPU-TTL.DAT
2014-01-22 22:36 - 2014-01-22 22:36 - 00000000 ____D C:\Users\Nina\AppData\Roaming\DigitalSites
2014-01-22 22:09 - 2014-01-22 22:09 - 00017352 _____ C:\Users\Nina\Desktop\Addition.txt
2014-01-22 21:38 - 2014-01-22 21:38 - 01236282 _____ C:\Users\Nina\Downloads\adwcleaner_3.017.exe
2014-01-22 21:28 - 2014-01-22 21:27 - 00017352 _____ C:\Users\Nina\Downloads\Addition.txt
2014-01-22 21:26 - 2014-01-22 21:26 - 00000000 ____D C:\FRST
2014-01-22 21:25 - 2014-01-23 21:58 - 01222144 _____ (Farbar) C:\Users\Nina\Desktop\FRST.exe
2014-01-22 21:25 - 2014-01-22 21:25 - 01222144 _____ (Farbar) C:\Users\Nina\Downloads\FRST.exe
2014-01-22 20:33 - 2014-01-22 20:33 - 00016486 _____ C:\Users\Nina\Desktop\AVSCAN-20140122-191224-8829FB0F.LOG
2014-01-22 19:09 - 2014-01-22 19:09 - 00000000 ____D C:\Users\Nina\AppData\Roaming\Malwarebytes
2014-01-22 19:08 - 2014-01-22 19:08 - 00001067 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-22 19:08 - 2014-01-22 19:08 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-22 19:08 - 2014-01-22 19:08 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2014-01-22 19:07 - 2014-01-22 19:07 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Nina\Downloads\mbam-setup-1.75.0.1300.exe
2014-01-20 20:18 - 2014-01-20 20:17 - 00005315 _____ C:\Windows\system32\jupdate-1.7.0_51-b13.log
2014-01-20 20:18 - 2013-12-15 16:46 - 00000000 ____D C:\ProgramData\Oracle
2014-01-20 20:18 - 2013-12-15 16:45 - 00000000 ____D C:\Program Files\Java
2014-01-18 18:37 - 2009-07-14 05:33 - 00298040 _____ C:\Windows\system32\FNTCACHE.DAT
2014-01-17 16:07 - 2012-09-16 17:41 - 00065632 _____ C:\Users\Nina\AppData\Local\GDIPFONTCACHEV1.DAT
2014-01-17 14:05 - 2014-01-17 14:05 - 05065889 _____ C:\Users\Nina\Downloads\Dafont-Top50-FontPack.zip
2014-01-17 14:01 - 2014-01-17 14:01 - 00902443 _____ C:\Users\Nina\Downloads\Leipzigfraktur_font.zip
2014-01-16 12:44 - 2014-01-16 12:44 - 00000673 _____ C:\Users\Nina\Desktop\Hochzeit.lnk
2014-01-15 22:59 - 2013-08-05 22:06 - 00000000 ____D C:\Windows\system32\MRT
2014-01-15 22:56 - 2012-09-18 22:15 - 83425928 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-15 13:09 - 2014-01-15 13:09 - 00921000 _____ (Oracle Corporation) C:\Users\Nina\Downloads\jxpiinstall.exe
2014-01-15 13:02 - 2012-11-19 18:59 - 00000000 ____D C:\Users\Nina\AppData\Roaming\elsterformular
2014-01-15 12:56 - 2014-01-15 12:56 - 00001187 _____ C:\Users\Public\Desktop\ElsterFormular.lnk
2014-01-15 12:56 - 2014-01-15 12:56 - 00000000 ____D C:\Program Files\ElsterFormular
2014-01-15 12:56 - 2012-11-19 18:58 - 00000000 ____D C:\ProgramData\elsterformular
2014-01-15 12:53 - 2014-01-15 12:53 - 78302976 _____ (Landesfinanzdirektion Thüringen) C:\Users\Nina\Downloads\ElsterFormular-15.0.20140114p.exe
2014-01-15 11:49 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\NDF
2014-01-10 20:21 - 2012-09-16 16:43 - 00000000 ____D C:\Users\Nina
2013-12-31 14:08 - 2012-09-16 17:20 - 00000000 ____D C:\Program Files\PDFCreator
2013-12-29 23:05 - 2012-09-16 17:13 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-12-28 17:37 - 2013-12-28 17:37 - 00000642 _____ C:\Users\Nina\Desktop\Fotos - Verknüpfung.lnk
Some content of TEMP:
====================
C:\Users\Nina\AppData\Local\Temp\avgnt.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-19 11:52
==================== End Of Log ============================ --- --- ---
--- --- ---
und
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 22-01-2014 02
Ran by Nina (administrator) on NINA-PC on 23-01-2014 22:03:30
Running from C:\Users\Nina\Desktop
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(AMD) C:\Windows\System32\atieclxx.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\AsLdrSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\HControl.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(ASUS) C:\Program Files\ASUS\ATK Hotkey\ATKOSD.exe
(ASUS) C:\Program Files\ASUS\ATK Hotkey\WDC.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-18] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM\...\Run: [CanonSolutionMenuEx] - C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE [1637528 2012-10-09] (CANON INC.)
HKLM\...\Run: [ATKMEDIA] - C:\Program Files\ASUS\ATK Media\DMedia.exe [159744 2009-04-20] (ASUS)
HKLM\...\Run: [ATKOSD2] - C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe [6859392 2009-08-17] (ASUS)
HKLM\...\Run: [HControlUser] - C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [3672384 2012-04-11] (DT Soft Ltd)
HKCU\...\Run: [WinPatrol] - C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe [455744 2013-12-10] (BillP Studios)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.asus.com
SearchScopes: HKLM - DefaultScope value is missing.
BHO: No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Winsock: Catalog5 05 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 19 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Nina\AppData\Roaming\Mozilla\Firefox\Profiles\q1jf9dpe.default
FF Homepage: www.google.de
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Users\Nina\AppData\Roaming\Mozilla\Firefox\Profiles\q1jf9dpe.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi [2012-11-26]
========================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-12-18] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-27] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1011768 2013-12-18] (Avira Operations GmbH & Co. KG)
S4 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-12-20] ()
R2 ASLDRService; C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe [84536 2009-06-15] (ASUS)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-27] (Avira Operations GmbH & Co. KG)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2012-10-28] (DT Soft Ltd)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2007-07-31] (ATK0100)
R3 pfc; C:\Windows\System32\drivers\pfc.sys [10368 2012-10-07] (Padus, Inc.)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-08-05] (Avira GmbH)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-23 22:01 - 2014-01-23 22:01 - 00001042 _____ C:\Users\Nina\Desktop\checkup.txt
2014-01-23 21:58 - 2014-01-22 21:25 - 01222144 _____ (Farbar) C:\Users\Nina\Desktop\FRST.exe
2014-01-23 20:02 - 2014-01-23 20:02 - 02347384 _____ (ESET) C:\Users\Nina\Downloads\esetsmartinstaller_enu(1).exe
2014-01-23 19:48 - 2014-01-23 19:48 - 00987425 _____ C:\Users\Nina\Downloads\SecurityCheck.exe
2014-01-23 19:48 - 2014-01-23 19:48 - 00987425 _____ C:\Users\Nina\Desktop\SecurityCheck.exe
2014-01-23 19:36 - 2014-01-23 19:29 - 00912440 _____ (BillP Studios) C:\Users\Nina\Desktop\wpsetup.exe
2014-01-23 19:35 - 2014-01-23 19:33 - 00448512 _____ (OldTimer Tools) C:\Users\Nina\Desktop\TFC.exe
2014-01-23 19:33 - 2014-01-23 19:33 - 00448512 _____ (OldTimer Tools) C:\Users\Nina\Downloads\TFC.exe
2014-01-23 19:30 - 2013-12-18 06:13 - 00231584 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-01-23 19:29 - 2014-01-23 19:29 - 00912440 _____ (BillP Studios) C:\Users\Nina\Downloads\wpsetup.exe
2014-01-23 19:29 - 2014-01-23 19:29 - 00000000 ____D C:\Users\Nina\AppData\Roaming\WinPatrol
2014-01-23 19:29 - 2014-01-23 19:29 - 00000000 ____D C:\ProgramData\InstallMate
2014-01-23 19:29 - 2014-01-23 19:29 - 00000000 ____D C:\Program Files\BillP Studios
2014-01-23 19:26 - 2014-01-23 19:26 - 02347384 _____ (ESET) C:\Users\Nina\Downloads\esetsmartinstaller_enu.exe
2014-01-22 23:01 - 2014-01-22 23:01 - 00020995 _____ C:\Users\Nina\Desktop\FRST1.txt
2014-01-22 22:59 - 2014-01-22 23:00 - 00000901 _____ C:\Users\Nina\Desktop\JRT.txt
2014-01-22 22:54 - 2014-01-22 22:54 - 00003381 _____ C:\Users\Nina\Desktop\AdwCleaner[S0].txt
2014-01-22 22:44 - 2014-01-22 22:44 - 00000000 ____D C:\Windows\ERUNT
2014-01-22 22:43 - 2014-01-22 22:43 - 01037068 _____ (Thisisu) C:\Users\Nina\Downloads\JRT(1).exe
2014-01-22 22:38 - 2014-01-22 22:38 - 01037068 _____ (Thisisu) C:\Users\Nina\Downloads\JRT.exe
2014-01-22 22:36 - 2014-01-22 22:37 - 00000153 _____ C:\Users\Nina\AppData\Roaming\WB.CFG
2014-01-22 22:36 - 2014-01-22 22:36 - 00000288 _____ C:\Windows\Tasks\Digital Sites.job
2014-01-22 22:36 - 2014-01-22 22:36 - 00000005 _____ C:\Users\Nina\AppData\Roaming\WBPU-TTL.DAT
2014-01-22 22:36 - 2014-01-22 22:36 - 00000000 ____D C:\Users\Nina\AppData\Roaming\DigitalSites
2014-01-22 22:27 - 2014-01-22 22:48 - 00000000 ____D C:\AdwCleaner
2014-01-22 22:09 - 2014-01-22 22:09 - 00017352 _____ C:\Users\Nina\Desktop\Addition.txt
2014-01-22 22:08 - 2014-01-23 22:03 - 00009357 _____ C:\Users\Nina\Desktop\FRST.txt
2014-01-22 21:38 - 2014-01-22 21:38 - 01236282 _____ C:\Users\Nina\Downloads\adwcleaner_3.017.exe
2014-01-22 21:27 - 2014-01-22 21:28 - 00017352 _____ C:\Users\Nina\Downloads\Addition.txt
2014-01-22 21:26 - 2014-01-22 23:01 - 00020995 _____ C:\Users\Nina\Downloads\FRST.txt
2014-01-22 21:26 - 2014-01-22 21:26 - 00000000 ____D C:\FRST
2014-01-22 21:25 - 2014-01-22 21:25 - 01222144 _____ (Farbar) C:\Users\Nina\Downloads\FRST.exe
2014-01-22 20:33 - 2014-01-22 20:33 - 00016486 _____ C:\Users\Nina\Desktop\AVSCAN-20140122-191224-8829FB0F.LOG
2014-01-22 19:09 - 2014-01-22 19:09 - 00000000 ____D C:\Users\Nina\AppData\Roaming\Malwarebytes
2014-01-22 19:08 - 2014-01-22 19:08 - 00001067 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-22 19:08 - 2014-01-22 19:08 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-22 19:08 - 2014-01-22 19:08 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2014-01-22 19:08 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-01-22 19:07 - 2014-01-22 19:07 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Nina\Downloads\mbam-setup-1.75.0.1300.exe
2014-01-20 20:18 - 2013-12-18 21:10 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-01-20 20:18 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-01-20 20:18 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-01-20 20:18 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-01-20 20:17 - 2014-01-20 20:18 - 00005315 _____ C:\Windows\system32\jupdate-1.7.0_51-b13.log
2014-01-17 14:05 - 2014-01-17 14:05 - 05065889 _____ C:\Users\Nina\Downloads\Dafont-Top50-FontPack.zip
2014-01-17 14:01 - 2014-01-17 14:01 - 00902443 _____ C:\Users\Nina\Downloads\Leipzigfraktur_font.zip
2014-01-16 12:44 - 2014-01-16 12:44 - 00000673 _____ C:\Users\Nina\Desktop\Hochzeit.lnk
2014-01-15 19:28 - 2013-11-27 02:14 - 00258560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-01-15 19:28 - 2013-11-27 02:13 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-01-15 19:28 - 2013-11-27 02:13 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-01-15 19:28 - 2013-11-27 02:13 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-01-15 19:28 - 2013-11-27 02:13 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-01-15 19:28 - 2013-11-27 02:13 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-01-15 19:28 - 2013-11-27 02:13 - 00006016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-01-15 19:28 - 2013-11-26 12:11 - 00240576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-01-15 19:28 - 2013-11-26 11:10 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-01-15 13:09 - 2014-01-15 13:09 - 00921000 _____ (Oracle Corporation) C:\Users\Nina\Downloads\jxpiinstall.exe
2014-01-15 12:56 - 2014-01-15 12:56 - 00001187 _____ C:\Users\Public\Desktop\ElsterFormular.lnk
2014-01-15 12:56 - 2014-01-15 12:56 - 00000000 ____D C:\Program Files\ElsterFormular
2014-01-15 12:53 - 2014-01-15 12:53 - 78302976 _____ (Landesfinanzdirektion Thüringen) C:\Users\Nina\Downloads\ElsterFormular-15.0.20140114p.exe
2013-12-28 17:37 - 2013-12-28 17:37 - 00000642 _____ C:\Users\Nina\Desktop\Fotos - Verknüpfung.lnk
==================== One Month Modified Files and Folders =======
2014-01-23 22:03 - 2014-01-22 22:08 - 00009357 _____ C:\Users\Nina\Desktop\FRST.txt
2014-01-23 22:01 - 2014-01-23 22:01 - 00001042 _____ C:\Users\Nina\Desktop\checkup.txt
2014-01-23 21:55 - 2012-09-29 08:37 - 01878749 _____ C:\Windows\WindowsUpdate.log
2014-01-23 21:52 - 2012-09-16 17:17 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-23 20:02 - 2014-01-23 20:02 - 02347384 _____ (ESET) C:\Users\Nina\Downloads\esetsmartinstaller_enu(1).exe
2014-01-23 19:48 - 2014-01-23 19:48 - 00987425 _____ C:\Users\Nina\Downloads\SecurityCheck.exe
2014-01-23 19:48 - 2014-01-23 19:48 - 00987425 _____ C:\Users\Nina\Desktop\SecurityCheck.exe
2014-01-23 19:33 - 2014-01-23 19:35 - 00448512 _____ (OldTimer Tools) C:\Users\Nina\Desktop\TFC.exe
2014-01-23 19:33 - 2014-01-23 19:33 - 00448512 _____ (OldTimer Tools) C:\Users\Nina\Downloads\TFC.exe
2014-01-23 19:29 - 2014-01-23 19:36 - 00912440 _____ (BillP Studios) C:\Users\Nina\Desktop\wpsetup.exe
2014-01-23 19:29 - 2014-01-23 19:29 - 00912440 _____ (BillP Studios) C:\Users\Nina\Downloads\wpsetup.exe
2014-01-23 19:29 - 2014-01-23 19:29 - 00000000 ____D C:\Users\Nina\AppData\Roaming\WinPatrol
2014-01-23 19:29 - 2014-01-23 19:29 - 00000000 ____D C:\ProgramData\InstallMate
2014-01-23 19:29 - 2014-01-23 19:29 - 00000000 ____D C:\Program Files\BillP Studios
2014-01-23 19:26 - 2014-01-23 19:26 - 02347384 _____ (ESET) C:\Users\Nina\Downloads\esetsmartinstaller_enu.exe
2014-01-23 18:49 - 2009-07-14 05:34 - 00014928 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-23 18:49 - 2009-07-14 05:34 - 00014928 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-23 18:40 - 2012-09-22 11:35 - 00000312 _____ C:\Windows\Tasks\GlaryInitialize.job
2014-01-23 18:40 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-23 16:42 - 2009-08-20 04:40 - 00006248 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-22 23:01 - 2014-01-22 23:01 - 00020995 _____ C:\Users\Nina\Desktop\FRST1.txt
2014-01-22 23:01 - 2014-01-22 21:26 - 00020995 _____ C:\Users\Nina\Downloads\FRST.txt
2014-01-22 23:00 - 2014-01-22 22:59 - 00000901 _____ C:\Users\Nina\Desktop\JRT.txt
2014-01-22 22:54 - 2014-01-22 22:54 - 00003381 _____ C:\Users\Nina\Desktop\AdwCleaner[S0].txt
2014-01-22 22:48 - 2014-01-22 22:27 - 00000000 ____D C:\AdwCleaner
2014-01-22 22:48 - 2009-07-14 05:56 - 00000000 ____D C:\Windows\DigitalLocker
2014-01-22 22:44 - 2014-01-22 22:44 - 00000000 ____D C:\Windows\ERUNT
2014-01-22 22:43 - 2014-01-22 22:43 - 01037068 _____ (Thisisu) C:\Users\Nina\Downloads\JRT(1).exe
2014-01-22 22:38 - 2014-01-22 22:38 - 01037068 _____ (Thisisu) C:\Users\Nina\Downloads\JRT.exe
2014-01-22 22:37 - 2014-01-22 22:36 - 00000153 _____ C:\Users\Nina\AppData\Roaming\WB.CFG
2014-01-22 22:36 - 2014-01-22 22:36 - 00000288 _____ C:\Windows\Tasks\Digital Sites.job
2014-01-22 22:36 - 2014-01-22 22:36 - 00000005 _____ C:\Users\Nina\AppData\Roaming\WBPU-TTL.DAT
2014-01-22 22:36 - 2014-01-22 22:36 - 00000000 ____D C:\Users\Nina\AppData\Roaming\DigitalSites
2014-01-22 22:09 - 2014-01-22 22:09 - 00017352 _____ C:\Users\Nina\Desktop\Addition.txt
2014-01-22 21:38 - 2014-01-22 21:38 - 01236282 _____ C:\Users\Nina\Downloads\adwcleaner_3.017.exe
2014-01-22 21:28 - 2014-01-22 21:27 - 00017352 _____ C:\Users\Nina\Downloads\Addition.txt
2014-01-22 21:26 - 2014-01-22 21:26 - 00000000 ____D C:\FRST
2014-01-22 21:25 - 2014-01-23 21:58 - 01222144 _____ (Farbar) C:\Users\Nina\Desktop\FRST.exe
2014-01-22 21:25 - 2014-01-22 21:25 - 01222144 _____ (Farbar) C:\Users\Nina\Downloads\FRST.exe
2014-01-22 20:33 - 2014-01-22 20:33 - 00016486 _____ C:\Users\Nina\Desktop\AVSCAN-20140122-191224-8829FB0F.LOG
2014-01-22 19:09 - 2014-01-22 19:09 - 00000000 ____D C:\Users\Nina\AppData\Roaming\Malwarebytes
2014-01-22 19:08 - 2014-01-22 19:08 - 00001067 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-22 19:08 - 2014-01-22 19:08 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-22 19:08 - 2014-01-22 19:08 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2014-01-22 19:07 - 2014-01-22 19:07 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Nina\Downloads\mbam-setup-1.75.0.1300.exe
2014-01-20 20:18 - 2014-01-20 20:17 - 00005315 _____ C:\Windows\system32\jupdate-1.7.0_51-b13.log
2014-01-20 20:18 - 2013-12-15 16:46 - 00000000 ____D C:\ProgramData\Oracle
2014-01-20 20:18 - 2013-12-15 16:45 - 00000000 ____D C:\Program Files\Java
2014-01-18 18:37 - 2009-07-14 05:33 - 00298040 _____ C:\Windows\system32\FNTCACHE.DAT
2014-01-17 16:07 - 2012-09-16 17:41 - 00065632 _____ C:\Users\Nina\AppData\Local\GDIPFONTCACHEV1.DAT
2014-01-17 14:05 - 2014-01-17 14:05 - 05065889 _____ C:\Users\Nina\Downloads\Dafont-Top50-FontPack.zip
2014-01-17 14:01 - 2014-01-17 14:01 - 00902443 _____ C:\Users\Nina\Downloads\Leipzigfraktur_font.zip
2014-01-16 12:44 - 2014-01-16 12:44 - 00000673 _____ C:\Users\Nina\Desktop\Hochzeit.lnk
2014-01-15 22:59 - 2013-08-05 22:06 - 00000000 ____D C:\Windows\system32\MRT
2014-01-15 22:56 - 2012-09-18 22:15 - 83425928 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-15 13:09 - 2014-01-15 13:09 - 00921000 _____ (Oracle Corporation) C:\Users\Nina\Downloads\jxpiinstall.exe
2014-01-15 13:02 - 2012-11-19 18:59 - 00000000 ____D C:\Users\Nina\AppData\Roaming\elsterformular
2014-01-15 12:56 - 2014-01-15 12:56 - 00001187 _____ C:\Users\Public\Desktop\ElsterFormular.lnk
2014-01-15 12:56 - 2014-01-15 12:56 - 00000000 ____D C:\Program Files\ElsterFormular
2014-01-15 12:56 - 2012-11-19 18:58 - 00000000 ____D C:\ProgramData\elsterformular
2014-01-15 12:53 - 2014-01-15 12:53 - 78302976 _____ (Landesfinanzdirektion Thüringen) C:\Users\Nina\Downloads\ElsterFormular-15.0.20140114p.exe
2014-01-15 11:49 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\NDF
2014-01-10 20:21 - 2012-09-16 16:43 - 00000000 ____D C:\Users\Nina
2013-12-31 14:08 - 2012-09-16 17:20 - 00000000 ____D C:\Program Files\PDFCreator
2013-12-29 23:05 - 2012-09-16 17:13 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-12-28 17:37 - 2013-12-28 17:37 - 00000642 _____ C:\Users\Nina\Desktop\Fotos - Verknüpfung.lnk
Some content of TEMP:
====================
C:\Users\Nina\AppData\Local\Temp\avgnt.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-19 11:52
==================== End Of Log ============================ --- --- ---
--- --- ---
Hier noch die addition.txt: Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 22-01-2014 02
Ran by Nina at 2014-01-23 22:04:18
Running from C:\Users\Nina\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Disabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Disabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
ACDSee 9 Foto-Manager (Version: 9.0.55 - ACD Systems Ltd.)
Adobe Flash Player 11 Plugin (Version: 11.9.900.170 - Adobe Systems Incorporated)
Adobe Reader X (10.1.9) - Deutsch (Version: 10.1.9 - Adobe Systems Incorporated)
Apple Application Support (Version: 2.3.6 - Apple Inc.)
Apple Mobile Device Support (Version: 7.0.0.117 - Apple Inc.)
Apple Software Update (Version: 2.1.3.127 - Apple Inc.)
ATK Hotkey (Version: 1.0.0053 - ASUS)
ATK Media (Version: 2.0.0005 - ASUS)
ATKOSD2 (Version: 7.0.0006 - ASUS)
Audible Download Manager (Version: 6.6.0.15 - Audible, Inc.)
Avira Free Antivirus (Version: 14.0.2.286 - Avira)
Avira SearchFree Toolbar (Version: 12.10.0.2948 - APN, LLC)
AviSynth 2.6 (Version: 2.6.0.2 - GPL Public release.)
AvsP (Version: - )
Bonjour (Version: 3.0.0.10 - Apple Inc.)
Canon MP Navigator EX 4.0 (Version: - )
Canon MP280 series MP Drivers (Version: - )
Canon Solution Menu EX (Version: - )
D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (Version: 4.45.4.0314 - DT Soft Ltd)
DVD slideshow GUI 0.9.5.4 (Version: 0.9.5.4 - Tin2tin)
ElsterFormular (Version: 15.0.20140114 - Landesfinanzdirektion Thüringen)
Fotogalerie (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Free YouTube to MP3 Converter version 3.12.2.430 (Version: 3.12.2.430 - DVDVideoSoft Ltd.)
GIMP 2.8.4 (Version: 2.8.4 - The GIMP Team)
Glary Utilities 2.51.0.1666 (Version: 2.51.0.1666 - Glarysoft Ltd)
GUI for dvdauthor 1.07 (Version: 1.07 - Boraxsoft)
Haali Media Splitter (Version: - )
Helix YUV Codecs (remove only) (Version: - )
iCloud (Version: 3.0.2.163 - Apple Inc.)
ImgBurn (Version: 2.5.5.0 - LIGHTNING UK!)
iTunes (Version: 11.1.3.8 - Apple Inc.)
Java 7 Update 51 (Version: 7.0.510 - Oracle)
Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden
Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation)
Movie Maker (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Mozilla Firefox 26.0 (x86 de) (Version: 26.0 - Mozilla)
Mozilla Maintenance Service (Version: 26.0 - Mozilla)
MSVCRT (Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT110 (Version: 16.4.1108.0727 - Microsoft) Hidden
OpenOffice 4.0.1 (Version: 4.01.9714 - Apache Software Foundation)
PDFCreator (Version: 1.5.0 - Frank Heindörfer, Philip Chinery)
Photo Common (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Photo Gallery (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Picasa 3 (Version: 3.9 - Google, Inc.)
QuickTime (Version: 7.74.80.86 - Apple Inc.)
Windows Live Communications Platform (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Essentials (Version: 16.4.3508.0205 - Microsoft Corporation)
Windows Live Essentials (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden
Windows Live Installer (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Photo Common (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live SOXE (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live UX Platform (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
WinPatrol (Version: 29.2.2013 - BillP Studios)
XnView 1.99.6 (Version: 1.99.6 - Gougelet Pierre-e)
==================== Restore Points =========================
31-12-2013 11:39:09 Geplanter Prüfpunkt
15-01-2014 21:55:47 Windows Update
20-01-2014 19:16:27 Installed Java 7 Update 51
23-01-2014 18:29:30 Windows Update
==================== Hosts content: ==========================
2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {3282E8CE-14C2-4D2C-BC98-B3E7D432F93E} - System32\Tasks\Digital Sites => C:\Users\Nina\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: {3DB032BF-328F-42D1-9459-62BD86CBDEFC} - System32\Tasks\GlaryInitialize => C:\Program Files\Glary Utilities\initialize.exe [2012-12-07] (Glarysoft Ltd)
Task: {43DF0539-97DC-42C9-A1BA-50F5E9E51118} - System32\Tasks\Freemium1ClickMaint => C:\Users\Nina\Downloads\1Click.exe
Task: {665823E8-5D36-4DFE-B97F-B07E0DC493D3} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {DF78C6EB-EE41-41B5-B38E-27E1CFAEE376} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-15] (Adobe Systems Incorporated)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\Digital Sites.job => C:\Users\Nina\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\Windows\Tasks\GlaryInitialize.job => C:\Program Files\Glary Utilities\initialize.exe
==================== Loaded Modules (whitelisted) =============
2013-12-21 19:36 - 2013-12-21 19:36 - 03559024 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll
2013-12-15 16:52 - 2013-12-15 16:52 - 16242056 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\ProgramData\TEMP:07BF512B
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
Name: ATI Mobility Radeon HD 4500 Series
Description: ATI Mobility Radeon HD 4500 Series
Class Guid: {4d36e968-e325-11ce-bfc1-08002be10318}
Manufacturer: ATI Technologies Inc.
Service: atikmdag
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (01/23/2014 06:41:22 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1".
Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (01/23/2014 06:41:22 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1".
Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (01/23/2014 06:41:10 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1".
Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (01/23/2014 06:41:09 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1".
Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (01/23/2014 05:19:09 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1".
Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (01/23/2014 05:19:09 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1".
Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (01/23/2014 05:18:52 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1".
Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (01/23/2014 05:18:52 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1".
Die abhängige Assemblierung "Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (01/23/2014 04:42:21 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT)
Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich.
Error: (01/23/2014 04:42:21 PM) (Source: Microsoft-Windows-LoadPerf) (User: NT-AUTORITÄT)
Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich.
System errors:
=============
Error: (01/23/2014 07:35:36 PM) (Source: Service Control Manager) (User: )
Description: Dienst "AMD External Events Utility" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (01/23/2014 06:40:56 PM) (Source: atikmdag) (User: )
Description: Display is not active
Error: (01/23/2014 06:40:56 PM) (Source: atikmdag) (User: )
Description: CPLIB :: General - Invalid Parameter
Error: (01/23/2014 05:18:36 PM) (Source: atikmdag) (User: )
Description: Display is not active
Error: (01/23/2014 05:18:36 PM) (Source: atikmdag) (User: )
Description: CPLIB :: General - Invalid Parameter
Error: (01/23/2014 05:05:15 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst MBAMScheduler erreicht.
Error: (01/23/2014 05:01:11 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst MBAMScheduler erreicht.
Error: (01/23/2014 03:50:18 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst MBAMScheduler erreicht.
Error: (01/23/2014 03:41:40 PM) (Source: atikmdag) (User: )
Description: Display is not active
Error: (01/23/2014 03:41:40 PM) (Source: atikmdag) (User: )
Description: CPLIB :: General - Invalid Parameter
Microsoft Office Sessions:
=========================
Error: (01/23/2014 06:41:22 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files\Canon\Solution Menu EX\MFC80U.DLL
Error: (01/23/2014 06:41:22 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files\Canon\Solution Menu EX\MFC80U.DLL
Error: (01/23/2014 06:41:10 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files\Canon\Solution Menu EX\MFC80U.DLL
Error: (01/23/2014 06:41:09 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files\Canon\Solution Menu EX\MFC80U.DLL
Error: (01/23/2014 05:19:09 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files\Canon\Solution Menu EX\MFC80U.DLL
Error: (01/23/2014 05:19:09 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files\Canon\Solution Menu EX\MFC80U.DLL
Error: (01/23/2014 05:18:52 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files\Canon\Solution Menu EX\MFC80U.DLL
Error: (01/23/2014 05:18:52 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files\Canon\Solution Menu EX\MFC80U.DLL
Error: (01/23/2014 04:42:21 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT)
Description: WmiApRplWmiApRpl8F20300004D070000
Error: (01/23/2014 04:42:21 PM) (Source: Microsoft-Windows-LoadPerf)(User: NT-AUTORITÄT)
Description: Performance1637070000000000000000000009030000
==================== Memory info ===========================
Percentage of memory in use: 43%
Total physical RAM: 3071.12 MB
Available physical RAM: 1740.21 MB
Total Pagefile: 6140.52 MB
Available Pagefile: 4639.18 MB
Total Virtual: 2047.88 MB
Available Virtual: 1913.91 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:99.9 GB) (Free:60.88 GB) NTFS
Drive d: () (Fixed) (Total:198.09 GB) (Free:178.15 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 97646C29)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=100 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=198 GB) - (Type=07 NTFS)
==================== End Of Log ============================ |