bei 32 bit kam das es mit meiner OS nicht geht am pc oder so und das ich 64 bit runterladen soll
first editor
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-07-2013
Ran by Bayramoglu (administrator) on 26-07-2013 17:23:22
Running from C:\Users\Bayramoglu\Downloads
Windows 8 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AVG Technologies CZ, s.r.o.) C:\PROGRA~2\AVG\AVG2013\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
(AMD) C:\WINDOWS\system32\atiesrxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
(Conexant Systems Inc.) C:\WINDOWS\system32\CxAudMsg64.exe
() C:\ProgramData\DatacardService\HWDeviceService64.exe
(Microsoft Corporation) C:\WINDOWS\system32\dashost.exe
() C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgemca.exe
(cake bake) C:\Program Files (x86)\Web Cake\WebCakeDesktop.Updater.exe
(AMD) C:\WINDOWS\system32\atieclxx.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Bake Cake) C:\Users\Bayramoglu\AppData\Roaming\Web Cake\WebCakeDesktop.exe
(Vimicro) C:\Program Files (x86)\USB Camera\VM331STI.EXE
(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe
(Inbox.com, Inc.) C:\Program Files (x86)\Inbox Toolbar\Inbox.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgui.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SmartAudio] - C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [cAudioFilterAgent] - C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [887968 2012-06-14] (Conexant Systems, Inc.)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-14] (Synaptics Incorporated)
HKLM\...\Run: [Energy Management] - C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17079376 2012-12-15] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] - C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [191568 2012-12-15] (Lenovo(beijing) Limited)
HKCU\...\Run: [Optimizer Pro] - C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe [135672 2013-06-07] (PC Utilities Pro)
HKCU\...\Run: [WebCake Desktop] - C:\Users\Bayramoglu\AppData\Roaming\Web Cake\WebCakeDesktop.exe [52504 2013-07-26] (Bake Cake)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.)
MountPoints2: F - "F:\AutoRun.exe"
MountPoints2: {eab668fe-60eb-11e2-be70-806e6f6e6963} - "F:\AutoRun.exe"
MountPoints2: {eab66ae7-60eb-11e2-be70-2016d812b098} - "F:\AutoRun.exe"
MountPoints2: {f52d4fac-611a-11e2-be71-2016d812b098} - "F:\AutoRun.exe"
HKLM-x32\...\Run: [331BigDog] - C:\Program Files (x86)\USB Camera\VM331STI.EXE [548864 2012-05-02] (Vimicro)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] - C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [508656 2012-07-25] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [YouCam Mirage] - C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2012-07-27] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] - C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [167024 2012-07-27] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GShortCut] - C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [217088 2012-04-18] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.)
HKLM-x32\...\Run: [Intel AppUp(SM) center] - C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-12] (Intel Corporation)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-11-28] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152544 2012-12-12] (Apple Inc.)
HKLM-x32\...\Run: [InboxToolbar] - C:\Program Files (x86)\Inbox Toolbar\Inbox.exe [1713288 2013-03-18] (Inbox.com, Inc.)
HKLM-x32\...\Run: [AVG_UI] - C:\Program Files (x86)\AVG\AVG2013\avgui.exe [4408368 2013-04-29] (AVG Technologies CZ, s.r.o.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
SearchScopes: HKLM - DefaultScope {68D5157B-6C94-42E3-B722-0047BB52E691} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS
SearchScopes: HKLM - {68D5157B-6C94-42E3-B722-0047BB52E691} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS
SearchScopes: HKLM-x32 - DefaultScope {68D5157B-6C94-42E3-B722-0047BB52E691} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS
SearchScopes: HKLM-x32 - {68D5157B-6C94-42E3-B722-0047BB52E691} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS
SearchScopes: HKCU - DefaultScope {68D5157B-6C94-42E3-B722-0047BB52E691} URL =
SearchScopes: HKCU - {68D5157B-6C94-42E3-B722-0047BB52E691} URL =
BHO-x32: LyricXeeker - {17E58097-6CA5-448B-830F-2A19678248FB} - C:\Program Files (x86)\LyriXeeker\125.dll (LyriXeeker Tech)
BHO-x32: WebCake - {2A5A2A90-3B30-4E6E-A955-2F232C6EF517} - C:\Program Files (x86)\Web Cake\WebCakeIEClient.dll (Web Cake LLC)
BHO-x32: DealPly Shopping - {ae48ed75-5a56-4c5f-bbce-6f1ac3875f66} - C:\Program Files (x86)\DealPly\DealPlyIE.dll (DealPly)
Handler: inbox - {37540F19-DD4C-478B-B2DF-C19281BCAF27} - No File
Handler-x32: inbox - {37540F19-DD4C-478B-B2DF-C19281BCAF27} - C:\PROGRA~2\INBOXT~1\Inbox.dll (Inbox.com, Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{9091E84A-8EBD-4154-B5AC-3D46B218DAA3}: [NameServer]10.74.210.210 10.74.210.211
Tcpip\..\Interfaces\{A4F9BB2B-59B3-4BF7-85FB-A7AC0D4935CE}: [NameServer]10.74.210.210 10.74.210.211
FireFox:
========
FF ProfilePath: C:\Users\Bayramoglu\AppData\Roaming\Mozilla\Firefox\Profiles\45q8jsx6.default
FF user.js: detected! => C:\Users\Bayramoglu\AppData\Roaming\Mozilla\Firefox\Profiles\45q8jsx6.default\user.js
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @tools.dpliveupdate.com/DealPlyLive Update;version=3 - C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\npGoogleUpdate3.dll (DealPly Technologies Ltd)
FF Plugin-x32: @tools.dpliveupdate.com/DealPlyLive Update;version=9 - C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\npGoogleUpdate3.dll (DealPly Technologies Ltd)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Extension: WebCake - C:\Users\Bayramoglu\AppData\Roaming\Mozilla\Firefox\Profiles\45q8jsx6.default\Extensions\plugin@getwebcake.com
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM-x32\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] C:\Program Files\T-Mobile\InternetManager_H\OCx64\addon
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] C:\Program Files\McAfee\MSK
FF HKCU\...\Firefox\Extensions: [lyrix@lyrixeeker.co] C:\Program Files (x86)\LyriXeeker\125.xpi
FF Extension: No Name - C:\Program Files (x86)\LyriXeeker\125.xpi
Chrome:
=======
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.72\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.72\pdf.dll ()
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll No File
CHR Extension: (Google Docs) - C:\Users\BAYRAM~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\BAYRAM~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (Inbox Toolbar) - C:\Users\BAYRAM~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apgjagobplilmcdfelodhgefiidomnfl\1.0.0.9_0
CHR Extension: (YouTube) - C:\Users\BAYRAM~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\BAYRAM~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Web Cake) - C:\Users\BAYRAM~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoijdanhaiflhibkljeklcghcmmfffh\1.0.3_0
CHR Extension: (DealPly Shopping) - C:\Users\BAYRAM~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\mphpbdjcljebbcnfopfngmfdackbbdgf\3.5.0.0_0
CHR Extension: (LyricXeeker) - C:\Users\BAYRAM~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\odnofacmifkjndflfmmplhckcbfjckhj\1.125_0
CHR Extension: (Gmail) - C:\Users\BAYRAM~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM-x32\...\Chrome\Extension: [apgjagobplilmcdfelodhgefiidomnfl] - C:\Program Files (x86)\Inbox Toolbar\Chrome\ibxtoolbar_chr.crx
CHR HKLM-x32\...\Chrome\Extension: [fjoijdanhaiflhibkljeklcghcmmfffh] - C:\Program Files (x86)\Web Cake\WebCakeLayers.crx
CHR HKLM-x32\...\Chrome\Extension: [odnofacmifkjndflfmmplhckcbfjckhj] - C:\Program Files (x86)\LyriXeeker\125.crx
==================== Services (Whitelisted) =================
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-08-06] (Advanced Micro Devices, Inc.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [4937264 2013-05-14] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [283136 2013-04-18] (AVG Technologies CZ, s.r.o.)
R2 CxAudMsg; C:\WINDOWS\system32\CxAudMsg64.exe [201376 2012-06-08] (Conexant Systems Inc.)
S2 dealplylive; C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe [148000 2013-07-26] (DealPly Technologies Ltd)
S3 dealplylivem; C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe [148000 2013-07-26] (DealPly Technologies Ltd)
R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [344928 2011-01-28] ()
S2 Internet Manager. RunOuc; C:\Program Files (x86)\T-Mobile\InternetManager_H\UpdateDog\ouc.exe [224096 2013-01-17] ()
R2 WebCakeUpdater; C:\Program Files (x86)\Web Cake\WebCakeDesktop.Updater.exe [50968 2013-07-26] (cake bake)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14920 2013-01-29] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [20912 2012-10-26] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdrivera.sys [246072 2013-03-29] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [71480 2013-02-08] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\system32\DRIVERS\avgldx64.sys [206136 2013-02-08] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [311096 2013-02-08] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [116536 2013-02-08] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [45880 2013-02-08] (AVG Technologies CZ, s.r.o.)
R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [248632 2013-06-27] (AVG Technologies CZ, s.r.o.)
R0 BMLoad; C:\Windows\System32\drivers\BMLoad.sys [16512 2013-01-17] (Bytemobile, Inc.)
S3 huawei_wwanecm; C:\Windows\system32\DRIVERS\ew_juwwanecm.sys [212992 2013-01-17] (Huawei Technologies Co., Ltd.)
R1 tcpipBM; C:\WINDOWS\system32\drivers\tcpipBM.sys [39552 2013-01-17] (Bytemobile, Inc.)
R1 tcpipBM; C:\WINDOWS\system32\drivers\tcpipBM.sys [39552 2013-01-17] (Bytemobile, Inc.)
R3 vm331avs; C:\Windows\System32\Drivers\vm331avs.sys [975104 2012-08-24] (Vimicro Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-07-26 17:23 - 2013-07-26 17:23 - 00000000 ____D C:\FRST
2013-07-26 17:21 - 2013-07-26 17:21 - 01779893 _____ (Farbar) C:\Users\Bayramoglu\Downloads\FRST64.exe
2013-07-26 17:20 - 2013-07-26 17:20 - 01220112 _____ (Farbar) C:\Users\Bayramoglu\Downloads\FRST.exe
2013-07-26 14:51 - 2013-07-26 15:39 - 00000000 ____D C:\Users\Bayramoglu\AppData\Roaming\Skype
2013-07-26 14:51 - 2013-07-26 14:51 - 00002517 _____ C:\Users\Public\Desktop\Skype.lnk
2013-07-26 14:51 - 2013-07-26 14:51 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-07-26 14:50 - 2013-07-26 14:51 - 00000000 ____D C:\ProgramData\Skype
2013-07-26 14:49 - 2013-07-26 14:50 - 31954536 _____ (Skype Technologies S.A.) C:\Users\Bayramoglu\Downloads\SkypeSetup66Full.exe
2013-07-26 14:36 - 2013-07-26 15:12 - 00000000 ____D C:\Users\Bayramoglu\AppData\Roaming\Web Cake
2013-07-26 14:36 - 2013-07-26 14:37 - 00000000 ____D C:\Program Files (x86)\Web Cake
2013-07-26 14:35 - 2013-07-26 16:40 - 00000934 _____ C:\WINDOWS\Tasks\DealPlyLiveUpdateTaskMachineUA.job
2013-07-26 14:35 - 2013-07-26 15:10 - 00000930 _____ C:\WINDOWS\Tasks\DealPlyLiveUpdateTaskMachineCore.job
2013-07-26 14:35 - 2013-07-26 14:35 - 00003906 _____ C:\WINDOWS\System32\Tasks\DealPlyLiveUpdateTaskMachineUA
2013-07-26 14:35 - 2013-07-26 14:35 - 00003670 _____ C:\WINDOWS\System32\Tasks\DealPlyLiveUpdateTaskMachineCore
2013-07-26 14:34 - 2013-07-26 16:34 - 00000326 _____ C:\WINDOWS\Tasks\Dealply.job
2013-07-26 14:34 - 2013-07-26 15:10 - 00000418 _____ C:\WINDOWS\Tasks\LyricXeeker Update.job
2013-07-26 14:34 - 2013-07-26 14:36 - 20586496 _____ C:\Users\Bayramoglu\Downloads\SkypeSetup [1].exe
2013-07-26 14:34 - 2013-07-26 14:34 - 00003068 _____ C:\WINDOWS\System32\Tasks\LyricXeeker Update
2013-07-26 14:34 - 2013-07-26 14:34 - 00002664 _____ C:\WINDOWS\System32\Tasks\Dealply
2013-07-26 14:34 - 2013-07-26 14:34 - 00001029 _____ C:\Users\Bayramoglu\Desktop\Optimizer Pro.lnk
2013-07-26 14:34 - 2013-07-26 14:34 - 00000000 ____D C:\Users\Bayramoglu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly
2013-07-26 14:34 - 2013-07-26 14:34 - 00000000 ____D C:\Users\Bayramoglu\AppData\Roaming\Dealply
2013-07-26 14:34 - 2013-07-26 14:34 - 00000000 ____D C:\Users\BAYRAM~1\AppData\Local\DealPlyLive
2013-07-26 14:34 - 2013-07-26 14:34 - 00000000 ____D C:\ProgramData\DealPlyLive
2013-07-26 14:34 - 2013-07-26 14:34 - 00000000 ____D C:\Program Files (x86)\Optimizer Pro
2013-07-26 14:34 - 2013-07-26 14:34 - 00000000 ____D C:\Program Files (x86)\LyriXeeker
2013-07-26 14:34 - 2013-07-26 14:34 - 00000000 ____D C:\Program Files (x86)\DealPlyLive
2013-07-26 14:34 - 2013-07-26 14:34 - 00000000 ____D C:\Program Files (x86)\DealPly
2013-07-21 16:32 - 2013-07-21 16:32 - 00000005 _____ C:\Users\Bayramoglu\AppData\Roaming\WBPU-TTL.DAT
2013-07-21 15:45 - 2013-07-21 15:45 - 00000000 ____D C:\Users\Bayramoglu\Qtrax
2013-07-21 15:41 - 2013-07-21 15:41 - 00003822 _____ C:\WINDOWS\System32\Tasks\QtraxPlayer
2013-07-21 15:37 - 2013-07-21 15:37 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-07-21 15:37 - 2013-07-21 15:37 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-07-21 15:32 - 2013-07-21 16:32 - 00000322 _____ C:\WINDOWS\Tasks\DSite.job
2013-07-21 15:32 - 2013-07-21 15:32 - 00002660 _____ C:\WINDOWS\System32\Tasks\DSite
2013-07-21 15:32 - 2013-07-21 15:32 - 00000000 ____D C:\Users\Bayramoglu\AppData\Roaming\DSite
2013-07-21 01:28 - 2013-07-21 01:31 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-07-17 03:09 - 2013-06-01 11:20 - 02219520 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2013-07-17 03:08 - 2013-06-01 13:34 - 02391280 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2013-07-17 03:08 - 2013-06-01 13:33 - 02233600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2013-07-17 03:08 - 2013-06-01 13:26 - 06987008 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2013-07-17 03:08 - 2013-06-01 13:26 - 00327936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys
2013-07-17 03:08 - 2013-06-01 12:24 - 02106176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2013-07-17 03:08 - 2013-06-01 11:24 - 01453568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2013-07-17 03:08 - 2013-06-01 11:23 - 01842176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2013-07-17 03:08 - 2013-06-01 11:21 - 00729600 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2013-07-17 03:08 - 2013-06-01 11:20 - 01527808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2013-07-17 03:08 - 2013-05-25 00:09 - 01403296 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2013-07-17 03:07 - 2013-06-01 13:54 - 00194816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2013-07-17 03:07 - 2013-06-01 13:54 - 00125184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2013-07-17 03:07 - 2013-06-01 13:29 - 00337152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2013-07-17 03:07 - 2013-06-01 13:29 - 00213248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UCX01000.SYS
2013-07-17 03:07 - 2013-06-01 11:25 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsGdiConverter.dll
2013-07-17 03:07 - 2013-06-01 11:25 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll
2013-07-17 03:07 - 2013-06-01 11:24 - 00850944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2013-07-17 03:07 - 2013-06-01 11:24 - 00493056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mscms.dll
2013-07-17 03:07 - 2013-06-01 11:23 - 00680960 _____ (Microsoft Corporation) C:\WINDOWS\system32\vds.exe
2013-07-17 03:07 - 2013-06-01 11:22 - 00523264 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsGdiConverter.dll
2013-07-17 03:07 - 2013-06-01 11:22 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2013-07-17 03:07 - 2013-06-01 11:22 - 00190976 _____ (Microsoft Corporation) C:\WINDOWS\system32\vdsutil.dll
2013-07-17 03:07 - 2013-06-01 11:22 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeParserTask.exe
2013-07-17 03:07 - 2013-06-01 11:21 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
2013-07-17 03:07 - 2013-06-01 11:20 - 01048576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2013-07-17 03:07 - 2013-06-01 11:20 - 00583168 _____ (Microsoft Corporation) C:\WINDOWS\system32\mscms.dll
2013-07-17 03:07 - 2013-06-01 11:19 - 00785408 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2013-07-17 03:07 - 2013-06-01 11:19 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSetupManager.dll
2013-07-17 03:07 - 2013-06-01 05:08 - 00037632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthAvrcpTg.sys
2013-07-17 03:07 - 2013-05-25 00:09 - 01271584 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2013-07-17 03:07 - 2013-05-25 00:09 - 01217352 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2013-07-17 03:07 - 2013-05-25 00:09 - 01093904 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2013-07-17 03:07 - 2013-05-20 02:08 - 00386642 _____ C:\WINDOWS\system32\ApnDatabase.xml
2013-07-17 03:06 - 2013-06-17 00:41 - 00997632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2013-07-17 02:11 - 2013-07-17 02:12 - 00281248 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-07-16 00:32 - 2013-05-16 00:35 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\tssdisai.dll
2013-07-15 17:31 - 2013-05-31 01:14 - 04036096 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2013-07-15 17:30 - 2013-06-01 11:25 - 00496640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll
2013-07-15 17:30 - 2013-06-01 11:21 - 00595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll
2013-07-15 17:29 - 2013-04-12 00:30 - 01421312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2013-07-15 17:29 - 2013-04-12 00:22 - 01838080 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2013-07-15 17:28 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2013-07-15 17:28 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2013-07-15 17:28 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2013-07-15 17:28 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2013-07-15 17:28 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2013-07-15 17:27 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2013-07-15 17:27 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2013-07-15 17:27 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2013-07-15 17:27 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2013-07-15 17:27 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2013-07-15 17:27 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2013-07-15 17:27 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2013-07-15 17:27 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2013-07-15 17:27 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2013-07-15 17:27 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2013-07-15 17:27 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2013-07-15 17:27 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2013-07-15 17:24 - 2013-05-04 08:59 - 02842112 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVDECOD.DLL
2013-07-15 17:24 - 2013-05-04 06:57 - 02620928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVDECOD.DLL
2013-06-27 00:46 - 2013-06-27 00:46 - 00248632 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgwfpa.sys
==================== One Month Modified Files and Folders =======
2013-07-26 17:23 - 2013-07-26 17:23 - 00000000 ____D C:\FRST
2013-07-26 17:21 - 2013-07-26 17:21 - 01779893 _____ (Farbar) C:\Users\Bayramoglu\Downloads\FRST64.exe
2013-07-26 17:20 - 2013-07-26 17:20 - 01220112 _____ (Farbar) C:\Users\Bayramoglu\Downloads\FRST.exe
2013-07-26 17:00 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\system32\sru
2013-07-26 16:51 - 2013-04-07 21:32 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-07-26 16:41 - 2013-01-18 00:11 - 00001138 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-26 16:40 - 2013-07-26 14:35 - 00000934 _____ C:\WINDOWS\Tasks\DealPlyLiveUpdateTaskMachineUA.job
2013-07-26 16:34 - 2013-07-26 14:34 - 00000326 _____ C:\WINDOWS\Tasks\Dealply.job
2013-07-26 16:31 - 2012-12-15 20:43 - 00753134 _____ C:\WINDOWS\system32\perfh007.dat
2013-07-26 16:31 - 2012-12-15 20:43 - 00155826 _____ C:\WINDOWS\system32\perfc007.dat
2013-07-26 16:31 - 2012-07-26 09:28 - 01745416 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-07-26 15:39 - 2013-07-26 14:51 - 00000000 ____D C:\Users\Bayramoglu\AppData\Roaming\Skype
2013-07-26 15:12 - 2013-07-26 14:36 - 00000000 ____D C:\Users\Bayramoglu\AppData\Roaming\Web Cake
2013-07-26 15:10 - 2013-07-26 14:35 - 00000930 _____ C:\WINDOWS\Tasks\DealPlyLiveUpdateTaskMachineCore.job
2013-07-26 15:10 - 2013-07-26 14:34 - 00000418 _____ C:\WINDOWS\Tasks\LyricXeeker Update.job
2013-07-26 15:10 - 2013-01-18 00:11 - 00001134 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-26 14:51 - 2013-07-26 14:51 - 00002517 _____ C:\Users\Public\Desktop\Skype.lnk
2013-07-26 14:51 - 2013-07-26 14:51 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-07-26 14:51 - 2013-07-26 14:50 - 00000000 ____D C:\ProgramData\Skype
2013-07-26 14:50 - 2013-07-26 14:49 - 31954536 _____ (Skype Technologies S.A.) C:\Users\Bayramoglu\Downloads\SkypeSetup66Full.exe
2013-07-26 14:42 - 2013-01-18 01:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-07-26 14:42 - 2012-07-26 09:22 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-07-26 14:37 - 2013-07-26 14:36 - 00000000 ____D C:\Program Files (x86)\Web Cake
2013-07-26 14:36 - 2013-07-26 14:34 - 20586496 _____ C:\Users\Bayramoglu\Downloads\SkypeSetup [1].exe
2013-07-26 14:35 - 2013-07-26 14:35 - 00003906 _____ C:\WINDOWS\System32\Tasks\DealPlyLiveUpdateTaskMachineUA
2013-07-26 14:35 - 2013-07-26 14:35 - 00003670 _____ C:\WINDOWS\System32\Tasks\DealPlyLiveUpdateTaskMachineCore
2013-07-26 14:34 - 2013-07-26 14:34 - 00003068 _____ C:\WINDOWS\System32\Tasks\LyricXeeker Update
2013-07-26 14:34 - 2013-07-26 14:34 - 00002664 _____ C:\WINDOWS\System32\Tasks\Dealply
2013-07-26 14:34 - 2013-07-26 14:34 - 00001029 _____ C:\Users\Bayramoglu\Desktop\Optimizer Pro.lnk
2013-07-26 14:34 - 2013-07-26 14:34 - 00000000 ____D C:\Users\Bayramoglu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly
2013-07-26 14:34 - 2013-07-26 14:34 - 00000000 ____D C:\Users\Bayramoglu\AppData\Roaming\Dealply
2013-07-26 14:34 - 2013-07-26 14:34 - 00000000 ____D C:\Users\BAYRAM~1\AppData\Local\DealPlyLive
2013-07-26 14:34 - 2013-07-26 14:34 - 00000000 ____D C:\ProgramData\DealPlyLive
2013-07-26 14:34 - 2013-07-26 14:34 - 00000000 ____D C:\Program Files (x86)\Optimizer Pro
2013-07-26 14:34 - 2013-07-26 14:34 - 00000000 ____D C:\Program Files (x86)\LyriXeeker
2013-07-26 14:34 - 2013-07-26 14:34 - 00000000 ____D C:\Program Files (x86)\DealPlyLive
2013-07-26 14:34 - 2013-07-26 14:34 - 00000000 ____D C:\Program Files (x86)\DealPly
2013-07-26 09:35 - 2013-01-22 23:35 - 00000000 ____D C:\ProgramData\MFAData
2013-07-25 23:31 - 2013-01-18 22:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-07-25 01:07 - 2012-07-26 07:26 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM
2013-07-24 05:45 - 2013-04-01 12:26 - 01873023 _____ C:\WINDOWS\WindowsUpdate.log
2013-07-24 04:29 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\AUInstallAgent
2013-07-22 10:10 - 2013-01-17 23:35 - 00003594 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-833875348-499972116-837255604-1002
2013-07-21 16:56 - 2013-04-05 19:44 - 00002444 _____ C:\WINDOWS\PFRO.log
2013-07-21 16:32 - 2013-07-21 16:32 - 00000005 _____ C:\Users\Bayramoglu\AppData\Roaming\WBPU-TTL.DAT
2013-07-21 16:32 - 2013-07-21 15:32 - 00000322 _____ C:\WINDOWS\Tasks\DSite.job
2013-07-21 15:45 - 2013-07-21 15:45 - 00000000 ____D C:\Users\Bayramoglu\Qtrax
2013-07-21 15:45 - 2013-01-17 23:26 - 00000000 ____D C:\Users\Bayramoglu
2013-07-21 15:41 - 2013-07-21 15:41 - 00003822 _____ C:\WINDOWS\System32\Tasks\QtraxPlayer
2013-07-21 15:37 - 2013-07-21 15:37 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-07-21 15:37 - 2013-07-21 15:37 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-07-21 15:32 - 2013-07-21 15:32 - 00002660 _____ C:\WINDOWS\System32\Tasks\DSite
2013-07-21 15:32 - 2013-07-21 15:32 - 00000000 ____D C:\Users\Bayramoglu\AppData\Roaming\DSite
2013-07-21 01:31 - 2013-07-21 01:28 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-07-21 01:00 - 2012-07-26 07:26 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2013-07-17 02:12 - 2013-07-17 02:11 - 00281248 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-07-17 02:09 - 2012-07-26 07:37 - 00000000 ____D C:\WINDOWS\servicing
2013-07-17 02:05 - 2012-07-26 09:52 - 00000000 ____D C:\Program Files\Windows Journal
2013-07-17 02:05 - 2012-07-26 07:38 - 00000000 ____D C:\WINDOWS\system32\oobe
2013-07-13 04:03 - 2013-01-18 02:08 - 00002154 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-07-13 03:36 - 2013-01-18 00:11 - 00004110 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2013-07-13 03:36 - 2013-01-18 00:11 - 00003874 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2013-07-09 19:57 - 2013-04-07 10:33 - 00000952 _____ C:\Users\Public\Desktop\AVG 2013.lnk
2013-06-28 23:21 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\system32\NDF
2013-06-28 11:30 - 2013-01-22 23:35 - 00000000 ____D C:\Users\BAYRAM~1\AppData\Local\Avg2013
2013-06-28 00:04 - 2013-06-17 18:33 - 00693112 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2013-06-28 00:04 - 2013-06-17 18:33 - 00078200 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2013-06-27 00:46 - 2013-06-27 00:46 - 00248632 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgwfpa.sys
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe
[2013-07-17 03:08] - [2013-06-01 13:34] - 2391280 ____A (Microsoft Corporation) 0E8E6463F81C80AFBED533E0F1F8895D
C:\Windows\SysWOW64\explorer.exe
[2013-07-17 03:08] - [2013-06-01 12:24] - 2106176 ____A (Microsoft Corporation) EAFE46B0292D2BD2467835E2ACF717CC
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys
[2013-07-17 03:08] - [2013-06-01 13:26] - 0327936 ____A (Microsoft Corporation) 78A5BBA3819FFFC62FFEC3E2220D102D
LastRegBack: 2013-07-21 10:00
==================== End Of Log ============================
--- --- ---
--- --- ---
--- --- ---
--- --- ---
--- --- ---
--- --- ---
adition editorFRST Additions Logfile:
Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 26-07-2013
Ran by Bayramoglu at 2013-07-26 17:25:36
Running from C:\Users\Bayramoglu\Downloads
Boot Mode: Normal
==========================================================
==================== Installed Programs =======================
Adobe AIR (x32 Version: 3.2.0.2070)
Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.224)
AMD Accelerated Video Transcoding (Version: 2.00.0002)
AMD APP SDK Runtime (Version: 10.0.938.2)
AMD Catalyst Install Manager (Version: 8.0.881.0)
AMD Fuel (Version: 2012.0806.1156.19437)
AMD VISION Engine Control Center (x32 Version: 2012.0806.1156.19437)
Apple Application Support (x32 Version: 2.3.2)
Apple Mobile Device Support (Version: 6.0.1.3)
Apple Software Update (x32 Version: 2.1.3.127)
AVG 2013 (Version: 13.0.3209)
AVG 2013 (Version: 13.0.3349)
AVG 2013 (Version: 2013.0.3349)
Benutzerhandbuch (x32 Version: 1.0.0.9)
Canon MX360 series MP Drivers
Catalyst Control Center - Branding (x32 Version: 1.00.0000)
Catalyst Control Center Graphics Previews Common (x32 Version: 2012.0806.1156.19437)
Catalyst Control Center InstallProxy (x32 Version: 2012.0806.1156.19437)
Catalyst Control Center Localization All (x32 Version: 2012.0806.1156.19437)
Catalyst Control Center Profiles Mobile (x32 Version: 2012.0806.1156.19437)
CCC Help Chinese Standard (x32 Version: 2012.0806.1155.19437)
CCC Help Chinese Traditional (x32 Version: 2012.0806.1155.19437)
CCC Help Czech (x32 Version: 2012.0806.1155.19437)
CCC Help Danish (x32 Version: 2012.0806.1155.19437)
CCC Help Dutch (x32 Version: 2012.0806.1155.19437)
CCC Help English (x32 Version: 2012.0806.1155.19437)
CCC Help Finnish (x32 Version: 2012.0806.1155.19437)
CCC Help French (x32 Version: 2012.0806.1155.19437)
CCC Help German (x32 Version: 2012.0806.1155.19437)
CCC Help Greek (x32 Version: 2012.0806.1155.19437)
CCC Help Hungarian (x32 Version: 2012.0806.1155.19437)
CCC Help Italian (x32 Version: 2012.0806.1155.19437)
CCC Help Japanese (x32 Version: 2012.0806.1155.19437)
CCC Help Korean (x32 Version: 2012.0806.1155.19437)
CCC Help Norwegian (x32 Version: 2012.0806.1155.19437)
CCC Help Polish (x32 Version: 2012.0806.1155.19437)
CCC Help Portuguese (x32 Version: 2012.0806.1155.19437)
CCC Help Russian (x32 Version: 2012.0806.1155.19437)
CCC Help Spanish (x32 Version: 2012.0806.1155.19437)
CCC Help Swedish (x32 Version: 2012.0806.1155.19437)
CCC Help Thai (x32 Version: 2012.0806.1155.19437)
CCC Help Turkish (x32 Version: 2012.0806.1155.19437)
ccc-utility64 (Version: 2012.0806.1156.19437)
CCleaner (Version: 4.00)
Conexant HD Audio (Version: 8.54.44.50)
Dealply (HKCU)
DealPly (remove only) (x32 Version: 4.8.7.2)
Dolby Advanced Audio v2 (x32 Version: 7.2.8000.16)
dows-Treiberpaket - Lenovo (ACPIVPC) System (06/15/2012 8.1.0.1) (Version: 06/15/2012 8.1.0.1)
Energy Management (x32 Version: 8.0.2.3)
Google Chrome (x32 Version: 28.0.1500.72)
Google Update Helper (x32 Version: 1.3.21.153)
Inbox Toolbar (x32 Version: 2.0.0.61)
Intel AppUp(SM) center (x32 Version: 3.6.1.33057.10)
Internet Manager (x32 Version: 22.001.18.00.748)
iTunes (Version: 11.0.1.12)
Lenovo EasyCamera (x32 Version: 13.12.824.1)
Lenovo OneKey Recovery (Version: 8.0.0.0828)
Lenovo OneKey Recovery (x32 Version: 8.0.0.0828)
Lenovo PowerDVD10 (x32 Version: 10.0.4310.52)
Lenovo YouCam (x32 Version: 4.1.3127)
LyricXeeker (x32)
Microsoft Office (x32 Version: 14.0.6120.5004)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Mozilla Firefox 22.0 (x86 de) (x32 Version: 22.0)
Mozilla Maintenance Service (x32 Version: 22.0)
Optimizer Pro v3.1 (x32 Version: 3.1)
Power2Go (x32 Version: 5.6.0.9109)
PowerXpressHybrid (x32 Version: 1.00.0000)
Qualcomm Atheros Client Installation Program (x32 Version: 10.0)
Realtek Ethernet Controller Driver (x32 Version: 8.3.730.2012)
Realtek USB 2.0 Card Reader (x32 Version: 6.1.8400.39030)
Shared C Run-time for x64 (Version: 10.0.0)
Skype™ 6.6 (x32 Version: 6.6.106)
SugarSync Manager (x32 Version: 1.9.61.90905)
Synaptics Pointing Device Driver (Version: 16.2.10.3)
UserGuide (x32 Version: 1.0.0.9)
Visual Studio 2010 x64 Redistributables (Version: 13.0.0.1)
Web Cake 3.00 (Version: 3.00)
Windows-Treiberpaket - Lenovo (WUDFRd) LenovoVhid (06/19/2012 10.13.29.733) (Version: 06/19/2012 10.13.29.733)
==================== Restore Points =========================
03-07-2013 03:03:37 Geplanter Prüfpunkt
10-07-2013 14:06:35 Geplanter Prüfpunkt
15-07-2013 15:52:40 Windows Update
20-07-2013 23:27:47 Windows Update
==================== Hosts content: ==========================
2012-07-26 07:26 - 2012-07-26 07:26 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {0034B89B-261A-4BE0-A13B-D77E4F2E757A} - System32\Tasks\Microsoft\Windows\WindowsUpdate\AUScheduledInstall
Task: {0A1DA9A1-F320-4E2F-BFC3-1D576C777804} - System32\Tasks\DealPlyLiveUpdateTaskMachineUA => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe [2013-07-26] (DealPly Technologies Ltd)
Task: {0E6606A1-3E30-4154-9E19-5590A40732DB} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program => C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe No File
Task: {10D85952-E3F6-47A1-96CF-5E1C2D874EA6} - System32\Tasks\Microsoft\Windows\SystemRestore\SR => C:\Windows\system32\srtasks.exe [2012-07-26] (Microsoft Corporation)
Task: {13A2AC02-B682-48CC-9155-2E2673580117} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Critical
Task: {17644F17-DC4C-4AC8-9444-7AAA52EB5CDC} - System32\Tasks\Microsoft\Windows\NetCfg\BindingWorkItemQueueHandler
Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => C:\Windows\system32\rundll32.exe [2012-07-26] (Microsoft Corporation)
Task: {1BB73E66-4FA1-46A6-B31D-57B75FD8BC6E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-18] (Google Inc.)
Task: {1DB7C2F1-876C-4F24-AD17-8428211113F9} - System32\Tasks\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents
Task: {214B24F4-FEB4-4C59-AF1F-70136065199C} - System32\Tasks\Microsoft\Windows\Shell\IndexerAutomaticMaintenance
Task: {23700E5C-0E77-499D-908A-415D5C6252F4} - System32\Tasks\Microsoft\Windows\Plug and Play\Device Install Group Policy
Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => C:\Windows\System32\rundll32.exe [2012-07-26] (Microsoft Corporation)
Task: {2C6B9EA8-7F5A-4ABA-BF96-8D352D02A743} - System32\Tasks\Microsoft\Windows\Device Setup\Metadata Refresh
Task: {2E030FA7-3D7C-4E1D-8CFE-56ADB26FD402} - System32\Tasks\Microsoft\Windows\PI\Sqm-Tasks
Task: {3054485A-F517-4E95-9977-4DD827B1E9B3} - System32\Tasks\Microsoft\Windows\WS\Badge Update
Task: {378401BA-A703-444A-A79C-3C47AD2DC5B6} - System32\Tasks\Microsoft\Windows\TaskScheduler\Maintenance Configurator
Task: {3AE164E7-30CD-40BC-9422-3EC7A5618965} - System32\Tasks\Microsoft\Windows\WS\WSTask
Task: {3C490ABD-D849-41AF-9AC4-87DD759B0996} - System32\Tasks\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem
Task: {4073C1B3-6E16-4AA8-B7F3-C6A6D35D5071} - System32\Tasks\Microsoft\Windows\TPM\Tpm-Maintenance
Task: {44B3F1B8-5943-4072-8D8C-A9484676AC44} - System32\Tasks\Microsoft\Windows\Live\Roaming\SynchronizeWithStorage
Task: {4603C7CB-B1C4-4ACE-BCC0-1ECF86BE7ABB} - System32\Tasks\DealPlyLiveUpdateTaskMachineCore => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe [2013-07-26] (DealPly Technologies Ltd)
Task: {483A8F5C-5D26-44B5-B49E-AF6741D1BBEB} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => C:\Windows\System32\MbaeParserTask.exe [2013-06-01] (Microsoft Corporation)
Task: {48EBE759-632B-4020-8CA0-BFDC69486B97} - System32\Tasks\OFFICE2010ACT => C:\ProgramData\Microsoft\Windows\OFFICEICON.vbs [2012-03-08] ()
Task: {4B952129-9AE9-41A3-BE2B-8AD2E06F66B6} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskLogon
Task: {54246547-F7C0-4888-98EE-6B6BF0ED813B} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-11] (Adobe Systems Incorporated)
Task: {5755E746-D7ED-4C20-A472-66C11834CDE4} - System32\Tasks\Microsoft\Windows\TaskScheduler\Manual Maintenance
Task: {5C4EFB77-EFA6-45DF-A373-D795C0725BFF} - System32\Tasks\Microsoft\Windows\Plug and Play\Device Install Reboot Required
Task: {627441F3-8526-4B62-BF9A-1A3EA414E71A} - System32\Tasks\Microsoft\Windows\SpacePort\SpaceAgentTask => C:\Windows\system32\SpaceAgent.exe [2012-07-26] (Microsoft Corporation)
Task: {63A1C69D-4D6D-48FA-B0AE-4997F296EB42} - System32\Tasks\MirageAgent => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [2012-07-27] (CyberLink)
Task: {662B4346-14DF-422A-B890-E5FBBB142FCC} - System32\Tasks\ROC_REG_JAN_DELETE => C:\ProgramData\AVG January 2013 Campaign\ROC.exe [2013-01-17] ()
Task: {6E9DE125-5583-4031-B572-FEE48F25CFFF} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyMonitor => C:\Windows\System32\wpcmon.exe [2012-09-20] (Microsoft Corporation)
Task: {6FDDEA7C-6310-428D-AEB2-54FFC72811EF} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319
Task: {74096F94-B654-4DB0-96F5-3C3408B92FE3} - System32\Tasks\Microsoft\Windows\PI\Secure-Boot-Update
Task: {776A9D6F-9BDF-4D70-B4AD-C3C08BF6F519} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-03-25] (Piriform Ltd)
Task: {7D9A9A1C-499C-40A6-8F8A-5BCC4CC9A87C} - System32\Tasks\Microsoft\Windows\TaskScheduler\Regular Maintenance
Task: {84258B19-1EBC-49CF-8016-E34750C89FEF} - System32\Tasks\Microsoft\Windows\WindowsUpdate\AUSessionConnect
Task: {845CB020-68B5-4C6B-9876-7BEC7B3E27AC} - System32\Tasks\Microsoft\Windows\TaskScheduler\Idle Maintenance
Task: {85F5BE69-2C8C-4AAF-AE3C-1170476923DC} - System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-833875348-499972116-837255604-1002
Task: {87354DAA-66DF-4B41-9346-15958D96E1D2} - System32\Tasks\Microsoft\Windows\FileHistory\File History (maintenance mode)
Task: {921A1D4E-32FB-46D7-B6C0-6F467884074D} - System32\Tasks\Microsoft\Windows\WS\Sync Licenses
Task: {9479EF8E-11D4-41B3-9783-CC65070D592D} - System32\Tasks\Microsoft\Windows\Time Synchronization\ForceSynchronizeTime
Task: {94DCF254-64FB-4C4E-8E12-5F4055C10C2A} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64
Task: {989A7C6D-BE82-4C3C-AF96-6116039E336B} - System32\Tasks\Microsoft\Windows\MemoryDiagnostic\RunFullMemoryDiagnostic
Task: {9E1576B4-33A9-4902-BE8F-2DB19F35512F} - System32\Tasks\DSite => C:\Users\BAYRAM~1\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE No File
Task: {A034C1AD-0AB3-41B0-A5C8-F69EB0B70FC1} - System32\Tasks\Microsoft\Windows\Servicing\StartComponentCleanup
Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => C:\Windows\System32\rundll32.exe [2012-07-26] (Microsoft Corporation)
Task: {A800277E-E202-4492-AD38-3312641CBC04} - System32\Tasks\Microsoft\Windows\Live\Roaming\MaintenanceTask
Task: {AB62FA47-2C99-44B1-A5D0-D4161423BE43} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyRefresh
Task: {AC6259DE-AC59-459E-849E-6ADFFD1ADE63} - System32\Tasks\Microsoft\Windows\Shell\CreateObjectTask
Task: {AEB0B5BD-B9E5-458A-898A-E559BD9EB51B} - System32\Tasks\Microsoft\Windows\SettingSync\BackgroundUploadTask
Task: {AF549BD8-337C-4BF7-8681-36A182E30507} - System32\Tasks\Microsoft\Windows\Chkdsk\ProactiveScan
Task: {BC76AEF7-2CF0-4EB6-B65B-A8803E0B5E12} - System32\Tasks\Microsoft\Windows\AppID\SmartScreenSpecific
Task: {C1ACCD1E-4385-4FB2-B5E4-7F2A57A626A2} - System32\Tasks\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan
Task: {C463FD1E-31C7-4C20-AB65-08E514CA152D} - System32\Tasks\Microsoft\Windows\IME\SQM data sender
Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => C:\Windows\system32\rundll32.exe [2012-07-26] (Microsoft Corporation)
Task: {CD1054FF-8005-4904-8B9C-436EAB1E2021} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskNetwork
Task: {D825323E-C121-4EEA-9DAA-3A8D57FFC359} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {DBCF6E1B-CE0A-441E-B7A5-219C8BE50C65} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Critical
Task: {DECE5921-598D-454B-9A04-B2DE95EFC1B3} - System32\Tasks\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan for Crash Recovery
Task: {E257399A-ED89-4929-9742-F7C0155350A7} - System32\Tasks\Dealply => C:\Users\BAYRAM~1\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.EXE [2013-07-26] ()
Task: {E2C379D3-8995-41E5-A052-D2D25FDB4393} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start => C:\WINDOWS\system32\sc.exe [2012-07-26] (Microsoft Corporation)
Task: {E4DFE66F-E089-4CC3-A70F-957223D565F4} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask
Task: {E68EEE82-8B14-4A3F-AC8F-27D21B0E6533} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-18] (Google Inc.)
Task: {E8DAA09B-DF2A-4951-9134-6FA9587793F9} - System32\Tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers => C:\Windows\System32\drvinst.exe [2012-09-20] (Microsoft Corporation)
Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => C:\Windows\system32\rundll32.exe [2012-07-26] (Microsoft Corporation)
Task: {EC9A3C42-DA61-4687-8D4B-968705955EBB} - System32\Tasks\Microsoft\Windows\WindowsUpdate\AUFirmwareInstall
Task: {ED0C1F69-C3A2-41EA-B8C3-3F0D83A1F6C0} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\BthSQM
Task: {F23F2432-F7E2-47FD-8254-9771B9968032} - System32\Tasks\Lenovo\LSC\Time72Task => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe No File
Task: {F58F3DAC-C95F-4399-B92A-F44770D639F1} - System32\Tasks\LyricXeeker Update => C:\Program Files (x86)\LyriXeeker\LyriXupdate.exe [2013-07-25] (LyriXeeker Tech)
Task: {F599D9B2-64EA-4D5C-BA58-387BC798343E} - System32\Tasks\Lenovo\LSC\RebootCountTask => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe No File
Task: {FF6D0765-BC30-4A23-900D-FF59C21E7698} - System32\Tasks\QtraxPlayer => C:\Program Files (x86)\Microsoft Silverlight\sllauncher.exe [2013-05-13] (Microsoft Corporation)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\Dealply.job => ?
Task: C:\WINDOWS\Tasks\DealPlyLiveUpdateTaskMachineCore.job => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe
Task: C:\WINDOWS\Tasks\DealPlyLiveUpdateTaskMachineUA.job => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe
Task: C:\WINDOWS\Tasks\DSite.job => ?
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\LyricXeeker Update.job => C:\Program Files (x86)\LyriXeeker\LyriXupdate.exe
Task: C:\WINDOWS\Tasks\ROC_REG_JAN_DELETE.job => C:\ProgramData\AVG January 2013 Campaign\ROC.exe
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (07/26/2013 03:34:31 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: UPDATE~1.EXE, Version: 0.0.0.0, Zeitstempel: 0x2a425e19
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000
ID des fehlerhaften Prozesses: 0xc3c
Startzeit der fehlerhaften Anwendung: 0xUPDATE~1.EXE0
Pfad der fehlerhaften Anwendung: UPDATE~1.EXE1
Pfad des fehlerhaften Moduls: UPDATE~1.EXE2
Berichtskennung: UPDATE~1.EXE3
Vollständiger Name des fehlerhaften Pakets: UPDATE~1.EXE4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: UPDATE~1.EXE5
Error: (07/26/2013 02:52:42 PM) (Source: MsiInstaller) (User: Trabzon61)
Description: Product: Skype Click to Call -- Error 1609. An error occurred while applying security settings. Users is not a valid user or group. This could be a problem with the package, or a problem connecting to a domain controller on the network. Check your network connection and click Retry, or Cancel to end the install. Unable to locate the user's SID, system error 1332(NULL)(NULL)(NULL)(NULL)(NULL)
Error: (07/26/2013 02:35:18 PM) (Source: MsiInstaller) (User: Trabzon61)
Description: Product: Google Update Helper -- Error 1316. A network error occurred while attempting to read from the file: C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\GoogleUpdateHelper.msi
Error: (07/25/2013 07:42:49 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: Trabzon61)
Description: Bei der Aktivierung der App „E046963F.LenovoSupport_k1h2ywk1493x8!App“ ist folgender Fehler aufgetreten: -2144927142. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (07/25/2013 07:42:49 PM) (Source: Application Hang) (User: )
Description: Programm Support.exe, Version 1.0.18.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: e54
Startzeit: 01ce895e4ce50fc4
Endzeit: 4294967295
Anwendungspfad: C:\Program Files\WindowsApps\E046963F.LenovoSupport_1.0.18.0_x86__k1h2ywk1493x8\Support.exe
Berichts-ID: 93730445-f551-11e2-beed-20898428dd4c
Vollständiger Name des fehlerhaften Pakets: E046963F.LenovoSupport_1.0.18.0_x86__k1h2ywk1493x8
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: App
Error: (07/25/2013 07:42:41 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: ismagent.exe, Version: 1.14.1.36458, Zeitstempel: 0x4fbe2d9c
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x77d3bda1
ID des fehlerhaften Prozesses: 0xf70
Startzeit der fehlerhaften Anwendung: 0xismagent.exe0
Pfad der fehlerhaften Anwendung: ismagent.exe1
Pfad des fehlerhaften Moduls: ismagent.exe2
Berichtskennung: ismagent.exe3
Vollständiger Name des fehlerhaften Pakets: ismagent.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: ismagent.exe5
Error: (07/25/2013 07:42:30 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: Trabzon61)
Description: Bei der Aktivierung der App „Microsoft.BingNews_8wekyb3d8bbwe!AppexNews“ ist folgender Fehler aufgetreten: -2144927142. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (07/25/2013 07:42:30 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: Trabzon61)
Description: Die App „Microsoft.BingNews_8wekyb3d8bbwe!AppexNews“ wurde nicht innerhalb der vorgesehenen Zeit gestartet.
Error: (07/25/2013 07:42:29 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: Trabzon61)
Description: Die App „E046963F.LenovoSupport_k1h2ywk1493x8!App“ wurde nicht innerhalb der vorgesehenen Zeit gestartet.
Error: (07/25/2013 07:42:30 PM) (Source: Application Hang) (User: )
Description: Programm wwahost.exe, Version 6.2.9200.16420 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: d7c
Startzeit: 01ce895e4ce50fc4
Endzeit: 4294967295
Anwendungspfad: C:\WINDOWS\system32\wwahost.exe
Berichts-ID:
Vollständiger Name des fehlerhaften Pakets: Microsoft.BingNews_1.2.0.135_x64__8wekyb3d8bbwe
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: AppexNews
System errors:
=============
Error: (07/26/2013 03:10:12 PM) (Source: DCOM) (User: Trabzon61)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (07/26/2013 03:10:12 PM) (Source: DCOM) (User: Trabzon61)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (07/26/2013 03:10:08 PM) (Source: DCOM) (User: Trabzon61)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (07/26/2013 03:10:08 PM) (Source: DCOM) (User: Trabzon61)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (07/26/2013 03:10:07 PM) (Source: DCOM) (User: Trabzon61)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (07/26/2013 03:10:07 PM) (Source: DCOM) (User: Trabzon61)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (07/26/2013 03:10:04 PM) (Source: DCOM) (User: Trabzon61)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (07/26/2013 03:10:04 PM) (Source: DCOM) (User: Trabzon61)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (07/26/2013 03:10:03 PM) (Source: DCOM) (User: Trabzon61)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (07/26/2013 03:10:02 PM) (Source: DCOM) (User: Trabzon61)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Microsoft Office Sessions:
=========================
Error: (07/26/2013 03:34:31 PM) (Source: Application Error)(User: )
Description: UPDATE~1.EXE0.0.0.02a425e19unknown0.0.0.000000000c000000500000000c3c01ce8a04cd331f21C:\Users\BAYRAM~1\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.EXEunknown197afcd4-f5f8-11e2-beee-20898428dd4c
Error: (07/26/2013 02:52:42 PM) (Source: MsiInstaller)(User: Trabzon61)
Description: Product: Skype Click to Call -- Error 1609. An error occurred while applying security settings. Users is not a valid user or group. This could be a problem with the package, or a problem connecting to a domain controller on the network. Check your network connection and click Retry, or Cancel to end the install. Unable to locate the user's SID, system error 1332(NULL)(NULL)(NULL)(NULL)(NULL)
Error: (07/26/2013 02:35:18 PM) (Source: MsiInstaller)(User: Trabzon61)
Description: Product: Google Update Helper -- Error 1316. A network error occurred while attempting to read from the file: C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\GoogleUpdateHelper.msi(NULL)(NULL)(NULL)(NULL)(NULL)
Error: (07/25/2013 07:42:49 PM) (Source: Microsoft-Windows-Immersive-Shell)(User: Trabzon61)
Description: E046963F.LenovoSupport_k1h2ywk1493x8!App-2144927142
Error: (07/25/2013 07:42:49 PM) (Source: Application Hang)(User: )
Description: Support.exe1.0.18.0e5401ce895e4ce50fc44294967295C:\Program Files\WindowsApps\E046963F.LenovoSupport_1.0.18.0_x86__k1h2ywk1493x8\Support.exe93730445-f551-11e2-beed-20898428dd4cE046963F.LenovoSupport_1.0.18.0_x86__k1h2ywk1493x8App
Error: (07/25/2013 07:42:41 PM) (Source: Application Error)(User: )
Description: ismagent.exe1.14.1.364584fbe2d9cunknown0.0.0.000000000c000000577d3bda1f7001ce895e4795d071C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exeunknown9a35a7eb-f551-11e2-beed-20898428dd4c
Error: (07/25/2013 07:42:30 PM) (Source: Microsoft-Windows-Immersive-Shell)(User: Trabzon61)
Description: Microsoft.BingNews_8wekyb3d8bbwe!AppexNews-2144927142
Error: (07/25/2013 07:42:30 PM) (Source: Microsoft-Windows-Immersive-Shell)(User: Trabzon61)
Description: Microsoft.BingNews_8wekyb3d8bbwe!AppexNews
Error: (07/25/2013 07:42:29 PM) (Source: Microsoft-Windows-Immersive-Shell)(User: Trabzon61)
Description: E046963F.LenovoSupport_k1h2ywk1493x8!App
Error: (07/25/2013 07:42:30 PM) (Source: Application Hang)(User: )
Description: wwahost.exe6.2.9200.16420d7c01ce895e4ce50fc44294967295C:\WINDOWS\system32\wwahost.exeMicrosoft.BingNews_1.2.0.135_x64__8wekyb3d8bbweAppexNews
==================== Memory info ===========================
Percentage of memory in use: 80%
Total physical RAM: 1606.25 MB
Available physical RAM: 313.36 MB
Total Pagefile: 2502.25 MB
Available Pagefile: 475.8 MB
Total Virtual: 8192 MB
Available Virtual: 8191.77 MB
==================== Drives ================================
Drive c: (Windows8_OS) (Fixed) (Total:250.76 GB) (Free:214.99 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:23.26 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 298 GB) (Disk ID: F5513EA5)
Partition: GPT Partition Type
==================== End Of Log ============================
--- --- ---
es hatte weiter gescannt und dann kam beides nochmal
first editor
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-07-2013
Ran by Bayramoglu (administrator) on 26-07-2013 17:26:35
Running from C:\Users\Bayramoglu\Downloads
Windows 8 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AVG Technologies CZ, s.r.o.) C:\PROGRA~2\AVG\AVG2013\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
(AMD) C:\WINDOWS\system32\atiesrxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
(Conexant Systems Inc.) C:\WINDOWS\system32\CxAudMsg64.exe
() C:\ProgramData\DatacardService\HWDeviceService64.exe
(Microsoft Corporation) C:\WINDOWS\system32\dashost.exe
() C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgemca.exe
(cake bake) C:\Program Files (x86)\Web Cake\WebCakeDesktop.Updater.exe
(AMD) C:\WINDOWS\system32\atieclxx.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Bake Cake) C:\Users\Bayramoglu\AppData\Roaming\Web Cake\WebCakeDesktop.exe
(Vimicro) C:\Program Files (x86)\USB Camera\VM331STI.EXE
(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe
(Inbox.com, Inc.) C:\Program Files (x86)\Inbox Toolbar\Inbox.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgui.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SmartAudio] - C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [cAudioFilterAgent] - C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [887968 2012-06-14] (Conexant Systems, Inc.)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-14] (Synaptics Incorporated)
HKLM\...\Run: [Energy Management] - C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17079376 2012-12-15] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] - C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [191568 2012-12-15] (Lenovo(beijing) Limited)
HKCU\...\Run: [Optimizer Pro] - C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe [135672 2013-06-07] (PC Utilities Pro)
HKCU\...\Run: [WebCake Desktop] - C:\Users\Bayramoglu\AppData\Roaming\Web Cake\WebCakeDesktop.exe [52504 2013-07-26] (Bake Cake)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.)
MountPoints2: F - "F:\AutoRun.exe"
MountPoints2: {eab668fe-60eb-11e2-be70-806e6f6e6963} - "F:\AutoRun.exe"
MountPoints2: {eab66ae7-60eb-11e2-be70-2016d812b098} - "F:\AutoRun.exe"
MountPoints2: {f52d4fac-611a-11e2-be71-2016d812b098} - "F:\AutoRun.exe"
HKLM-x32\...\Run: [331BigDog] - C:\Program Files (x86)\USB Camera\VM331STI.EXE [548864 2012-05-02] (Vimicro)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] - C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [508656 2012-07-25] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [YouCam Mirage] - C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2012-07-27] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] - C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [167024 2012-07-27] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GShortCut] - C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [217088 2012-04-18] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.)
HKLM-x32\...\Run: [Intel AppUp(SM) center] - C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-12] (Intel Corporation)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-11-28] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152544 2012-12-12] (Apple Inc.)
HKLM-x32\...\Run: [InboxToolbar] - C:\Program Files (x86)\Inbox Toolbar\Inbox.exe [1713288 2013-03-18] (Inbox.com, Inc.)
HKLM-x32\...\Run: [AVG_UI] - C:\Program Files (x86)\AVG\AVG2013\avgui.exe [4408368 2013-04-29] (AVG Technologies CZ, s.r.o.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
SearchScopes: HKLM - DefaultScope {68D5157B-6C94-42E3-B722-0047BB52E691} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS
SearchScopes: HKLM - {68D5157B-6C94-42E3-B722-0047BB52E691} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS
SearchScopes: HKLM-x32 - DefaultScope {68D5157B-6C94-42E3-B722-0047BB52E691} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS
SearchScopes: HKLM-x32 - {68D5157B-6C94-42E3-B722-0047BB52E691} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS
SearchScopes: HKCU - DefaultScope {68D5157B-6C94-42E3-B722-0047BB52E691} URL =
SearchScopes: HKCU - {68D5157B-6C94-42E3-B722-0047BB52E691} URL =
BHO-x32: LyricXeeker - {17E58097-6CA5-448B-830F-2A19678248FB} - C:\Program Files (x86)\LyriXeeker\125.dll (LyriXeeker Tech)
BHO-x32: WebCake - {2A5A2A90-3B30-4E6E-A955-2F232C6EF517} - C:\Program Files (x86)\Web Cake\WebCakeIEClient.dll (Web Cake LLC)
BHO-x32: DealPly Shopping - {ae48ed75-5a56-4c5f-bbce-6f1ac3875f66} - C:\Program Files (x86)\DealPly\DealPlyIE.dll (DealPly)
Handler: inbox - {37540F19-DD4C-478B-B2DF-C19281BCAF27} - No File
Handler-x32: inbox - {37540F19-DD4C-478B-B2DF-C19281BCAF27} - C:\PROGRA~2\INBOXT~1\Inbox.dll (Inbox.com, Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{9091E84A-8EBD-4154-B5AC-3D46B218DAA3}: [NameServer]10.74.210.210 10.74.210.211
Tcpip\..\Interfaces\{A4F9BB2B-59B3-4BF7-85FB-A7AC0D4935CE}: [NameServer]10.74.210.210 10.74.210.211
FireFox:
========
FF ProfilePath: C:\Users\Bayramoglu\AppData\Roaming\Mozilla\Firefox\Profiles\45q8jsx6.default
FF user.js: detected! => C:\Users\Bayramoglu\AppData\Roaming\Mozilla\Firefox\Profiles\45q8jsx6.default\user.js
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @tools.dpliveupdate.com/DealPlyLive Update;version=3 - C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\npGoogleUpdate3.dll (DealPly Technologies Ltd)
FF Plugin-x32: @tools.dpliveupdate.com/DealPlyLive Update;version=9 - C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\npGoogleUpdate3.dll (DealPly Technologies Ltd)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Extension: WebCake - C:\Users\Bayramoglu\AppData\Roaming\Mozilla\Firefox\Profiles\45q8jsx6.default\Extensions\plugin@getwebcake.com
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM-x32\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] C:\Program Files\T-Mobile\InternetManager_H\OCx64\addon
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] C:\Program Files\McAfee\MSK
FF HKCU\...\Firefox\Extensions: [lyrix@lyrixeeker.co] C:\Program Files (x86)\LyriXeeker\125.xpi
FF Extension: No Name - C:\Program Files (x86)\LyriXeeker\125.xpi
Chrome:
=======
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.72\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.72\pdf.dll ()
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll No File
CHR Extension: (Google Docs) - C:\Users\BAYRAM~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\BAYRAM~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (Inbox Toolbar) - C:\Users\BAYRAM~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apgjagobplilmcdfelodhgefiidomnfl\1.0.0.9_0
CHR Extension: (YouTube) - C:\Users\BAYRAM~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\BAYRAM~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Web Cake) - C:\Users\BAYRAM~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjoijdanhaiflhibkljeklcghcmmfffh\1.0.3_0
CHR Extension: (DealPly Shopping) - C:\Users\BAYRAM~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\mphpbdjcljebbcnfopfngmfdackbbdgf\3.5.0.0_0
CHR Extension: (LyricXeeker) - C:\Users\BAYRAM~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\odnofacmifkjndflfmmplhckcbfjckhj\1.125_0
CHR Extension: (Gmail) - C:\Users\BAYRAM~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM-x32\...\Chrome\Extension: [apgjagobplilmcdfelodhgefiidomnfl] - C:\Program Files (x86)\Inbox Toolbar\Chrome\ibxtoolbar_chr.crx
CHR HKLM-x32\...\Chrome\Extension: [fjoijdanhaiflhibkljeklcghcmmfffh] - C:\Program Files (x86)\Web Cake\WebCakeLayers.crx
CHR HKLM-x32\...\Chrome\Extension: [odnofacmifkjndflfmmplhckcbfjckhj] - C:\Program Files (x86)\LyriXeeker\125.crx
==================== Services (Whitelisted) =================
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-08-06] (Advanced Micro Devices, Inc.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [4937264 2013-05-14] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [283136 2013-04-18] (AVG Technologies CZ, s.r.o.)
R2 CxAudMsg; C:\WINDOWS\system32\CxAudMsg64.exe [201376 2012-06-08] (Conexant Systems Inc.)
S2 dealplylive; C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe [148000 2013-07-26] (DealPly Technologies Ltd)
S3 dealplylivem; C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe [148000 2013-07-26] (DealPly Technologies Ltd)
R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [344928 2011-01-28] ()
S2 Internet Manager. RunOuc; C:\Program Files (x86)\T-Mobile\InternetManager_H\UpdateDog\ouc.exe [224096 2013-01-17] ()
R2 WebCakeUpdater; C:\Program Files (x86)\Web Cake\WebCakeDesktop.Updater.exe [50968 2013-07-26] (cake bake)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14920 2013-01-29] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [20912 2012-10-26] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdrivera.sys [246072 2013-03-29] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [71480 2013-02-08] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\system32\DRIVERS\avgldx64.sys [206136 2013-02-08] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [311096 2013-02-08] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [116536 2013-02-08] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [45880 2013-02-08] (AVG Technologies CZ, s.r.o.)
R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [248632 2013-06-27] (AVG Technologies CZ, s.r.o.)
R0 BMLoad; C:\Windows\System32\drivers\BMLoad.sys [16512 2013-01-17] (Bytemobile, Inc.)
S3 huawei_wwanecm; C:\Windows\system32\DRIVERS\ew_juwwanecm.sys [212992 2013-01-17] (Huawei Technologies Co., Ltd.)
R1 tcpipBM; C:\WINDOWS\system32\drivers\tcpipBM.sys [39552 2013-01-17] (Bytemobile, Inc.)
R1 tcpipBM; C:\WINDOWS\system32\drivers\tcpipBM.sys [39552 2013-01-17] (Bytemobile, Inc.)
R3 vm331avs; C:\Windows\System32\Drivers\vm331avs.sys [975104 2012-08-24] (Vimicro Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-07-26 17:25 - 2013-07-26 17:26 - 00025260 _____ C:\Users\Bayramoglu\Downloads\Addition.txt
2013-07-26 17:23 - 2013-07-26 17:23 - 00000000 ____D C:\FRST
2013-07-26 17:21 - 2013-07-26 17:21 - 01779893 _____ (Farbar) C:\Users\Bayramoglu\Downloads\FRST64.exe
2013-07-26 17:20 - 2013-07-26 17:20 - 01220112 _____ (Farbar) C:\Users\Bayramoglu\Downloads\FRST.exe
2013-07-26 14:51 - 2013-07-26 15:39 - 00000000 ____D C:\Users\Bayramoglu\AppData\Roaming\Skype
2013-07-26 14:51 - 2013-07-26 14:51 - 00002517 _____ C:\Users\Public\Desktop\Skype.lnk
2013-07-26 14:51 - 2013-07-26 14:51 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-07-26 14:50 - 2013-07-26 14:51 - 00000000 ____D C:\ProgramData\Skype
2013-07-26 14:49 - 2013-07-26 14:50 - 31954536 _____ (Skype Technologies S.A.) C:\Users\Bayramoglu\Downloads\SkypeSetup66Full.exe
2013-07-26 14:36 - 2013-07-26 15:12 - 00000000 ____D C:\Users\Bayramoglu\AppData\Roaming\Web Cake
2013-07-26 14:36 - 2013-07-26 14:37 - 00000000 ____D C:\Program Files (x86)\Web Cake
2013-07-26 14:35 - 2013-07-26 16:40 - 00000934 _____ C:\WINDOWS\Tasks\DealPlyLiveUpdateTaskMachineUA.job
2013-07-26 14:35 - 2013-07-26 15:10 - 00000930 _____ C:\WINDOWS\Tasks\DealPlyLiveUpdateTaskMachineCore.job
2013-07-26 14:35 - 2013-07-26 14:35 - 00003906 _____ C:\WINDOWS\System32\Tasks\DealPlyLiveUpdateTaskMachineUA
2013-07-26 14:35 - 2013-07-26 14:35 - 00003670 _____ C:\WINDOWS\System32\Tasks\DealPlyLiveUpdateTaskMachineCore
2013-07-26 14:34 - 2013-07-26 16:34 - 00000326 _____ C:\WINDOWS\Tasks\Dealply.job
2013-07-26 14:34 - 2013-07-26 15:10 - 00000418 _____ C:\WINDOWS\Tasks\LyricXeeker Update.job
2013-07-26 14:34 - 2013-07-26 14:36 - 20586496 _____ C:\Users\Bayramoglu\Downloads\SkypeSetup [1].exe
2013-07-26 14:34 - 2013-07-26 14:34 - 00003068 _____ C:\WINDOWS\System32\Tasks\LyricXeeker Update
2013-07-26 14:34 - 2013-07-26 14:34 - 00002664 _____ C:\WINDOWS\System32\Tasks\Dealply
2013-07-26 14:34 - 2013-07-26 14:34 - 00001029 _____ C:\Users\Bayramoglu\Desktop\Optimizer Pro.lnk
2013-07-26 14:34 - 2013-07-26 14:34 - 00000000 ____D C:\Users\Bayramoglu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly
2013-07-26 14:34 - 2013-07-26 14:34 - 00000000 ____D C:\Users\Bayramoglu\AppData\Roaming\Dealply
2013-07-26 14:34 - 2013-07-26 14:34 - 00000000 ____D C:\Users\BAYRAM~1\AppData\Local\DealPlyLive
2013-07-26 14:34 - 2013-07-26 14:34 - 00000000 ____D C:\ProgramData\DealPlyLive
2013-07-26 14:34 - 2013-07-26 14:34 - 00000000 ____D C:\Program Files (x86)\Optimizer Pro
2013-07-26 14:34 - 2013-07-26 14:34 - 00000000 ____D C:\Program Files (x86)\LyriXeeker
2013-07-26 14:34 - 2013-07-26 14:34 - 00000000 ____D C:\Program Files (x86)\DealPlyLive
2013-07-26 14:34 - 2013-07-26 14:34 - 00000000 ____D C:\Program Files (x86)\DealPly
2013-07-21 16:32 - 2013-07-21 16:32 - 00000005 _____ C:\Users\Bayramoglu\AppData\Roaming\WBPU-TTL.DAT
2013-07-21 15:45 - 2013-07-21 15:45 - 00000000 ____D C:\Users\Bayramoglu\Qtrax
2013-07-21 15:41 - 2013-07-21 15:41 - 00003822 _____ C:\WINDOWS\System32\Tasks\QtraxPlayer
2013-07-21 15:37 - 2013-07-21 15:37 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-07-21 15:37 - 2013-07-21 15:37 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-07-21 15:32 - 2013-07-21 16:32 - 00000322 _____ C:\WINDOWS\Tasks\DSite.job
2013-07-21 15:32 - 2013-07-21 15:32 - 00002660 _____ C:\WINDOWS\System32\Tasks\DSite
2013-07-21 15:32 - 2013-07-21 15:32 - 00000000 ____D C:\Users\Bayramoglu\AppData\Roaming\DSite
2013-07-21 01:28 - 2013-07-21 01:31 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-07-17 03:09 - 2013-06-01 11:20 - 02219520 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2013-07-17 03:08 - 2013-06-01 13:34 - 02391280 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2013-07-17 03:08 - 2013-06-01 13:33 - 02233600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2013-07-17 03:08 - 2013-06-01 13:26 - 06987008 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2013-07-17 03:08 - 2013-06-01 13:26 - 00327936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys
2013-07-17 03:08 - 2013-06-01 12:24 - 02106176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2013-07-17 03:08 - 2013-06-01 11:24 - 01453568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2013-07-17 03:08 - 2013-06-01 11:23 - 01842176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2013-07-17 03:08 - 2013-06-01 11:21 - 00729600 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2013-07-17 03:08 - 2013-06-01 11:20 - 01527808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2013-07-17 03:08 - 2013-05-25 00:09 - 01403296 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2013-07-17 03:07 - 2013-06-01 13:54 - 00194816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2013-07-17 03:07 - 2013-06-01 13:54 - 00125184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2013-07-17 03:07 - 2013-06-01 13:29 - 00337152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2013-07-17 03:07 - 2013-06-01 13:29 - 00213248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UCX01000.SYS
2013-07-17 03:07 - 2013-06-01 11:25 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsGdiConverter.dll
2013-07-17 03:07 - 2013-06-01 11:25 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll
2013-07-17 03:07 - 2013-06-01 11:24 - 00850944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2013-07-17 03:07 - 2013-06-01 11:24 - 00493056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mscms.dll
2013-07-17 03:07 - 2013-06-01 11:23 - 00680960 _____ (Microsoft Corporation) C:\WINDOWS\system32\vds.exe
2013-07-17 03:07 - 2013-06-01 11:22 - 00523264 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsGdiConverter.dll
2013-07-17 03:07 - 2013-06-01 11:22 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2013-07-17 03:07 - 2013-06-01 11:22 - 00190976 _____ (Microsoft Corporation) C:\WINDOWS\system32\vdsutil.dll
2013-07-17 03:07 - 2013-06-01 11:22 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeParserTask.exe
2013-07-17 03:07 - 2013-06-01 11:21 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
2013-07-17 03:07 - 2013-06-01 11:20 - 01048576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2013-07-17 03:07 - 2013-06-01 11:20 - 00583168 _____ (Microsoft Corporation) C:\WINDOWS\system32\mscms.dll
2013-07-17 03:07 - 2013-06-01 11:19 - 00785408 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2013-07-17 03:07 - 2013-06-01 11:19 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSetupManager.dll
2013-07-17 03:07 - 2013-06-01 05:08 - 00037632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthAvrcpTg.sys
2013-07-17 03:07 - 2013-05-25 00:09 - 01271584 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2013-07-17 03:07 - 2013-05-25 00:09 - 01217352 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2013-07-17 03:07 - 2013-05-25 00:09 - 01093904 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2013-07-17 03:07 - 2013-05-20 02:08 - 00386642 _____ C:\WINDOWS\system32\ApnDatabase.xml
2013-07-17 03:06 - 2013-06-17 00:41 - 00997632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2013-07-17 02:11 - 2013-07-17 02:12 - 00281248 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-07-16 00:32 - 2013-05-16 00:35 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\tssdisai.dll
2013-07-15 17:31 - 2013-05-31 01:14 - 04036096 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2013-07-15 17:30 - 2013-06-01 11:25 - 00496640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll
2013-07-15 17:30 - 2013-06-01 11:21 - 00595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll
2013-07-15 17:29 - 2013-04-12 00:30 - 01421312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2013-07-15 17:29 - 2013-04-12 00:22 - 01838080 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2013-07-15 17:28 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2013-07-15 17:28 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2013-07-15 17:28 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2013-07-15 17:28 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2013-07-15 17:28 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2013-07-15 17:27 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2013-07-15 17:27 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2013-07-15 17:27 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2013-07-15 17:27 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2013-07-15 17:27 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2013-07-15 17:27 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2013-07-15 17:27 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2013-07-15 17:27 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2013-07-15 17:27 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2013-07-15 17:27 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2013-07-15 17:27 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2013-07-15 17:27 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2013-07-15 17:24 - 2013-05-04 08:59 - 02842112 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVDECOD.DLL
2013-07-15 17:24 - 2013-05-04 06:57 - 02620928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVDECOD.DLL
2013-06-27 00:46 - 2013-06-27 00:46 - 00248632 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgwfpa.sys
==================== One Month Modified Files and Folders =======
2013-07-26 17:27 - 2013-01-22 23:35 - 00000000 ____D C:\ProgramData\MFAData
2013-07-26 17:26 - 2013-07-26 17:25 - 00025260 _____ C:\Users\Bayramoglu\Downloads\Addition.txt
2013-07-26 17:23 - 2013-07-26 17:23 - 00000000 ____D C:\FRST
2013-07-26 17:21 - 2013-07-26 17:21 - 01779893 _____ (Farbar) C:\Users\Bayramoglu\Downloads\FRST64.exe
2013-07-26 17:20 - 2013-07-26 17:20 - 01220112 _____ (Farbar) C:\Users\Bayramoglu\Downloads\FRST.exe
2013-07-26 17:00 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\system32\sru
2013-07-26 16:51 - 2013-04-07 21:32 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-07-26 16:41 - 2013-01-18 00:11 - 00001138 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-26 16:40 - 2013-07-26 14:35 - 00000934 _____ C:\WINDOWS\Tasks\DealPlyLiveUpdateTaskMachineUA.job
2013-07-26 16:34 - 2013-07-26 14:34 - 00000326 _____ C:\WINDOWS\Tasks\Dealply.job
2013-07-26 16:31 - 2012-12-15 20:43 - 00753134 _____ C:\WINDOWS\system32\perfh007.dat
2013-07-26 16:31 - 2012-12-15 20:43 - 00155826 _____ C:\WINDOWS\system32\perfc007.dat
2013-07-26 16:31 - 2012-07-26 09:28 - 01745416 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-07-26 15:39 - 2013-07-26 14:51 - 00000000 ____D C:\Users\Bayramoglu\AppData\Roaming\Skype
2013-07-26 15:12 - 2013-07-26 14:36 - 00000000 ____D C:\Users\Bayramoglu\AppData\Roaming\Web Cake
2013-07-26 15:10 - 2013-07-26 14:35 - 00000930 _____ C:\WINDOWS\Tasks\DealPlyLiveUpdateTaskMachineCore.job
2013-07-26 15:10 - 2013-07-26 14:34 - 00000418 _____ C:\WINDOWS\Tasks\LyricXeeker Update.job
2013-07-26 15:10 - 2013-01-18 00:11 - 00001134 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-26 14:51 - 2013-07-26 14:51 - 00002517 _____ C:\Users\Public\Desktop\Skype.lnk
2013-07-26 14:51 - 2013-07-26 14:51 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-07-26 14:51 - 2013-07-26 14:50 - 00000000 ____D C:\ProgramData\Skype
2013-07-26 14:50 - 2013-07-26 14:49 - 31954536 _____ (Skype Technologies S.A.) C:\Users\Bayramoglu\Downloads\SkypeSetup66Full.exe
2013-07-26 14:42 - 2013-01-18 01:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-07-26 14:42 - 2012-07-26 09:22 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-07-26 14:37 - 2013-07-26 14:36 - 00000000 ____D C:\Program Files (x86)\Web Cake
2013-07-26 14:36 - 2013-07-26 14:34 - 20586496 _____ C:\Users\Bayramoglu\Downloads\SkypeSetup [1].exe
2013-07-26 14:35 - 2013-07-26 14:35 - 00003906 _____ C:\WINDOWS\System32\Tasks\DealPlyLiveUpdateTaskMachineUA
2013-07-26 14:35 - 2013-07-26 14:35 - 00003670 _____ C:\WINDOWS\System32\Tasks\DealPlyLiveUpdateTaskMachineCore
2013-07-26 14:34 - 2013-07-26 14:34 - 00003068 _____ C:\WINDOWS\System32\Tasks\LyricXeeker Update
2013-07-26 14:34 - 2013-07-26 14:34 - 00002664 _____ C:\WINDOWS\System32\Tasks\Dealply
2013-07-26 14:34 - 2013-07-26 14:34 - 00001029 _____ C:\Users\Bayramoglu\Desktop\Optimizer Pro.lnk
2013-07-26 14:34 - 2013-07-26 14:34 - 00000000 ____D C:\Users\Bayramoglu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly
2013-07-26 14:34 - 2013-07-26 14:34 - 00000000 ____D C:\Users\Bayramoglu\AppData\Roaming\Dealply
2013-07-26 14:34 - 2013-07-26 14:34 - 00000000 ____D C:\Users\BAYRAM~1\AppData\Local\DealPlyLive
2013-07-26 14:34 - 2013-07-26 14:34 - 00000000 ____D C:\ProgramData\DealPlyLive
2013-07-26 14:34 - 2013-07-26 14:34 - 00000000 ____D C:\Program Files (x86)\Optimizer Pro
2013-07-26 14:34 - 2013-07-26 14:34 - 00000000 ____D C:\Program Files (x86)\LyriXeeker
2013-07-26 14:34 - 2013-07-26 14:34 - 00000000 ____D C:\Program Files (x86)\DealPlyLive
2013-07-26 14:34 - 2013-07-26 14:34 - 00000000 ____D C:\Program Files (x86)\DealPly
2013-07-25 23:31 - 2013-01-18 22:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-07-25 01:07 - 2012-07-26 07:26 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM
2013-07-24 05:45 - 2013-04-01 12:26 - 01873023 _____ C:\WINDOWS\WindowsUpdate.log
2013-07-24 04:29 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\AUInstallAgent
2013-07-22 10:10 - 2013-01-17 23:35 - 00003594 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-833875348-499972116-837255604-1002
2013-07-21 16:56 - 2013-04-05 19:44 - 00002444 _____ C:\WINDOWS\PFRO.log
2013-07-21 16:32 - 2013-07-21 16:32 - 00000005 _____ C:\Users\Bayramoglu\AppData\Roaming\WBPU-TTL.DAT
2013-07-21 16:32 - 2013-07-21 15:32 - 00000322 _____ C:\WINDOWS\Tasks\DSite.job
2013-07-21 15:45 - 2013-07-21 15:45 - 00000000 ____D C:\Users\Bayramoglu\Qtrax
2013-07-21 15:45 - 2013-01-17 23:26 - 00000000 ____D C:\Users\Bayramoglu
2013-07-21 15:41 - 2013-07-21 15:41 - 00003822 _____ C:\WINDOWS\System32\Tasks\QtraxPlayer
2013-07-21 15:37 - 2013-07-21 15:37 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-07-21 15:37 - 2013-07-21 15:37 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-07-21 15:32 - 2013-07-21 15:32 - 00002660 _____ C:\WINDOWS\System32\Tasks\DSite
2013-07-21 15:32 - 2013-07-21 15:32 - 00000000 ____D C:\Users\Bayramoglu\AppData\Roaming\DSite
2013-07-21 01:31 - 2013-07-21 01:28 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-07-21 01:00 - 2012-07-26 07:26 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2013-07-17 02:12 - 2013-07-17 02:11 - 00281248 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-07-17 02:09 - 2012-07-26 07:37 - 00000000 ____D C:\WINDOWS\servicing
2013-07-17 02:05 - 2012-07-26 09:52 - 00000000 ____D C:\Program Files\Windows Journal
2013-07-17 02:05 - 2012-07-26 07:38 - 00000000 ____D C:\WINDOWS\system32\oobe
2013-07-13 04:03 - 2013-01-18 02:08 - 00002154 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-07-13 03:36 - 2013-01-18 00:11 - 00004110 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2013-07-13 03:36 - 2013-01-18 00:11 - 00003874 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2013-07-09 19:57 - 2013-04-07 10:33 - 00000952 _____ C:\Users\Public\Desktop\AVG 2013.lnk
2013-06-28 23:21 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\system32\NDF
2013-06-28 11:30 - 2013-01-22 23:35 - 00000000 ____D C:\Users\BAYRAM~1\AppData\Local\Avg2013
2013-06-28 00:04 - 2013-06-17 18:33 - 00693112 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2013-06-28 00:04 - 2013-06-17 18:33 - 00078200 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2013-06-27 00:46 - 2013-06-27 00:46 - 00248632 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgwfpa.sys
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe
[2013-07-17 03:08] - [2013-06-01 13:34] - 2391280 ____A (Microsoft Corporation) 0E8E6463F81C80AFBED533E0F1F8895D
C:\Windows\SysWOW64\explorer.exe
[2013-07-17 03:08] - [2013-06-01 12:24] - 2106176 ____A (Microsoft Corporation) EAFE46B0292D2BD2467835E2ACF717CC
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys
[2013-07-17 03:08] - [2013-06-01 13:26] - 0327936 ____A (Microsoft Corporation) 78A5BBA3819FFFC62FFEC3E2220D102D
LastRegBack: 2013-07-21 10:00
==================== End Of Log ============================
--- --- ---
--- --- ---
--- --- ---
--- --- ---
first adition
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 26-07-2013
Ran by Bayramoglu at 2013-07-26 17:28:51
Running from C:\Users\Bayramoglu\Downloads
Boot Mode: Normal
==========================================================
==================== Installed Programs =======================
Adobe AIR (x32 Version: 3.2.0.2070)
Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.224)
AMD Accelerated Video Transcoding (Version: 2.00.0002)
AMD APP SDK Runtime (Version: 10.0.938.2)
AMD Catalyst Install Manager (Version: 8.0.881.0)
AMD Fuel (Version: 2012.0806.1156.19437)
AMD VISION Engine Control Center (x32 Version: 2012.0806.1156.19437)
Apple Application Support (x32 Version: 2.3.2)
Apple Mobile Device Support (Version: 6.0.1.3)
Apple Software Update (x32 Version: 2.1.3.127)
AVG 2013 (Version: 13.0.3209)
AVG 2013 (Version: 13.0.3349)
AVG 2013 (Version: 2013.0.3349)
Benutzerhandbuch (x32 Version: 1.0.0.9)
Canon MX360 series MP Drivers
Catalyst Control Center - Branding (x32 Version: 1.00.0000)
Catalyst Control Center Graphics Previews Common (x32 Version: 2012.0806.1156.19437)
Catalyst Control Center InstallProxy (x32 Version: 2012.0806.1156.19437)
Catalyst Control Center Localization All (x32 Version: 2012.0806.1156.19437)
Catalyst Control Center Profiles Mobile (x32 Version: 2012.0806.1156.19437)
CCC Help Chinese Standard (x32 Version: 2012.0806.1155.19437)
CCC Help Chinese Traditional (x32 Version: 2012.0806.1155.19437)
CCC Help Czech (x32 Version: 2012.0806.1155.19437)
CCC Help Danish (x32 Version: 2012.0806.1155.19437)
CCC Help Dutch (x32 Version: 2012.0806.1155.19437)
CCC Help English (x32 Version: 2012.0806.1155.19437)
CCC Help Finnish (x32 Version: 2012.0806.1155.19437)
CCC Help French (x32 Version: 2012.0806.1155.19437)
CCC Help German (x32 Version: 2012.0806.1155.19437)
CCC Help Greek (x32 Version: 2012.0806.1155.19437)
CCC Help Hungarian (x32 Version: 2012.0806.1155.19437)
CCC Help Italian (x32 Version: 2012.0806.1155.19437)
CCC Help Japanese (x32 Version: 2012.0806.1155.19437)
CCC Help Korean (x32 Version: 2012.0806.1155.19437)
CCC Help Norwegian (x32 Version: 2012.0806.1155.19437)
CCC Help Polish (x32 Version: 2012.0806.1155.19437)
CCC Help Portuguese (x32 Version: 2012.0806.1155.19437)
CCC Help Russian (x32 Version: 2012.0806.1155.19437)
CCC Help Spanish (x32 Version: 2012.0806.1155.19437)
CCC Help Swedish (x32 Version: 2012.0806.1155.19437)
CCC Help Thai (x32 Version: 2012.0806.1155.19437)
CCC Help Turkish (x32 Version: 2012.0806.1155.19437)
ccc-utility64 (Version: 2012.0806.1156.19437)
CCleaner (Version: 4.00)
Conexant HD Audio (Version: 8.54.44.50)
Dealply (HKCU)
DealPly (remove only) (x32 Version: 4.8.7.2)
Dolby Advanced Audio v2 (x32 Version: 7.2.8000.16)
dows-Treiberpaket - Lenovo (ACPIVPC) System (06/15/2012 8.1.0.1) (Version: 06/15/2012 8.1.0.1)
Energy Management (x32 Version: 8.0.2.3)
Google Chrome (x32 Version: 28.0.1500.72)
Google Update Helper (x32 Version: 1.3.21.153)
Inbox Toolbar (x32 Version: 2.0.0.61)
Intel AppUp(SM) center (x32 Version: 3.6.1.33057.10)
Internet Manager (x32 Version: 22.001.18.00.748)
iTunes (Version: 11.0.1.12)
Lenovo EasyCamera (x32 Version: 13.12.824.1)
Lenovo OneKey Recovery (Version: 8.0.0.0828)
Lenovo OneKey Recovery (x32 Version: 8.0.0.0828)
Lenovo PowerDVD10 (x32 Version: 10.0.4310.52)
Lenovo YouCam (x32 Version: 4.1.3127)
LyricXeeker (x32)
Microsoft Office (x32 Version: 14.0.6120.5004)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Mozilla Firefox 22.0 (x86 de) (x32 Version: 22.0)
Mozilla Maintenance Service (x32 Version: 22.0)
Optimizer Pro v3.1 (x32 Version: 3.1)
Power2Go (x32 Version: 5.6.0.9109)
PowerXpressHybrid (x32 Version: 1.00.0000)
Qualcomm Atheros Client Installation Program (x32 Version: 10.0)
Realtek Ethernet Controller Driver (x32 Version: 8.3.730.2012)
Realtek USB 2.0 Card Reader (x32 Version: 6.1.8400.39030)
Shared C Run-time for x64 (Version: 10.0.0)
Skype™ 6.6 (x32 Version: 6.6.106)
SugarSync Manager (x32 Version: 1.9.61.90905)
Synaptics Pointing Device Driver (Version: 16.2.10.3)
UserGuide (x32 Version: 1.0.0.9)
Visual Studio 2010 x64 Redistributables (Version: 13.0.0.1)
Web Cake 3.00 (Version: 3.00)
Windows-Treiberpaket - Lenovo (WUDFRd) LenovoVhid (06/19/2012 10.13.29.733) (Version: 06/19/2012 10.13.29.733)
==================== Restore Points =========================
03-07-2013 03:03:37 Geplanter Prüfpunkt
10-07-2013 14:06:35 Geplanter Prüfpunkt
15-07-2013 15:52:40 Windows Update
20-07-2013 23:27:47 Windows Update
==================== Hosts content: ==========================
2012-07-26 07:26 - 2012-07-26 07:26 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {0034B89B-261A-4BE0-A13B-D77E4F2E757A} - System32\Tasks\Microsoft\Windows\WindowsUpdate\AUScheduledInstall
Task: {0A1DA9A1-F320-4E2F-BFC3-1D576C777804} - System32\Tasks\DealPlyLiveUpdateTaskMachineUA => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe [2013-07-26] (DealPly Technologies Ltd)
Task: {0E6606A1-3E30-4154-9E19-5590A40732DB} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program => C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe No File
Task: {10D85952-E3F6-47A1-96CF-5E1C2D874EA6} - System32\Tasks\Microsoft\Windows\SystemRestore\SR => C:\Windows\system32\srtasks.exe [2012-07-26] (Microsoft Corporation)
Task: {13A2AC02-B682-48CC-9155-2E2673580117} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Critical
Task: {17644F17-DC4C-4AC8-9444-7AAA52EB5CDC} - System32\Tasks\Microsoft\Windows\NetCfg\BindingWorkItemQueueHandler
Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => C:\Windows\system32\rundll32.exe [2012-07-26] (Microsoft Corporation)
Task: {1BB73E66-4FA1-46A6-B31D-57B75FD8BC6E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-18] (Google Inc.)
Task: {1DB7C2F1-876C-4F24-AD17-8428211113F9} - System32\Tasks\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents
Task: {214B24F4-FEB4-4C59-AF1F-70136065199C} - System32\Tasks\Microsoft\Windows\Shell\IndexerAutomaticMaintenance
Task: {23700E5C-0E77-499D-908A-415D5C6252F4} - System32\Tasks\Microsoft\Windows\Plug and Play\Device Install Group Policy
Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => C:\Windows\System32\rundll32.exe [2012-07-26] (Microsoft Corporation)
Task: {2C6B9EA8-7F5A-4ABA-BF96-8D352D02A743} - System32\Tasks\Microsoft\Windows\Device Setup\Metadata Refresh
Task: {2E030FA7-3D7C-4E1D-8CFE-56ADB26FD402} - System32\Tasks\Microsoft\Windows\PI\Sqm-Tasks
Task: {3054485A-F517-4E95-9977-4DD827B1E9B3} - System32\Tasks\Microsoft\Windows\WS\Badge Update
Task: {378401BA-A703-444A-A79C-3C47AD2DC5B6} - System32\Tasks\Microsoft\Windows\TaskScheduler\Maintenance Configurator
Task: {3AE164E7-30CD-40BC-9422-3EC7A5618965} - System32\Tasks\Microsoft\Windows\WS\WSTask
Task: {3C490ABD-D849-41AF-9AC4-87DD759B0996} - System32\Tasks\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem
Task: {4073C1B3-6E16-4AA8-B7F3-C6A6D35D5071} - System32\Tasks\Microsoft\Windows\TPM\Tpm-Maintenance
Task: {44B3F1B8-5943-4072-8D8C-A9484676AC44} - System32\Tasks\Microsoft\Windows\Live\Roaming\SynchronizeWithStorage
Task: {4603C7CB-B1C4-4ACE-BCC0-1ECF86BE7ABB} - System32\Tasks\DealPlyLiveUpdateTaskMachineCore => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe [2013-07-26] (DealPly Technologies Ltd)
Task: {483A8F5C-5D26-44B5-B49E-AF6741D1BBEB} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => C:\Windows\System32\MbaeParserTask.exe [2013-06-01] (Microsoft Corporation)
Task: {48EBE759-632B-4020-8CA0-BFDC69486B97} - System32\Tasks\OFFICE2010ACT => C:\ProgramData\Microsoft\Windows\OFFICEICON.vbs [2012-03-08] ()
Task: {4B952129-9AE9-41A3-BE2B-8AD2E06F66B6} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskLogon
Task: {54246547-F7C0-4888-98EE-6B6BF0ED813B} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-11] (Adobe Systems Incorporated)
Task: {5755E746-D7ED-4C20-A472-66C11834CDE4} - System32\Tasks\Microsoft\Windows\TaskScheduler\Manual Maintenance
Task: {5C4EFB77-EFA6-45DF-A373-D795C0725BFF} - System32\Tasks\Microsoft\Windows\Plug and Play\Device Install Reboot Required
Task: {627441F3-8526-4B62-BF9A-1A3EA414E71A} - System32\Tasks\Microsoft\Windows\SpacePort\SpaceAgentTask => C:\Windows\system32\SpaceAgent.exe [2012-07-26] (Microsoft Corporation)
Task: {63A1C69D-4D6D-48FA-B0AE-4997F296EB42} - System32\Tasks\MirageAgent => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [2012-07-27] (CyberLink)
Task: {662B4346-14DF-422A-B890-E5FBBB142FCC} - System32\Tasks\ROC_REG_JAN_DELETE => C:\ProgramData\AVG January 2013 Campaign\ROC.exe [2013-01-17] ()
Task: {6E9DE125-5583-4031-B572-FEE48F25CFFF} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyMonitor => C:\Windows\System32\wpcmon.exe [2012-09-20] (Microsoft Corporation)
Task: {6FDDEA7C-6310-428D-AEB2-54FFC72811EF} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319
Task: {74096F94-B654-4DB0-96F5-3C3408B92FE3} - System32\Tasks\Microsoft\Windows\PI\Secure-Boot-Update
Task: {776A9D6F-9BDF-4D70-B4AD-C3C08BF6F519} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-03-25] (Piriform Ltd)
Task: {7D9A9A1C-499C-40A6-8F8A-5BCC4CC9A87C} - System32\Tasks\Microsoft\Windows\TaskScheduler\Regular Maintenance
Task: {84258B19-1EBC-49CF-8016-E34750C89FEF} - System32\Tasks\Microsoft\Windows\WindowsUpdate\AUSessionConnect
Task: {845CB020-68B5-4C6B-9876-7BEC7B3E27AC} - System32\Tasks\Microsoft\Windows\TaskScheduler\Idle Maintenance
Task: {85F5BE69-2C8C-4AAF-AE3C-1170476923DC} - System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-833875348-499972116-837255604-1002
Task: {87354DAA-66DF-4B41-9346-15958D96E1D2} - System32\Tasks\Microsoft\Windows\FileHistory\File History (maintenance mode)
Task: {921A1D4E-32FB-46D7-B6C0-6F467884074D} - System32\Tasks\Microsoft\Windows\WS\Sync Licenses
Task: {9479EF8E-11D4-41B3-9783-CC65070D592D} - System32\Tasks\Microsoft\Windows\Time Synchronization\ForceSynchronizeTime
Task: {94DCF254-64FB-4C4E-8E12-5F4055C10C2A} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64
Task: {989A7C6D-BE82-4C3C-AF96-6116039E336B} - System32\Tasks\Microsoft\Windows\MemoryDiagnostic\RunFullMemoryDiagnostic
Task: {9E1576B4-33A9-4902-BE8F-2DB19F35512F} - System32\Tasks\DSite => C:\Users\BAYRAM~1\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE No File
Task: {A034C1AD-0AB3-41B0-A5C8-F69EB0B70FC1} - System32\Tasks\Microsoft\Windows\Servicing\StartComponentCleanup
Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => C:\Windows\System32\rundll32.exe [2012-07-26] (Microsoft Corporation)
Task: {A800277E-E202-4492-AD38-3312641CBC04} - System32\Tasks\Microsoft\Windows\Live\Roaming\MaintenanceTask
Task: {AB62FA47-2C99-44B1-A5D0-D4161423BE43} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyRefresh
Task: {AC6259DE-AC59-459E-849E-6ADFFD1ADE63} - System32\Tasks\Microsoft\Windows\Shell\CreateObjectTask
Task: {AEB0B5BD-B9E5-458A-898A-E559BD9EB51B} - System32\Tasks\Microsoft\Windows\SettingSync\BackgroundUploadTask
Task: {AF549BD8-337C-4BF7-8681-36A182E30507} - System32\Tasks\Microsoft\Windows\Chkdsk\ProactiveScan
Task: {BC76AEF7-2CF0-4EB6-B65B-A8803E0B5E12} - System32\Tasks\Microsoft\Windows\AppID\SmartScreenSpecific
Task: {C1ACCD1E-4385-4FB2-B5E4-7F2A57A626A2} - System32\Tasks\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan
Task: {C463FD1E-31C7-4C20-AB65-08E514CA152D} - System32\Tasks\Microsoft\Windows\IME\SQM data sender
Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => C:\Windows\system32\rundll32.exe [2012-07-26] (Microsoft Corporation)
Task: {CD1054FF-8005-4904-8B9C-436EAB1E2021} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskNetwork
Task: {D825323E-C121-4EEA-9DAA-3A8D57FFC359} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {DBCF6E1B-CE0A-441E-B7A5-219C8BE50C65} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Critical
Task: {DECE5921-598D-454B-9A04-B2DE95EFC1B3} - System32\Tasks\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan for Crash Recovery
Task: {E257399A-ED89-4929-9742-F7C0155350A7} - System32\Tasks\Dealply => C:\Users\BAYRAM~1\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.EXE [2013-07-26] ()
Task: {E2C379D3-8995-41E5-A052-D2D25FDB4393} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start => C:\WINDOWS\system32\sc.exe [2012-07-26] (Microsoft Corporation)
Task: {E4DFE66F-E089-4CC3-A70F-957223D565F4} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask
Task: {E68EEE82-8B14-4A3F-AC8F-27D21B0E6533} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-01-18] (Google Inc.)
Task: {E8DAA09B-DF2A-4951-9134-6FA9587793F9} - System32\Tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers => C:\Windows\System32\drvinst.exe [2012-09-20] (Microsoft Corporation)
Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => C:\Windows\system32\rundll32.exe [2012-07-26] (Microsoft Corporation)
Task: {EC9A3C42-DA61-4687-8D4B-968705955EBB} - System32\Tasks\Microsoft\Windows\WindowsUpdate\AUFirmwareInstall
Task: {ED0C1F69-C3A2-41EA-B8C3-3F0D83A1F6C0} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\BthSQM
Task: {F23F2432-F7E2-47FD-8254-9771B9968032} - System32\Tasks\Lenovo\LSC\Time72Task => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe No File
Task: {F58F3DAC-C95F-4399-B92A-F44770D639F1} - System32\Tasks\LyricXeeker Update => C:\Program Files (x86)\LyriXeeker\LyriXupdate.exe [2013-07-25] (LyriXeeker Tech)
Task: {F599D9B2-64EA-4D5C-BA58-387BC798343E} - System32\Tasks\Lenovo\LSC\RebootCountTask => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe No File
Task: {FF6D0765-BC30-4A23-900D-FF59C21E7698} - System32\Tasks\QtraxPlayer => C:\Program Files (x86)\Microsoft Silverlight\sllauncher.exe [2013-05-13] (Microsoft Corporation)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\Dealply.job => ?
Task: C:\WINDOWS\Tasks\DealPlyLiveUpdateTaskMachineCore.job => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe
Task: C:\WINDOWS\Tasks\DealPlyLiveUpdateTaskMachineUA.job => C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe
Task: C:\WINDOWS\Tasks\DSite.job => ?
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\LyricXeeker Update.job => C:\Program Files (x86)\LyriXeeker\LyriXupdate.exe
Task: C:\WINDOWS\Tasks\ROC_REG_JAN_DELETE.job => C:\ProgramData\AVG January 2013 Campaign\ROC.exe
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (07/26/2013 03:34:31 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: UPDATE~1.EXE, Version: 0.0.0.0, Zeitstempel: 0x2a425e19
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000
ID des fehlerhaften Prozesses: 0xc3c
Startzeit der fehlerhaften Anwendung: 0xUPDATE~1.EXE0
Pfad der fehlerhaften Anwendung: UPDATE~1.EXE1
Pfad des fehlerhaften Moduls: UPDATE~1.EXE2
Berichtskennung: UPDATE~1.EXE3
Vollständiger Name des fehlerhaften Pakets: UPDATE~1.EXE4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: UPDATE~1.EXE5
Error: (07/26/2013 02:52:42 PM) (Source: MsiInstaller) (User: Trabzon61)
Description: Product: Skype Click to Call -- Error 1609. An error occurred while applying security settings. Users is not a valid user or group. This could be a problem with the package, or a problem connecting to a domain controller on the network. Check your network connection and click Retry, or Cancel to end the install. Unable to locate the user's SID, system error 1332(NULL)(NULL)(NULL)(NULL)(NULL)
Error: (07/26/2013 02:35:18 PM) (Source: MsiInstaller) (User: Trabzon61)
Description: Product: Google Update Helper -- Error 1316. A network error occurred while attempting to read from the file: C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\GoogleUpdateHelper.msi
Error: (07/25/2013 07:42:49 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: Trabzon61)
Description: Bei der Aktivierung der App „E046963F.LenovoSupport_k1h2ywk1493x8!App“ ist folgender Fehler aufgetreten: -2144927142. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (07/25/2013 07:42:49 PM) (Source: Application Hang) (User: )
Description: Programm Support.exe, Version 1.0.18.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: e54
Startzeit: 01ce895e4ce50fc4
Endzeit: 4294967295
Anwendungspfad: C:\Program Files\WindowsApps\E046963F.LenovoSupport_1.0.18.0_x86__k1h2ywk1493x8\Support.exe
Berichts-ID: 93730445-f551-11e2-beed-20898428dd4c
Vollständiger Name des fehlerhaften Pakets: E046963F.LenovoSupport_1.0.18.0_x86__k1h2ywk1493x8
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: App
Error: (07/25/2013 07:42:41 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: ismagent.exe, Version: 1.14.1.36458, Zeitstempel: 0x4fbe2d9c
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x77d3bda1
ID des fehlerhaften Prozesses: 0xf70
Startzeit der fehlerhaften Anwendung: 0xismagent.exe0
Pfad der fehlerhaften Anwendung: ismagent.exe1
Pfad des fehlerhaften Moduls: ismagent.exe2
Berichtskennung: ismagent.exe3
Vollständiger Name des fehlerhaften Pakets: ismagent.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: ismagent.exe5
Error: (07/25/2013 07:42:30 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: Trabzon61)
Description: Bei der Aktivierung der App „Microsoft.BingNews_8wekyb3d8bbwe!AppexNews“ ist folgender Fehler aufgetreten: -2144927142. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (07/25/2013 07:42:30 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: Trabzon61)
Description: Die App „Microsoft.BingNews_8wekyb3d8bbwe!AppexNews“ wurde nicht innerhalb der vorgesehenen Zeit gestartet.
Error: (07/25/2013 07:42:29 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: Trabzon61)
Description: Die App „E046963F.LenovoSupport_k1h2ywk1493x8!App“ wurde nicht innerhalb der vorgesehenen Zeit gestartet.
Error: (07/25/2013 07:42:30 PM) (Source: Application Hang) (User: )
Description: Programm wwahost.exe, Version 6.2.9200.16420 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: d7c
Startzeit: 01ce895e4ce50fc4
Endzeit: 4294967295
Anwendungspfad: C:\WINDOWS\system32\wwahost.exe
Berichts-ID:
Vollständiger Name des fehlerhaften Pakets: Microsoft.BingNews_1.2.0.135_x64__8wekyb3d8bbwe
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: AppexNews
System errors:
=============
Error: (07/26/2013 03:10:12 PM) (Source: DCOM) (User: Trabzon61)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (07/26/2013 03:10:12 PM) (Source: DCOM) (User: Trabzon61)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (07/26/2013 03:10:08 PM) (Source: DCOM) (User: Trabzon61)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (07/26/2013 03:10:08 PM) (Source: DCOM) (User: Trabzon61)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (07/26/2013 03:10:07 PM) (Source: DCOM) (User: Trabzon61)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (07/26/2013 03:10:07 PM) (Source: DCOM) (User: Trabzon61)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (07/26/2013 03:10:04 PM) (Source: DCOM) (User: Trabzon61)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (07/26/2013 03:10:04 PM) (Source: DCOM) (User: Trabzon61)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (07/26/2013 03:10:03 PM) (Source: DCOM) (User: Trabzon61)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (07/26/2013 03:10:02 PM) (Source: DCOM) (User: Trabzon61)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Microsoft Office Sessions:
=========================
Error: (07/26/2013 03:34:31 PM) (Source: Application Error)(User: )
Description: UPDATE~1.EXE0.0.0.02a425e19unknown0.0.0.000000000c000000500000000c3c01ce8a04cd331f21C:\Users\BAYRAM~1\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.EXEunk nown197afcd4-f5f8-11e2-beee-20898428dd4c
Error: (07/26/2013 02:52:42 PM) (Source: MsiInstaller)(User: Trabzon61)
Description: Product: Skype Click to Call -- Error 1609. An error occurred while applying security settings. Users is not a valid user or group. This could be a problem with the package, or a problem connecting to a domain controller on the network. Check your network connection and click Retry, or Cancel to end the install. Unable to locate the user's SID, system error 1332(NULL)(NULL)(NULL)(NULL)(NULL)
Error: (07/26/2013 02:35:18 PM) (Source: MsiInstaller)(User: Trabzon61)
Description: Product: Google Update Helper -- Error 1316. A network error occurred while attempting to read from the file: C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\GoogleUpdateHelper.msi(NULL)(NULL)(NULL)(NULL)(NULL)
Error: (07/25/2013 07:42:49 PM) (Source: Microsoft-Windows-Immersive-Shell)(User: Trabzon61)
Description: E046963F.LenovoSupport_k1h2ywk1493x8!App-2144927142
Error: (07/25/2013 07:42:49 PM) (Source: Application Hang)(User: )
Description: Support.exe1.0.18.0e5401ce895e4ce50fc44294967295C:\Program Files\WindowsApps\E046963F.LenovoSupport_1.0.18.0_x86__k1h2ywk1493x8\Support.exe93730445-f551-11e2-beed-20898428dd4cE046963F.LenovoSupport_1.0.18.0_x86__k1h2ywk1493x8App
Error: (07/25/2013 07:42:41 PM) (Source: Application Error)(User: )
Description: ismagent.exe1.14.1.364584fbe2d9cunknown0.0.0.000000000c000000577d3bda1f7001ce895e4795d071C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exeunknown9a35a7eb-f551-11e2-beed-20898428dd4c
Error: (07/25/2013 07:42:30 PM) (Source: Microsoft-Windows-Immersive-Shell)(User: Trabzon61)
Description: Microsoft.BingNews_8wekyb3d8bbwe!AppexNews-2144927142
Error: (07/25/2013 07:42:30 PM) (Source: Microsoft-Windows-Immersive-Shell)(User: Trabzon61)
Description: Microsoft.BingNews_8wekyb3d8bbwe!AppexNews
Error: (07/25/2013 07:42:29 PM) (Source: Microsoft-Windows-Immersive-Shell)(User: Trabzon61)
Description: E046963F.LenovoSupport_k1h2ywk1493x8!App
Error: (07/25/2013 07:42:30 PM) (Source: Application Hang)(User: )
Description: wwahost.exe6.2.9200.16420d7c01ce895e4ce50fc44294967295C:\WINDOWS\system32\wwahost.exeMicrosoft.BingNews_1.2.0.135_x64__8wekyb3d8bbweAppexNews
könntest du dir das anschauen habe das getan was du gemeint hattest und ne frage die berichte kamen 3 mal die ersten 2 habe ich gepostet die letzten habe ich noch falls du möchtest das ich sie auch poste
danke