Rimelblanco | 04.09.2013 16:17 | Hallo,
bin sehr erleichtert!!! :taenzer:
frst
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-09-2013 03
Ran by Mi (administrator) on MI-PC on 04-09-2013 16:52:59
Running from C:\Users\Mi\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(Acer Group) C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe
(Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Google Inc.) C:\Users\Mi\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Mi\AppData\Local\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Users\Mi\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Policies\Explorer: [NoActiveDesktop] 1
HKLM\...\Policies\Explorer: [NoActiveDesktopChanges] 1
HKCU\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2010-07-14] (Google Inc.)
HKLM-x32\...\Run: [DivXMediaServer] - C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [x]
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [345144 2013-08-31] (Avira Operations GmbH & Co. KG)
HKU\Default\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Packard Bell\Screensaver\run_Packard Bell.exe [154144 2010-07-29] ()
AppInit_DLLs: [0 ] ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0407&m=easynote_tk85&r=273601111065l0434z145f47l2h579
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
SearchScopes: HKCU - {3B5D965F-D6E8-4C1E-AD5D-4238C55043ED} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=827316&p={searchTerms}
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO-x32: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Mi\AppData\Roaming\Mozilla\Firefox\Profiles\97u5otcz.default
FF SearchEngineOrder.3: Bing
FF Homepage: user_pref("browser.startup.homepage", );
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=1.6.0_33 - C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=16.0.2.32 - c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=16.0.2.32 - c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Mi\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Mi\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Extension: LyricsGet - C:\Users\Mi\AppData\Roaming\Mozilla\Firefox\Profiles\97u5otcz.default\Extensions\131
FF Extension: hdvc3 - C:\Users\Mi\AppData\Roaming\Mozilla\Firefox\Profiles\97u5otcz.default\Extensions\hdvc3@hdvidcodec.com.xpi
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF HKLM-x32\...\Firefox\Extensions: [{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}] C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF HKLM-x32\...\Firefox\Extensions: [{FCE04E1F-9378-4f39-96F6-5689A9159E45}] C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
Chrome:
=======
CHR HomePage: hxxp://www.gmx.net/
CHR RestoreOnStartup: "hxxp://www.gmx.net/"
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Mi\AppData\Local\Google\Chrome\Application\29.0.1547.62\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Mi\AppData\Local\Google\Chrome\Application\29.0.1547.62\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Users\Mi\AppData\Local\Google\Chrome\Application\29.0.1547.62\gcswf32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.300.12) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U30) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll No File
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL No File
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll No File
CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll No File
CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer Version Plugin) - c:\program files (x86)\real\realplayer\Netscape6\nprpjplug.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
CHR Plugin: (RealJukebox NS Plugin) - c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll No File
CHR Extension: (YouTube) - C:\Users\Mi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Mi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (AT_CathKidston) - C:\Users\Mi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndlpkmaeinmnbiadacenijnhlolneopm\3_1
CHR Extension: (Chrome In-App Payments service) - C:\Users\Mi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0
CHR Extension: (Gmail) - C:\Users\Mi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
CHR HKLM-x32\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx
CHR StartMenuInternet: Google Chrome - C:\Users\Mi\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-08-31] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-08-31] (Avira Operations GmbH & Co. KG)
R2 ePowerSvc; C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [868896 2010-06-11] (Acer Incorporated)
S3 GameConsoleService; C:\Program Files (x86)\Packard Bell Games\Packard Bell Game Console\GameConsoleService.exe [246520 2010-04-04] (WildTangent, Inc.)
R2 GREGService; C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe [23584 2010-01-08] (Acer Incorporated)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe [255744 2010-06-28] (NewTech Infosystems, Inc.)
R2 OfficeSvc; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [1900728 2013-06-09] (Microsoft Corporation)
R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-04-16] ()
R2 Updater Service; C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe [243232 2010-01-29] (Acer Group)
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-08-31] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-08-31] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-08-31] (Avira Operations GmbH & Co. KG)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-03 20:15 - 2013-09-03 20:15 - 01028757 _____ (Thisisu) C:\Users\Mi\Desktop\JRT.exe
2013-09-03 19:27 - 2013-09-03 20:09 - 00000000 ____D C:\AdwCleaner
2013-09-03 19:27 - 2013-09-03 19:27 - 01037222 _____ C:\Users\Mi\Desktop\adwcleaner.exe
2013-08-31 20:02 - 2013-08-31 20:02 - 00000000 ____D C:\FRST
2013-08-31 18:28 - 2013-08-31 18:28 - 00083672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-08-31 11:36 - 2013-08-31 11:36 - 00000000 ____D C:\Users\Mi\AppData\Roaming\Malwarebytes
2013-08-31 11:35 - 2013-08-31 11:35 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Mi\Downloads\mbam-setup-1.75.0.1300.exe
2013-08-31 11:35 - 2013-08-31 11:35 - 00001125 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-31 11:35 - 2013-08-31 11:35 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-31 11:35 - 2013-08-31 11:35 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-31 11:35 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-08-31 11:26 - 2013-08-31 11:26 - 01027511 _____ (Thisisu) C:\Users\Mi\Downloads\JRT.exe
2013-08-31 11:26 - 2013-08-31 11:26 - 00000000 ____D C:\Windows\ERUNT
2013-08-31 10:20 - 2013-08-31 10:20 - 00377856 _____ C:\Users\Mi\Downloads\gmer_2.1.19163.exe
2013-08-31 09:43 - 2013-08-31 11:48 - 00010192 _____ C:\Windows\PFRO.log
2013-08-31 09:39 - 2013-09-02 17:11 - 00000238 _____ C:\Users\Mi\Downloads\defogger_enable.log
2013-08-31 09:07 - 2013-09-04 16:44 - 00000560 _____ C:\Windows\setupact.log
2013-08-31 09:07 - 2013-08-31 09:07 - 00000000 _____ C:\Windows\setuperr.log
2013-08-31 09:05 - 2013-08-31 09:40 - 00000466 _____ C:\Users\Mi\Downloads\defogger_disable.log
2013-08-31 09:05 - 2013-08-31 09:05 - 00050477 _____ C:\Users\Mi\Downloads\Defogger.exe
2013-08-31 08:39 - 2013-08-31 08:39 - 00002766 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2013-08-31 08:39 - 2013-08-31 08:39 - 00000000 ____D C:\Program Files\CCleaner
2013-08-31 08:38 - 2013-08-31 08:38 - 04454952 _____ (Piriform Ltd) C:\Users\Mi\Downloads\ccsetup405.exe
2013-08-31 08:16 - 2013-08-31 08:16 - 00000000 ____D C:\Users\Mi\AppData\Roaming\Avira
2013-08-31 08:10 - 2013-08-31 08:10 - 00002082 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
2013-08-31 08:10 - 2013-08-31 08:10 - 00000000 ____D C:\ProgramData\Avira
2013-08-31 08:10 - 2013-08-31 08:10 - 00000000 ____D C:\Program Files (x86)\Avira
2013-08-31 08:10 - 2013-08-31 08:09 - 00130016 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-08-31 08:10 - 2013-08-31 08:09 - 00100712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-08-31 08:10 - 2013-08-31 08:09 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-08-31 06:03 - 2013-08-31 06:03 - 00003134 _____ C:\Windows\System32\Tasks\{CD6B34B8-153C-4761-885B-2FDFF150510F}
2013-08-31 05:58 - 2013-08-31 05:58 - 00003332 _____ C:\Windows\System32\Tasks\{BDE8B102-21DB-4A1E-841E-2EF76B7B24E2}
2013-08-31 05:44 - 2013-08-31 05:54 - 00000898 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog
2013-08-31 05:43 - 2013-08-31 05:43 - 00000000 ____D C:\Users\Mi\AppData\Local\avgchrome
2013-08-31 05:38 - 2013-08-31 05:56 - 00000000 ____D C:\Program Files (x86)\HDPlayer
2013-08-31 05:38 - 2013-08-31 05:38 - 00000000 ____D C:\Program Files (x86)\FreeHDSport.TV
2013-08-31 05:16 - 2013-08-02 19:29 - 00217176 _____ C:\Windows\SysWOW64\unrar.dll
2013-08-31 04:58 - 2013-08-31 06:06 - 00000000 ____D C:\Program Files\DivX
2013-08-31 04:54 - 2013-08-31 06:06 - 00000000 ____D C:\ProgramData\DivX
2013-08-31 04:54 - 2013-08-31 06:06 - 00000000 ____D C:\Program Files (x86)\DivX
2013-08-19 12:14 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-19 12:14 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-08-19 12:14 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-19 12:14 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-19 12:14 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-19 12:14 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-19 12:14 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-19 12:14 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-08-19 12:14 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-08-19 12:14 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-19 12:14 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-08-19 12:14 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-19 12:14 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-08-19 12:14 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-08-19 12:14 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-08-19 12:14 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-08-19 12:14 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-08-19 12:14 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-08-19 12:14 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-08-19 12:14 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-08-19 12:14 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-08-19 12:14 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-08-19 12:14 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-08-19 12:14 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-08-19 12:14 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-08-19 12:13 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-19 12:13 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-19 12:13 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-19 12:13 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-08-19 12:13 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-08-19 12:13 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-08-19 11:57 - 2013-08-19 12:00 - 00000000 ____D C:\Windows\system32\MRT
2013-08-18 19:19 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-18 19:19 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-08-18 19:19 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-18 19:19 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-18 19:19 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-18 19:19 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-18 19:19 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-08-18 19:19 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-08-18 19:19 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-08-18 19:19 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-08-18 19:18 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-18 19:18 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-08-18 19:18 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-18 19:18 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-08-18 19:18 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-18 19:18 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
==================== One Month Modified Files and Folders =======
2013-09-04 16:51 - 2009-07-14 06:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-04 16:51 - 2009-07-14 06:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-04 16:50 - 2013-09-04 16:50 - 01950416 _____ (Farbar) C:\Users\Mi\Desktop\FRST64.exe
2013-09-04 16:48 - 2010-09-04 04:20 - 01499123 _____ C:\Windows\WindowsUpdate.log
2013-09-04 16:46 - 2011-02-11 22:02 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-09-04 16:44 - 2013-08-31 09:07 - 00000560 _____ C:\Windows\setupact.log
2013-09-04 16:44 - 2013-08-01 09:04 - 00003328 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1421037755-2221258896-2660180059-1000
2013-09-04 16:44 - 2013-08-01 09:04 - 00003188 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1421037755-2221258896-2660180059-1000
2013-09-04 16:44 - 2011-02-11 22:02 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-09-04 16:44 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-03 23:16 - 2011-02-12 15:35 - 00001108 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1421037755-2221258896-2660180059-1000UA.job
2013-09-03 23:09 - 2013-02-25 22:36 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-09-03 21:16 - 2011-02-12 15:35 - 00001056 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1421037755-2221258896-2660180059-1000Core.job
2013-09-03 20:15 - 2013-09-03 20:15 - 01028757 _____ (Thisisu) C:\Users\Mi\Desktop\JRT.exe
2013-09-03 20:09 - 2013-09-03 19:27 - 00000000 ____D C:\AdwCleaner
2013-09-03 20:08 - 2010-09-04 14:11 - 00718150 _____ C:\Windows\system32\perfh007.dat
2013-09-03 20:08 - 2010-09-04 14:11 - 00155646 _____ C:\Windows\system32\perfc007.dat
2013-09-03 20:08 - 2009-07-14 07:13 - 01658436 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-03 19:27 - 2013-09-03 19:27 - 01037222 _____ C:\Users\Mi\Desktop\adwcleaner.exe
2013-09-02 17:11 - 2013-08-31 09:39 - 00000238 _____ C:\Users\Mi\Downloads\defogger_enable.log
2013-09-02 17:11 - 2011-01-14 15:15 - 00000000 ____D C:\Users\Mi
2013-08-31 20:02 - 2013-08-31 20:02 - 00000000 ____D C:\FRST
2013-08-31 18:28 - 2013-08-31 18:28 - 00083672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-08-31 11:48 - 2013-08-31 09:43 - 00010192 _____ C:\Windows\PFRO.log
2013-08-31 11:36 - 2013-08-31 11:36 - 00000000 ____D C:\Users\Mi\AppData\Roaming\Malwarebytes
2013-08-31 11:35 - 2013-08-31 11:35 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Mi\Downloads\mbam-setup-1.75.0.1300.exe
2013-08-31 11:35 - 2013-08-31 11:35 - 00001125 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-31 11:35 - 2013-08-31 11:35 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-31 11:35 - 2013-08-31 11:35 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-31 11:26 - 2013-08-31 11:26 - 01027511 _____ (Thisisu) C:\Users\Mi\Downloads\JRT.exe
2013-08-31 11:26 - 2013-08-31 11:26 - 00000000 ____D C:\Windows\ERUNT
2013-08-31 11:19 - 2012-06-13 20:22 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-31 11:18 - 2011-01-14 15:25 - 00000000 ____D C:\Users\Mi\AppData\Local\Google
2013-08-31 11:18 - 2010-07-14 11:25 - 00000000 ____D C:\Program Files (x86)\Google
2013-08-31 10:20 - 2013-08-31 10:20 - 00377856 _____ C:\Users\Mi\Downloads\gmer_2.1.19163.exe
2013-08-31 09:40 - 2013-08-31 09:05 - 00000466 _____ C:\Users\Mi\Downloads\defogger_disable.log
2013-08-31 09:38 - 2011-01-14 15:17 - 00000000 ___RD C:\Users\Mi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-08-31 09:07 - 2013-08-31 09:07 - 00000000 _____ C:\Windows\setuperr.log
2013-08-31 09:05 - 2013-08-31 09:05 - 00050477 _____ C:\Users\Mi\Downloads\Defogger.exe
2013-08-31 08:40 - 2011-06-26 20:44 - 00000000 ____D C:\Program Files (x86)\PDFCreator
2013-08-31 08:40 - 2011-04-19 01:16 - 00000000 ____D C:\Users\Mi\AppData\Local\CrashDumps
2013-08-31 08:40 - 2007-07-12 03:49 - 00000000 ____D C:\Windows\Panther
2013-08-31 08:39 - 2013-08-31 08:39 - 00002766 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2013-08-31 08:39 - 2013-08-31 08:39 - 00000000 ____D C:\Program Files\CCleaner
2013-08-31 08:38 - 2013-08-31 08:38 - 04454952 _____ (Piriform Ltd) C:\Users\Mi\Downloads\ccsetup405.exe
2013-08-31 08:16 - 2013-08-31 08:16 - 00000000 ____D C:\Users\Mi\AppData\Roaming\Avira
2013-08-31 08:10 - 2013-08-31 08:10 - 00002082 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
2013-08-31 08:10 - 2013-08-31 08:10 - 00000000 ____D C:\ProgramData\Avira
2013-08-31 08:10 - 2013-08-31 08:10 - 00000000 ____D C:\Program Files (x86)\Avira
2013-08-31 08:09 - 2013-08-31 08:10 - 00130016 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-08-31 08:09 - 2013-08-31 08:10 - 00100712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-08-31 08:09 - 2013-08-31 08:10 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-08-31 06:06 - 2013-08-31 04:58 - 00000000 ____D C:\Program Files\DivX
2013-08-31 06:06 - 2013-08-31 04:54 - 00000000 ____D C:\ProgramData\DivX
2013-08-31 06:06 - 2013-08-31 04:54 - 00000000 ____D C:\Program Files (x86)\DivX
2013-08-31 06:03 - 2013-08-31 06:03 - 00003134 _____ C:\Windows\System32\Tasks\{CD6B34B8-153C-4761-885B-2FDFF150510F}
2013-08-31 05:58 - 2013-08-31 05:58 - 00003332 _____ C:\Windows\System32\Tasks\{BDE8B102-21DB-4A1E-841E-2EF76B7B24E2}
2013-08-31 05:56 - 2013-08-31 05:38 - 00000000 ____D C:\Program Files (x86)\HDPlayer
2013-08-31 05:54 - 2013-08-31 05:44 - 00000898 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog
2013-08-31 05:44 - 2011-01-14 15:15 - 00123168 _____ C:\Users\Mi\AppData\Local\GDIPFONTCACHEV1.DAT
2013-08-31 05:43 - 2013-08-31 05:43 - 00000000 ____D C:\Users\Mi\AppData\Local\avgchrome
2013-08-31 05:38 - 2013-08-31 05:38 - 00000000 ____D C:\Program Files (x86)\FreeHDSport.TV
2013-08-31 05:23 - 2011-12-21 16:44 - 00000000 ____D C:\ProgramData\Symantec
2013-08-31 05:23 - 2010-07-14 11:31 - 00000000 ____D C:\ProgramData\Norton
2013-08-31 05:03 - 2009-07-14 06:45 - 00492872 _____ C:\Windows\system32\FNTCACHE.DAT
2013-08-29 22:50 - 2011-02-12 15:38 - 00002362 _____ C:\Users\Mi\Desktop\Google Chrome.lnk
2013-08-27 01:11 - 2012-09-14 22:54 - 00000000 ____D C:\Users\Mi\AppData\Roaming\Skype
2013-08-24 00:26 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-08-21 14:45 - 2011-02-10 00:45 - 00000000 ____D C:\Users\Mi\Documents\Uni
2013-08-20 23:09 - 2013-02-25 22:36 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-08-20 23:09 - 2013-02-25 22:36 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-08-20 23:09 - 2013-02-25 22:36 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-08-19 12:00 - 2013-08-19 11:57 - 00000000 ____D C:\Windows\system32\MRT
2013-08-19 11:56 - 2011-11-27 15:07 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-08-18 21:37 - 2013-05-19 14:43 - 00000000 ____D C:\Program Files\Microsoft Office 15
2013-08-06 10:35 - 2013-07-12 17:40 - 00000000 ____D C:\Users\Mi\Documents\Job Bewerbungen
Files to move or delete:
====================
C:\Users\Mi\AppData\Local\Temp\6_Offer_13.exe
C:\Users\Mi\AppData\Local\Temp\BackupSetup.exe
C:\Users\Mi\AppData\Local\Temp\Quarantine.exe
C:\Users\Mi\AppData\Local\Temp\uninst1.exe
C:\Users\Mi\AppData\Local\Temp\vcredist_x64.exe
C:\Users\Mi\AppData\Local\Temp\VuuPCSetup_full.exe
C:\Users\Mi\AppData\Local\Temp\nsa93E7.tmp\inetc.dll
C:\Users\Mi\AppData\Local\Temp\nsa93E7.tmp\IpConfig.dll
C:\Users\Mi\AppData\Local\Temp\nsa93E7.tmp\NSISEncrypt.dll
C:\Users\Mi\AppData\Local\Temp\nsa93E7.tmp\nsJSON.dll
C:\Users\Mi\AppData\Local\Temp\nsa93E7.tmp\System.dll
C:\Users\Mi\AppData\Local\Temp\nsa93E7.tmp\UserInfo.dll
C:\Users\Mi\AppData\Local\Temp\nsa93E7.tmp\version.dll
C:\Users\Mi\AppData\Local\Temp\MSS\3.0.318.3\mcbrwsr2.dll
C:\Users\Mi\AppData\Local\Temp\MSS\3.0.318.3\McInstallerRes.dll
C:\Users\Mi\AppData\Local\Temp\MSS\3.0.318.3\McInstallerRes_LD.dll
C:\Users\Mi\AppData\Local\Temp\MSS\3.0.318.3\McInstallerStartup.dll
C:\Users\Mi\AppData\Local\Temp\MSS\3.0.318.3\McUICnt.exe
C:\Users\Mi\AppData\Local\Temp\MSS\3.0.318.3\SecurityScanner.dll
C:\Users\Mi\AppData\Local\Temp\jrt\erunt\ERUNT.EXE
C:\Users\Mi\AppData\Local\Temp\is357113909\OpenItSetup.exe
C:\Users\Mi\AppData\Local\Temp\is357113909\wajam_validate.exe
C:\Users\Mi\AppData\Local\Temp\EDA3D750-BAB0-7891-BCB1-B8DFD6D8A995\Latest\BExternal.dll
C:\Users\Mi\AppData\Local\Temp\EDA3D750-BAB0-7891-BCB1-B8DFD6D8A995\Latest\BUSolForMontiera.dll
C:\Users\Mi\AppData\Local\Temp\EDA3D750-BAB0-7891-BCB1-B8DFD6D8A995\Latest\ccp.exe
C:\Users\Mi\AppData\Local\Temp\EDA3D750-BAB0-7891-BCB1-B8DFD6D8A995\Latest\ChromeToolbarSetup.dll
C:\Users\Mi\AppData\Local\Temp\EDA3D750-BAB0-7891-BCB1-B8DFD6D8A995\Latest\CrxInstaller.dll
C:\Users\Mi\AppData\Local\Temp\EDA3D750-BAB0-7891-BCB1-B8DFD6D8A995\Latest\enhancedNT.dll
C:\Users\Mi\AppData\Local\Temp\EDA3D750-BAB0-7891-BCB1-B8DFD6D8A995\Latest\GUninstaller.exe
C:\Users\Mi\AppData\Local\Temp\EDA3D750-BAB0-7891-BCB1-B8DFD6D8A995\Latest\IEHelper.dll
C:\Users\Mi\AppData\Local\Temp\EDA3D750-BAB0-7891-BCB1-B8DFD6D8A995\Latest\MntrDLLInstall.dll
C:\Users\Mi\AppData\Local\Temp\EDA3D750-BAB0-7891-BCB1-B8DFD6D8A995\Latest\sqlite3.dll
C:\Users\Mi\AppData\Local\Temp\B7AC181C-BAB0-7891-9D3F-2B813286D9DA\BabylonTBUpdater.dll
C:\Users\Mi\AppData\Local\Temp\B7AC181C-BAB0-7891-9D3F-2B813286D9DA\BabylonTBUpdater.exe
C:\Users\Mi\AppData\Local\Temp\B7AC181C-BAB0-7891-9D3F-2B813286D9DA\Latest\BabylonTBUpdater.dll
C:\Users\Mi\AppData\Local\Temp\B7AC181C-BAB0-7891-9D3F-2B813286D9DA\Latest\BabylonTBUpdater.exe
C:\Users\Mi\AppData\Local\Temp\B7AC181C-BAB0-7891-9D3F-2B813286D9DA\Latest\BExternal.dll
C:\Users\Mi\AppData\Local\Temp\B7AC181C-BAB0-7891-9D3F-2B813286D9DA\Latest\IEHelper.dll
C:\Users\Mi\AppData\Local\Temp\B7AC181C-BAB0-7891-9D3F-2B813286D9DA\Latest\sqlite3.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-24 00:14
==================== End Of Log ============================ --- --- ---
--- --- ---
addition Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 03-09-2013 03
Ran by Mi at 2013-09-04 16:53:54
Running from C:\Users\Mi\Desktop
Boot Mode: Normal
==========================================================
==================== Installed Programs =======================
7-Zip 9.20 (x32)
Acrobat.com (x32 Version: 1.6.65)
Adobe Flash Player 11 ActiveX (x32 Version: 11.8.800.94)
Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.94)
Adobe Reader X (10.1.7) - Deutsch (x32 Version: 10.1.7)
Advertising Center (x32 Version: 0.0.0.2)
Agatha Christie - Death on the Nile (x32 Version: 2.2.0.95)
Apple Application Support (x32 Version: 2.3.4)
Apple Mobile Device Support (Version: 6.1.0.13)
Apple Software Update (x32 Version: 2.1.3.127)
Avira Free Antivirus (x32 Version: 13.0.0.3885)
Backup Manager Basic (x32 Version: 2.0.0.68)
Bejeweled 2 Deluxe (x32 Version: 2.2.0.95)
Bonjour (Version: 3.0.0.10)
Broadcom Gigabit NetLink Controller (Version: 14.0.2.3)
Build-a-lot 2 (x32 Version: 2.2.0.95)
Chuzzle Deluxe (x32 Version: 2.2.0.95)
Cisco AnyConnect VPN Client (x32 Version: 2.5.3054)
Diner Dash 2 Restaurant Rescue (x32 Version: 2.2.0.95)
Dropbox (HKCU Version: 2.0.22)
eaner (Version: 4.05)
ETDWare PS/2-x64 7.0.6.5_WHQL (Version: 7.0.6.5)
Farm Frenzy (x32 Version: 2.2.0.95)
FATE (x32 Version: 2.2.0.95)
Final Drive Nitro (x32 Version: 2.2.0.95)
Google Chrome (HKCU Version: 29.0.1547.62)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0)
Google Toolbar for Internet Explorer (x32 Version: 7.5.4413.1752)
Google Update Helper (x32 Version: 1.3.21.153)
Identity Card (x32 Version: 1.00.3003)
ImagXpress (x32 Version: 7.0.74.0)
Insaniquarium Deluxe (x32 Version: 2.2.0.95)
Intel(R) Control Center (x32 Version: 1.2.1.1007)
Intel(R) Graphics Media Accelerator Driver (x32 Version: 8.15.10.2125)
Intel(R) Management Engine Components (x32 Version: 6.0.0.1179)
Intel(R) Rapid Storage Technology (x32 Version: 9.6.2.1001)
iTunes (Version: 11.0.4.4)
Java Auto Updater (x32 Version: 2.0.7.1)
Java(TM) 6 Update 33 (x32 Version: 6.0.330)
Jewel Quest Solitaire 2 (x32 Version: 2.2.0.95)
John Deere Drive Green (x32 Version: 2.2.0.95)
Junk Mail filter update (x32 Version: 14.0.8089.726)
Launch Manager (x32 Version: 4.0.12)
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft .NET Framework 4.5 (Version: 4.5.50709)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Choice Guard (x32 Version: 2.0.48.0)
Microsoft Office Professional Plus 2013 - de-de (Version: 15.0.4517.1509)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (x32 Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
MSVCRT (x32 Version: 14.0.1468.721)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
Nero 9 Essentials (x32)
Nero ControlCenter (x32 Version: 9.0.0.1)
Nero DiscSpeed (x32 Version: 5.4.13.100)
Nero DiscSpeed Help (x32 Version: 5.4.4.100)
Nero DriveSpeed (x32 Version: 4.4.12.100)
Nero DriveSpeed Help (x32 Version: 4.4.4.100)
Nero Express Help (x32 Version: 9.4.37.100)
Nero InfoTool (x32 Version: 6.4.12.100)
Nero InfoTool Help (x32 Version: 6.4.4.100)
Nero Installer (x32 Version: 4.4.9.0)
Nero Online Upgrade (x32 Version: 1.3.0.0)
Nero StartSmart (x32 Version: 9.4.37.100)
Nero StartSmart Help (x32 Version: 9.4.27.100)
Nero StartSmart OEM (x32 Version: 9.4.10.100)
NeroExpress (x32 Version: 9.4.37.100)
neroxml (x32 Version: 1.0.0)
Office 15 Click-to-Run Extensibility Component (Version: 15.0.4517.1509)
Office 15 Click-to-Run Licensing Component (Version: 15.0.4517.1509)
Office 15 Click-to-Run Localization Component (Version: 15.0.4517.1509)
Packard Bell Game Console (x32)
Packard Bell Games (x32 Version: 1.0.1.3)
Packard Bell InfoCentre (x32 Version: 3.02.3000)
Packard Bell MyBackup (x32 Version: 2.0.0.68)
Packard Bell Power Management (x32 Version: 5.00.3005)
Packard Bell Recovery Management (x32 Version: 4.05.3013)
Packard Bell Registration (x32 Version: 1.03.3003)
Packard Bell ScreenSaver (x32 Version: 1.1.0806.2010)
Packard Bell Social Networks (x32 Version: 1.0.1901)
Packard Bell Updater (x32 Version: 1.02.3001)
PDFCreator (x32 Version: 1.2.1)
Penguins! (x32 Version: 2.2.0.95)
Plants vs. Zombies (x32 Version: 2.2.0.95)
Polar Bowler (x32 Version: 2.2.0.95)
Polar Golfer (x32 Version: 2.2.0.95)
RealDownloader (x32 Version: 1.3.2)
RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0)
RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0)
RealPlayer (x32 Version: 16.0.2)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6141)
Realtek USB 2.0 Card Reader (x32 Version: 6.1.7600.30122)
RealUpgrade 1.1 (x32 Version: 1.1.0)
Skype Click to Call (x32 Version: 6.3.11079)
Skype™ 6.6 (x32 Version: 6.6.106)
Update for Microsoft .NET Framework 4.5 (KB2750147) (x32 Version: 1)
Update for Microsoft .NET Framework 4.5 (KB2805221) (x32 Version: 1)
Update for Microsoft .NET Framework 4.5 (KB2805226) (x32 Version: 1)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0)
Virtual Villagers 4 - The Tree of Life (x32 Version: 2.2.0.95)
Welcome Center (x32 Version: 1.02.3004)
Windows Live Anmelde-Assistent (x32 Version: 5.000.818.5)
Windows Live Call (x32 Version: 14.0.8064.0206)
Windows Live Communications Platform (x32 Version: 14.0.8064.206)
Windows Live Essentials (x32 Version: 14.0.8089.0726)
Windows Live Essentials (x32 Version: 14.0.8089.726)
Windows Live Fotogalerie (x32 Version: 14.0.8081.709)
Windows Live Mail (x32 Version: 14.0.8089.0726)
Windows Live Messenger (x32 Version: 14.0.8089.0726)
Windows Live Movie Maker (x32 Version: 14.0.8091.0730)
Windows Live Sync (x32 Version: 14.0.8089.726)
Windows Live Writer (x32 Version: 14.0.8089.0726)
Windows Live-Uploadtool (x32 Version: 14.0.8014.1029)
Windows Media Player Firefox Plugin (x32 Version: 1.0.0.8)
Zuma Deluxe (x32 Version: 2.2.0.95)
Zuma's Revenge (x32 Version: 2.2.0.95)
==================== Restore Points =========================
31-07-2013 18:01:35 Removed COMODO Internet Security
31-07-2013 18:11:48 Removed COMODO Internet Security
19-08-2013 09:54:56 Windows Update
31-08-2013 07:20:13 RegClean Pro Sa, Aug 31, 13 09:20
01-09-2013 02:43:30 Windows Update
==================== Hosts content: ==========================
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {00E5AE6D-75C6-45B6-BF1E-3E5EFC6DC5BD} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2013-08-18] (Microsoft Corporation)
Task: {01AA4AFB-D598-48CF-B45D-654AA2A843E9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-02-11] (Google Inc.)
Task: {044A6734-E90E-4F8F-B357-B2DC8AB3B5EC} - System32\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime => start w32time task_started
Task: {0CDAB9F1-E481-440E-8AF9-CBD4845E7FC5} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1421037755-2221258896-2660180059-1000UA => C:\Users\Mi\AppData\Local\Google\Update\GoogleUpdate.exe [2011-02-11] (Google Inc.)
Task: {192FD973-1721-4C58-953F-262C8E8045FF} - System32\Tasks\{9FBD96BC-3443-44CE-9DB2-31071D5D7A9A} => c:\users\mi\appdata\local\google\chrome\application\chrome.exe [2013-08-24] (Google Inc.)
Task: {325BAE89-378D-4125-AB57-920809854659} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2013-08-18] (Microsoft Corporation)
Task: {36DF1781-86B0-43EE-8A99-F7053A683600} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [2013-06-09] (Microsoft Corporation)
Task: {378F5C71-5EA3-4D18-82C7-CB88C0495846} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-20] (Adobe Systems Incorporated)
Task: {7558B638-FD02-49A0-B8A0-E8696427C61C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-02-11] (Google Inc.)
Task: {7DBEA57B-46C2-4D5B-B111-ED92EBF102BF} - System32\Tasks\Games\UpdateCheck_S-1-5-21-1421037755-2221258896-2660180059-1000
Task: {7E1163DB-66B6-4B8C-B443-AB2396B08FBC} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1421037755-2221258896-2660180059-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-04-16] (RealNetworks, Inc.)
Task: {854B246A-9B75-4225-A692-DC16791A8AD3} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-1421037755-2221258896-2660180059-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-04-16] (RealNetworks, Inc.)
Task: {A863BDC4-B0B7-4C67-89F9-7020A35C8578} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {AF8A1C48-E4B4-4850-BFC5-28343DA923C9} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => start osppsvc
Task: {BFE37087-84EA-4BE2-AFF2-0616C4BE278B} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation)
Task: {D59AD166-FA87-4716-B26D-0EFEF684BAFC} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-1421037755-2221258896-2660180059-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-04-16] (RealNetworks, Inc.)
Task: {EB0DB37B-F0E2-46E4-BDA5-DB4BEE19A173} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1421037755-2221258896-2660180059-1000Core => C:\Users\Mi\AppData\Local\Google\Update\GoogleUpdate.exe [2011-02-11] (Google Inc.)
Task: {F17FD8AC-AF8C-40F1-AD39-13F032777ECA} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1421037755-2221258896-2660180059-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-04-16] (RealNetworks, Inc.)
Task: {F218B1C6-1D1A-4D41-BAFB-CA2D391A8B0F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-08-21] (Piriform Ltd)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1421037755-2221258896-2660180059-1000Core.job => C:\Users\Mi\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1421037755-2221258896-2660180059-1000UA.job => C:\Users\Mi\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2013-05-25 02:36 - 2013-05-25 02:36 - 00164016 _____ (Dropbox, Inc.) C:\Users\Mi\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
2013-04-23 08:42 - 2013-04-23 08:42 - 00829264 _____ (Microsoft Corporation) C:\Windows\system32\MSVCR100.dll
2013-04-23 08:42 - 2013-04-23 08:42 - 00608080 _____ (Microsoft Corporation) C:\Windows\system32\MSVCP100.dll
2013-08-29 22:50 - 2013-08-24 19:48 - 47099856 _____ (Google Inc.) C:\Users\Mi\AppData\Local\Google\Chrome\Application\29.0.1547.62\chrome.dll
2013-08-29 22:50 - 2013-08-24 19:48 - 09962960 _____ (The ICU Project) C:\Users\Mi\AppData\Local\Google\Chrome\Application\29.0.1547.62\icudt.dll
2013-08-29 22:50 - 2013-08-24 18:07 - 00081768 _____ (Microsoft Corporation) C:\Users\Mi\AppData\Local\Google\Chrome\Application\29.0.1547.62\xinput1_3.dll
2013-05-25 02:36 - 2013-05-25 02:36 - 00130736 _____ (Dropbox, Inc.) C:\Users\Mi\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
2013-08-29 22:50 - 2013-08-24 18:07 - 03231688 _____ (Microsoft Corporation) C:\Users\Mi\AppData\Local\Google\Chrome\Application\29.0.1547.62\D3DCompiler_46.dll
2013-08-29 22:50 - 2013-08-24 19:49 - 00709584 _____ () C:\Users\Mi\AppData\Local\Google\Chrome\Application\29.0.1547.62\libglesv2.dll
2013-08-29 22:50 - 2013-08-24 19:49 - 00099792 _____ () C:\Users\Mi\AppData\Local\Google\Chrome\Application\29.0.1547.62\libegl.dll
2013-08-29 22:50 - 2013-08-24 19:49 - 04053456 _____ () C:\Users\Mi\AppData\Local\Google\Chrome\Application\29.0.1547.62\pdf.dll
2013-08-29 22:50 - 2013-08-24 19:49 - 00410576 _____ () C:\Users\Mi\AppData\Local\Google\Chrome\Application\29.0.1547.62\ppGoogleNaClPluginChrome.dll
2013-08-29 22:50 - 2013-08-24 19:49 - 02110928 _____ (Google Inc.) C:\Users\Mi\AppData\Local\Google\Chrome\Application\29.0.1547.62\libpeerconnection.dll
2013-08-29 22:50 - 2013-08-24 19:48 - 01604560 _____ () C:\Users\Mi\AppData\Local\Google\Chrome\Application\29.0.1547.62\ffmpegsumo.dll
==================== Alternate Data Streams (whitelisted) ==========
==================== Faulty Device Manager Devices =============
Name: Cisco AnyConnect VPN Virtual Miniport Adapter for Windows x64
Description: Cisco AnyConnect VPN Virtual Miniport Adapter for Windows x64
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: vpnva
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
System errors:
=============
Microsoft Office Sessions:
=========================
CodeIntegrity Errors:
===================================
Date: 2012-12-04 00:36:37.079
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2012-12-04 00:36:36.833
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
==================== Memory info ===========================
Percentage of memory in use: 38%
Total physical RAM: 2806.71 MB
Available physical RAM: 1721.52 MB
Total Pagefile: 5611.61 MB
Available Pagefile: 4101.33 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB
==================== Drives ================================
Drive c: (Packard Bell) (Fixed) (Total:284.99 GB) (Free:220.88 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 3EF599D9)
Partition 1: (Not Active) - (Size=13 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=285 GB) - (Type=07 NTFS)
==================== End Of Log ============================
systemlook Code:
SystemLook 30.07.11 by jpshortstuff
Log created at 16:59 on 04/09/2013 by Mi
Administrator - Elevation successful
========== filefind ==========
Searching for "*lucky leap*"
No files found.
Searching for "*babylon*"
C:\AdwCleaner\Quarantine\C\Users\Mi\AppData\RoaMing\Mozilla\Firefox\Profiles\97u5otcz.default\searchplugins\Babylon.xml.vir --a---- 6513 bytes [03:42 31/08/2013] [03:42 31/08/2013] 98BEDE4CE4BFC0B2F19D5A5E9934506E
C:\Users\Mi\AppData\Local\Temp\B7AC181C-BAB0-7891-9D3F-2B813286D9DA\BabylonTBUpdater.dll --a---- 240128 bytes [03:42 31/08/2013] [08:06 05/07/2011] 3D7567505014D5F1057FBE6829AEF25C
C:\Users\Mi\AppData\Local\Temp\B7AC181C-BAB0-7891-9D3F-2B813286D9DA\BabylonTBUpdater.exe --a---- 2660 bytes [03:42 31/08/2013] [09:22 28/06/2011] ED6AE57387AD7A607B820EF37FB29103
C:\Users\Mi\AppData\Local\Temp\B7AC181C-BAB0-7891-9D3F-2B813286D9DA\Latest\Babylon.dat --a---- 12384 bytes [03:42 31/08/2013] [14:49 23/12/2012] 825E5733974586A0A1229A53361ED13E
C:\Users\Mi\AppData\Local\Temp\B7AC181C-BAB0-7891-9D3F-2B813286D9DA\Latest\BabylonTBUpdater.dll --a---- 240128 bytes [03:42 31/08/2013] [08:06 05/07/2011] 3D7567505014D5F1057FBE6829AEF25C
C:\Users\Mi\AppData\Local\Temp\B7AC181C-BAB0-7891-9D3F-2B813286D9DA\Latest\BabylonTBUpdater.exe --a---- 2660 bytes [03:42 31/08/2013] [09:22 28/06/2011] ED6AE57387AD7A607B820EF37FB29103
C:\Users\Mi\AppData\Local\Temp\EDA3D750-BAB0-7891-BCB1-B8DFD6D8A995\Latest\Babylon.dat --a---- 12384 bytes [07:16 31/08/2013] [12:17 19/02/2013] 825E5733974586A0A1229A53361ED13E
Searching for "*mixidj*"
C:\AdwCleaner\Quarantine\C\Users\Mi\AppData\RoaMing\Mozilla\Firefox\Profiles\97u5otcz.default\searchplugins\mixidj.xml.vir --a---- 1305 bytes [03:43 31/08/2013] [03:43 31/08/2013] 8E997E4C329BAF1312D363E88EBC27BA
C:\Users\Mi\AppData\Local\Temp\B7AC181C-BAB0-7891-9D3F-2B813286D9DA\Latest\MixiDJChromeTB.zpb --a---- 78065 bytes [03:43 31/08/2013] [03:43 31/08/2013] B34C544922F355DD651B0ACCE605814B
Searching for "*Wajam*"
C:\Users\Mi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1RGJRZVG\wajamV[1].png --a---- 1389 bytes [07:15 31/08/2013] [07:15 31/08/2013] D199E5A2ED9738289F03B9B136E6FAD4
C:\Users\Mi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1RGJRZVG\Wajam_bg[1].png --a---- 78518 bytes [07:15 31/08/2013] [07:15 31/08/2013] 6350843A1904C65D885C5C68AC1EC412
C:\Users\Mi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1RGJRZVG\Wajam_EN[1].png --a---- 15739 bytes [07:15 31/08/2013] [07:15 31/08/2013] 6689EF49D73862CEFC6BACFA5575F76B
C:\Users\Mi\AppData\Local\Temp\is357113909\wajam_validate.exe ------- 11264 bytes [15:44 15/08/2013] [15:44 15/08/2013] 46F5C497F96E733176B010FF0EE56DE3
Searching for "*LyricsGet*"
No files found.
Searching for "*hdvc3*"
C:\Users\Mi\AppData\Roaming\Mozilla\Firefox\Profiles\97u5otcz.default\extensions\hdvc3@hdvidcodec.com.xpi --a---- 233016 bytes [08:44 30/06/2013] [08:44 30/06/2013] 7B9F889A721DE58C15FDF9EA9C9CE8BD
========== folderfind ==========
Searching for "*lucky leap*"
C:\AdwCleaner\Quarantine\C\Program Files (x86)\lucky leap d------ [18:08 03/09/2013]
Searching for "*babylon*"
C:\AdwCleaner\Quarantine\C\Users\Mi\AppData\RoaMing\Mozilla\Firefox\Profiles\97u5otcz.default\Extensions\ffxtlbr@babylon.com d------ [18:08 03/09/2013]
C:\ProgramData\WildTangent\Packard Bell Game Console\UI\htdocs2\Common\product\babylonia d------ [09:15 14/07/2010]
C:\Users\All Users\WildTangent\Packard Bell Game Console\UI\htdocs2\Common\product\babylonia d------ [09:15 14/07/2010]
Searching for "*mixidj*"
No folders found.
Searching for "*Wajam*"
No folders found.
Searching for "*LyricsGet*"
No folders found.
Searching for "*hdvc3*"
No folders found.
========== regfind ==========
Searching for "lucky leap"
No data found.
Searching for "babylon"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}]
"DllName"="BabylonToolbar.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}]
"DllName"="BabylonToolbar.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}]
"DllName"="BabylonToolbarTlbr.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}]
"DllName"="BabylonToolbar.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}]
"DllName"="BabylonToolbar.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}]
"DllName"="BabylonToolbarTlbr.dll"
Searching for "mixidj"
No data found.
Searching for "Wajam"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}]
@="IWajamBHO"
Searching for "LyricsGet"
No data found.
Searching for "hdvc3"
No data found.
Searching for " "
[HKEY_CURRENT_USER\Software\AppDataLow\Software\HDvid Codec V1\Plugins\104]
"JavaScript"="if (typeof appAPI.internal.monetization === "undefined") {
appAPI.internal.monetization = {};
}
if (typeof appAPI.internal.monetization.plugins === "undefined") {
appAPI.internal.monetization.plugins = {};
}
appAPI.internal.monetization.plugins[104] = function() {
if (typeof appAPI.internal.monetization.verticals !== "undefined") {
if (!appAPI.internal.monetization.verticals.shopping){
return;
}
}
var permanentData = {gui:[],actions:[]};
var permanentCache = ["c822c1b63853ed273b89687ac505f9fa","738aa8d3bc02eb8712acd0eb2cf6dfd5","2351f600bf62102c56b3941c39225683","16524241cd11b1b1c6b3ab30874047d6","241fe8af1e038118cd817048a65f803e","5ed33f7008771c9d49e3716aeaeca581","e50173d2983f028042965a37357931fc","8e1b7a68ae2f404bfafaafd53d293cde","dc29a383b9b0932dbd9f75e4af9b51f5","f4c4b31d11e30ca1511d807c10cd68f3","8862aa846eeafd1f61c5ad22580d0148","b53e20c91b81ec25a6d06d4cf351d0b2","1f89d526fc52417e16d99b9f069f
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell]
"ConfigXML"=" <PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="1" XmlRenderingType="text" > <InitializationParameters> <Param Name="PSVersion" Value="2.0"/> </InitializationParameters> <Resources> <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" SupportsOptions="true" ExactMatch="true"> <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/> <Capability Type="Shell"/> </Resource> </Res
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\WSMAN\Plugin\Microsoft.PowerShell32]
"ConfigXML"="<PlugInConfiguration xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Name="microsoft.powershell32" Filename="%windir%\system32\pwrshplugin.dll" SDKVersion="1" XmlRenderingType="text" Architecture="32" > <InitializationParameters> <Param Name="PSVersion" Value="2.0"/> </InitializationParameters> <Resources> <Resource ResourceUri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell32" SupportsOptions="true" ExactMatch="true"> <Security xmlns="hxxp://schemas.microsoft.com/wbem/wsman/1/config/PluginConfiguration" Uri="hxxp://schemas.microsoft.com/powershell/microsoft.powershell32" ExactMatch="true" Sddl="O:NSG:BAD:P(A;;GA;;;BA)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)"/>
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_APPLE&PROD_IPOD&REV_1.62#000A27001D6AF209&0#]
"DeviceDesc"="iPod "
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_SAMSUNG&PROD_DSC&REV_1.00#0000000104C52004&0#]
"DeviceDesc"="DSC "
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_APPLE&PROD_IPOD&REV_1.62#000A27001D6AF209&0#]
"DeviceDesc"="iPod "
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_SAMSUNG&PROD_DSC&REV_1.00#0000000104C52004&0#]
"DeviceDesc"="DSC "
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_APPLE&PROD_IPOD&REV_1.62#000A27001D6AF209&0#]
"DeviceDesc"="iPod "
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\WpdBusEnumRoot\UMB\2&37c186b&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_SAMSUNG&PROD_DSC&REV_1.00#0000000104C52004&0#]
"DeviceDesc"="DSC "
[HKEY_USERS\S-1-5-21-1421037755-2221258896-2660180059-1000\Software\AppDataLow\Software\HDvid Codec V1\Plugins\104]
"JavaScript"="if (typeof appAPI.internal.monetization === "undefined") {
appAPI.internal.monetization = {};
}
if (typeof appAPI.internal.monetization.plugins === "undefined") {
appAPI.internal.monetization.plugins = {};
}
appAPI.internal.monetization.plugins[104] = function() {
if (typeof appAPI.internal.monetization.verticals !== "undefined") {
if (!appAPI.internal.monetization.verticals.shopping){
return;
}
}
var permanentData = {gui:[],actions:[]};
var permanentCache = ["c822c1b63853ed273b89687ac505f9fa","738aa8d3bc02eb8712acd0eb2cf6dfd5","2351f600bf62102c56b3941c39225683","16524241cd11b1b1c6b3ab30874047d6","241fe8af1e038118cd817048a65f803e","5ed33f7008771c9d49e3716aeaeca581","e50173d2983f028042965a37357931fc","8e1b7a68ae2f404bfafaafd53d293cde","dc29a383b9b0932dbd9f75e4af9b51f5","f4c4b31d11e30ca1511d807c10cd68f3","8862aa846eeafd1f61c5ad22580d0148","b53e20c91b81ec25a6d06d4
-= EOF =- Zu deiner Frage: der Rechner läuft sehr gut, ich hatte absolut keine Auffälligkeiten oder Probleme mit den Browsern.
Ganz herzlichen Danke nochmal für deine Unterstützung!! |