pinarobler | 12.05.2014 18:56 | Nach der Installation von MBAM meldete McAfee, es habe einen Trojaner gefunden und deswegen werde der PC jetzt neu gestartet. Nach dem Neustart meldete McAfee dann keine Bedrohungen mehr. Name der Bedrohung war "Artemis!06F9331DF45A" und Ort Desktop\Cobofix.exe.
Hier nun die Logfiles:
AdwCleaner: Code:
# AdwCleaner v3.208 - Bericht erstellt am 12/05/2014 um 08:47:39
# Aktualisiert 11/05/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (32 bits)
# Benutzername : Tina - KOKOLORES
# Gestartet von : C:\Users\Tina\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\Tina\AppData\Roaming\pdfforge
Datei Gelöscht : C:\Windows\System32\Tasks\SMupdate1
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D6BBC603-014C-4EDD-9AAC-56ED37D89305}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D6BBC603-014C-4EDD-9AAC-56ED37D89305}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : HKCU\Software\GOffers
Schlüssel Gelöscht : HKCU\Software\Goobzo
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17041
-\\ Mozilla Firefox v29.0.1 (de)
[ Datei : C:\Users\Tina\AppData\Roaming\Mozilla\Firefox\Profiles\hasy1go5.default\prefs.js ]
*************************
AdwCleaner[R0].txt - [1753 octets] - [12/05/2014 08:44:25]
AdwCleaner[S0].txt - [1682 octets] - [12/05/2014 08:47:39]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1742 octets] ########## JRT: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Professional x86
Ran by Tina on 12.05.2014 at 8:56:11,08
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Successfully deleted the following from C:\Users\Tina\AppData\Roaming\mozilla\firefox\profiles\hasy1go5.default\prefs.js
user_pref("extensions.xkit7.extension_auto_tagger", "{\"script\":\"//* TITLE Auto Tagger **//\\r\\n//* VERSION 0.4 REV C **//\\r\\n//* DESCRIPTION Tags posts automatically. **
user_pref("extensions.xkit7.extension_blacklist", "{\"script\":\"//* TITLE Blacklist **//\\r\\n//* VERSION 2.7 REV B **//\\r\\n//* DESCRIPTION Clean your dash **//\\r\\n//* DE
user_pref("extensions.xkit7.extension_go_to_dash", "{\"script\":\"//* TITLE Go-To-Dash **//\\r\\n//* VERSION 1.0 REV F **//\\r\\n//* DESCRIPTION View a post on a blog on your
user_pref("extensions.xkit7.extension_one_click_postage", "{\"script\":\"//* TITLE One-Click Postage **//\\r\\n//* VERSION 3.3 REV C **//\\r\\n//* DESCRIPTION Lets you easily
user_pref("extensions.xkit7.extension_one_click_reply", "{\"script\":\"//* TITLE One-Click Reply **//\\r\\n//* VERSION 1.9 REV F **//\\r\\n//* DESCRIPTION Lets you reply to no
user_pref("extensions.xkit7.extension_tweaks", "{\"script\":\"//* TITLE Tweaks **//\\r\\n//* VERSION 2.9 REV A **//\\r\\n//* DESCRIPTION Various little tweaks for your dashboa
user_pref("extensions.xkit7.extension_xinbox", "{\"script\":\"//* TITLE XInbox **//\\r\\n//* VERSION 1.9 REV B **//\\r\\n//* DESCRIPTION Enhances your Inbox experience **//\\r
user_pref("extensions.xkit7.extension_xkit_patches", "{\"script\":\"//* TITLE XKit Patches **//\\r\\n//* VERSION 2.4 REV F **//\\r\\n//* DESCRIPTION Patches framework **//\\r\
user_pref("extensions.xkit7.extension_xkit_preferences", "{\"script\":\"//* TITLE XKit Preferences **//\\r\\n//* VERSION 3.2 REV A **//\\r\\n//* DESCRIPTION Lets you customize
user_pref("extensions.xkit7.xkit_extension_storage__xkit_preferences", "{\"news\":{\"value\":\"[{\\\"id\\\":91111,\\\"title\\\":\\\"Welcome to XKit!\\\",\\\"message\\\":\\\"<h
Emptied folder: C:\Users\Tina\AppData\Roaming\mozilla\firefox\profiles\hasy1go5.default\minidumps [23 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 12.05.2014 at 10:38:51,86
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ MBAM: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 12.05.2014
Suchlauf-Zeit: 19:42:01
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.05.12.01
Rootkit Datenbank: v2014.03.27.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: Tina
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 243898
Verstrichene Zeit: 7 Std, 37 Min, 42 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 0
(No malicious items detected)
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 0
(No malicious items detected)
Dateien: 0
(No malicious items detected)
Physische Sektoren: 0
(No malicious items detected)
(end) FRST:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:11-05-2014 01
Ran by Tina (administrator) on KOKOLORES on 12-05-2014 19:46:44
Running from C:\Users\Tina\Desktop
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Logitech Inc.) C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Realsil Microelectronics Inc.) C:\Program Files\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
() C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
(pdfforge GmbH) C:\Program Files\PDF Architect\HelperService.exe
(pdfforge GmbH) C:\Program Files\PDF Architect\ConversionService.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(McAfee, Inc.) C:\Program Files\McAfee\MSC\McAPExe.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(Apple Inc.) D:\Program Files\iTunes\iTunesHelper.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(McAfee, Inc.) C:\Program Files\McAfee\VirusScan\McVsShld.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [IntelWireless] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1210640 2011-01-05] (Intel(R) Corporation)
HKLM\...\Run: [HTC Sync Loader] => C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe [659456 2013-09-03] ()
HKLM\...\Run: [HP Software Update] => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM\...\Run: [iTunesHelper] => D:\Program Files\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
HKLM\...\Run: [mcpltui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [517392 2014-04-25] (McAfee, Inc.)
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoFolderOptions] 0
HKU\.DEFAULT\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-4221202307-2618622504-1707876447-1000\...\RunOnce: [FlashPlayerUpdate] - C:\Windows\system32\Macromed\Flash\FlashUtil32_12_0_0_77_Plugin.exe [841096 2014-03-16] (Adobe Systems Incorporated)
Startup: C:\Users\Tina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Tina\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x8F88AE4ED291CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Tina\AppData\Roaming\Mozilla\Firefox\Profiles\hasy1go5.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 - D:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - D:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin: @mcafee.com/MSC,version=10 - c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - D:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin: @videolan.org/vlc,version=2.0.8 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin HKCU: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - D:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: XKit - C:\Users\Tina\AppData\Roaming\Mozilla\Firefox\Profiles\hasy1go5.default\Extensions\xkit@studioxenix.com.xpi [2014-01-05]
FF Extension: Adblock Plus - C:\Users\Tina\AppData\Roaming\Mozilla\Firefox\Profiles\hasy1go5.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-08-05]
========================== Services (Whitelisted) =================
S3 cphs; C:\Windows\system32\IntelCpHeciSvc.exe [277616 2012-12-14] (Intel Corporation)
R2 HomeNetSvc; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [281560 2013-07-30] (McAfee, Inc.)
R2 IconMan_R; C:\Program Files\Realtek\Realtek PCIE Card Reader\RIconMan.exe [1755136 2011-07-12] (Realsil Microelectronics Inc.)
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [145568 2014-04-25] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [281560 2013-07-30] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [281560 2013-07-30] (McAfee, Inc.)
S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [471592 2013-08-02] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [281560 2013-07-30] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [281560 2013-07-30] (McAfee, Inc.)
R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [644088 2014-01-21] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [169800 2014-03-17] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [175480 2014-03-17] (McAfee, Inc.)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [227600 2011-01-05] ()
R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] ()
R2 PDF Architect Helper Service; C:\Program Files\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH)
R2 PDF Architect Service; C:\Program Files\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH)
S2 SkypeUpdate; D:\Program Files\Skype\Updater\Updater.exe [172192 2013-10-23] (Skype Technologies)
R2 UMVPFSrv; C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [450848 2012-01-18] (Logitech Inc.)
==================== Drivers (Whitelisted) ====================
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [61400 2014-03-17] (McAfee, Inc.)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [147912 2013-09-23] (McAfee, Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-04-03] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [107736 2014-05-12] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51416 2014-04-03] (Malwarebytes Corporation)
R3 MEI; C:\Windows\System32\DRIVERS\HECI.sys [41088 2010-10-19] (Intel Corporation)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [134600 2014-03-17] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [236480 2014-03-17] (McAfee, Inc.)
S3 mfebopk; C:\Windows\System32\drivers\mfebopk.sys [66408 2014-03-17] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [367776 2014-03-17] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [573968 2014-03-17] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [330248 2014-01-21] (McAfee, Inc.)
S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [81264 2014-01-21] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [214856 2014-03-17] (McAfee, Inc.)
R3 NETwNs32; C:\Windows\System32\DRIVERS\NETwNs32.sys [7435264 2011-01-04] (Intel Corporation)
R3 nusb3hub; C:\Windows\System32\DRIVERS\nusb3hub.sys [67456 2011-07-12] (Renesas Electronics Corporation)
R3 nusb3xhc; C:\Windows\System32\DRIVERS\nusb3xhc.sys [161024 2011-07-12] (Renesas Electronics Corporation)
S3 RSPCIESTOR; C:\Windows\System32\DRIVERS\RtsPStor.sys [253544 2011-07-12] (Realtek Semiconductor Corp.)
S3 ss_bbus; C:\Windows\System32\DRIVERS\ss_bbus.sys [98432 2014-01-23] (MCCI)
S3 ss_bmdfl; C:\Windows\System32\DRIVERS\ss_bmdfl.sys [14848 2014-01-23] (MCCI Corporation)
S3 ss_bmdm; C:\Windows\System32\DRIVERS\ss_bmdm.sys [123648 2014-01-23] (MCCI Corporation)
S3 ss_bserd; C:\Windows\System32\DRIVERS\ss_bserd.sys [100224 2014-01-23] (MCCI Corporation)
S3 catchme; \??\C:\Users\Tina\AppData\Local\Temp\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-12 19:46 - 2014-05-12 19:47 - 00012294 _____ () C:\Users\Tina\Desktop\FRST.txt
2014-05-12 19:46 - 2014-05-12 19:46 - 00000000 ____D () C:\Users\Tina\Desktop\FRST-OlderVersion
2014-05-12 19:45 - 2014-05-12 19:45 - 00001155 _____ () C:\Users\Tina\Desktop\mbam.txt
2014-05-12 12:04 - 2014-05-12 12:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2014-05-12 11:59 - 2014-05-12 12:04 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-12 11:58 - 2014-05-12 11:58 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-12 11:58 - 2014-05-12 11:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-12 11:58 - 2014-05-12 11:58 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-12 11:58 - 2014-05-12 11:58 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-05-12 11:58 - 2014-04-03 09:51 - 00073432 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 11:58 - 2014-04-03 09:51 - 00051416 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-12 11:58 - 2014-04-03 09:50 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-12 11:55 - 2014-05-12 11:56 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Tina\Desktop\mbam-setup-2.0.1.1004.exe
2014-05-12 10:39 - 2014-05-12 10:38 - 00002649 _____ () C:\Users\Tina\Desktop\JRT.txt
2014-05-12 08:56 - 2014-05-12 08:56 - 00000000 ____D () C:\Windows\ERUNT
2014-05-12 08:51 - 2014-05-12 08:51 - 01016261 _____ (Thisisu) C:\Users\Tina\Desktop\JRT.exe
2014-05-12 08:44 - 2014-05-12 08:47 - 00000000 ____D () C:\AdwCleaner
2014-05-12 08:43 - 2014-05-12 08:43 - 01325827 _____ () C:\Users\Tina\Desktop\adwcleaner.exe
2014-05-11 14:42 - 2014-05-11 14:42 - 00016076 _____ () C:\ComboFix.txt
2014-05-11 13:51 - 2014-05-11 14:42 - 00000000 ____D () C:\Qoobox
2014-05-11 13:51 - 2014-05-11 14:37 - 00000000 ____D () C:\Windows\erdnt
2014-05-11 13:51 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-05-11 13:51 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-05-11 13:51 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-05-11 13:51 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-05-11 13:51 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-05-11 13:51 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-05-11 13:51 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-05-11 13:51 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-05-10 20:18 - 2014-05-10 20:18 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-05-10 18:04 - 2014-05-12 19:46 - 00000000 ____D () C:\FRST
2014-05-10 18:02 - 2014-05-12 19:46 - 01056256 _____ (Farbar) C:\Users\Tina\Desktop\FRST.exe
2014-05-10 16:57 - 2014-05-12 12:00 - 00011522 _____ () C:\Windows\PFRO.log
2014-05-10 16:57 - 2014-05-12 12:00 - 00000224 _____ () C:\Windows\setupact.log
2014-05-10 16:57 - 2014-05-10 16:57 - 00000000 _____ () C:\Windows\setuperr.log
2014-05-10 13:27 - 2014-05-10 16:14 - 00007597 _____ () C:\Users\Tina\AppData\Local\Resmon.ResmonCfg
2014-05-10 13:11 - 2014-05-10 13:11 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-05-08 15:31 - 2014-05-12 12:04 - 00001844 _____ () C:\Users\Public\Desktop\McAfee Total Protection.lnk
2014-05-08 15:31 - 2013-09-23 13:48 - 00147912 _____ (McAfee, Inc.) C:\Windows\system32\Drivers\HipShieldK.sys
2014-05-08 15:27 - 2014-05-08 15:27 - 00000000 ____D () C:\Program Files\McAfee.com
2014-05-08 15:19 - 2014-03-17 19:37 - 00175480 _____ (McAfee, Inc.) C:\Windows\system32\mfevtps.exe
2014-05-08 15:13 - 2014-05-08 15:13 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-08 15:10 - 2014-04-29 14:48 - 17384448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-08 15:10 - 2014-04-29 14:34 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-07 13:53 - 2014-04-14 04:11 - 00361984 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-07 13:53 - 2014-04-14 04:07 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-02 18:04 - 2014-05-02 18:04 - 00012839 _____ () C:\Users\Tina\AppData\Local\recently-used.xbel
2014-04-22 06:38 - 2014-03-06 10:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-04-22 06:38 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-04-22 06:38 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-04-22 06:38 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-04-22 06:38 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-04-22 06:38 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-04-22 06:38 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-04-22 06:38 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-04-22 06:38 - 2014-03-06 09:38 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-04-22 06:38 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-04-22 06:38 - 2014-03-06 09:28 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-04-22 06:38 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-04-22 06:38 - 2014-03-06 09:18 - 00575488 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-04-22 06:38 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-04-22 06:38 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-04-22 06:38 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-04-22 06:38 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-04-22 06:38 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-04-22 06:37 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-04-22 06:37 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-04-22 06:37 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-04-22 06:37 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-04-22 06:37 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-04-22 06:37 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-04-21 10:24 - 2014-04-21 10:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-04-21 10:23 - 2014-04-21 10:24 - 00000000 ____D () C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
2014-04-21 10:23 - 2014-04-21 10:23 - 00000000 ____D () C:\Program Files\iPod
2014-04-19 21:39 - 2014-05-06 19:23 - 00000000 ____D () C:\Users\Tina\AppData\Local\gtk-2.0
2014-04-19 21:39 - 2014-04-19 21:39 - 00000000 ____D () C:\Users\Tina\.thumbnails
2014-04-19 21:34 - 2014-05-02 18:04 - 00000000 ____D () C:\Users\Tina\.gimp-2.8
2014-04-19 21:34 - 2014-04-19 21:34 - 00000000 ____D () C:\Users\Tina\AppData\Local\gegl-0.2
2014-04-19 17:48 - 2014-04-19 17:48 - 00000748 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
2014-04-19 17:38 - 2014-04-19 17:39 - 90396104 _____ (The GIMP Team ) C:\Users\Tina\Downloads\gimp-2.8.10-setup.exe
2014-04-15 20:53 - 2014-04-15 20:53 - 00000000 ____D () C:\Program Files\directx
2014-04-13 14:56 - 2014-04-13 14:56 - 00001121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-04-13 14:56 - 2014-04-13 14:56 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-04-13 14:55 - 2014-04-13 14:56 - 00000000 ____D () C:\Program Files\CCleaner
2014-04-13 14:53 - 2014-04-13 14:56 - 00000000 ____D () C:\Users\Tina\AppData\Local\Google
2014-04-13 14:53 - 2014-04-13 14:56 - 00000000 ____D () C:\Program Files\Google
2014-04-13 14:53 - 2014-04-13 14:53 - 04787368 _____ (Piriform Ltd) C:\Users\Tina\Downloads\ccsetup412.exe
2014-04-13 14:16 - 2014-04-13 14:16 - 00000000 ____D () C:\Users\Tina\AppData\Roaming\PDAppFlex
2014-04-13 14:10 - 2014-04-13 14:10 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2014-04-12 21:10 - 2014-04-27 22:02 - 00000000 ____D () C:\Users\Tina\AppData\Roaming\HpUpdate
==================== One Month Modified Files and Folders =======
2014-05-12 19:47 - 2014-05-12 19:46 - 00012294 _____ () C:\Users\Tina\Desktop\FRST.txt
2014-05-12 19:46 - 2014-05-12 19:46 - 00000000 ____D () C:\Users\Tina\Desktop\FRST-OlderVersion
2014-05-12 19:46 - 2014-05-10 18:04 - 00000000 ____D () C:\FRST
2014-05-12 19:46 - 2014-05-10 18:02 - 01056256 _____ (Farbar) C:\Users\Tina\Desktop\FRST.exe
2014-05-12 19:45 - 2014-05-12 19:45 - 00001155 _____ () C:\Users\Tina\Desktop\mbam.txt
2014-05-12 19:40 - 2013-08-05 13:26 - 01541732 _____ () C:\Windows\WindowsUpdate.log
2014-05-12 12:08 - 2009-07-14 06:34 - 00022032 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-12 12:08 - 2009-07-14 06:34 - 00022032 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-12 12:04 - 2014-05-12 12:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2014-05-12 12:04 - 2014-05-12 11:59 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-12 12:04 - 2014-05-08 15:31 - 00001844 _____ () C:\Users\Public\Desktop\McAfee Total Protection.lnk
2014-05-12 12:01 - 2013-08-06 11:30 - 00000000 ____D () C:\Users\Tina\AppData\Roaming\Dropbox
2014-05-12 12:00 - 2014-05-10 16:57 - 00011522 _____ () C:\Windows\PFRO.log
2014-05-12 12:00 - 2014-05-10 16:57 - 00000224 _____ () C:\Windows\setupact.log
2014-05-12 12:00 - 2014-03-01 22:29 - 00000000 ____D () C:\Users\Tina\AppData\Local\Htc
2014-05-12 12:00 - 2013-08-05 14:07 - 00000000 ____D () C:\Program Files\McAfee
2014-05-12 12:00 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-12 11:58 - 2014-05-12 11:58 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-12 11:58 - 2014-05-12 11:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-12 11:58 - 2014-05-12 11:58 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-12 11:58 - 2014-05-12 11:58 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-05-12 11:56 - 2014-05-12 11:55 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Tina\Desktop\mbam-setup-2.0.1.1004.exe
2014-05-12 10:38 - 2014-05-12 10:39 - 00002649 _____ () C:\Users\Tina\Desktop\JRT.txt
2014-05-12 09:23 - 2013-08-05 13:54 - 00000000 ____D () C:\Program Files\Common Files\McAfee
2014-05-12 08:56 - 2014-05-12 08:56 - 00000000 ____D () C:\Windows\ERUNT
2014-05-12 08:51 - 2014-05-12 08:51 - 01016261 _____ (Thisisu) C:\Users\Tina\Desktop\JRT.exe
2014-05-12 08:48 - 2013-08-19 09:05 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-05-12 08:47 - 2014-05-12 08:44 - 00000000 ____D () C:\AdwCleaner
2014-05-12 08:43 - 2014-05-12 08:43 - 01325827 _____ () C:\Users\Tina\Desktop\adwcleaner.exe
2014-05-11 14:42 - 2014-05-11 14:42 - 00016076 _____ () C:\ComboFix.txt
2014-05-11 14:42 - 2014-05-11 13:51 - 00000000 ____D () C:\Qoobox
2014-05-11 14:42 - 2009-07-14 04:37 - 00000000 __RHD () C:\Users\Default
2014-05-11 14:42 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2014-05-11 14:37 - 2014-05-11 13:51 - 00000000 ____D () C:\Windows\erdnt
2014-05-11 14:35 - 2009-07-14 04:04 - 00000215 _____ () C:\Windows\system.ini
2014-05-10 20:18 - 2014-05-10 20:18 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-05-10 16:57 - 2014-05-10 16:57 - 00000000 _____ () C:\Windows\setuperr.log
2014-05-10 16:14 - 2014-05-10 13:27 - 00007597 _____ () C:\Users\Tina\AppData\Local\Resmon.ResmonCfg
2014-05-10 13:12 - 2013-09-16 21:18 - 00000000 ____D () C:\Program Files\Common Files\ArcSoft
2014-05-10 13:12 - 2013-08-05 15:20 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2014-05-10 13:11 - 2014-05-10 13:11 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-05-10 13:10 - 2013-08-05 13:54 - 00000000 ____D () C:\ProgramData\McAfee
2014-05-10 13:07 - 2014-03-01 21:35 - 00000000 ____D () C:\Users\Tina\AppData\Roaming\Samsung
2014-05-10 13:07 - 2014-03-01 21:35 - 00000000 ____D () C:\Users\Tina\AppData\Local\Samsung
2014-05-10 13:07 - 2014-03-01 21:31 - 00000000 ____D () C:\ProgramData\Samsung
2014-05-08 15:56 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-05-08 15:27 - 2014-05-08 15:27 - 00000000 ____D () C:\Program Files\McAfee.com
2014-05-08 15:13 - 2014-05-08 15:13 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-06 19:25 - 2013-08-05 13:32 - 00000000 ____D () C:\Users\Tina
2014-05-06 19:24 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\wfp
2014-05-06 19:23 - 2014-04-19 21:39 - 00000000 ____D () C:\Users\Tina\AppData\Local\gtk-2.0
2014-05-06 19:23 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\NDF
2014-05-06 19:23 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\registration
2014-05-02 18:04 - 2014-05-02 18:04 - 00012839 _____ () C:\Users\Tina\AppData\Local\recently-used.xbel
2014-05-02 18:04 - 2014-04-19 21:34 - 00000000 ____D () C:\Users\Tina\.gimp-2.8
2014-04-29 14:48 - 2014-05-08 15:10 - 17384448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-29 14:34 - 2014-05-08 15:10 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-28 23:36 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2014-04-27 23:35 - 2013-08-22 11:49 - 00000000 ____D () C:\Users\Tina\AppData\Roaming\vlc
2014-04-27 22:02 - 2014-04-12 21:10 - 00000000 ____D () C:\Users\Tina\AppData\Roaming\HpUpdate
2014-04-25 15:47 - 2010-11-20 23:01 - 01618856 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-23 06:44 - 2013-08-06 11:38 - 00000976 _____ () C:\Users\Tina\Desktop\Dropbox.lnk
2014-04-23 06:44 - 2013-08-06 11:33 - 00000000 ____D () C:\Users\Tina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-04-23 06:38 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE
2014-04-21 13:29 - 2013-08-07 21:01 - 00000000 ____D () C:\Users\Tina\AppData\Roaming\Skype
2014-04-21 10:24 - 2014-04-21 10:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-04-21 10:24 - 2014-04-21 10:23 - 00000000 ____D () C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
2014-04-21 10:23 - 2014-04-21 10:23 - 00000000 ____D () C:\Program Files\iPod
2014-04-21 10:23 - 2013-08-05 14:55 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-04-21 10:18 - 2013-08-05 14:55 - 00000000 ____D () C:\ProgramData\Apple
2014-04-19 22:02 - 2014-04-05 14:20 - 00002248 _____ () C:\Users\Public\Desktop\HP Photosmart 5520 series.lnk
2014-04-19 21:39 - 2014-04-19 21:39 - 00000000 ____D () C:\Users\Tina\.thumbnails
2014-04-19 21:34 - 2014-04-19 21:34 - 00000000 ____D () C:\Users\Tina\AppData\Local\gegl-0.2
2014-04-19 17:48 - 2014-04-19 17:48 - 00000748 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
2014-04-19 17:39 - 2014-04-19 17:38 - 90396104 _____ (The GIMP Team ) C:\Users\Tina\Downloads\gimp-2.8.10-setup.exe
2014-04-19 10:46 - 2009-07-14 06:33 - 03739608 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-04-15 20:53 - 2014-04-15 20:53 - 00000000 ____D () C:\Program Files\directx
2014-04-14 04:11 - 2014-05-07 13:53 - 00361984 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-04-14 04:07 - 2014-05-07 13:53 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-04-13 15:17 - 2013-08-27 15:36 - 00000000 ____D () C:\Program Files\PDFCreator
2014-04-13 14:59 - 2013-08-05 14:23 - 00000000 ____D () C:\Windows\Panther
2014-04-13 14:56 - 2014-04-13 14:56 - 00001121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-04-13 14:56 - 2014-04-13 14:56 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-04-13 14:56 - 2014-04-13 14:55 - 00000000 ____D () C:\Program Files\CCleaner
2014-04-13 14:56 - 2014-04-13 14:53 - 00000000 ____D () C:\Users\Tina\AppData\Local\Google
2014-04-13 14:56 - 2014-04-13 14:53 - 00000000 ____D () C:\Program Files\Google
2014-04-13 14:53 - 2014-04-13 14:53 - 04787368 _____ (Piriform Ltd) C:\Users\Tina\Downloads\ccsetup412.exe
2014-04-13 14:46 - 2014-03-01 22:25 - 00000000 ____D () C:\ProgramData\Adobe
2014-04-13 14:45 - 2013-08-05 15:45 - 00000000 ____D () C:\Users\Tina\AppData\Roaming\Adobe
2014-04-13 14:44 - 2014-03-01 22:25 - 00000000 ____D () C:\Program Files\Adobe
2014-04-13 14:17 - 2013-08-05 20:56 - 00000000 ____D () C:\Users\Tina\AppData\Local\Adobe
2014-04-13 14:16 - 2014-04-13 14:16 - 00000000 ____D () C:\Users\Tina\AppData\Roaming\PDAppFlex
2014-04-13 14:16 - 2013-08-05 15:15 - 00085360 _____ () C:\Users\Tina\AppData\Local\GDIPFONTCACHEV1.DAT
2014-04-13 14:10 - 2014-04-13 14:10 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
Some content of TEMP:
====================
C:\Users\Tina\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpnzekqv.dll
C:\Users\Tina\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-05-10 13:45
==================== End Of Log ============================ --- --- ---
Addition: Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version:11-05-2014 01
Ran by Tina at 2014-05-12 19:47:18
Running from C:\Users\Tina\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: McAfee Anti-Virus und Anti-Spyware (Enabled - Up to date) {ADA629C7-7F48-5689-624A-3B76997E0892}
AS: McAfee Anti-Virus und Anti-Spyware (Enabled - Up to date) {16C7C823-5972-5907-58FA-0004E2F9422F}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: McAfee Firewall (Enabled) {959DA8E2-3527-57D1-4915-924367AD4FE9}
==================== Installed Programs ======================
7-Zip 9.20 (HKLM\...\7-Zip) (Version: - )
Adobe AIR (HKLM\...\Adobe AIR) (Version: 3.8.0.870 - Adobe Systems Incorporated)
Adobe AIR (Version: 3.8.0.870 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 12 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated)
Apple Application Support (HKLM\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{18D47FA1-0440-48D3-A7E0-DA09537FF471}) (Version: 7.1.1.3 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Audacity 2.0.3 (HKLM\...\Audacity_is1) (Version: 2.0.3 - Audacity Team)
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 4.12 - Piriform)
D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
Die Sims™ 3 (HKLM\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.55.4 - Electronic Arts)
Dropbox (HKCU\...\Dropbox) (Version: 2.6.31 - Dropbox, Inc.)
Fotogalerie (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
GIMP 2.8.10 (HKLM\...\GIMP-2_is1) (Version: 2.8.10 - The GIMP Team)
HP FWUpdateEDO2 (HKLM\...\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: 1.2.0.0 - Hewlett-Packard)
HP Photosmart 5520 series - Grundlegende Software für das Gerät (HKLM\...\{88EFC235-396D-4A12-96AE-48C3451A0F79}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Photosmart 5520 series Hilfe (HKLM\...\{640A03B3-4E6B-4440-A350-E6A8D6348F12}) (Version: 27.0.0 - Hewlett Packard)
HP Update (HKLM\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard)
HTC BMP USB Driver (HKLM\...\{31A559C1-9E4D-423B-9DD3-34A6C5398752}) (Version: 1.0.5375 - HTC)
HTC Driver Installer (HKLM\...\{4CEEE5D0-F905-4688-B9F9-ECC710507796}) (Version: 4.5.0.001 - HTC Corporation)
HTC Sync (HKLM\...\{CBDAE89D-8ABD-4DC5-9309-C2C58696B371}) (Version: 3.3.63 - HTC Corporation)
ICQ 8.1 (build 6337) (HKCU\...\ICQ) (Version: 8.1.6337.0 - Mail.Ru)
Intel PROSet Wireless (Version: - ) Hidden
Intel(R) Processor Graphics (HKLM\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2932 - Intel Corporation)
Intel(R) PROSet/Wireless WiFi-Software (HKLM\...\{1927E640-A2C6-4BA7-8F43-FFD2AE3DFCF3}) (Version: 14.0.2000 - Intel Corporation)
IPTInstaller (HKLM\...\{08208143-777D-4A06-BB54-71BF0AD1BB70}) (Version: 4.0.8 - HTC)
iTunes (HKLM\...\{2F21564D-DE05-4C6D-B21E-08B9D313FAB3}) (Version: 11.1.5.5 - Apple Inc.)
JDownloader 0.9 (HKLM\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH)
Malwarebytes Anti-Malware Version 2.0.1.1004 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation)
McAfee Total Protection (HKLM\...\MSC) (Version: 12.8.957 - McAfee, Inc.)
Microsoft – Speichern als PDF oder XPS – Add-In für 2007 Microsoft Office-Programme (HKLM\...\{90120000-00B2-0407-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (Version: - Microsoft) Hidden
Microsoft Office Access MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (Version: - Microsoft) Hidden
Microsoft Office Publisher MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft_VC80_CRT_x86 (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC90_CRT_x86 (Version: 1.00.0000 - Adobe) Hidden
Microsoft-Maus- und Tastatur-Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.2.173.0 - Microsoft Corporation)
Microsoft-Maus- und Tastatur-Center (Version: 2.2.173.0 - Microsoft Corporation) Hidden
Movie Maker (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Mozilla Firefox 29.0.1 (x86 de) (HKLM\...\Mozilla Firefox 29.0.1 (x86 de)) (Version: 29.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MP3jam 1.1.0.11 (HKLM\...\MP3jam_is1) (Version: 1.1.0.11 - MP3jam)
MSVCRT (Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT110 (Version: 16.4.1108.0727 - Microsoft) Hidden
MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
Origin (HKLM\...\Origin) (Version: 9.3.1.4482 - Electronic Arts, Inc.)
PDF Architect (HKLM\...\{064A929A-4DE8-40CF-A901-BD40C14E4D25}) (Version: 1.1.83.9982 - pdfforge GmbH)
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.1 - pdfforge)
PDF-Viewer (HKLM\...\{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: 2.5.211.0 - Tracker Software Products Ltd)
Photo Common (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Photo Gallery (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
PureSync (Version: 3.7.6 - Jumping Bytes) Hidden
PureSync 3.7.6 (HKLM\...\PureSync) (Version: 3.7.6 - Jumping Bytes)
Realtek Ethernet Controller Driver (HKLM\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.40.126.2011 - Realtek)
Realtek PCIE Card Reader (HKLM\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7600.80 - Realtek Semiconductor Corp.)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.1.16.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (Version: 2.1.16.0 - Renesas Electronics Corporation) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.34.0 - SAMSUNG Electronics Co., Ltd.)
Shared C Run-time for x86 (Version: 10.0.0 - McAfee) Hidden
Skype™ 6.14 (HKLM\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.)
SSLx86 (Version: 1.0.0 - Sony Corporation ) Hidden
Unknown Device Identifier 8.00 (HKLM\...\Unknown Device Identifier_is1) (Version: - Huntersoft)
Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6FAA03BD-2B51-4029-9AD9-64A3B8E3C84C}) (Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{EA54F104-79D2-48CC-9ABC-91A63C43D353}) (Version: - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{53DEC068-4690-4F6B-9946-7D21EF02236B}) (Version: - Microsoft)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2878297) 32-Bit Edition (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{9B1DEEA3-B4ED-49F0-9EF7-4A820EEEA7F1}) (Version: - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft)
Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version: - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft)
VLC media player 2.0.8 (HKLM\...\VLC media player) (Version: 2.0.8 - VideoLAN)
VPMx86 (Version: 1.0.0 - Sony Corporation ) Hidden
Windows Live Communications Platform (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)
Windows Live Essentials (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden
Windows Live Installer (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Photo Common (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live SOXE (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live UX Platform (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
==================== Restore Points =========================
30-04-2014 12:09:50 Geplanter Prüfpunkt
01-05-2014 08:48:55 Windows Update
03-05-2014 09:03:26 Windows Update
06-05-2014 13:56:32 Wiederherstellungsvorgang
06-05-2014 20:28:46 Windows Update
07-05-2014 10:25:51 Windows Modules Installer
07-05-2014 10:26:33 Windows Modules Installer
08-05-2014 13:09:14 Windows Update
08-05-2014 14:43:33 Removed Samsung Kies
10-05-2014 11:09:08 Removed GTA2
10-05-2014 11:10:29 Removed Java 7 Update 45
10-05-2014 11:12:03 Entfernt WebCam Companion
==================== Hosts content: ==========================
2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {17E6B037-FCD7-4DFB-AB33-FE341A403BB5} - System32\Tasks\Microsoft\Windows\Multimedia\SMupdate3 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update3
Task: {274C59F4-BE53-4528-B2CE-C154A5FD6DDE} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation)
Task: {3D83A9C8-A411-4D4C-9C23-B2D4CC7AF084} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation)
Task: {559C4F57-4525-42E1-BD61-98304AFC257A} - System32\Tasks\Launch HTC Sync Loader => C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe [2013-09-03] ()
Task: {72D09447-A35F-4872-BEA3-BA057A7F5EEC} - System32\Tasks\CR setup => C:\Users\Tina\AppData\Local\Temp\Stub\-1901924738\ytd_bu10_setup.exe <==== ATTENTION
Task: {8D3B72C1-F796-49D6-AC0A-8B9571F64372} - System32\Tasks\Microsoft\Windows\Maintenance\SMupdate2 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update2
Task: {9C061CF4-4593-4FA1-8484-EF58E5CA2B47} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-03-18] (Piriform Ltd)
Task: {A4CB0702-9D23-48ED-8022-5291862A5717} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation)
Task: {B2A668B1-6BCA-4AE7-9791-B5A736811B0E} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation)
Task: {C0A65B31-D324-4962-9BE7-D730F5910E34} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2013-05-13] (Microsoft)
==================== Loaded Modules (whitelisted) =============
2014-02-12 20:58 - 2014-02-12 20:58 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2014-02-12 20:58 - 2014-02-12 20:58 - 01044808 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2014-03-01 22:26 - 2012-12-07 18:26 - 00167424 _____ () C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
2012-12-14 02:02 - 2012-12-14 02:02 - 00094208 _____ () C:\Windows\System32\IccLibDll.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"
==================== EXE Association (whitelisted) =============
==================== Disabled items from MSCONFIG ==============
MSCONFIG\startupreg: APSDaemon => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: HP Photosmart 5520 series (NET) => "C:\Program Files\HP\HP Photosmart 5520 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN3A1530WW0602:NW" -scfn "HP Photosmart 5520 series (NET)" -AutoStart 1
MSCONFIG\startupreg: icq => C:\Users\Tina\AppData\Roaming\ICQM\icq.exe -CU
MSCONFIG\startupreg: iTunesHelper => "D:\Program Files\iTunes\iTunesHelper.exe"
==================== Faulty Device Manager Devices =============
Name: Standard-VGA-Grafikkarte
Description: Standard-VGA-Grafikkarte
Class Guid: {4d36e968-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standardgrafikkartentypen)
Service: vga
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (05/12/2014 07:40:31 PM) (Source: Bonjour Service) (User: ) (EventID: 100)
Description: Task Scheduling Error: m->NextScheduledSPRetry 9877469
Error: (05/12/2014 07:40:31 PM) (Source: Bonjour Service) (User: ) (EventID: 100)
Description: Task Scheduling Error: m->NextScheduledEvent 9877469
Error: (05/12/2014 07:40:31 PM) (Source: Bonjour Service) (User: ) (EventID: 100)
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (05/12/2014 07:40:30 PM) (Source: Bonjour Service) (User: ) (EventID: 100)
Description: Task Scheduling Error: m->NextScheduledSPRetry 9876470
Error: (05/12/2014 07:40:30 PM) (Source: Bonjour Service) (User: ) (EventID: 100)
Description: Task Scheduling Error: m->NextScheduledEvent 9876470
Error: (05/12/2014 07:40:30 PM) (Source: Bonjour Service) (User: ) (EventID: 100)
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (05/12/2014 07:40:28 PM) (Source: Bonjour Service) (User: ) (EventID: 100)
Description: Task Scheduling Error: m->NextScheduledSPRetry 9875441
Error: (05/12/2014 07:40:28 PM) (Source: Bonjour Service) (User: ) (EventID: 100)
Description: Task Scheduling Error: m->NextScheduledEvent 9875441
Error: (05/12/2014 07:40:28 PM) (Source: Bonjour Service) (User: ) (EventID: 100)
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (05/12/2014 07:40:27 PM) (Source: Bonjour Service) (User: ) (EventID: 100)
Description: Task Scheduling Error: m->NextScheduledSPRetry 9874411
System errors:
=============
Error: (05/12/2014 07:41:21 PM) (Source: Service Control Manager) (User: ) (EventID: 7011)
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst IconMan_R erreicht.
Error: (05/12/2014 07:40:26 PM) (Source: Service Control Manager) (User: ) (EventID: 7011)
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Wlansvc erreicht.
Error: (05/12/2014 04:25:13 PM) (Source: Service Control Manager) (User: ) (EventID: 7011)
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Netman erreicht.
Error: (05/12/2014 04:25:13 PM) (Source: DCOM) (User: ) (EventID: 10010)
Description: {FE9617F6-E606-42AA-BECC-0E9CDA246D63}
Error: (05/12/2014 11:59:46 AM) (Source: Service Control Manager) (User: ) (EventID: 7000)
Description: Der Dienst "UPnP-Gerätehost" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1069
Error: (05/12/2014 11:59:46 AM) (Source: Service Control Manager) (User: ) (EventID: 7038)
Description: Der Dienst "upnphost" konnte sich nicht als "NT AUTHORITY\LocalService" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden:
%%1352
Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC).
Error: (05/12/2014 11:59:46 AM) (Source: DCOM) (User: ) (EventID: 10005)
Description: 1069upnphost{204810B9-73B2-11D4-BF42-00B0D0118B56}
Microsoft Office Sessions:
=========================
Error: (04/17/2014 10:26:32 PM) (Source: Microsoft Office 12 Sessions) (User: ) (EventID: 7001)
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6691.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 357 seconds with 120 seconds of active time. This session ended with a crash.
==================== Memory info ===========================
Percentage of memory in use: 43%
Total physical RAM: 2477.82 MB
Available physical RAM: 1400.23 MB
Total Pagefile: 4953.94 MB
Available Pagefile: 3524.05 MB
Total Virtual: 2047.88 MB
Available Virtual: 1913.86 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:151.27 GB) (Free:117.83 GB) NTFS
Drive d: () (Fixed) (Total:314.39 GB) (Free:68 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 2D3D172A)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=151 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=314 GB) - (Type=07 NTFS)
==================== End Of Log ============================ |