der-kurti | 01.07.2014 17:20 | und hier ist die zweite: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-06-2014
Ran by Erkut at 2014-07-01 18:16:52
Running from C:\Users\Erkut\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
==================== Installed Programs ======================
Absolute Reminder (HKLM-x32\...\{40F4FF7A-B214-4453-B973-080B09CED019}) (Version: 2.2.0.26 - Absolute Software)
Adobe Photoshop Elements 11 (HKLM-x32\...\Adobe Photoshop Elements 11) (Version: 11.0 - Adobe Systems Incorporated)
Adobe Photoshop Elements 11 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
Adobe Reader X (10.1.3) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.3 - Adobe Systems Incorporated)
AMD Accelerated Video Transcoding (Version: 12.5.100.21127 - Advanced Micro Devices, Inc.) Hidden
AMD APP SDK Runtime (Version: 10.0.1016.4 - Advanced Micro Devices Inc.) Hidden
AMD Catalyst Install Manager (HKLM\...\{77A7CE43-5A1E-8282-931B-E0CC4C075793}) (Version: 8.0.891.0 - Advanced Micro Devices, Inc.)
avast! Free Antivirus (HKLM-x32\...\Avast) (Version: 9.0.2021 - AVAST Software)
Bitcasa version 0.9.20.4135 (HKLM\...\{EDA09459-AD7D-4434-BA0C-647F6703EA12}_is1) (Version: 0.9.20.4135 - Bitcasa Inc.)
Buzzdock (HKLM\...\{ac225167-00fc-452d-94c5-bb93600e7d9a}) (Version: - Alactro LLC)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center (x32 Version: 2012.1127.15.314 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2012.1127.15.314 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2012.1127.15.314 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Profiles Mobile (x32 Version: 2012.1127.15.314 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (x32 Version: 2012.1127.0014.314 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (x32 Version: 2012.1127.0014.314 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (x32 Version: 2012.1127.0014.314 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (x32 Version: 2012.1127.0014.314 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (x32 Version: 2012.1127.0014.314 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (x32 Version: 2012.1127.0014.314 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (x32 Version: 2012.1127.0014.314 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (x32 Version: 2012.1127.0014.314 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (x32 Version: 2012.1127.0014.314 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (x32 Version: 2012.1127.0014.314 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (x32 Version: 2012.1127.0014.314 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (x32 Version: 2012.1127.0014.314 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (x32 Version: 2012.1127.0014.314 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (x32 Version: 2012.1127.0014.314 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (x32 Version: 2012.1127.0014.314 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (x32 Version: 2012.1127.0014.314 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (x32 Version: 2012.1127.0014.314 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (x32 Version: 2012.1127.0014.314 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (x32 Version: 2012.1127.0014.314 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (x32 Version: 2012.1127.0014.314 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (x32 Version: 2012.1127.0014.314 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (x32 Version: 2012.1127.0014.314 - Advanced Micro Devices, Inc.) Hidden
ccc-utility64 (Version: 2012.1127.15.314 - Advanced Micro Devices, Inc.) Hidden
CyberLink PowerDVD 10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.4421.02 - CyberLink Corp.)
CyberLink PowerDVD 10 (x32 Version: 10.0.4421.02 - CyberLink Corp.) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dropbox (HKCU\...\Dropbox) (Version: 2.8.2 - Dropbox, Inc.)
Easy File Share (HKLM-x32\...\{A7C37D4B-F37A-42E8-9B6A-B28C18AD4C12}) (Version: 1.3.6 - Samsung Electronics CO.,LTD.)
Elements 11 Organizer (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
E-POP (HKLM-x32\...\{F06DD8D9-9DC8-430C-835C-C9BF21E05CC1}) (Version: 1.0.1 - Samsung Electronics CO., LTD.)
ETDWare X64 11.7.10.4_WHQL (HKLM\...\Elantech) (Version: 11.7.10.4 - ELAN Microelectronic Corp.)
Firebird SQL Server - MAGIX Edition (HKLM-x32\...\{39AB2E37-1A55-4292-A5D3-971E9F70D0F8}) (Version: 2.1.32.0 - MAGIX AG)
Fotogalerie (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Galerie de photos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 35.0.1916.153 - Google Inc.)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
Help Desk (HKLM\...\{AEC9D273-E162-4614-83F1-722B8C74B185}) (Version: 1.0.96 - Samsung Electronics CO., LTD.)
Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.36843 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.30.1349 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.2963 - Intel Corporation)
Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed (Version: 15.6.1.0536 - Intel Corporation) Hidden
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{DA2600C1-6BDF-4FD1-8F3D-148929CC1385}) (Version: 2.6.1210.0278 - Intel Corporation)
Intel(R) PROSet/Wireless WiFi Software Driver (Version: 15.06.1000.0199 - Intel Corporation) Hidden
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.7.0.1013 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Intel(R) WiDi (HKLM\...\{6097158B-0184-4140-BEC3-7885794D2571}) (Version: 3.5.40.0 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{87d45b7e-19da-4dd5-9214-5e0d587c312f}) (Version: 15.6.1 - Intel Corporation)
Intel® PROSet/Wireless WiFi Software (Version: 15.06.1000.0142 - Intel Corporation) Hidden
Intel® Trusted Connect Service Client (Version: 1.27.757.1 - Intel Corporation) Hidden
IntelliMemory (HKLM\...\{40320F22-7D70-49DB-9D66-B6FAE5F36B47}) (Version: 1.0.32.0 - Condusiv Technologies)
MAGIX Speed burnR (MSI) (HKLM-x32\...\MX.{49209082-E4F9-410D-B74D-E6506977F30B}) (Version: 7.0.2.6 - MAGIX AG)
MAGIX Speed burnR (MSI) (Version: 7.0.2.6 - MAGIX AG) Hidden
MAGIX Video deluxe 2014 Plus (HKLM-x32\...\MX.{85061988-E889-4A37-9CB7-4F695AC35544}) (Version: 13.0.2.8 - MAGIX AG)
MAGIX Video deluxe 2014 Plus (Version: 13.0.2.8 - MAGIX AG) Hidden
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden
MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
OEM Application Profile (HKLM-x32\...\{EE55B368-EBDF-98F3-CFE7-7CE4ADBC4553}) (Version: 1.00.0004 - Advanced Micro Devices, Inc.)
Phone Screen Sharing (HKLM-x32\...\{DF02C515-40B5-45AC-A601-5DC69D03885C}) (Version: 2.0.0.21 - RSUPPORT)
Photo Common (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Photo Gallery (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
PowerXpressHybrid (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
PSE11 STI Installer (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
PX Profile Update (x32 Version: 1.00.1. - AMD) Hidden
Raccolta foto (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.9.1212.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6818 - Realtek Semiconductor Corp.)
Realtek USB Card Reader (HKLM-x32\...\{1E496A68-4943-424E-829D-5C3C85B7B8F2}) (Version: 6.2.9200.39036 - Realtek Semiconductor Corp.)
Recovery (HKLM-x32\...\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 6.0.9.7 - Samsung Electronics CO., LTD.)
S Agent (Version: 1.1.47 - Samsung Electronics CO., LTD.) Hidden
Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.5.2.13021_11 - Samsung Electronics Co., Ltd.)
Samsung Kies (x32 Version: 2.5.2.13021_11 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.25.0 - SAMSUNG Electronics Co., Ltd.)
Settings (HKLM-x32\...\{8CB5C357-12E5-41B1-A024-D57D4E6F32D9}) (Version: 2.0.1 - Samsung Electronics CO., LTD.)
SideSync (HKLM-x32\...\{59687468-8CE9-4ABF-9C6A-5C31F0E09F8B}) (Version: 2.0.0 - Samsung Electronics CO., LTD.)
SRS Premium Sound (HKLM-x32\...\{E44F8A34-529E-4318-A0E1-1893C337A47F}) (Version: 1.00.2600 - DTS, Inc.)
Support Center (HKLM\...\{AB0DEFBB-1A16-47B5-86D2-39F0A2B24AE4}) (Version: 2.1.1210 - Samsung Electronics CO., LTD.)
Support Center FAQ (x32 Version: 1.0.14 - Samsung Electronics CO., LTD.) Hidden
SW Update (HKLM-x32\...\{D2B5F1E3-EA56-4D84-A453-A213B32974CB}) (Version: 2.1.25 - Samsung Electronics CO., LTD.)
sweet-page uninstall (HKLM-x32\...\sweet-page uninstall) (Version: - sweet-page) <==== ATTENTION
User Guide (HKLM-x32\...\{C7343D0D-E05B-4561-AAF1-8EDF0FEA1EAE}) (Version: 1.2.00 - Samsung Electronics CO., LTD.)
Windows Live (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)
Windows Live (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Communications Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Essentials (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
==================== Restore Points =========================
25-06-2014 17:55:23 Intel® PROSet/Wireless Software
28-06-2014 08:40:25 Wiederherstellungsvorgang
29-06-2014 10:55:21 Sprachpaketdeinstallation
01-07-2014 15:09:52 ComboFix created restore point
==================== Hosts content: ==========================
2012-07-26 07:26 - 2014-06-30 19:34 - 00000027 ____A C:\windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
Task: {03A70337-00BA-4B18-8888-7FB3BF4444E4} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2012-09-13] (Intel Corporation)
Task: {072A0C1E-9D0B-4A5A-8E94-89BE06D1F513} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\windows\system32\MRT.exe [2014-06-01] (Microsoft Corporation)
Task: {0EFABB3C-98CC-4CF7-839E-1C6E9662DFBD} - System32\Tasks\Microsoft\Windows\Setup\Pre-staged GDR Notification => C:\Windows\system32\NotificationUI.exe [2014-04-19] (Microsoft Corporation)
Task: {129BFEBC-FC51-47FA-A67D-FB068A7B2B57} - System32\Tasks\Settings => C:\Program Files (x86)\Samsung\Settings\sSettings.exe [2014-01-29] (Samsung Electronics CO., LTD.)
Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {40254841-9AA3-442B-934D-BE1BCD6A39ED} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2012-09-13] (Intel Corporation)
Task: {43D4FDAA-4606-4A46-831F-DEC7419338C5} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\20.3.0.36\WSCStub.exe
Task: {779A1234-9901-4668-827A-4CB7A6C4D817} - System32\Tasks\advRecovery => C:\Program Files\Samsung\Recovery\WCScheduler.exe [2013-04-30] (SEC)
Task: {7CACB453-74E4-4097-B0A4-21624104B2C3} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-06-28] (AVAST Software)
Task: {9D8A24F5-BE19-44C2-B301-82191EB33F73} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\20.3.0.36\SymErr.exe
Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {B591987F-6924-4519-B933-58E7291EC981} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\20.3.0.36\SymErr.exe
Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {DD4AC9A6-1819-47F1-89EE-F6EC68EEEDC0} - System32\Tasks\SAgent => C:\Program Files\Samsung\S Agent\CommonAgent.exe [2014-03-19] (Samsung Electronics CO., LTD.)
Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {EE6722B4-1A9B-4008-9EBB-90351FB18C81} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-06-25] (Google Inc.)
Task: {F4FED40C-6C6C-4101-8A4E-2E19DFE6446D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-06-25] (Google Inc.)
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2014-01-29 13:20 - 2014-01-29 13:20 - 00084800 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe
2013-01-03 02:50 - 2012-11-01 07:43 - 00175008 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4396.1016_x64__8wekyb3d8bbwe\ModernShared\ErrorReporting\ErrorReporting.dll
2013-02-05 06:50 - 2013-01-16 05:27 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2014-03-19 11:41 - 2014-03-19 11:41 - 00088624 _____ () C:\Program Files\Samsung\S Agent\ToastX64.dll
2014-06-28 18:04 - 2014-06-28 18:04 - 00301152 _____ () C:\Program Files\AVAST Software\Avast\aswProperty.dll
2014-07-01 17:38 - 2014-07-01 17:38 - 02789376 _____ () C:\Program Files\AVAST Software\Avast\defs\14063001\algo.dll
2014-01-29 13:20 - 2014-01-29 13:20 - 00027968 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdWrapper.dll
2014-01-29 13:20 - 2014-01-29 13:20 - 01141056 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmd.dll
2014-01-29 13:20 - 2014-01-29 13:20 - 00109888 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsBase.dll
2014-01-29 13:20 - 2014-01-29 13:20 - 00056440 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\HookDllPS2.dll
2014-01-29 13:20 - 2014-01-29 13:20 - 00211064 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\WinCRT.dll
2014-01-29 13:20 - 2014-01-29 13:20 - 00025920 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsAPI.dll
2014-01-29 13:20 - 2014-01-29 13:20 - 00109888 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsBase.dll
2014-01-29 13:20 - 2014-01-29 13:20 - 00059712 _____ () C:\Program Files (x86)\Samsung\Settings\EasyMovieEnhancer.dll
2014-01-29 13:20 - 2014-01-29 13:20 - 00102720 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsCmdClient.dll
2014-06-25 17:40 - 2014-06-05 15:58 - 00716616 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\libglesv2.dll
2014-06-25 17:40 - 2014-06-05 15:58 - 00126280 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\libegl.dll
2014-06-25 17:40 - 2014-06-05 15:58 - 04217672 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\pdf.dll
2014-06-25 17:40 - 2014-06-05 15:58 - 00414536 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\ppGoogleNaClPluginChrome.dll
2014-06-25 17:40 - 2014-06-05 15:58 - 01732424 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\ffmpegsumo.dll
2014-07-01 18:04 - 2014-07-01 18:04 - 00043008 _____ () c:\users\erkut\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpcxcm0m.dll
2013-08-23 21:01 - 2013-08-23 21:01 - 25100288 _____ () C:\Users\Erkut\AppData\Roaming\Dropbox\bin\libcef.dll
2014-06-28 18:04 - 2014-06-28 18:04 - 19329904 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2013-05-24 17:47 - 2013-01-14 20:25 - 01200088 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
==================== EXE Association (whitelisted) =============
==================== MSCONFIG/TASK MANAGER disabled items =========
==================== Faulty Device Manager Devices =============
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (07/01/2014 05:27:41 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: der-kurti.exe, Version: 0.0.0.0, Zeitstempel: 0x4f25baec
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.2.9200.16578, Zeitstempel: 0x515fac6e
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00059472
ID des fehlerhaften Prozesses: 0x774
Startzeit der fehlerhaften Anwendung: 0xder-kurti.exe0
Pfad der fehlerhaften Anwendung: der-kurti.exe1
Pfad des fehlerhaften Moduls: der-kurti.exe2
Berichtskennung: der-kurti.exe3
Vollständiger Name des fehlerhaften Pakets: der-kurti.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: der-kurti.exe5
Error: (06/30/2014 07:18:02 PM) (Source: ESENT) (EventID: 454) (User: )
Description: taskhostex (2076) WebCacheLocal: Bei Datenbankwiederherstellung trat ein unerwarteter Fehler -1032 auf.
Error: (06/30/2014 07:18:02 PM) (Source: ESENT) (EventID: 490) (User: )
Description: taskhostex (2076) WebCacheLocal: Versuch, Datei "C:\Users\Erkut\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat" für den Lese-/Schreibzugriff zu öffnen, ist mit Systemfehler 32 (0x00000020): "Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird. " fehlgeschlagen. Fehler -1032 (0xfffffbf8) beim Öffnen von Dateien.
Error: (06/30/2014 06:36:55 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: der-kurti.exe, Version: 0.0.0.0, Zeitstempel: 0x4f25baec
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.2.9200.16578, Zeitstempel: 0x515fac6e
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00059472
ID des fehlerhaften Prozesses: 0x1b4c
Startzeit der fehlerhaften Anwendung: 0xder-kurti.exe0
Pfad der fehlerhaften Anwendung: der-kurti.exe1
Pfad des fehlerhaften Moduls: der-kurti.exe2
Berichtskennung: der-kurti.exe3
Vollständiger Name des fehlerhaften Pakets: der-kurti.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: der-kurti.exe5
Error: (06/30/2014 06:36:42 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: der-kurti.exe, Version: 0.0.0.0, Zeitstempel: 0x4f25baec
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.2.9200.16578, Zeitstempel: 0x515fac6e
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00059472
ID des fehlerhaften Prozesses: 0x1268
Startzeit der fehlerhaften Anwendung: 0xder-kurti.exe0
Pfad der fehlerhaften Anwendung: der-kurti.exe1
Pfad des fehlerhaften Moduls: der-kurti.exe2
Berichtskennung: der-kurti.exe3
Vollständiger Name des fehlerhaften Pakets: der-kurti.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: der-kurti.exe5
Error: (06/30/2014 06:30:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: der-kurti.exe, Version: 0.0.0.0, Zeitstempel: 0x4f25baec
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.2.9200.16578, Zeitstempel: 0x515fac6e
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00059472
ID des fehlerhaften Prozesses: 0xf9c
Startzeit der fehlerhaften Anwendung: 0xder-kurti.exe0
Pfad der fehlerhaften Anwendung: der-kurti.exe1
Pfad des fehlerhaften Moduls: der-kurti.exe2
Berichtskennung: der-kurti.exe3
Vollständiger Name des fehlerhaften Pakets: der-kurti.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: der-kurti.exe5
Error: (06/30/2014 06:11:54 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: der-kurti.exe, Version: 0.0.0.0, Zeitstempel: 0x4f25baec
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.2.9200.16578, Zeitstempel: 0x515fac6e
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00059472
ID des fehlerhaften Prozesses: 0x8f8
Startzeit der fehlerhaften Anwendung: 0xder-kurti.exe0
Pfad der fehlerhaften Anwendung: der-kurti.exe1
Pfad des fehlerhaften Moduls: der-kurti.exe2
Berichtskennung: der-kurti.exe3
Vollständiger Name des fehlerhaften Pakets: der-kurti.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: der-kurti.exe5
Error: (06/30/2014 06:05:28 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: der-kurti.exe, Version: 0.0.0.0, Zeitstempel: 0x4f25baec
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.2.9200.16578, Zeitstempel: 0x515fac6e
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00059472
ID des fehlerhaften Prozesses: 0x730
Startzeit der fehlerhaften Anwendung: 0xder-kurti.exe0
Pfad der fehlerhaften Anwendung: der-kurti.exe1
Pfad des fehlerhaften Moduls: der-kurti.exe2
Berichtskennung: der-kurti.exe3
Vollständiger Name des fehlerhaften Pakets: der-kurti.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: der-kurti.exe5
Error: (06/30/2014 05:49:26 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: der-kurti.exe, Version: 0.0.0.0, Zeitstempel: 0x4f25baec
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.2.9200.16578, Zeitstempel: 0x515fac6e
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00059472
ID des fehlerhaften Prozesses: 0x10e0
Startzeit der fehlerhaften Anwendung: 0xder-kurti.exe0
Pfad der fehlerhaften Anwendung: der-kurti.exe1
Pfad des fehlerhaften Moduls: der-kurti.exe2
Berichtskennung: der-kurti.exe3
Vollständiger Name des fehlerhaften Pakets: der-kurti.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: der-kurti.exe5
Error: (06/29/2014 08:18:04 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: der-kurti.exe, Version: 0.0.0.0, Zeitstempel: 0x4f25baec
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.2.9200.16578, Zeitstempel: 0x515fac6e
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00059472
ID des fehlerhaften Prozesses: 0x109c
Startzeit der fehlerhaften Anwendung: 0xder-kurti.exe0
Pfad der fehlerhaften Anwendung: der-kurti.exe1
Pfad des fehlerhaften Moduls: der-kurti.exe2
Berichtskennung: der-kurti.exe3
Vollständiger Name des fehlerhaften Pakets: der-kurti.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: der-kurti.exe5
System errors:
=============
Error: (07/01/2014 06:02:57 PM) (Source: Microsoft-Windows-Kernel-General) (EventID: 6) (User: NT-AUTORITÄT)
Description: 0xc000014d0
Error: (07/01/2014 05:35:30 PM) (Source: Microsoft-Windows-Kernel-General) (EventID: 6) (User: NT-AUTORITÄT)
Description: 0xc000014d0
Error: (07/01/2014 05:30:37 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Adobe Active File Monitor V11" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (07/01/2014 05:18:34 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (07/01/2014 05:15:34 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (06/30/2014 07:34:16 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (06/30/2014 07:33:21 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \??\C:\ComboFix\catchme.sys
Error: (06/30/2014 07:29:31 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (06/30/2014 07:23:39 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "SW Update Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (06/30/2014 07:23:39 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "WindowsProtectManger Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Microsoft Office Sessions:
=========================
Error: (07/01/2014 05:27:41 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: der-kurti.exe0.0.0.04f25baecntdll.dll6.2.9200.16578515fac6ec00000050005947277401cf9540fe6f95e3C:\Users\Erkut\Desktop\der-kurti.exeC:\windows\SYSTEM32\ntdll.dll3cf1eaec-0134-11e4-be89-c4d987011e08
Error: (06/30/2014 07:18:02 PM) (Source: ESENT) (EventID: 454) (User: )
Description: taskhostex2076WebCacheLocal: -1032
Error: (06/30/2014 07:18:02 PM) (Source: ESENT) (EventID: 490) (User: )
Description: taskhostex2076WebCacheLocal: C:\Users\Erkut\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat-1032 (0xfffffbf8)32 (0x00000020)Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird.
Error: (06/30/2014 06:36:55 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: der-kurti.exe0.0.0.04f25baecntdll.dll6.2.9200.16578515fac6ec0000005000594721b4c01cf948180fad3c7C:\Users\Erkut\Desktop\der-kurti.exeC:\windows\SYSTEM32\ntdll.dllbeaed4a3-0074-11e4-be88-c4d987011e08
Error: (06/30/2014 06:36:42 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: der-kurti.exe0.0.0.04f25baecntdll.dll6.2.9200.16578515fac6ec000000500059472126801cf948179064558C:\Users\Erkut\Desktop\der-kurti.exeC:\windows\SYSTEM32\ntdll.dllb6d9368d-0074-11e4-be88-c4d987011e08
Error: (06/30/2014 06:30:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: der-kurti.exe0.0.0.04f25baecntdll.dll6.2.9200.16578515fac6ec000000500059472f9c01cf948091b50e5eC:\Users\Erkut\Desktop\der-kurti.exeC:\windows\SYSTEM32\ntdll.dlld3616df2-0073-11e4-be88-c4d987011e08
Error: (06/30/2014 06:11:54 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: der-kurti.exe0.0.0.04f25baecntdll.dll6.2.9200.16578515fac6ec0000005000594728f801cf947e024f9144C:\Users\Erkut\Desktop\der-kurti.exeC:\windows\SYSTEM32\ntdll.dll401a86fa-0071-11e4-be87-c4d987011e08
Error: (06/30/2014 06:05:28 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: der-kurti.exe0.0.0.04f25baecntdll.dll6.2.9200.16578515fac6ec00000050005947273001cf947d1c4e8927C:\Users\Erkut\Desktop\der-kurti.exeC:\windows\SYSTEM32\ntdll.dll5a1fb874-0070-11e4-be87-c4d987011e08
Error: (06/30/2014 05:49:26 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: der-kurti.exe0.0.0.04f25baecntdll.dll6.2.9200.16578515fac6ec00000050005947210e001cf947ade08d785C:\Users\Erkut\Desktop\der-kurti.exeC:\windows\SYSTEM32\ntdll.dll1cade2ca-006e-11e4-be87-c4d987011e08
Error: (06/29/2014 08:18:04 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: der-kurti.exe0.0.0.04f25baecntdll.dll6.2.9200.16578515fac6ec000000500059472109c01cf93c676eaadebC:\Users\Erkut\Desktop\der-kurti.exeC:\windows\SYSTEM32\ntdll.dllb58ca191-ffb9-11e3-be87-c4d987011e08
CodeIntegrity Errors:
===================================
Date: 2014-06-30 19:33:21.289
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
==================== Memory info ===========================
Percentage of memory in use: 81%
Total physical RAM: 8076.76 MB
Available physical RAM: 1478.91 MB
Total Pagefile: 16268.77 MB
Available Pagefile: 9469.83 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:906.82 GB) (Free:830.08 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 932 GB) (Disk ID: 68918664)
Partition: GPT Partition Type.
==================== End Of Log ============================ |