Code:
Alles auswählen Aufklappen ATTFilter
Avira Free Antivirus
Erstellungsdatum der Reportdatei: Dienstag, 10. September 2013 16:50
Das Programm läuft als uneingeschränkte Vollversion.
Online-Dienste stehen zur Verfügung.
Lizenznehmer : Avira Free Antivirus
Seriennummer : 0000149996-ADJIE-0000001
Plattform : Windows 7 Home Premium
Windowsversion : (Service Pack 1) [6.1.7601]
Boot Modus : Normal gebootet
Benutzername : SYSTEM
Computername : ALEXANDE-PC
Versionsinformationen:
BUILD.DAT : 13.0.0.4052 55009 Bytes 29.08.2013 17:56:00
AVSCAN.EXE : 13.6.20.2100 639032 Bytes 04.09.2013 09:00:42
AVSCANRC.DLL : 13.6.20.2174 63032 Bytes 04.09.2013 09:00:42
LUKE.DLL : 13.6.20.2174 65080 Bytes 04.09.2013 09:01:18
AVSCPLR.DLL : 13.6.20.2174 92216 Bytes 04.09.2013 09:00:42
AVREG.DLL : 13.6.20.2174 250424 Bytes 04.09.2013 09:00:41
avlode.dll : 13.6.20.2174 497720 Bytes 04.09.2013 09:00:39
avlode.rdf : 13.0.1.42 26846 Bytes 28.08.2013 17:53:01
VBASE000.VDF : 7.11.70.0 66736640 Bytes 04.04.2013 18:16:12
VBASE001.VDF : 7.11.74.226 2201600 Bytes 30.04.2013 20:16:32
VBASE002.VDF : 7.11.80.60 2751488 Bytes 28.05.2013 20:02:42
VBASE003.VDF : 7.11.85.214 2162688 Bytes 21.06.2013 12:07:57
VBASE004.VDF : 7.11.91.176 3903488 Bytes 23.07.2013 20:56:29
VBASE005.VDF : 7.11.98.186 6822912 Bytes 29.08.2013 18:03:21
VBASE006.VDF : 7.11.98.187 2048 Bytes 29.08.2013 18:03:22
VBASE007.VDF : 7.11.98.188 2048 Bytes 29.08.2013 18:03:22
VBASE008.VDF : 7.11.98.189 2048 Bytes 29.08.2013 18:03:22
VBASE009.VDF : 7.11.98.190 2048 Bytes 29.08.2013 18:03:22
VBASE010.VDF : 7.11.98.191 2048 Bytes 29.08.2013 18:03:22
VBASE011.VDF : 7.11.98.192 2048 Bytes 29.08.2013 18:03:23
VBASE012.VDF : 7.11.98.193 2048 Bytes 29.08.2013 18:03:23
VBASE013.VDF : 7.11.99.52 270848 Bytes 30.08.2013 18:17:32
VBASE014.VDF : 7.11.99.167 210944 Bytes 02.09.2013 09:51:28
VBASE015.VDF : 7.11.100.3 265216 Bytes 03.09.2013 20:50:59
VBASE016.VDF : 7.11.100.95 220160 Bytes 04.09.2013 20:59:50
VBASE017.VDF : 7.11.100.197 143872 Bytes 05.09.2013 09:36:48
VBASE018.VDF : 7.11.101.11 227840 Bytes 06.09.2013 08:04:48
VBASE019.VDF : 7.11.101.79 148480 Bytes 07.09.2013 14:04:37
VBASE020.VDF : 7.11.101.169 305664 Bytes 10.09.2013 13:08:27
VBASE021.VDF : 7.11.101.170 2048 Bytes 10.09.2013 13:08:27
VBASE022.VDF : 7.11.101.171 2048 Bytes 10.09.2013 13:08:28
VBASE023.VDF : 7.11.101.172 2048 Bytes 10.09.2013 13:08:28
VBASE024.VDF : 7.11.101.173 2048 Bytes 10.09.2013 13:08:28
VBASE025.VDF : 7.11.101.174 2048 Bytes 10.09.2013 13:08:28
VBASE026.VDF : 7.11.101.175 2048 Bytes 10.09.2013 13:08:28
VBASE027.VDF : 7.11.101.176 2048 Bytes 10.09.2013 13:08:29
VBASE028.VDF : 7.11.101.177 2048 Bytes 10.09.2013 13:08:29
VBASE029.VDF : 7.11.101.178 2048 Bytes 10.09.2013 13:08:29
VBASE030.VDF : 7.11.101.179 2048 Bytes 10.09.2013 13:08:29
VBASE031.VDF : 7.11.101.196 60416 Bytes 10.09.2013 13:08:29
Engineversion : 8.2.12.118
AEVDF.DLL : 8.1.3.4 102774 Bytes 16.06.2013 14:38:20
AESCRIPT.DLL : 8.1.4.148 516478 Bytes 07.09.2013 08:05:02
AESCN.DLL : 8.1.10.4 131446 Bytes 08.04.2013 18:16:19
AESBX.DLL : 8.2.16.26 1245560 Bytes 23.08.2013 22:31:41
AERDL.DLL : 8.2.0.128 688504 Bytes 16.06.2013 14:38:19
AEPACK.DLL : 8.3.2.24 749945 Bytes 20.06.2013 08:40:06
AEOFFICE.DLL : 8.1.2.76 205181 Bytes 08.08.2013 13:36:33
AEHEUR.DLL : 8.1.4.608 6148474 Bytes 07.09.2013 08:05:01
AEHELP.DLL : 8.1.27.6 266617 Bytes 27.08.2013 14:35:11
AEGEN.DLL : 8.1.7.14 446839 Bytes 07.09.2013 08:04:50
AEEXP.DLL : 8.4.1.60 323959 Bytes 07.09.2013 08:05:02
AEEMU.DLL : 8.1.3.2 393587 Bytes 11.07.2012 12:26:55
AECORE.DLL : 8.1.32.0 201081 Bytes 23.08.2013 22:31:35
AEBB.DLL : 8.1.1.4 53619 Bytes 05.11.2012 16:26:41
AVWINLL.DLL : 13.6.20.2174 23608 Bytes 04.09.2013 09:00:22
AVPREF.DLL : 13.6.20.2174 48184 Bytes 04.09.2013 09:00:40
AVREP.DLL : 13.6.20.2174 175672 Bytes 04.09.2013 09:00:41
AVARKT.DLL : 13.6.20.2174 258104 Bytes 04.09.2013 09:00:29
AVEVTLOG.DLL : 13.6.20.2174 165432 Bytes 04.09.2013 09:00:35
SQLITE3.DLL : 3.7.0.1 397704 Bytes 01.03.2013 21:54:31
AVSMTP.DLL : 13.6.20.2174 60472 Bytes 04.09.2013 09:00:43
NETNT.DLL : 13.6.20.2174 13368 Bytes 04.09.2013 09:01:19
RCIMAGE.DLL : 13.6.20.2174 4786744 Bytes 04.09.2013 09:00:22
RCTEXT.DLL : 13.6.20.2174 68152 Bytes 04.09.2013 09:00:22
Konfiguration für den aktuellen Suchlauf:
Job Name..............................: AVGuardAsyncScan
Konfigurationsdatei...................: C:\ProgramData\Avira\AntiVir Desktop\TEMP\AVGUARD_522f2206\guard_slideup.avp
Protokollierung.......................: standard
Primäre Aktion........................: Reparieren
Sekundäre Aktion......................: Quarantäne
Durchsuche Masterbootsektoren.........: ein
Durchsuche Bootsektoren...............: aus
Durchsuche aktive Programme...........: ein
Durchsuche Registrierung..............: aus
Suche nach Rootkits...................: aus
Integritätsprüfung von Systemdateien..: aus
Prüfe alle Dateien....................: Alle Dateien
Durchsuche Archive....................: ein
Rekursionstiefe einschränken..........: 20
Archiv Smart Extensions...............: ein
Makrovirenheuristik...................: ein
Dateiheuristik........................: Vollständig
Beginn des Suchlaufs: Dienstag, 10. September 2013 16:50
Der Suchlauf über gestartete Prozesse wird begonnen:
Durchsuche Prozess 'svchost.exe' - '53' Modul(e) wurden durchsucht
Durchsuche Prozess 'nvvsvc.exe' - '36' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '37' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '78' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '97' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '61' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '156' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '74' Modul(e) wurden durchsucht
Durchsuche Prozess 'nvxdsync.exe' - '58' Modul(e) wurden durchsucht
Durchsuche Prozess 'nvvsvc.exe' - '68' Modul(e) wurden durchsucht
Durchsuche Prozess 'spoolsv.exe' - '94' Modul(e) wurden durchsucht
Durchsuche Prozess 'sched.exe' - '44' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '64' Modul(e) wurden durchsucht
Durchsuche Prozess 'armsvc.exe' - '29' Modul(e) wurden durchsucht
Durchsuche Prozess 'avguard.exe' - '108' Modul(e) wurden durchsucht
Durchsuche Prozess 'AppleMobileDeviceService.exe' - '73' Modul(e) wurden durchsucht
Durchsuche Prozess 'mDNSResponder.exe' - '36' Modul(e) wurden durchsucht
Durchsuche Prozess 'mbamscheduler.exe' - '38' Modul(e) wurden durchsucht
Durchsuche Prozess 'mbamservice.exe' - '47' Modul(e) wurden durchsucht
Durchsuche Prozess 'nvstreamsvc.exe' - '58' Modul(e) wurden durchsucht
Durchsuche Prozess 'daemonu.exe' - '79' Modul(e) wurden durchsucht
Durchsuche Prozess 'PnkBstrA.exe' - '33' Modul(e) wurden durchsucht
Durchsuche Prozess 'RichVideo.exe' - '29' Modul(e) wurden durchsucht
Durchsuche Prozess 'PSIA.exe' - '86' Modul(e) wurden durchsucht
Durchsuche Prozess 'sftvsa.exe' - '33' Modul(e) wurden durchsucht
Durchsuche Prozess 'sftlist.exe' - '76' Modul(e) wurden durchsucht
Durchsuche Prozess 'CVHSVC.EXE' - '91' Modul(e) wurden durchsucht
Durchsuche Prozess 'mbamgui.exe' - '47' Modul(e) wurden durchsucht
Durchsuche Prozess 'Dwm.exe' - '40' Modul(e) wurden durchsucht
Durchsuche Prozess 'Explorer.EXE' - '179' Modul(e) wurden durchsucht
Durchsuche Prozess 'RAVCpl64.exe' - '54' Modul(e) wurden durchsucht
Durchsuche Prozess 'ETDCtrl.exe' - '60' Modul(e) wurden durchsucht
Durchsuche Prozess 'NvTmru.exe' - '56' Modul(e) wurden durchsucht
Durchsuche Prozess 'ScanToPCActivationApp.exe' - '61' Modul(e) wurden durchsucht
Durchsuche Prozess 'Skype.exe' - '137' Modul(e) wurden durchsucht
Durchsuche Prozess 'hpwuschd2.exe' - '33' Modul(e) wurden durchsucht
Durchsuche Prozess 'psi_tray.exe' - '44' Modul(e) wurden durchsucht
Durchsuche Prozess 'avgnt.exe' - '93' Modul(e) wurden durchsucht
Durchsuche Prozess 'iTunesHelper.exe' - '81' Modul(e) wurden durchsucht
Durchsuche Prozess 'nvstreamsvc.exe' - '66' Modul(e) wurden durchsucht
Durchsuche Prozess 'conhost.exe' - '21' Modul(e) wurden durchsucht
Durchsuche Prozess 'nvtray.exe' - '61' Modul(e) wurden durchsucht
Durchsuche Prozess 'avshadow.exe' - '20' Modul(e) wurden durchsucht
Durchsuche Prozess 'DllHost.exe' - '46' Modul(e) wurden durchsucht
Durchsuche Prozess 'SearchIndexer.exe' - '50' Modul(e) wurden durchsucht
Durchsuche Prozess 'iPodService.exe' - '34' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '38' Modul(e) wurden durchsucht
Durchsuche Prozess 'ETDCtrlHelper.exe' - '35' Modul(e) wurden durchsucht
Durchsuche Prozess 'HPNetworkCommunicator.exe' - '52' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '49' Modul(e) wurden durchsucht
Durchsuche Prozess 'firefox.exe' - '118' Modul(e) wurden durchsucht
Durchsuche Prozess 'LMS.exe' - '34' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '64' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '62' Modul(e) wurden durchsucht
Durchsuche Prozess 'WLIDSVC.EXE' - '77' Modul(e) wurden durchsucht
Durchsuche Prozess 'WLIDSvcM.exe' - '18' Modul(e) wurden durchsucht
Durchsuche Prozess 'wmpnetwk.exe' - '123' Modul(e) wurden durchsucht
Durchsuche Prozess 'UNS.exe' - '46' Modul(e) wurden durchsucht
Durchsuche Prozess 'plugin-container.exe' - '83' Modul(e) wurden durchsucht
Durchsuche Prozess 'FlashPlayerPlugin_11_8_800_94.exe' - '61' Modul(e) wurden durchsucht
Durchsuche Prozess 'FlashPlayerPlugin_11_8_800_94.exe' - '73' Modul(e) wurden durchsucht
Durchsuche Prozess 'wmiprvse.exe' - '34' Modul(e) wurden durchsucht
Durchsuche Prozess 'avscan.exe' - '111' Modul(e) wurden durchsucht
Durchsuche Prozess 'smss.exe' - '2' Modul(e) wurden durchsucht
Durchsuche Prozess 'csrss.exe' - '16' Modul(e) wurden durchsucht
Durchsuche Prozess 'wininit.exe' - '27' Modul(e) wurden durchsucht
Durchsuche Prozess 'csrss.exe' - '18' Modul(e) wurden durchsucht
Durchsuche Prozess 'services.exe' - '34' Modul(e) wurden durchsucht
Durchsuche Prozess 'lsass.exe' - '66' Modul(e) wurden durchsucht
Durchsuche Prozess 'lsm.exe' - '16' Modul(e) wurden durchsucht
Durchsuche Prozess 'winlogon.exe' - '32' Modul(e) wurden durchsucht
Der Suchlauf über die ausgewählten Dateien wird begonnen:
Beginne mit der Suche in 'C:\Windows\SysWOW64\FLASHPLAYERUPDATESERVICE.EXE'
Der zu durchsuchende Pfad C:\Windows\SysWOW64\FLASHPLAYERUPDATESERVICE.EXE konnte nicht geöffnet werden!
Systemfehler [2]: Das System kann die angegebene Datei nicht finden.
Ende des Suchlaufs: Dienstag, 10. September 2013 16:50
Benötigte Zeit: 00:05 Minute(n)
Der Suchlauf wurde vollständig durchgeführt.
0 Verzeichnisse wurden überprüft
833 Dateien wurden geprüft
0 Viren bzw. unerwünschte Programme wurden gefunden
0 Dateien wurden als verdächtig eingestuft
0 Dateien wurden gelöscht
0 Viren bzw. unerwünschte Programme wurden repariert
0 Dateien wurden in die Quarantäne verschoben
0 Dateien wurden umbenannt
0 Dateien konnten nicht durchsucht werden
833 Dateien ohne Befall
3 Archive wurden durchsucht
0 Warnungen
0 Hinweise
FRST Logfile:
Code:
Alles auswählen Aufklappen ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-09-2013 01
Ran by Alexande (administrator) on ALEXANDE-PC on 10-09-2013 16:55:58
Running from C:\Users\Alexande\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
() C:\windows\SysWOW64\PnkBstrA.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\PSIA.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Photosmart 6510 series\Bin\ScanToPCActivationApp.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Photosmart 6510 series\Bin\HPNetworkCommunicator.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Adobe Systems, Inc.) C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
(Adobe Systems, Inc.) C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
(Avira Operations GmbH & Co. KG) C:\program files (x86)\avira\antivir desktop\avcenter.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11895400 2011-06-25] (Realtek Semiconductor)
HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [2588968 2010-11-13] (ELAN Microelectronics Corp.)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-07-27] (NVIDIA Corporation)
HKLM\...\Policies\Explorer: [NoActiveDesktop] 1
HKLM\...\Policies\Explorer: [NoActiveDesktopChanges] 1
HKCU\...\Run: [Steam] - C:\Program Files (x86)\Steam\Steam.exe [1635752 2013-05-04] (Valve Corporation)
HKCU\...\Run: [HP Photosmart 6510 series (NET)] - C:\Program Files\HP\HP Photosmart 6510 series\Bin\ScanToPCActivationApp.exe [2672488 2011-05-25] (Hewlett-Packard Co.)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.)
HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-03-24] (Hewlett-Packard)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-04] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-08-16] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
AppInit_DLLs: C:\windows\system32\nvinitx.dll, C:\PROGRA~1\NVIDIA~1\NVSTRE~1\rxinput.dll [653600 2013-07-27] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\PROGRA~2\NVIDIA~1\NVSTRE~1\rxinput.dll, C:\windows\SysWOW64\nvinit.dll [214448 2013-06-21] (NVIDIA Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung.msn.com
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Samsung BHO Class - {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Alexande\AppData\Roaming\Mozilla\Firefox\Profiles\9x18qiq4.default
FF SelectedSearchEngine: Google
FF Homepage: www.google.de
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Ask Toolbar - C:\Users\Alexande\AppData\Roaming\Mozilla\Firefox\Profiles\9x18qiq4.default\Extensions\toolbar_ATU4@apn.ask.com
FF Extension: toolbar_ATU4 - C:\Users\Alexande\AppData\Roaming\Mozilla\Firefox\Profiles\9x18qiq4.default\Extensions\toolbar_ATU4@apn.ask.com.xpi
FF Extension: No Name - C:\Users\Alexande\AppData\Roaming\Mozilla\Firefox\Profiles\9x18qiq4.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF HKLM-x32\...\Firefox\Extensions: [quickprint@hp.com] C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension
FF Extension: SmartPrintButton - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension
Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR HKLM-x32\...\Chrome\Extension: [mjdepfkicdcciagbigfcmdhknnoaaegf] - C:\Program Files (x86)\Deskperience\Word Capture\wcxChrome.crx
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-09-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-04] (Avira Operations GmbH & Co. KG)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14984480 2013-07-27] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-07-03] ()
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2009-12-01] ()
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia)
S2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [660184 2013-07-03] (Secunia)
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-09-04] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132088 2013-09-04] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-04-08] (Avira Operations GmbH & Co. KG)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39712 2013-05-14] (NVIDIA Corporation)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-07-03] (Secunia)
S3 rtport; C:\windows\SysWOW64\drivers\rtport.sys [15144 2012-01-11] (Windows (R) 2003 DDK 3790 provider)
S3 rtport; C:\windows\SysWOW64\drivers\rtport.sys [15144 2012-01-11] (Windows (R) 2003 DDK 3790 provider)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-10 16:52 - 2013-09-10 16:53 - 01949196 _____ (Farbar) C:\Users\Alexande\Downloads\FRST64.exe
2013-09-09 20:26 - 2013-09-09 20:26 - 00000000 ____D C:\Program Files (x86)\ESET
2013-09-09 20:25 - 2013-09-09 20:26 - 02347384 _____ (ESET) C:\Users\Alexande\Downloads\esetsmartinstaller_enu.exe
2013-09-09 20:21 - 2013-09-09 20:21 - 00000000 ____D C:\windows\ERUNT
2013-09-09 18:57 - 2013-09-09 18:57 - 00000000 ____D C:\Users\Alexande\AppData\Local\Secunia PSI
2013-09-09 18:55 - 2013-09-09 18:55 - 03272136 _____ (Secunia) C:\Users\Alexande\Downloads\PSISetup711.exe
2013-09-09 18:55 - 2013-09-09 18:55 - 00000000 ____D C:\Program Files (x86)\Secunia
2013-09-09 17:58 - 2013-09-09 17:58 - 00002019 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk
2013-09-09 17:57 - 2013-09-09 17:57 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-09-09 17:12 - 2013-09-09 17:12 - 00000000 ____D C:\Users\Alexande\AppData\Local\{DD5388F5-3F85-4C17-96C0-FEC492C95AFD}
2013-09-08 01:04 - 2013-09-10 15:42 - 00002652 _____ C:\windows\PFRO.log
2013-09-08 00:51 - 2013-09-08 00:51 - 00001109 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2013-09-08 00:51 - 2013-09-08 00:51 - 00000000 ____D C:\Users\Alexande\AppData\Roaming\Malwarebytes
2013-09-08 00:51 - 2013-09-08 00:51 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-08 00:51 - 2013-09-08 00:51 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-09-08 00:51 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2013-09-08 00:48 - 2013-09-08 00:50 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Alexande\Downloads\mbam-setup-1.75.0.1300.exe
2013-09-07 20:50 - 2013-09-07 20:50 - 04054000 _____ (LionSea Software ) C:\Users\Alexande\Downloads\setup.exe
2013-09-07 18:34 - 2013-09-10 15:43 - 00000840 _____ C:\windows\setupact.log
2013-09-07 18:34 - 2013-09-07 18:34 - 00000000 _____ C:\windows\setuperr.log
2013-09-07 15:34 - 2013-09-07 15:34 - 00377856 _____ C:\Users\Alexande\Downloads\gmer_2.1.19163.exe
2013-09-07 14:35 - 2013-09-07 14:36 - 00042038 _____ C:\Users\Alexande\Downloads\Addition.txt
2013-09-07 13:53 - 2013-09-07 18:33 - 00000000 ____D C:\AdwCleaner
2013-09-05 12:56 - 2013-09-05 12:56 - 00001783 _____ C:\Users\Public\Desktop\iTunes.lnk
2013-09-05 12:55 - 2013-09-05 12:56 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-09-05 12:55 - 2013-09-05 12:56 - 00000000 ____D C:\Program Files\iTunes
2013-09-05 12:55 - 2013-09-05 12:56 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-09-05 12:55 - 2013-09-05 12:55 - 00000000 ____D C:\Program Files\iPod
2013-08-29 21:03 - 2013-08-29 21:03 - 00000000 ____D C:\Users\Alexande\Documents\CyberLink
2013-08-15 00:57 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-08-15 00:57 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-08-15 00:57 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2013-08-15 00:57 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-08-15 00:57 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-08-15 00:57 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-08-15 00:57 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-08-15 00:57 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2013-08-15 00:57 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2013-08-15 00:57 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2013-08-15 00:57 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2013-08-15 00:57 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2013-08-15 00:57 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-08-15 00:57 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2013-08-15 00:57 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-08-15 00:57 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2013-08-15 00:57 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2013-08-15 00:57 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2013-08-15 00:57 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2013-08-15 00:57 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2013-08-15 00:57 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2013-08-15 00:57 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2013-08-15 00:57 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2013-08-15 00:57 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll
2013-08-15 00:57 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2013-08-15 00:57 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2013-08-15 00:57 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2013-08-15 00:57 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2013-08-15 00:57 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2013-08-15 00:57 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2013-08-15 00:57 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\windows\SysWOW64\RegisterIEPKEYs.exe
2013-08-15 00:52 - 2013-08-15 00:54 - 00000000 ____D C:\windows\system32\MRT
2013-08-15 00:48 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
2013-08-15 00:48 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2013-08-15 00:48 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2013-08-15 00:48 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll
2013-08-15 00:48 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll
2013-08-15 00:48 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
2013-08-15 00:48 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsvc.dll
2013-08-15 00:48 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptnet.dll
2013-08-15 00:47 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\windows\system32\WMVDECOD.DLL
2013-08-15 00:47 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMVDECOD.DLL
2013-08-15 00:47 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2013-08-15 00:47 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
2013-08-15 00:47 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2013-08-15 00:47 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2013-08-15 00:47 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2013-08-15 00:47 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2013-08-15 00:47 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2013-08-15 00:47 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2013-08-15 00:47 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2013-08-15 00:47 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2013-08-15 00:47 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2013-08-15 00:47 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2013-08-15 00:47 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2013-08-15 00:47 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2013-08-15 00:47 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2013-08-15 00:47 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2013-08-15 00:47 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys
==================== One Month Modified Files and Folders =======
2013-09-10 16:53 - 2013-09-10 16:53 - 00000000 ____D C:\FRST
2013-09-10 16:53 - 2013-09-10 16:52 - 01949196 _____ (Farbar) C:\Users\Alexande\Downloads\FRST64.exe
2013-09-10 15:52 - 2009-07-14 06:45 - 00020992 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-10 15:52 - 2009-07-14 06:45 - 00020992 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-10 15:46 - 2011-09-06 18:21 - 01434633 _____ C:\windows\WindowsUpdate.log
2013-09-10 15:44 - 2012-04-30 17:37 - 00000000 ____D C:\Program Files (x86)\Steam
2013-09-10 15:43 - 2013-09-07 18:34 - 00000840 _____ C:\windows\setupact.log
2013-09-10 15:42 - 2013-09-08 01:04 - 00002652 _____ C:\windows\PFRO.log
2013-09-09 20:26 - 2013-09-09 20:26 - 00000000 ____D C:\Program Files (x86)\ESET
2013-09-09 20:26 - 2013-09-09 20:25 - 02347384 _____ (ESET) C:\Users\Alexande\Downloads\esetsmartinstaller_enu.exe
2013-09-09 20:21 - 2013-09-09 20:21 - 00000000 ____D C:\windows\ERUNT
2013-09-09 18:58 - 2012-04-30 22:26 - 00692104 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2013-09-09 18:58 - 2012-04-30 22:26 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-09-09 18:58 - 2012-04-30 22:26 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2013-09-09 18:57 - 2013-09-09 18:57 - 00000000 ____D C:\Users\Alexande\AppData\Local\Secunia PSI
2013-09-09 18:55 - 2013-09-09 18:55 - 03272136 _____ (Secunia) C:\Users\Alexande\Downloads\PSISetup711.exe
2013-09-09 18:55 - 2013-09-09 18:55 - 00000000 ____D C:\Program Files (x86)\Secunia
2013-09-09 18:23 - 2012-04-30 14:47 - 00000000 ____D C:\ProgramData\Adobe
2013-09-09 18:22 - 2012-04-30 18:49 - 00000000 ____D C:\Users\Alexande\AppData\Roaming\Adobe
2013-09-09 18:19 - 2013-02-04 23:38 - 00000000 ____D C:\Users\Alexande\AppData\Roaming\Skype
2013-09-09 18:06 - 2012-04-30 14:47 - 00000000 ____D C:\Users\Alexande\AppData\Local\Adobe
2013-09-09 17:58 - 2013-09-09 17:58 - 00002019 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk
2013-09-09 17:57 - 2013-09-09 17:57 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-09-09 17:54 - 2009-07-14 05:20 - 00000000 ____D C:\windows\system32\NDF
2013-09-09 17:12 - 2013-09-09 17:12 - 00000000 ____D C:\Users\Alexande\AppData\Local\{DD5388F5-3F85-4C17-96C0-FEC492C95AFD}
2013-09-08 01:16 - 2011-09-06 07:08 - 00697542 _____ C:\windows\system32\perfh007.dat
2013-09-08 01:16 - 2011-09-06 07:08 - 00148548 _____ C:\windows\system32\perfc007.dat
2013-09-08 01:16 - 2009-07-14 07:13 - 01614924 _____ C:\windows\system32\PerfStringBackup.INI
2013-09-08 00:51 - 2013-09-08 00:51 - 00001109 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2013-09-08 00:51 - 2013-09-08 00:51 - 00000000 ____D C:\Users\Alexande\AppData\Roaming\Malwarebytes
2013-09-08 00:51 - 2013-09-08 00:51 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-08 00:51 - 2013-09-08 00:51 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-09-08 00:50 - 2013-09-08 00:48 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Alexande\Downloads\mbam-setup-1.75.0.1300.exe
2013-09-07 20:50 - 2013-09-07 20:50 - 04054000 _____ (LionSea Software ) C:\Users\Alexande\Downloads\setup.exe
2013-09-07 18:34 - 2013-09-07 18:34 - 00000000 _____ C:\windows\setuperr.log
2013-09-07 18:33 - 2013-09-07 13:53 - 00000000 ____D C:\AdwCleaner
2013-09-07 15:34 - 2013-09-07 15:34 - 00377856 _____ C:\Users\Alexande\Downloads\gmer_2.1.19163.exe
2013-09-07 15:19 - 2013-08-02 00:29 - 00000000 ____D C:\windows\Minidump
2013-09-07 15:19 - 2012-05-12 07:42 - 00000000 ____D C:\Users\Alexande\AppData\Local\CrashDumps
2013-09-07 15:19 - 2011-02-11 21:57 - 00000000 ____D C:\windows\Panther
2013-09-07 15:00 - 2012-05-31 16:05 - 00000000 ____D C:\Program Files (x86)\DsNET Corp
2013-09-07 14:36 - 2013-09-07 14:35 - 00042038 _____ C:\Users\Alexande\Downloads\Addition.txt
2013-09-07 10:04 - 2012-09-03 15:36 - 00000262 _____ C:\windows\Tasks\HP Photo Creations Messager.job
2013-09-05 12:59 - 2009-07-14 07:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-09-05 12:56 - 2013-09-05 12:56 - 00001783 _____ C:\Users\Public\Desktop\iTunes.lnk
2013-09-05 12:56 - 2013-09-05 12:55 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-09-05 12:56 - 2013-09-05 12:55 - 00000000 ____D C:\Program Files\iTunes
2013-09-05 12:56 - 2013-09-05 12:55 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-09-05 12:55 - 2013-09-05 12:55 - 00000000 ____D C:\Program Files\iPod
2013-09-04 11:01 - 2013-05-07 20:33 - 00081112 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avnetflt.sys
2013-09-04 11:01 - 2013-04-08 20:16 - 00132088 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avipbb.sys
2013-09-04 11:01 - 2013-04-08 20:16 - 00105344 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avgntflt.sys
2013-08-30 08:54 - 2013-07-03 14:58 - 00281392 _____ C:\windows\SysWOW64\PnkBstrB.xtr
2013-08-30 08:54 - 2013-06-25 14:06 - 00281392 _____ C:\windows\SysWOW64\PnkBstrB.exe
2013-08-29 21:03 - 2013-08-29 21:03 - 00000000 ____D C:\Users\Alexande\Documents\CyberLink
2013-08-27 18:13 - 2009-07-14 07:08 - 00032596 _____ C:\windows\Tasks\SCHEDLGU.TXT
2013-08-27 18:12 - 2013-01-10 15:37 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-08-21 16:00 - 2012-04-30 22:03 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-15 13:03 - 2009-07-14 05:20 - 00000000 ____D C:\windows\rescache
2013-08-15 00:54 - 2013-08-15 00:52 - 00000000 ____D C:\windows\system32\MRT
2013-08-15 00:52 - 2012-05-06 01:04 - 78161360 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2013-08-14 11:33 - 2013-07-24 22:28 - 00000000 ____D C:\Users\Alexande\Documents\Documents ThenachProgram
Files to move or delete:
====================
C:\Users\Alexande\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-09-02 13:33
==================== End Of Log ============================
--- --- ---
Code:
Alles auswählen Aufklappen ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-09-2013 01
Ran by Alexande at 2013-09-10 16:56:47
Running from C:\Users\Alexande\Downloads
Boot Mode: Normal
==========================================================
==================== Installed Programs =======================
„Windows Live Essentials“ (x32 Version: 15.4.3502.0922)
„Windows Live Mail“ (x32 Version: 15.4.3502.0922)
„Windows Live Messenger“ (x32 Version: 15.4.3502.0922)
„Windows Live“ fotogalerija (x32 Version: 15.4.3502.0922)
Adobe Flash Player 11 ActiveX (x32 Version: 11.8.800.94)
Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.94)
Adobe Reader XI (11.0.03) - Deutsch (x32 Version: 11.0.03)
Agatha Christie - Death on the Nile (x32 Version: 2.2.0.82)
Apple Application Support (x32 Version: 2.3.4)
Apple Mobile Device Support (Version: 6.1.0.13)
Apple Software Update (x32 Version: 2.1.3.127)
Assassin's Creed(R) III v1.06 (x32 Version: 1.06)
Avira Free Antivirus (x32 Version: 13.0.0.4052)
BatteryLifeExtender (x32 Version: 1.0.11)
Bejeweled 2 Deluxe (x32 Version: 2.2.0.95)
Bonjour (Version: 3.0.0.10)
Build-a-lot (x32 Version: 2.2.0.82)
ChargeableUSB (x32 Version: 1.0.0.0)
Chuzzle Deluxe (x32 Version: 2.2.0.82)
CyberLink Media Suite (x32 Version: 8.0.2227)
CyberLink Media+ Player10 (x32 Version: 10.0.1110.00)
CyberLink MediaShow (x32 Version: 5.0.1130a)
CyberLink Power2Go (x32 Version: 6.1.3802)
CyberLink PowerDirector (x32 Version: 8.0.3306)
CyberLink YouCam (x32 Version: 3.1.3509)
D3DX10 (x32 Version: 15.4.2368.0902)
Diner Dash 2 Restaurant Rescue (x32 Version: 2.2.0.82)
dm-Fotowelt (x32 Version: 5.0.1)
Easy Content Share (x32 Version: 1.0)
Easy Display Manager (x32 Version: 3.2)
Easy Migration (x32 Version: 1.0)
Easy Network Manager (x32 Version: 4.4.7)
Easy SpeedUp Manager (x32 Version: 2.1.1.1)
EasyBatteryManager (x32 Version: 4.0.0.4)
EasyFileShare (x32 Version: 1.0.11)
ESET Online Scanner v3 (x32)
Farm Frenzy (x32 Version: 2.2.0.82)
Fast Start (x32 Version: 2.2.0.0)
FIFA 11 (x32 Version: 1.0.0.0)
Fotogalerija Windows Live (x32 Version: 15.4.3502.0922)
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922)
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922)
Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922)
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922)
Galerie foto Windows Live (x32 Version: 15.4.3502.0922)
Grand Theft Auto: Episodes from Liberty City (x32 Version: 1.0.0003.135)
Grand Theft Auto: Episodes From Liberty City (x32 Version: 1.1.0.0)
HP Photo Creations (x32 Version: 1.0.0.5192)
HP Photosmart 6510 series - Grundlegende Software für das Gerät (Version: 24.0.342.0)
HP Photosmart 6510 series Hilfe (x32 Version: 140.0.2.2)
HP Update (x32 Version: 5.003.000.004)
Insaniquarium Deluxe (x32 Version: 2.2.0.82)
Intel PROSet Wireless (x32)
Intel(R) Control Center (x32 Version: 1.2.1.1007)
Intel(R) Management Engine Components (x32 Version: 7.0.0.1144)
Intel(R) Processor Graphics (x32 Version: 8.15.10.2266)
Intel(R) PROSet/Wireless WiFi Software (Version: 14.01.1000)
Intel(R) Rapid Storage Technology (x32 Version: 10.0.0.1046)
iTunes (Version: 11.0.5.5)
J.L.A. Thenach Search & Research (x32 Version: 4.0)
John Deere Drive Green (x32 Version: 2.2.0.82)
Junk Mail filter update (x32 Version: 15.4.3502.0922)
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300)
Mesh Runtime (x32 Version: 15.4.5722.2)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Games for Windows - LIVE (x32 Version: 3.1.186.0)
Microsoft Games for Windows - LIVE Redistributable (x32 Version: 3.5.92.0)
Microsoft Office 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000)
Microsoft Office Klick-und-Los 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Starter 2010 - Deutsch (x32 Version: 14.0.4763.1000)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Movie Color Enhancer (x32 Version: 1.0)
Mozilla Firefox 23.0.1 (x86 de) (x32 Version: 23.0.1)
Mozilla Maintenance Service (x32 Version: 23.0.1)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT_amd64 (x32 Version: 15.4.2862.0708)
NVIDIA GeForce Experience 1.6 (Version: 1.6)
NVIDIA Grafiktreiber 320.49 (Version: 320.49)
NVIDIA Install Application (Version: 2.1002.131.854)
NVIDIA Optimus 7.2.17 (Version: 7.2.17)
NVIDIA PhysX (x32 Version: 9.13.0604)
NVIDIA PhysX-Systemsoftware 9.13.0604 (Version: 9.13.0604)
NVIDIA Systemsteuerung 320.49 (Version: 320.49)
NVIDIA Update 7.2.17 (Version: 7.2.17)
NVIDIA Update Components (Version: 7.2.17)
NVIDIA Virtual Audio 1.2.1 (Version: 1.2.1)
Peggle (x32 Version: 2.2.0.82)
Penguins! (x32 Version: 2.2.0.82)
PhoneShare (x32 Version: 9.1.4)
Plants vs. Zombies (x32 Version: 2.2.0.82)
Poczta usługi Windows Live (x32 Version: 15.4.3502.0922)
Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922)
Polar Golfer (x32 Version: 2.2.0.82)
Pošta Windows Live (x32 Version: 15.4.3502.0922)
PunkBuster Services (x32 Version: 0.991)
Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922)
Realtek Ethernet Controller Driver (x32 Version: 7.44.421.2011)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6400)
Samsung AnyWeb Print (x32 Version: 2.0.67.1)
Samsung Printer Live Update (x32)
Samsung Recovery Solution 5 (x32 Version: 5.0.0.9)
Samsung Support Center (x32 Version: 1.1.24)
Samsung Universal Print Driver (x32 Version: 2.02.05.00:27)
Samsung Universal Scan Driver (x32 Version: 1.2.5.0)
Samsung Update Plus (x32 Version: 3.0.0.17)
Secunia PSI (3.0.0.7011) (x32 Version: 3.0.0.7011)
SHIELD Streaming (Version: 1.05.19)
Skype™ 6.6 (x32 Version: 6.6.106)
Sniper: Ghost Warrior (x32)
Steam (x32 Version: 1.0.0.0)
Überwachungstool für die Intel® Turbo-Boost-Technik 2.0 (Version: 2.0.82.0)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1)
Uplay (x32 Version: 3.0)
User Guide (x32 Version: 1.5)
Ware PS/2-X64 8.0.7.2_WHQL (Version: 8.0.7.2)
WildTangent Games (x32 Version: 1.0.1.5)
WildTangent ORB Game Console (x32)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3502.0922)
Windows Live fotoattēlu galerija (x32 Version: 15.4.3502.0922)
Windows Live Fotogaléria (x32 Version: 15.4.3502.0922)
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922)
Windows Live Foto-galerija (x32 Version: 15.4.3502.0922)
Windows Live Fotogalleri (x32 Version: 15.4.3502.0922)
Windows Live Fotoğraf Galerisi (x32 Version: 15.4.3502.0922)
Windows Live Fotótár (x32 Version: 15.4.3502.0922)
Windows Live Galeria de Fotos (x32 Version: 15.4.3502.0922)
Windows Live Galerija fotografija (x32 Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4225.0)
Windows Live Installer (x32 Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3508.1109)
Windows Live Mail (x32 Version: 15.4.3502.0922)
Windows Live Mesh (x32 Version: 15.4.3502.0922)
Windows Live Messenger (x32 Version: 15.4.3502.0922)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (x32 Version: 15.4.3502.0922)
Windows Live Photo Common (x32 Version: 15.4.3502.0922)
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922)
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109)
Windows Live Pošta (x32 Version: 15.4.3502.0922)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (x32 Version: 15.4.3502.0922)
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922)
Windows Live Temel Parçalar (x32 Version: 15.4.3502.0922)
Windows Live UX Platform (x32 Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109)
Windows Live Writer (x32 Version: 15.4.3502.0922)
Windows Live Writer Resources (x32 Version: 15.4.3502.0922)
Windows Live 메일 (x32 Version: 15.4.3502.0922)
Windows Live 사진 갤러리 (x32 Version: 15.4.3502.0922)
Windows Live 필수 패키지 (x32 Version: 15.4.3502.0922)
Windows Live 影像中心 (x32 Version: 15.4.3502.0922)
Windows Live 照片库 (x32 Version: 15.4.3502.0922)
Windows Live 程式集 (x32 Version: 15.4.3502.0922)
Windows Live 程式集 (x32 Version: 15.4.3508.1109)
Windows Live 软件包 (x32 Version: 15.4.3502.0922)
Windows Liven asennustyökalu (x32 Version: 15.4.3502.0922)
Windows Liven sähköposti (x32 Version: 15.4.3502.0922)
Windows Liven valokuvavalikoima (x32 Version: 15.4.3502.0922)
WordCaptureX Pro (x32 Version: 4.0.0)
Zuma Deluxe (x32 Version: 2.2.0.95)
Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922)
Основные компоненты Windows Live (x32 Version: 15.4.3502.0922)
Почта Windows Live (x32 Version: 15.4.3502.0922)
Фотоальбом Windows Live (x32 Version: 15.4.3502.0922)
Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922)
גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922)
بريد Windows Live (x32 Version: 15.4.3502.0922)
معرض صور Windows Live (x32 Version: 15.4.3502.0922)
==================== Restore Points =========================
09-09-2013 18:22:23 Ende der Bereinigung
10-09-2013 13:17:42 Windows Update
==================== Hosts content: ==========================
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {01D4A7F9-5150-4EC5-B7F8-30C2AADE48CB} - System32\Tasks\EasyDisplayMgr => C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe [2010-12-23] (Samsung Electronics Co., Ltd.)
Task: {044A6734-E90E-4F8F-B357-B2DC8AB3B5EC} - System32\Tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime => Sc.exe start w32time task_started
Task: {29016D0D-D292-412E-8711-87920D3702FE} - System32\Tasks\WifiManager => C:\Program Files (x86)\Samsung\Easy Display Manager\WifiManager.exe [2011-01-04] (Samsung Electronics Co., Ltd.)
Task: {32E14DE7-8567-4443-AB9C-1346CC2B385A} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe
Task: {3D6580A8-4A79-42B7-B770-D1DA83237176} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {4E07C5D4-549B-4670-B7FF-EAB1BAAC2353} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\windows\System32\lpksetup.exe [2010-11-21] (Microsoft Corporation)
Task: {5F10A772-E125-4719-9EAA-164E50E2AB51} - System32\Tasks\Open Hardware Monitor\Startup => C:\Users\Alexande\Downloads\openhardwaremonitor-v0.5.1-beta\OpenHardwareMonitor\OpenHardwareMonitor.exe
Task: {610322BD-41E1-4C1D-BBE9-7543E6378176} - System32\Tasks\SamsungSupportCenter => C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe [2011-02-07] (SAMSUNG Electronics)
Task: {61D95673-03BD-4B23-B070-9C11E64A3EE7} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2010-11-10] (CyberLink)
Task: {639DB434-484C-4701-A27B-07E98282F790} - System32\Tasks\AdobeFlashPlayerUpdate 2 => C:\windows\SysWOW64\FlashPlayerUpdateService.exe
Task: {723B9801-4B27-4C9F-BF42-900AE7A12E7A} - System32\Tasks\HP Photo Creations Messager => C:\ProgramData\HP Photo Creations\MessageCheck.exe [2011-02-15] ()
Task: {962B33F1-C72C-4770-81DD-3BC2E72A6D40} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {A363F639-9E4A-496B-8BC4-6916AA3AF700} - System32\Tasks\SmartRestarter => C:\Program Files\Samsung\SamsungFastStart\SmartRestarter.exe [2010-08-05] (Samsung Electronics Co., Ltd.)
Task: {A6DA99AD-4A10-4098-BFB0-E63A57F19F69} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-09] (Adobe Systems Incorporated)
Task: {AA0CAF3C-F73A-4818-89C6-F7BA872077B5} - System32\Tasks\hpUrlLauncher.exe_{DB246A5E-01D2-4FF0-A11E-DD8AAF71A97E} => C:\Program Files\HP\HP Photosmart 6510 series\Bin\utils\hpUrlLauncher.exe [2011-05-25] (Hewlett-Packard Co.)
Task: {BC4487A0-30DD-4188-AFA2-CBD494A44A74} - \Browser Manager No Task File
Task: {C304D9BA-DD1E-4728-AF0A-786A137D404A} - System32\Tasks\BatteryLifeExtender => C:\Program Files (x86)\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe [2010-12-18] (Samsung Electronics. Co. Ltd.)
Task: {D74DB977-BD01-4FEE-9E52-94C259B4853E} - System32\Tasks\AdobeFlashPlayerUpdate => C:\windows\SysWOW64\FlashPlayerUpdateService.exe
Task: {E38490B7-F5BE-4067-9D93-352DA5349896} - System32\Tasks\EasyPartitionManager => C:\Windows\MSetup\BA46-12225A02\EPM.exe
Task: {E64E75B9-3AAF-455E-9684-D3FB4A9791B0} - System32\Tasks\EasyBatteryManager => C:\Program Files (x86)\Samsung\EasyBatteryManager\EasyBatteryMgr4.exe [2010-07-20] (SAMSUNG Electronics co., LTD.)
Task: {E7110FB6-91D1-4C30-99AC-E10225F61CAD} - System32\Tasks\MovieColorEnhancer => C:\Program Files (x86)\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe [2010-11-29] (Samsung Electronics Co., Ltd.)
Task: {E87DA5B9-4D35-4893-BCE2-C8014991C057} - System32\Tasks\SUPBackground => C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe [2011-01-12] (Samsung Electronics)
Task: {EC0654ED-D944-4CA6-B922-16CA8F505861} - System32\Tasks\EasySpeedUpManager => C:\Program Files (x86)\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe [2011-01-11] (Samsung Electronics Co., Ltd.)
Task: {F4FC3FAA-A827-47D0-ADA1-920DF12C08B8} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task
Task: {FEE2F150-F394-4963-83B3-DAD1AA3FB459} - System32\Tasks\advSRS5 => C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe [2010-11-17] (SEC)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\HP Photo Creations Messager.job => C:\ProgramData\HP Photo Creations\MessageCheck.exe
==================== Loaded Modules (whitelisted) =============
2013-08-03 11:33 - 2013-06-21 14:06 - 00266448 _____ (NVIDIA Corporation) C:\windows\system32\nvinitx.dll
2013-08-03 11:33 - 2013-06-21 14:06 - 01059560 _____ (NVIDIA Corporation) C:\windows\system32\nvumdshimx.dll
2011-09-06 02:28 - 2010-11-04 04:30 - 00149608 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RtkCfg64.dll
2011-09-06 02:28 - 2011-06-24 00:37 - 03115112 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RtkAPO64.dll
2011-05-25 17:35 - 2011-05-25 17:35 - 03098472 _____ (TODO: <Company name>) C:\Program Files\HP\HP Photosmart 6510 series\Bin\ScanToPCActivationUI.dll
2013-08-03 11:33 - 2013-06-21 14:06 - 00214448 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvinit.dll
2013-06-21 09:53 - 2013-06-21 09:53 - 00088680 ____R (Skype Technologies) C:\Program Files (x86)\Skype\Updater\Updater.dll
2013-03-01 23:59 - 2013-09-04 11:00 - 00055352 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\cfglib.dll
2013-03-01 23:59 - 2013-09-04 11:00 - 00349752 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccguard.dll
2013-03-01 23:59 - 2013-09-04 11:00 - 00029240 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccgrdrc.dll
2013-03-01 23:59 - 2013-09-04 11:00 - 00229432 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccgrdw.dll
2013-03-01 23:59 - 2013-09-04 11:01 - 00218168 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\gpipc.dll
2013-03-01 23:59 - 2013-09-04 11:01 - 00419384 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccwgrd.dll
2013-03-01 23:59 - 2013-09-04 11:00 - 00807992 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccgen.dll
2013-03-01 23:59 - 2013-09-04 11:00 - 00049720 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccgenrc.dll
2013-03-01 23:59 - 2013-09-04 11:01 - 00220216 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccupdate.dll
2013-03-01 23:59 - 2013-09-04 11:01 - 00028728 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccupdrc.dll
2013-03-01 23:59 - 2013-09-04 11:00 - 00083000 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\cclic.dll
2013-03-01 23:59 - 2013-09-04 11:00 - 00009784 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\cclicrc.dll
2013-03-01 23:59 - 2013-09-04 11:00 - 00237624 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccmsg.dll
2013-03-01 23:59 - 2013-09-04 11:00 - 00010296 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccmsgrc.dll
2013-03-01 23:59 - 2013-09-04 11:00 - 00014392 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccmainrc.dll
2012-08-27 21:33 - 2012-08-27 21:33 - 00053608 _____ (Open Source Software community project) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\pthreadVC2.dll
2012-08-27 21:33 - 2012-08-27 21:33 - 00087912 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2012-08-27 21:33 - 2012-08-27 21:33 - 01242512 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2011-08-30 23:05 - 2011-08-30 23:05 - 00085864 _____ (Apple Inc.) C:\windows\system32\dnssd.dll
2012-04-30 22:03 - 2013-08-21 16:00 - 03551640 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2013-09-09 17:36 - 2013-09-09 18:07 - 16166280 _____ () C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll
2013-03-01 23:59 - 2013-09-04 11:00 - 00361528 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccprofil.dll
2013-03-01 23:59 - 2013-09-04 11:01 - 00039480 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccscanrc.dll
2013-03-01 23:59 - 2013-09-04 11:01 - 00321592 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccquamgr.dll
2013-03-01 23:59 - 2013-09-04 11:01 - 00024120 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccquarc.dll
2013-03-01 23:59 - 2013-09-04 11:01 - 00255544 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccsched.dll
2013-03-01 23:59 - 2013-09-04 11:01 - 00025656 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccscherc.dll
2013-03-01 23:59 - 2013-09-04 11:01 - 00241720 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccreport.dll
2013-03-01 23:59 - 2013-09-04 11:01 - 00015928 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccreporc.dll
2013-03-01 23:59 - 2013-09-04 11:00 - 00274488 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccev.dll
2013-03-01 23:59 - 2013-09-04 11:00 - 00017976 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccevrc.dll
2013-03-01 23:59 - 2013-09-04 11:01 - 00120888 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccwebtabs.dll
2013-03-01 23:59 - 2013-09-04 11:01 - 00010296 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccwebtabsrc.dll
2013-03-01 23:59 - 2013-09-04 11:00 - 00080440 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\cclicw.dll
2013-03-01 23:59 - 2013-09-04 11:00 - 00147512 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccevw.dll
2013-03-01 23:59 - 2013-03-01 23:54 - 00397704 _____ () C:\program files (x86)\avira\antivir desktop\sqlite3.dll
2013-03-01 23:59 - 2013-09-04 11:01 - 00043064 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\guardmsg.dll
2013-03-01 23:59 - 2013-09-04 11:00 - 00014392 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\avesvcr.dll
2013-03-01 23:59 - 2013-09-04 11:01 - 00013368 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\schedr.dll
2013-03-01 23:59 - 2013-09-04 11:00 - 00051256 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\updaterc.dll
2013-03-01 23:59 - 2013-09-04 11:00 - 00063032 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\avscanrc.dll
2013-03-01 23:59 - 2013-09-04 11:01 - 00152120 _____ (Avira Operations GmbH & Co. KG) c:\program files (x86)\avira\antivir desktop\ccrepow.dll
2010-11-21 05:24 - 2010-11-21 05:24 - 00320000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WINSPOOL.DRV
==================== Alternate Data Streams (whitelisted) ==========
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (09/10/2013 03:43:20 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/10/2013 03:43:14 PM) (Source: NvStreamSvc) (User: )
Description: NvStreamSvcUnregistering VAD endpoint [0]
Error: (09/10/2013 03:43:10 PM) (Source: NvStreamSvc) (User: )
Description: NvStreamSvcNvVAD endpoint registered successfully [0]
Error: (09/09/2013 08:26:15 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Error: (09/09/2013 08:26:11 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.
Error: (09/09/2013 06:32:13 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/09/2013 06:30:53 PM) (Source: NvStreamSvc) (User: )
Description: NvStreamSvcUnregistering VAD endpoint [0]
Error: (09/09/2013 06:30:50 PM) (Source: NvStreamSvc) (User: )
Description: NvStreamSvcNvVAD endpoint registered successfully [0]
Error: (09/09/2013 05:50:05 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/09/2013 05:49:57 PM) (Source: NvStreamSvc) (User: )
Description: NvStreamSvcUnregistering VAD endpoint [0]
System errors:
=============
Error: (09/07/2013 03:10:06 PM) (Source: DCOM) (User: )
Description: {3EB3C877-1F16-487C-9050-104DBCD66683}
Error: (09/07/2013 10:28:50 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Intel(R) Management and Security Application User Notification Service" wurde nicht richtig gestartet.
Error: (09/07/2013 10:26:48 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Update" wurde nicht richtig gestartet.
Error: (09/07/2013 10:13:58 AM) (Source: Service Control Manager) (User: )
Description: Dienst "Intel(R) Management and Security Application User Notification Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (09/07/2013 10:13:57 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Intel(R) Management and Security Application Local Management Service" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (09/07/2013 10:13:50 AM) (Source: Service Control Manager) (User: )
Description: Dienst "Tor Win32 Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (09/07/2013 10:13:39 AM) (Source: Service Control Manager) (User: )
Description: Dienst "Client Virtualization Handler" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (09/07/2013 10:13:39 AM) (Source: Service Control Manager) (User: )
Description: Dienst "Application Virtualization Client" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (09/07/2013 10:13:38 AM) (Source: Service Control Manager) (User: )
Description: Dienst "Application Virtualization Service Agent" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (09/07/2013 10:13:30 AM) (Source: Service Control Manager) (User: )
Description: Dienst "Cyberlink RichVideo Service(CRVS)" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Microsoft Office Sessions:
=========================
Error: (09/10/2013 03:43:20 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/10/2013 03:43:14 PM) (Source: NvStreamSvc)(User: )
Description: NvStreamSvcUnregistering VAD endpoint [0]
Error: (09/10/2013 03:43:10 PM) (Source: NvStreamSvc)(User: )
Description: NvStreamSvcNvVAD endpoint registered successfully [0]
Error: (09/09/2013 08:26:15 PM) (Source: SideBySide)(User: )
Description: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Alexande\Downloads\esetsmartinstaller_enu.exe
Error: (09/09/2013 08:26:11 PM) (Source: SideBySide)(User: )
Description: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Alexande\Downloads\esetsmartinstaller_enu.exe
Error: (09/09/2013 06:32:13 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/09/2013 06:30:53 PM) (Source: NvStreamSvc)(User: )
Description: NvStreamSvcUnregistering VAD endpoint [0]
Error: (09/09/2013 06:30:50 PM) (Source: NvStreamSvc)(User: )
Description: NvStreamSvcNvVAD endpoint registered successfully [0]
Error: (09/09/2013 05:50:05 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/09/2013 05:49:57 PM) (Source: NvStreamSvc)(User: )
Description: NvStreamSvcUnregistering VAD endpoint [0]
==================== Memory info ===========================
Percentage of memory in use: 36%
Total physical RAM: 6056.19 MB
Available physical RAM: 3853.91 MB
Total Pagefile: 12110.57 MB
Available Pagefile: 9659.23 MB
Total Virtual: 8192 MB
Available Virtual: 8191.78 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:325 GB) (Free:205.36 GB) NTFS
Drive d: () (Fixed) (Total:582.75 GB) (Free:580.89 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 932 GB) (Disk ID: 817D105E)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=325 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=583 GB) - (Type=OF Extended)
Partition 4: (Not Active) - (Size=24 GB) - (Type=27)
==================== End Of Log ============================